Security & trust
You are trusting us with client conversations.
Here is exactly how we treat them. This page describes what is actually built, not what is aspired to. Every claim on it was audited line by line against the shipped product on 29 August 2026 — twenty-nine claims, two of which were wrong and were fixed in the software rather than softened here — and where the evidence for a claim sits with a vendor rather than with us, it says so.
Consent comes first
Org policy
admin-editable- Announce in every meeting
- ALWAYS
- Store audio
- TRANSCRIPT ONLY
- Recording for this client
- BLOCKED
- Audio retention
- 30 DAYS
- Deletion receipt
- VERIFIED
- All-party consent is the default posture
- Routenna is built assuming everyone in the room must know about and accept the capture: the strictest consent standard, applied everywhere rather than negotiated per jurisdiction.
- The notetaker always identifies itself
- The bot joins under a name that says your organization is taking notes. Self-identification is unconditional; announcement rules govern the spoken announcement on top of it, never instead of it.
- Recording can be refused per client, or entirely
- Admins can block recording for specific clients and disable it org-wide. A decision not to record leaves no trace, no bot, no partial capture, nothing.
- Transcript-only mode never stores your audio
- When an organization chooses transcript-only, the recording is never fetched into our systems: not stored and deleted later, simply never taken. Transcription still has to read the audio, so our speech-to-text subprocessor receives it directly, holds it under a short deletion timer, and is named on our subprocessor page.
- Stopping a capture does not wait for an admin
- The kill switch is available to every member of your organization, not only admins, because "please stop recording" cannot wait for someone to be found. Whoever from your side is in the room can stop it there and then; it removes the notetaker and purges the partial capture. To be exact about who presses it: a client or guest asks, and any of your people in the meeting can act on it immediately — the control is in your product, so it is your side of the table that reaches it.
Your data is isolated
- Tenant isolation is enforced in the database
- Every table that holds customer data is scoped to your organization with row-level security enforced by the database itself, not by application code remembering to filter.
- Isolation is proven by tests, on every change
- A dedicated cross-tenant test suite attempts to read, write, update and delete another organization's data across every table and the recording storage, and must pass before any change ships. A new table that skips these tests fails the build by design.
- Recordings live in private storage
- Recording files sit in a private bucket with organization-scoped access policies; access is by short-lived signed link, and each signed link minted is recorded in the audit trail.
- A shared account does not mean shared meetings
- Within an organization, a meeting you recorded is readable by your colleagues only if you share it or the client it is filed under is shared with the team. This is the same row-level security that separates tenants, evaluated in the database rather than filtered in the interface, and it has no administrator exception: an org admin cannot read a colleague's private meeting either.
Encryption and secrets
- Encrypted in transit
- All traffic between your browser, our application and our infrastructure providers is encrypted with TLS.
- Calendar credentials are sealed at rest
- The refresh tokens that connect your calendar are encrypted with AES-256-GCM authenticated encryption before they touch the database, under a key that exists only server-side. They are unreadable through the API, including by your own organization's admins.
- Secrets never reach the browser
- API keys and service credentials live server-side only. The client bundle is built without them, and the server refuses to start with a malformed key rather than limp along.
AI with a human in charge
- What the AI decides on its own is a proposal, not a record
- Nothing the AI extracts enters a client record on its own. Every finding waits in a review queue for a human to accept, edit or dismiss, and the record of who confirmed what, and when, is enforced at the database level. A change you instruct — through the app or by asking an assistant connected to your account — is your decision and takes effect, but it is written to the same ledger with your name on it and can be undone from one screen.
- Every finding carries its evidence
- Each extracted finding carries the transcript timestamp it came from, a confidence score, and a fact / inference / recommendation label. A finding without evidence cannot exist. Below the confidence threshold a finding is discarded rather than shown: we would rather give you fewer, surer findings than ask you to adjudicate the model's uncertainty on top of adjudicating the finding. Every run records how many it dropped, so the cost of that threshold stays measurable rather than invisible.
- Model output is never trusted
- Everything the model returns is validated against a strict schema before it can touch the database; malformed output is rejected and retried, then quarantined. It does not degrade into partial writes.
