🛡️

Security

MeetGrade handles real conversations, so we take protecting them seriously. This page explains how we secure your data and how security researchers can report issues to us safely.

How we protect your data

Encryption in transit

Traffic to and from MeetGrade is encrypted in transit over TLS, so data moving between your browser, our servers and our subprocessors is protected on the wire.

Encryption at rest in the EU

Customer data is encrypted at rest, and recordings and files are stored in the EU. The application is hosted in the EU (eu-west).

Access controls

Access to systems and data is limited to what's needed to operate the service. Sign-in uses Google OAuth, and roles inside the product control what each user can see and do.

No AI training on your data

We do not use your calls, transcripts or analysis to train AI models, and our AI subprocessors do not train their models on your content.

Recording is always disclosed

When MeetGrade records a meeting, a visible bot joins the call — never a silent one. Participants can see that the meeting is being recorded.

Around 30-day retention

Recordings are retained for around 30 days by default. We keep data for as long as needed to provide the service, and no longer than necessary.

On certifications — straight talk

SOC 2 is on our roadmap. We're not certified yet, and we don't display badges we haven't earned. When we complete an audit or certification, we'll say so here with the details — until then, we'd rather be honest about where we are than imply a status we don't hold.

For the third-party services that process data on our behalf, see our subprocessors page.

Vulnerability disclosure policy

We value the work of the security research community. If you believe you've found a security vulnerability in MeetGrade, we want to hear about it, and this policy describes how to report it and what you can expect from us.

Safe harbor

We consider security research and vulnerability disclosure conducted in good faith under this policy to be authorized. If you make a good-faith effort to comply with this policy during your research, we will consider your research to be authorized, we will not pursue or support legal action against you for accidental, good-faith violations, and we will waive any restrictions in our terms of service or acceptable use policy that would otherwise interfere with such research — to the limited extent needed to permit it. If a third party brings legal action against you for activity that complied with this policy, we will make this authorization known. Always act in good faith and within the scope below.

In scope

The MeetGrade application and its public web properties at the meetgrade.com domain. Please only test against your own account and your own data — never against another customer's.

Out of scope

  • Denial-of-service (DoS/DDoS), volumetric testing, or anything that degrades service for others.
  • Social engineering, phishing, or physical attacks against our team, users, or facilities.
  • Vulnerabilities in third-party services and subprocessors — report those to the vendor directly.
  • Accessing, modifying, or deleting data that isn't yours, and exfiltrating any data.
  • Reports from automated scanners with no demonstrated, exploitable impact.

How to report

Email hello@meetgrade.com with a clear description of the issue, the steps to reproduce it, and the potential impact. Give us reasonable time to investigate and fix the issue before disclosing it publicly, and avoid accessing or modifying data that isn't yours while you research.

Our commitment and disclosure timeline

We aim to acknowledge your report within 5 business days, keep you updated as we investigate, and work with you on coordinated disclosure once a fix is in place. We practice coordinated disclosure: we ask that you don't share details publicly until we've had a chance to remediate and we've agreed on timing together.

Recognition

We don't run a paid bug-bounty program and don't offer monetary rewards. We're grateful for responsible disclosure and are happy to credit researchers who report valid issues, if they'd like to be acknowledged.