Legal
Security
Last updated 22 September 2026.
Recordist's security model is simple to state: the meeting never leaves the machine by default, and nothing on the machine can reach it without your user account's permissions and a token you hold. We do not claim the software is unbreakable; we claim that the design keeps the sensitive material where you can control it.
Architecture
- No server-side processing. Audio capture, transcription, search and (with the local model) note generation all run in the desktop process. There is no Recordist backend that stores or relays meeting content.
- Loopback only. The local API (port 47321), the MCP HTTP transport (47322) and the A2A endpoint (47323) bind to
127.0.0.1and reject requests carrying any otherHost. They are unreachable from the network, including your LAN. - Token authentication. Every request to those ports must carry a bearer token generated on first launch and stored in
api_tokenin the app's data folder with owner-only permissions (0600). The token is local and per-user: the gateway reads it from disk, and the Chrome extension obtains it once through a short-lived 6-digit pairing code. It never needs to leave your machine and should never be shared. Details for developers are in the Developers section. - Explicit consent to record. Recording starts only from the confirm prompt, from the global hotkey you press yourself, from a per-app allowance you turned on yourself (empty by default), or, if you enable it, from a remote start request that must still carry the token. Remote start is off by default.
- Minimal permissions. The app asks for microphone and system-audio permission to record, and calendar and notifications optionally. It does not request screen content, accessibility, contacts or location. The extension is restricted to the supported meeting sites and the loopback address.
Data at rest
- Files are protected by your operating-system account. We recommend full-disk encryption (FileVault, BitLocker, LUKS).
- Optional database encryption with SQLCipher (Settings → Privacy → Encrypt database).
- API keys for third-party AI providers are stored in the OS keychain, never in plain files, exports, diagnostics or logs.
- Logs contain no transcript text.
Data in transit
The app makes outbound connections only for model downloads, update checks, optional licence verification or recovery, and to an AI provider you configure with your own key. All use HTTPS. Model files are verified against a published SHA-256 before use. Every outbound request is written to the Privacy Ledger in the app.
Licensing
Licence keys are Ed25519-signed and verified offline with a public key embedded in the app. The private key exists only as a secret in the licence service and is never present on user machines. A compromise of the website or the licence service therefore cannot expose meeting data, because none is held there.
Supply chain
- Early builds are not yet code-signed; signing and notarisation land before general availability. All platforms publish
SHA256SUMS.txtper release. - Builds are produced by our automated pipeline from tagged commits. Dependencies are pinned through lockfiles and audited for known vulnerabilities as part of the release routine.
- The website loads no third-party scripts. Fonts come from Google Fonts; nothing else is external. The films on this site are served from our own domain with the browser's built-in player.
Website and checkout
The site is static and served with security headers (no framing, no MIME sniffing, strict referrer policy). Payment pages are hosted by Stripe; card details never touch our infrastructure. The licence-issuing service validates Stripe webhook signatures before issuing any key. Site forms are rate-limited, and anything that looks like an API or licence key is removed before a support message is stored or sent to the assistant.
What we do not do
- No telemetry, analytics or crash reporting.
- No accounts, so no passwords to lose.
- No bots joining meetings, so no meeting-platform credentials or OAuth grants.
Reporting a vulnerability
Please email [email protected] with a description, steps to reproduce and the app version. We acknowledge reports within 3 business days and aim to ship a fix for confirmed high-severity issues within 14 days. We ask that you give us reasonable time to fix before disclosing publicly, and we will credit you in the changelog if you wish. There is no paid bounty programme at this time. Please do not test against other people's machines or data.
Supported versions
Security fixes are released for the current minor version. The Free plan receives them on the same day as paid plans.
Trust Center
The Trust Center has the plain-language version of this page: the traffic table, permissions, retention and deletion, and how to report a problem.
Changes
This page is updated as the architecture evolves. Material changes are noted in the changelog.