Caption.Ed Compliance and Security

We store all recording data on Google Cloud Platform (GCP), and we’ve configured it to use only UK-based data centers. For other data types, like emails, we work with a handful of trusted subprocessors. They’ve all been thoroughly audited to ensure they meet our strict security standards.

Here’s our list of subprocessors:

We do collect some basic PII (Personally Identifiable Information), like your email address, to set up your account. Depending on what you’re recording, your session data might also contain PII.

Your data is stored indefinitely, but you’re always in control. You can delete your recordings and sessions in the app at any time. We also support Data Subject Access Requests and can provide a full data export upon contract exit for admin-level requests.

Our Terms & Conditions and Privacy Policy govern all data usage, and you can review them at any time.

How do we know you take this seriously?

We’re committed to keeping your data secure, and we have the certifications to prove it. Caption.Ed is ISO 27001 certified, and all of our audits are aligned with these controls. We also take a proactive approach with penetration testing. We have third-party specialists conduct annual tests, and we run automated weekly scans to catch any potential vulnerabilities. Executive summaries of these tests are available upon request.

The scope of our audits is comprehensive, covering all systems, services, and teams that handle confidential data.

Can you tell us what controls you have in place?

We protect our systems and your data with multiple layers of security. Our infrastructure is secured with firewalls and intrusion prevention systems, and we use vulnerability scans to regularly check for weaknesses. We manage access to data with strict controls, ensuring that only authorised personnel can access sensitive information. Your data is also logically separated from other users in our database.

Finally, we encrypt all your data both at rest and in transit. We use strong encryption standards to keep your data secure whether it’s stored on our servers or being sent over the internet.

Security Layers

  • ▸ Firewalls, Intrusion Detection & Prevention (IDS/IPS)
  • ▸ SIEM via GCP Log Analyzer
  • ▸ Regular scans via Intruder.io

Access Control

  • ▸ Role-based access control (RBAC)
  • ▸ Principle of Least Privilege (PoLP)
  • ▸ Multi-tenant DB with logical separation by unique keys

Encryption

  • At rest: AES-256 using GCP KMS
  • In transit: TLS 1.2 or higher
  • Key management: Google Cloud KMS (no customer-managed keys currently)

Learn more about
how we protect your data

Secure Development Practices

We integrate security directly into our development process. Our vulnerability management includes automated scanning with Intruder.io and regular dependency updates through Dependabot. For Static Code Analysis (SAST), all code is reviewed and scanned for vulnerabilities before it’s merged. Our annual penetration tests are also designed to address the OWASP Top 10 vulnerabilities.

We also use Cloudflare as a Web Application Firewall (WAF) to help mitigate common web threats, and we’re actively working to implement protections against things like XSS and SQL injection.

Our Policies

Here’s the list of policies that govern our security practices:

▸ Information Security Policy
▸ Access Control Policy
▸ Incident Response Plan
Cryptography Policy (or references to key management + encryption)
▸ Operations/Change Management Policy (may be titled differently)
▸ Data Retention Policy
▸ Privacy Policy
▸ Acceptable Use Policy
▸ Risk Management Policy

Artificial Intelligence – What about AI? 

We use Google Gemini to power our AI meeting summary functionality. This feature is completely opt-in, and is used to generate summarised content from transcripts. This means that after creating a transcript from audio input, the system can further process this transcript to provide concise summaries of the conversation or text.

We want to be clear that your data is never used to train the model, and all of our AI tools are hosted within the EU for secure data management.