Security

Last updated: August 11, 2026

Where we are honest with you first

Bookedt is an early-stage product. We do not hold SOC 2, ISO 27001, or Cyber Essentials, and we have not had an external penetration test. We would rather tell you that plainly than let you assume otherwise and find out during procurement.

What follows is what we actually do today. If you need a certification before you can buy, tell us — it helps us decide when to start, and we will say so here the moment one is real.

Your data is separated from everyone else's

Every record belongs to a workspace, and every query is scoped to the workspace of the person asking. The workspace is always worked out on our server from a validated token — it is never a value your browser can supply — so a request cannot claim to be a workspace it is not.

Being straight with you about how that is enforced: today it is enforced in one place, our application code. Our database also has row-level security available, but our own server connects with a privileged role that bypasses it by design, so it is not currently a second, independent barrier. Moving to per-request database credentials, so the database enforces separation on its own, is our top open engineering item. We will say so here when it is done.

We have tested cross-workspace access ourselves, including on the meeting inbox and the briefs — a request for another workspace's record returns nothing. That is our own testing, not an external audit.

Encryption

  • In transit: everything moves over TLS. There is no unencrypted path into the product.
  • At rest: the databases we use encrypt their storage.
  • Secrets: the credentials you give us — CRM tokens, chat webhook URLs, API keys — are encrypted with a separate key before they are written down, so a database dump alone does not yield working credentials.
  • Passwords: hashed with bcrypt. We cannot read your password, and neither can anyone who takes the database.
  • Our own API keys: stored hashed. If you lose one we can only issue a new one, never show you the old one.

Access to your data

Access to production systems is limited to the people who need it to run the service. We do not browse customer meetings, recordings or transcripts. Where we have had to look at something to fix a fault, it is because a customer asked us to.

Connecting and disconnecting a CRM is written to an append-only audit trail — who, when, which provider. That trail never contains the credential itself.

What our AI providers may and may not do

Recordings are transcribed by Deepgram, with Groq as a fallback, and summarised by Anthropic. Anthropic and Groq are contractually barred from training their models on your data. We do not train models on it either.

Deepgram is worth naming specifically. Its standard terms allow it to keep and train on submitted audio unless each individual request opts out — it is not an account setting. We send every transcription request opted out of model improvement. We mention it because it is the kind of default that is easy to miss, and because meeting audio is the most sensitive thing we handle.

AI output can be wrong. Bookedt always shows it to a person before it goes anywhere, and never sends anything to your customers on its own.

Recording

No bot joins your calls. Recording happens in the browser of the person who chose to record, which means nothing appears in the meeting that your guests have not already seen. The audio is kept only long enough to transcribe it — normally about a day — and is then deleted; the transcript and summary are what remain, and there is no player, download or share link for a recording anywhere in the product. Whoever starts a recording is responsible for telling the other participants — see our privacy policy for what the law expects of them and of us.

The companies we depend on

We run on Vercel, Railway, Neon and Supabase, and use Deepgram, Groq, Anthropic and FullEnrich as processors. They are contractually limited to using your data to provide their service to us. A full list, and what each one gets, is in the privacy policy.

How we handle problems

We fix security issues before features. When we have found problems in our own reviews we have rotated the affected credentials, deployed the fix, and verified it against the live system rather than assuming the deploy worked.

If you believe you have found a vulnerability, email support@bookedt.io. Tell us what you found and how to reproduce it. We will confirm we have received it, and we will not take action against anyone who reports something in good faith and does not access or alter other people's data while doing it.

Related