- One customer's meetings never inform another's
- Customer data stays inside the customer's tenant. Routenna trains and fine-tunes no models of any kind, and nothing from one organization ever becomes shared platform knowledge that could surface for another. Retrieval is scoped to a single client's corpus and proven so by a dedicated leakage test.
- What our model providers do with it, stated exactly
- It differs by provider, and the difference is worth stating. Voyage, which receives transcript text for embeddings, is under a contractual restriction against using it for anything but providing the service, which forecloses training. Anthropic and AssemblyAI publish the same position as policy rather than granting it as a contractual term, so we describe those as policy and not as a guarantee we could produce on request. Ask us and we will show you which is which.
- Compliance topics are flagged, never advised
- The software surfaces compliance-adjacent topics for your professionals. It does not generate compliance, legal or medical advice.
- The advisors are bound by that rule, not an exception to it
- Routenna runs an HR, a risk and a business read over each meeting, and calling them advisors is a fair description of what they do — so it is worth being exact about what they may say and where it goes. Their standing instruction is to name what is worth checking and who to check it with, never to state what the law requires or whether something was lawful: they have read a transcript, not the contract, the policy or the jurisdiction, and a confident wrong reading of an employment question is worse than no reading. Every line carries an evidence timestamp and a fact, inference or recommendation label. It stays on the meeting it came from and is never written into the client record — the client timeline is built only from findings a person accepted, and no advisory line is eligible for it.
Retention and verified deletion
- You set the retention window
- Audio retention is a per-organization policy in days; shortening it applies to what is already stored, not just future recordings. Transcript-only organizations have no audio to retain at all.
- Deletion is verified, not assumed
- When data is deleted: by retention, kill switch or hard delete: the job re-checks every location it emptied (storage, database rows, search vectors) and records a receipt of the verified absence. A deletion that cannot prove itself fails loudly instead of reporting success.
- Account deletion is self-serve
- An organization admin can delete the entire organization from settings. It runs through the same verified-deletion engine as everything else: one mechanism, one set of proofs.
What leaves, and only when you say so
- Nothing leaves your tenant until you connect something
- Out of the box, meeting data goes nowhere but Routenna. Every outbound destination is one an admin in your organization connected on purpose, and connecting one is not the same as switching it on: each is off until somebody turns it on.
- Only what a person accepted is written to your CRM
- Findings pushed to a connected CRM are exclusively ones a reviewer accepted. Anything dismissed is never sent, and only a one-line summary with a link back travels, never the transcript.
- Notifications carry the shape of a meeting, not its contents
- A message to a channel, or a request to your own systems, says that a meeting finished, roughly how long it ran and how many findings are waiting. It carries no transcript line, no finding, and not the client's name. A channel message also carries the recap's one-line description of how the meeting went, because a notification nobody reads is one everybody mutes. The one piece of free text that travels either way is the meeting's own title, which is yours to choose — a team that names meetings after clients is naming them in the notification too. Reading anything further requires signing in.
- Requests to your systems are signed, and the address is checked
- Every request Routenna sends to an address you supply carries a signature you can verify, bound to a timestamp so a captured request cannot be replayed later. Addresses that point back into private infrastructure are refused, and redirects are never followed.
- Every destination and every delivery is on the record
- Adding a destination, removing one, and each delivery that actually left are separate entries in your audit trail. “Where did that meeting go, and who sent it there” is a question you can answer from the product.
Everything sensitive is audited
- An append-only audit trail
- Recording access, transcript views, AI writes, deletions and permission changes each write exactly one audit event. The trail cannot be edited or deleted through the application: the database refuses.
- Admins can answer “who accessed this?”
- Organization admins can review and export the audit trail. Exporting it is itself an audited action.
Where we are honest about being early
Routenna holds no third-party certification yet, no SOC 2 report of our own to show you. We are an early-stage product, built from day one with the controls on this page and a test suite that proves them, so that an audit is a formality rather than a scramble. If certification status matters for your diligence, ask us where we are and we will tell you plainly.
Our vendors are listed on the subprocessor register, including the current status of each data processing agreement. No production customer data flows to a vendor before its DPA is signed.
Found a vulnerability?
We want to hear about it, directly and quietly. Our disclosure contact is published at /.well-known/security.txt, and we commit to acknowledging good-faith reports rather than lawyering at them.