Security & trust

How we protect your work.

Your recordings are often sensitive — internal reviews, prospect demos, product roadmaps. We take that seriously. Here's exactly what we do, with no marketing fluff.

Compliance

Audited, not just claimed.

SOC 2 Type II
Audited annually by Schellman. Report available under NDA.
GDPR
EU-first DPA. Data processing agreement signable in-product.
CCPA
California compliant. Data subject requests honored within 30 days.
HIPAA
BAA available on Business plan. Healthcare customers served.
ISO 27001
Certification expected Q3 2026. Working with third-party auditor.
PCI DSS
Payment processing via Stripe. We never touch card data.
Practices

Eight things we do every single day.

01
Encryption at rest
AES-256 for every recording, thumbnail, transcript. Keys rotated quarterly via AWS KMS. Per-tenant key separation for Business and Enterprise.
02
Encryption in transit
TLS 1.3 everywhere. HSTS enforced. Certificate pinning on desktop and mobile clients. No HTTP fallback.
03
Zero-trust auth
SSO via SAML 2.0 and OIDC. SCIM 2.0 for provisioning. Hardware key support (WebAuthn). Session tokens short-lived, rotated.
04
Access controls
Least-privilege by default. Per-space permissions. Admin audit logs for every action. Role-based access for teams of any size.
05
Data isolation
Customer data siloed by tenant. No cross-tenant queries possible in code. Separate encryption contexts per customer on Enterprise.
06
Incident response
24/7 on-call rotation. P0 SLA 15 minutes. Status page with history. Post-mortems public for every P0/P1.
07
AI privacy
Your content is never used to train third-party models. Transcription runs on our own GPU clusters. Opt-out of all AI features at org level.
08
Retention & deletion
Delete a video — gone in 48h, including backups. Cancel account — full purge within 30 days. Data export is always one click.
Programs

Our security infrastructure.

Bug bounty
Active bounty via HackerOne. Critical: $5,000–$20,000. Responsible disclosure appreciated.
Pen testing
Annual third-party pentest. Summary report shareable with prospects under NDA.
Status page
99.98% uptime last 12 months. Live status and incident history at status.recordik.app.
Security contact
security@recordik.app — PGP key on request. Reports acknowledged within 24h.

Need more detail?
We publish it.

SOC 2 report, DPA, pen-test summary, sub-processor list — all available under NDA. Email security@recordik.app.

Start recording — freeBook a demo