Log in
Trust & Security

Built to pass your security review.

Disclosure, watermarking, data residency, and governance aren't settings to hunt for — they are how MeetCrew is built. This is the short version — the full security overview (PDF) is the long one.

Audit chain, verified nightly

Every disclosure, opt-out, and deletion is written to a hash-chained log. A nightly integrity check re-verifies it end to end — a failure raises an alert and is never silently overwritten.

Disclosure

It can't quietly be in the room.

Every teammate makes itself known — and can't switch its own disclosure off.

In the participant list

It appears as a named participant with an AI badge — not a hidden background bot.

On screen, every frame

An "AI colleague" banner is composited into every frame it sends, for the whole meeting. It ships on and can't be turned off by end users.

It says so, out loud

When it joins, it introduces itself audibly as an AI participant.

Anyone can opt out, live

Say "[Name], please leave" or "don't remember this conversation" and it is honored immediately — and logged.

Only where an admin allowed it

A teammate joins only the meetings a tenant admin has authorized — no self-service crashing of calls.

The disclosure statement

Plain-language, one page, always current.

Read it →
Biometric privacy

No voice biometrics. By design.

The biometric-privacy lawsuits hitting meeting AI are about voiceprints. MeetCrew is architected to remove the most common basis for these claims: it recognizes people the way your directory already does, and stores no voice-derived biometrics anywhere.

Identity from your directory, not your voice

Cross-meeting recognition uses Microsoft Entra platform identity — email and display name — never voice characteristics.

No voiceprints, so no voiceprint database

No voice-derived biometric identifier is created or stored in the schema, for anyone in the meeting.

Anonymous speakers are first-class

Speakers without a durable identifier stay anonymous by label, and are never identified by voice.

Consent controls, ready if you need them

Named attribution uses platform identity only, and the consent-gated attribution controls are there when your jurisdiction or policy calls for them.

Your agent, your memory

Meeting memory your agent can read — and act on.

MeetCrew exposes structured meeting memory to your own agent over an MCP server or API — under your identity, inside your tenant. Your agent reads what was decided and acts on it: close an action item, resolve an open question, update a decision.

It’s your agent, not ours

Access runs under a Microsoft Entra service principal your admin grants in the console — and can revoke. No shared keys, no MeetCrew back door.

Scoped to your tenant, enforced by us

Every call is locked to a single tenant and enforced server-side. Another customer’s agent can’t reach your memory — not even by guessing IDs.

Down to a single teammate

Reads and actions are scoped to one named deployment by default. Reaching across deployments takes an explicit admin opt-in.

Actionable, within hard limits

Your agent reads decisions, action items, open questions, statements, and topics — and acts on the workflow ones: close an action item, resolve an open question, update a decision. It can’t delete records, rewrite transcripts, or touch provenance or the audit trail.

No voiceprints exposed

Attribution comes from Microsoft Entra identity, not voice. The interface exposes no voiceprints and no speaker audio, and content stays in the Azure boundary.

Every read and write is logged

Every read and every action over the MCP server and API is logged and attributable to the Entra identity that made it — you can see who did what, and when. Actions are kept as durable audit events for seven years; reads are kept in operational logs for 90 days.

The developer docs

Auth, tools, and the memory schema.

Read them →
Provenance

Everything it says is watermarked.

Watermarked speech

Its synthesized voice carries an audio watermark, sealed at the moment of synthesis.

Origin metadata

Artifacts it generates carry embedded provenance — what was made, when, and by which teammate — readable by any standard metadata tool. A record of origin, not a signature.

A tamper-evident audit chain

Disclosures, opt-outs, and deletions are hash-chained and re-verified nightly. Fail-closed: a broken link alerts, it is not quietly rewritten.

Data control

Your data, your region, your keys.

In-region inference

Language inference runs on in-region Azure OpenAI — meeting content stays inside the Azure boundary.

Residency pinned, no cross-region copies

Each deployment is pinned to its region, with no cross-region replication of your data.

The capture layer stores nothing

The meeting bot runs Zero Data Retention by default — the vendor keeps no recording at any point — so your durable memory exists only in your MeetCrew tenant.

Geo-fenced to where we operate

The fence is an allow-list: a teammate joins only when the meeting's region resolves to one we run in, and refuses everything else. The EU and the UK are not supported in v1.

Retention you control, deleted when it expires

Retention is enforced to the jurisdiction's statutory ceiling; expired records are deleted.

Right to erasure, honored on the queryable surface

On a data-subject deletion request, the person is regenerated out of the memory your agents query and search — not merely hidden — and a durable marker stops any later re-extraction from reintroducing them. The source transcript is a bounded, non-queryable residual, deleted on request.

Bring your own key, revoke any time

On Enterprise, your memory is encrypted at rest under a key held in your own Azure Key Vault or Managed HSM — across all three memory tiers. Rotate or revoke it whenever you need; revoke, and the data goes dark.

Exports support double-wrapping

Exports can be encrypted twice — a tenant key plus your own recipient key — so that once you supply a recipient key, neither of us can decrypt the artifact alone.

Never used to train models

Your meeting content is not used to train any model — ours or anyone else's.

Governance

Governed by your admins. Isolated by tenant.

Microsoft Entra, end to end

Teammates authenticate through Entra; access follows your existing identity and conditional-access policies.

Tenant-admin authorization

Admins decide which teammates exist, where they may join, and who can configure them — per deployment.

Every action attributed

Administrative actions are recorded against the real administrator, distinct from the anonymized meeting record.

Hard tenant isolation

One MeetCrew tenant maps to one Entra tenant, with hard isolation between customers by construction.

Why this posture exists

We built for the law meeting AI is running into.

AI in meetings is under real legal pressure — biometric-privacy law like Illinois' BIPA (740 ILCS 14) and data-protection rules like GDPR Articles 4(14) and 9(1). We did not bolt compliance on afterward; we architected MeetCrew so the most aggressive theories have far less to attach to: no voiceprints, disclosure that ships on, and an allow-list that keeps the Service to the regions we run in. This describes how the product is built and is not legal advice.

Bring your security team to the demo.

We like those meetings. We will walk your controls, share the security overview, and answer the hard questions.

These are architecture commitments, not third-party certifications — MeetCrew is not SOC 2 certified yet (it is on the roadmap), so today we walk your team through the controls directly. You remain responsible for obtaining any recording or participation consent your jurisdiction requires. Availability is limited to supported regions (the US and Canada, in v1). Microsoft, Teams, Entra, and Azure are trademarks of Microsoft; MeetCrew is an independent Microsoft Partner. Found a security issue? Report a vulnerability.