Security

Meeting BaaS (operated by SAS SPOKE) is built with security and privacy as core requirements. Our full security program — including SOC 2 controls, subprocessors, and real-time compliance status — is available in our public Trust Center.

Infrastructure & Hosting

  • All services are hosted within the European Union on SOC 2 Type II compliant cloud providers.
  • Data is encrypted in transit (TLS) and at rest.
  • Access to production systems is restricted, logged, and reviewed.

Meeting Data & Retention

  • Recordings and transcripts are stored only for as long as your configuration requires.
  • Auto-delete by default: meeting data is automatically deleted after a configurable retention period.
  • Meeting bots join calls only when explicitly requested through the API.

Subprocessors

A current list of subprocessors, along with their purpose and location, is maintained in the Trust Center and updated whenever changes occur.

Vulnerability Disclosure

If you believe you have found a security vulnerability in Meeting BaaS, please report it to security@meetingbaas.com. We treat security reports with high priority and will acknowledge your report promptly.

Compliance Documents

For audit reports, penetration test summaries, and additional documentation, visit the Trust Center.