Home/Security

Security and compliance

MeetStream security keeps meeting data under your control. Everything is encrypted in transit and at rest. Write it straight to your own storage. MeetStream is ISO 27001 certified.

Certifications and compliance

ISO/IEC 27001:2022CertifiedSOC 2 Type 2Under auditGDPRCompliantHIPAANot held today
The status of each, with the certificate details in the table below.
ItemStatus, 2 September 2026
ISO/IEC 27001:2022Certified. Certificate 630036. Issued by Amtivo Group Limited (British Assessment Bureau) to MeetStream Technologies Pte Ltd. First certified 19 August 2025. Valid to 18 August 2028. You can see it on the Trust Center. No lead gate.
SOC 2 Type 2Under audit. This row changes on the day the report is issued.
GDPRCompliant. The DPA is on the Trust Center. The bot is visible and named, so the room knows. Calendar access is read-only. A deletion webhook lets you clear data per bot.
HIPAANot held. We do not sign Business Associate Agreements today. Tell us if you need one.

We keep the documents a security review asks for. We share them during vendor checks. Email info@meetstream.ai to start one.

Encryption

All data is encrypted in transit and at rest. Every artefact, on every call.

RecordingsComposed MP4Streams per personAudio and videoTranscriptsText and timingsLive mediaOver a secure WebSocket
Your meeting content is guarded from the bot in the call to the file in a bucket.
Security

Data residency and bring your own storage

Recordingsfrom the first byteStreams per personfrom the first byteTranscriptsfrom the first byteYour bucketyour region, your rules
Every artefact lands in your own bucket, in your own region, from the first byte.

With your own storage, every artefact goes straight to your own bucket. Use Amazon S3, Alibaba Cloud OSS, or any S3-compatible endpoint.

You set retention, lifecycle, Object Lock and access rules there. A write-only mode keeps reads on your own side.

  • Your recordings go straight to your own bucket
  • Your region, your retention, your access rules
  • Write-only mode: MeetStream writes, and reads stay with you
Security

Retention and deletion

ControlWhat it does
Thirty days freeThe default life of stored media
Retention per botOne setting changes that to whatever you need
Delete endpointClears any bot media on demand
Deletion webhookFires when media expires or is removed, and the bot is marked expired

The deletion webhook is your signal to clear caches. For your own rules end to end, use bring your own storage.

Access control

API keys and roles in the dashboard govern access. Your team decides who can see recordings, transcripts and account settings.

Scope and rotate keys as your needs change. Keys for transcription and voice models live there too.

LIVE PRODUCTEvery bot with platform, status and duration, governed by API keys and roles
Every bot, with its platform, status and duration. API keys and roles govern access. Meeting links masked for privacy.

Privacy and transparency

Visible and namedIn the participant listIt can say soA joining messageRead-only calendarsNothing is changed
The room can see the bot, and a joining message can state the recording notice.

Calendar access is read-only. A user's calendar stays exactly as it is.

The data processing agreement is on the Trust Center. So are the policies and the sub-processor list a GDPR review asks for.

How do I report a vulnerability?

Email info@meetstream.ai with the details. We will reply within two business days. Found a security issue? We want to hear from you. Reporting it keeps every team on MeetStream safer.

FAQ

Frequently asked questions

Is MeetStream SOC 2 compliant?

SOC 2 Type 2 is under audit, and the report goes to the Trust Center on the day it is issued. We share security documents for vendor reviews on request. The Trust Center at trust.meetstream.ai holds what is public today.

Is MeetStream ISO 27001 certified?

Yes. Certificate 630036, ISO/IEC 27001:2022. Amtivo Group Limited (British Assessment Bureau) issued it to MeetStream Technologies Pte Ltd. First certified 19 August 2025. Valid to 18 August 2028. You can see it on the Trust Center.

Is MeetStream HIPAA compliant?

MeetStream holds ISO/IEC 27001:2022 certification, and HIPAA certification is separate from it. We do not sign Business Associate Agreements today. Tell us if you need one and we will share the roadmap.

Is meeting data encrypted?

Yes. We encrypt all data in transit and at rest. That covers recordings and transcripts. Live media over the secure WebSocket is encrypted too.

Where are recordings stored?

You choose. With bring-your-own storage, recordings and media go straight to your own bucket, in your region and account, under your retention and access rules. Otherwise MeetStream holds the media in encrypted storage and you fetch it through the API.

Is MeetStream GDPR compliant?

Yes. A data processing agreement is on the Trust Center. The bot always joins as a visible, named participant, and calendar access is read-only. Delete data per bot through the API, and a deletion webhook confirms it.

Who can access my data?

API keys and role-based access in the dashboard control access. Your team decides who can view recordings, transcripts and account settings. You can scope and rotate keys as needed.

Build on infrastructure you can verify

One API to join, record, stream and transcribe meetings. You can check the certificate number. The audit status is stated plainly.