Security
Your meeting data stays yours
Your meeting data is encrypted, securely stored, and never used to train AI models.
Bluedot is independently audited, with security controls continuously monitored and reviewed.
SOC 2 Type II
Bluedot maintains independently audited controls for security, availability, and confidentiality under the SOC 2 Type II framework.
GDPR
Bluedot maintains GDPR-compliant controls and data processing practices to protect personal data across collection, access, storage, retention, and deletion.
Your data stays yours
No training on customer data: Customer data is never used to train or improve AI models.
No AI provider retention: Data is not stored, logged, or retained by AI providers after generation.
Encryption in transit and at rest: Data is protected with AES-256 encryption and TLS.
Data deletion: Deleted data is removed immediately, with backups cleared within 30 days.
How your data is protected
Infrastructure and data security
Data is stored in AWS with network isolation, least-privilege access, and encryption in transit and at rest. Production access is restricted, logged, and continuously monitored.
Access and identity controls
Role-based access controls define access at every level. Internal access is limited to authorized personnel, with full audit trails and enforced authentication policies.
Independent audits and testing
Bluedot undergoes annual third-party penetration testing, with continuous monitoring across infrastructure, access, and anomalies.
Compliance and insurance
Bluedot maintains GDPR-aligned controls, Cyber Liability and Tech E&O insurance, and documented practices for incident response, risk management, and vendor security.
Governance and controls
Workspace-level permissions: Organization admins can control workspace settings, manage user access, and enforce security policies across the company.
Enterprise agreements: Bluedot supports DPAs, standard contractual clauses (SCCs), and customer-specific terms. Security documentation and audit reports are available on request.
SSO and SCIM provisioning: Supports SSO, SAML, and SCIM for centralized identity management, automated user provisioning, and access control through your identity provider.
Custom data retention: Workspace admins can configure retention policies for recordings, transcripts, and AI-generated notes to meet internal data governance requirements.
FAQs
Is Bluedot secure and compliant with industry standards?
Is Bluedot GDPR compliant?
How does Bluedot monitor and secure its infrastructure?
What happens to our data when we stop using Bluedot?
Does Bluedot send a consent message?
Capture meeting notes with confidence
Capture and manage meeting data with independently audited controls, protected systems, and workspace-level governance.