Log in
Trust & Security

Built to pass your security review.

Disclosure, watermarking, data residency, and governance aren't settings to hunt for — they are how MeetCrew is built. This is the short version — the full security overview (PDF) is the long one.

Audit chain, verified nightly

Every disclosure, opt-out, and deletion is written to a hash-chained log. A nightly integrity check re-verifies it end to end — a failure raises an alert and is never silently overwritten.

Disclosure

It can't quietly be in the room.

Every teammate makes itself known — and can't switch its own disclosure off.

In the participant list

It appears as a named participant with an AI badge — not a hidden background bot.

On screen, every frame

An "AI colleague" banner is composited into every frame it sends, for the whole meeting. It ships on and can't be turned off by end users.

It says so, out loud

When it joins, it introduces itself audibly as an AI participant.

Anyone can opt out, live

Say "[Name], please leave" or "don't remember this conversation" and it is honored immediately — and logged.

Only where an admin allowed it

A teammate joins only the meetings a tenant admin has authorized — no self-service crashing of calls.

The disclosure statement

Plain-language, one page, always current.

Read it
Biometric privacy

No voice biometrics. By design.

The biometric-privacy lawsuits hitting meeting AI are about voiceprints. MeetCrew is architected to remove the most common basis for these claims: it recognizes people the way your directory already does, and stores no voice-derived biometrics anywhere.

Identity from your directory, not your voice

Cross-meeting recognition uses Microsoft Entra platform identity — email and display name — never voice characteristics.

No voiceprints, so no voiceprint database

No voice-derived biometric identifier is created or stored in the schema, for anyone in the meeting.

Anonymous speakers are first-class

Speakers without a durable identifier stay anonymous by label; named attribution is off by default in v1.

Consent controls, ready if you need them

The consent-gated attribution controls stay dormant unless named attribution is ever switched on.

Your agent, your memory

Meeting memory your agent can read — and act on.

MeetCrew exposes structured meeting memory to your own agent over an MCP server or API — under your identity, inside your tenant. Your agent reads what was decided and acts on it: close an action item, resolve an open question, update a decision.

It’s your agent, not ours

Access runs under a Microsoft Entra service principal your admin grants in the console — and can revoke. No shared keys, no MeetCrew back door.

Scoped to your tenant, enforced by us

Every call is locked to a single tenant and enforced server-side. Another customer’s agent can’t reach your memory — not even by guessing IDs.

Down to a single teammate

Reads and actions are scoped to one named deployment by default. Reaching across deployments takes an explicit admin opt-in.

Actionable, within hard limits

Your agent reads decisions, action items, open questions, statements, and topics — and acts on the workflow ones: close an action item, resolve an open question, update a decision. It can’t delete records, rewrite transcripts, or touch provenance or the audit trail.

No voiceprints exposed

Attribution comes from Microsoft Entra identity, not voice. The interface exposes no voiceprints and no speaker audio, and content stays in the Azure boundary.

Every read and write is logged

Every read and every action over the MCP server and API is logged and attributable to the Entra identity that made it — you can see who did what, and when.

The developer docs

Auth, tools, and the memory schema.

Read them
Provenance

Everything it says is watermarked and provable.

Watermarked speech

Its synthesized voice carries an audio watermark, sealed at the moment of synthesis.

C2PA content credentials

Stored artifacts carry C2PA-style origin metadata — what was generated, when, and by which teammate.

A tamper-evident audit chain

Disclosures, opt-outs, and deletions are hash-chained and re-verified nightly. Fail-closed: a broken link alerts, it is not quietly rewritten.

Data control

Your data, your region, your keys.

In-region inference

Language inference runs on in-region Azure OpenAI — meeting content stays inside the Azure boundary.

Residency pinned, no cross-region copies

Each deployment is pinned to its region, with no cross-region replication of your data.

The capture layer stores nothing

The meeting bot runs Zero Data Retention by default — the vendor keeps no recording at any point — so your durable memory exists only in your MeetCrew tenant.

Geo-fenced where the law is strictest

A teammate will not join if the organizer's tenant is out of scope. Illinois, the EU, and the UK are excluded in v1.

Retention you control, shredded when it expires

Retention is enforced to the jurisdiction's statutory ceiling; expired records are cryptographically shredded.

Right to erasure, honored on the queryable surface

On a data-subject deletion request, the person is regenerated out of the memory your agents query and search — not merely hidden — and a durable marker stops any later re-extraction from reintroducing them. The source transcript is a bounded, non-queryable residual, deleted on request.

Bring your own key, revoke any time

On Enterprise, your memory is encrypted at rest under a key held in your own Azure Key Vault or Managed HSM — across all three memory tiers. Rotate or revoke it whenever you need; revoke, and the data goes dark.

Exports double-wrapped

Exports are encrypted twice — a tenant key plus your own recipient key — so data leaving the boundary stays yours.

Never used to train models

Your meeting content is not used to train any model — ours or anyone else's.

Governance

Governed by your admins. Isolated by tenant.

Microsoft Entra, end to end

Teammates authenticate through Entra; access follows your existing identity and conditional-access policies.

Tenant-admin authorization

Admins decide which teammates exist, where they may join, and who can configure them — per deployment.

Every action attributed

Administrative actions are recorded against the real administrator, distinct from the anonymized meeting record.

Hard tenant isolation

One MeetCrew tenant maps to one Entra tenant, with hard isolation between customers by construction.

Why this posture exists

We built for the law meeting AI is running into.

AI in meetings is under real legal pressure — biometric-privacy law like Illinois' BIPA (740 ILCS 14) and data-protection rules like GDPR Article 4(11). We did not bolt compliance on afterward; we architected MeetCrew so the most aggressive theories have far less to attach to: no voiceprints, disclosure that ships on, and geo-fencing out of the regions where the rules bite hardest. This describes how the product is built and is not legal advice.

Bring your security team to the demo.

We like those meetings. We will walk your controls, share the security overview, and answer the hard questions.

These are architecture commitments, not third-party certifications — MeetCrew is not SOC 2 certified yet (it is on the roadmap), so today we walk your team through the controls directly. You remain responsible for obtaining any recording or participation consent your jurisdiction requires. Availability is limited to supported regions (US excluding Illinois, and Canada, in v1). Microsoft, Teams, Entra, and Azure are trademarks of Microsoft; MeetCrew is an independent Microsoft Partner. Found a security issue? Report a vulnerability.