Skip to content
Your data, your control

Security & Privacy

Consulting firms handle sensitive client data. We built RecapCRM with that reality at the center — not as an afterthought.

Consent

Full transparency. Participants are always notified. Configurable consent workflows.

Encryption

AES-256 at rest. TLS 1.3 in transit. Zero-knowledge architecture.

Access Control

Role-based permissions. Audit logs. SSO with Google and Microsoft.

Compliance

SOC 2 Type II path. GDPR compliant. Regular third-party assessments.

Recording Consent & Transparency

All participants are notified when recording begins. No silent recording, ever.

Configurable consent workflows: automatic notification, require explicit opt-in, or host-controlled recording.

Recordings can be paused or stopped at any time during the meeting.

Off-the-record mode for sensitive discussions. One click to pause, one click to resume.

Consent Workflow Options

Notify All

Participants see a banner when recording starts. Default setting.

Require Opt-In

Each participant must consent before recording begins.

Host Controlled

Only the meeting host can start and stop recording.

Data Encryption

AES-256 encryption at rest. All recordings, transcripts, and CRM data are encrypted with AES-256 before they touch a disk.

TLS 1.3 in transit. Every connection between your browser, our servers, and third-party integrations uses TLS 1.3.

Separate encryption layers. Transcripts are encrypted separately from audio recordings, with independent key management.

Zero-knowledge architecture. RecapCRM employees cannot access your meeting content. Encryption keys are scoped to your organization.

Encryption at restAES-256
Encryption in transitTLS 1.3
Key managementPer-org keys
Employee access to contentNone
Audio + transcript isolationSeparate layers

Access Controls

Role-based access. Control who can view, edit, or share client records. Admins, managers, and team members each see only what they should.

Team-level permissions. Restrict access by practice area, engagement team, or client. Your healthcare team does not see your financial services data.

Audit logs. Full trail of who accessed what record, when, and from where. Available to admins at any time.

SSO support. Sign in with Google Workspace or Microsoft 365. Enforce your organization's existing authentication policies.

Audit Log
Apr 12, 9:41aSarah M. viewed Acme Corp meeting recap
Apr 12, 9:38aMark L. exported Q1 contacts as CSV
Apr 12, 9:15aAdmin changed permissions for Healthcare team
Apr 11, 4:22pSarah M. shared recap with client@acme.com

Data Residency & Retention

SOC 2 certified infrastructure. All data is stored on SOC 2 Type II certified cloud infrastructure with geographic redundancy.

Configurable retention. Set auto-delete policies for recordings: 30, 60, 90, or 365 days. Transcripts and recaps can follow different schedules.

Full data export. Export all your data at any time in JSON or CSV format. Your data is never locked in.

Right to deletion. Request complete removal of all your organization's data. We honor deletion requests within 30 days.

Retention Policy Settings

Audio recordings90 days
Transcripts365 days
Meeting recapsIndefinite
CRM recordsIndefinite

All policies configurable per organization.

Compliance

SOC 2 Type II

Infrastructure hosted on SOC 2 Type II certified providers. RecapCRM's own SOC 2 certification is on our near-term roadmap.

GDPR Compliant

Full GDPR-compliant data handling. Data processing agreements available. Right to access, rectification, and erasure honored.

Third-Party Assessments

Regular security assessments by independent third parties. Penetration testing conducted annually.

Responsible AI

Your meeting content is never used to train AI models. Transcription and summarization happen in isolated, ephemeral compute environments.

Built for consulting firm requirements

We understand that consulting firms operate under strict confidentiality obligations. RecapCRM is designed with those constraints in mind.

Per-client recording controls

Enable or disable recording on a per-client basis. Some clients may require no recording. Easy to configure.

Engagement-level access

Restrict data access to specific engagement teams. Associates on Client A cannot see Client B data.

NDA-compatible terms

Data handling terms available for inclusion in client NDAs. We work with your legal team to meet specific requirements.

Privilege considerations

For firms with legal clients, configurable controls to protect privileged communications. Consult your legal counsel on recording policies.

Security FAQ

Can RecapCRM employees see my meeting recordings?
No. RecapCRM uses a zero-knowledge architecture. Your meeting content is encrypted with keys scoped to your organization. Our engineering team cannot decrypt or access your recordings, transcripts, or recaps.
Is my data used to train AI models?
Never. Your meeting content is processed for transcription and summarization only. It is never included in training datasets for any AI model. This is a contractual commitment, not just a policy.
What happens if I cancel my account?
You can export all your data before cancellation. After account closure, all data is permanently deleted within 30 days. We provide a grace period and clear instructions for data export during the cancellation process.
Do you have a DPA for GDPR compliance?
Yes. We provide a standard Data Processing Agreement that covers GDPR requirements. Custom DPAs are available for enterprise customers with specific regulatory needs.

Questions about security?

We are happy to walk through our security architecture with your IT or compliance team. Or start with a free account and see the controls firsthand.