# Your meeting data stays yours

Your meeting data is encrypted, securely stored, and never used to train AI models.

Bluedot is independently audited, with security controls continuously monitored and reviewed.

[View trust center](https://trust.bluedothq.com/)

### SOC 2 Type II

Bluedot maintains independently audited controls for security, availability, and confidentiality under the SOC 2 Type II framework.

### GDPR

Bluedot maintains GDPR-compliant controls and data processing practices to protect personal data across collection, access, storage, retention, and deletion.

## Your data stays yours

No training on customer data: Customer data is never used to train or improve AI models.

No AI provider retention: Data is not stored, logged, or retained by AI providers after generation.

Encryption in transit and at rest: Data is protected with AES-256 encryption and TLS.

Data deletion: Deleted data is removed immediately, with backups cleared within 30 days.

## How your data is protected

### Infrastructure and data security

Data is stored in AWS with network isolation, least-privilege access, and encryption in transit and at rest. Production access is restricted, logged, and continuously monitored.

### Access and identity controls

Role-based access controls define access at every level. Internal access is limited to authorized personnel, with full audit trails and enforced authentication policies.

### Independent audits and testing

Bluedot undergoes annual third-party penetration testing, with continuous monitoring across infrastructure, access, and anomalies.

### Compliance and insurance

Bluedot maintains GDPR-aligned controls, Cyber Liability and Tech E&O insurance, and documented practices for incident response, risk management, and vendor security.

## Governance and controls

Workspace-level permissions: Organization admins can control workspace settings, manage user access, and enforce security policies across the company.

Enterprise agreements: Bluedot supports DPAs, standard contractual clauses (SCCs), and customer-specific terms. Security documentation and audit reports are available on request.

SSO and SCIM provisioning: Supports SSO, SAML, and SCIM for centralized identity management, automated user provisioning, and access control through your identity provider.

Custom data retention: Workspace admins can configure retention policies for recordings, transcripts, and AI-generated notes to meet internal data governance requirements.

## **FAQs**

### Is Bluedot secure and compliant with industry standards?

### Is Bluedot GDPR compliant?

### How does Bluedot monitor and secure its infrastructure?

### What happens to our data when we stop using Bluedot?

### Does Bluedot send a consent message?

Capture and manage meeting data with independently audited controls, protected systems, and workspace-level governance.
