Security & Privacy
Consulting firms handle sensitive client data. We built RecapCRM with that reality at the center — not as an afterthought.
Consent
Full transparency. Participants are always notified. Configurable consent workflows.
Encryption
AES-256 at rest. TLS 1.3 in transit. Zero-knowledge architecture.
Access Control
Role-based permissions. Audit logs. SSO with Google and Microsoft.
Compliance
SOC 2 Type II path. GDPR compliant. Regular third-party assessments.
Recording Consent & Transparency
All participants are notified when recording begins. No silent recording, ever.
Configurable consent workflows: automatic notification, require explicit opt-in, or host-controlled recording.
Recordings can be paused or stopped at any time during the meeting.
Off-the-record mode for sensitive discussions. One click to pause, one click to resume.
Consent Workflow Options
Notify All
Participants see a banner when recording starts. Default setting.
Require Opt-In
Each participant must consent before recording begins.
Host Controlled
Only the meeting host can start and stop recording.
Data Encryption
AES-256 encryption at rest. All recordings, transcripts, and CRM data are encrypted with AES-256 before they touch a disk.
TLS 1.3 in transit. Every connection between your browser, our servers, and third-party integrations uses TLS 1.3.
Separate encryption layers. Transcripts are encrypted separately from audio recordings, with independent key management.
Zero-knowledge architecture. RecapCRM employees cannot access your meeting content. Encryption keys are scoped to your organization.
Access Controls
Role-based access. Control who can view, edit, or share client records. Admins, managers, and team members each see only what they should.
Team-level permissions. Restrict access by practice area, engagement team, or client. Your healthcare team does not see your financial services data.
Audit logs. Full trail of who accessed what record, when, and from where. Available to admins at any time.
SSO support. Sign in with Google Workspace or Microsoft 365. Enforce your organization's existing authentication policies.
Data Residency & Retention
SOC 2 certified infrastructure. All data is stored on SOC 2 Type II certified cloud infrastructure with geographic redundancy.
Configurable retention. Set auto-delete policies for recordings: 30, 60, 90, or 365 days. Transcripts and recaps can follow different schedules.
Full data export. Export all your data at any time in JSON or CSV format. Your data is never locked in.
Right to deletion. Request complete removal of all your organization's data. We honor deletion requests within 30 days.
Retention Policy Settings
All policies configurable per organization.
Compliance
SOC 2 Type II
Infrastructure hosted on SOC 2 Type II certified providers. RecapCRM's own SOC 2 certification is on our near-term roadmap.
GDPR Compliant
Full GDPR-compliant data handling. Data processing agreements available. Right to access, rectification, and erasure honored.
Third-Party Assessments
Regular security assessments by independent third parties. Penetration testing conducted annually.
Responsible AI
Your meeting content is never used to train AI models. Transcription and summarization happen in isolated, ephemeral compute environments.
Built for consulting firm requirements
We understand that consulting firms operate under strict confidentiality obligations. RecapCRM is designed with those constraints in mind.
Per-client recording controls
Enable or disable recording on a per-client basis. Some clients may require no recording. Easy to configure.
Engagement-level access
Restrict data access to specific engagement teams. Associates on Client A cannot see Client B data.
NDA-compatible terms
Data handling terms available for inclusion in client NDAs. We work with your legal team to meet specific requirements.
Privilege considerations
For firms with legal clients, configurable controls to protect privileged communications. Consult your legal counsel on recording policies.
Security FAQ
Can RecapCRM employees see my meeting recordings?
Is my data used to train AI models?
What happens if I cancel my account?
Do you have a DPA for GDPR compliance?
Questions about security?
We are happy to walk through our security architecture with your IT or compliance team. Or start with a free account and see the controls firsthand.