Skip to main content
Your meetings stay yours

Meeting data security: encryption, tenant isolation, on-premise

What happens to a recording from the moment the Khulasa notetaker joins a Google Meet, Zoom or Microsoft Teams meeting to the day it is deleted — and who can see it in between.

Khulasa is an AI notetaker that joins your meetings as a named participant and returns Arabic and English transcripts and summaries. That makes it a processor of some of your most sensitive conversations, so this page states plainly what we do with them: recordings, transcripts and summaries are delivered over HTTPS, isolated per organisation, visible only to the people your roles allow, and never used to train models. Teams that cannot send audio to a cloud provider at all can run the same product as a private cloud or on their own servers.

Encrypted connections and encrypted backups

Recordings, transcripts and summaries are encrypted in transit with TLS. Media is never handed out through a public storage URL: audio is streamed through the API behind your session, so a link copied out of the app does not open the file for anyone else. Encrypted backups of the database are kept for at most 14 days, as the Terms describe.

Role-based access to meeting notes

Organisation roles, workspace groups and per-recording sharing decide exactly who can open each meeting: private to its owner, shared with a group, open to the whole workspace, or shared with named people. Public share links stay switched off until an admin enables them, and when they are enabled they expire by default. The same rules cover the transcript, the summary and the action items, because they belong to the recording they came from.

Tenant isolation between organisations

Every organisation's data is strictly separated: your recordings, transcripts and summaries never mix with anyone else's, and nothing you record can be reached from another workspace. Each recording belongs to your organisation rather than to the person who requested it, so access is governed by your organisation's rules, not by a personal account.

No model training on your meetings

Your meeting content is processed to produce your transcript and analysis and to run and secure the service — nothing else. We do not use it to train AI models. Emails and phone numbers can be redacted before the analysis is stored, so what sits in the database is only what you chose to keep.

You choose where the audio is processed

The cloud plans use managed speech and language models to transcribe and summarise your meetings. Private Cloud and On-Premise are built to run self-hosted models inside your own environment, so audio does not have to leave it; the model setup is confirmed with you when we size it. Retention is yours to set as well: choose a window after which recordings are erased everywhere, place a legal hold to exempt one, or delete anything permanently at any time.

On-premise and private-cloud meeting AI

Some organisations — government bodies, banks, law firms, boards — cannot send meeting audio to a cloud provider at all. For them Khulasa runs as a private cloud or fully on-premise. Both are built to run self-hosted speech and language models, so audio does not have to leave the deployment.

Private Cloud is a dedicated, isolated deployment we run for you, hosted where you need it; the location is agreed with you when we set it up. On-Premise is the same system installed on your own hardware, able to run with no outbound connection at all: the notetaker joins the meeting, the audio is transcribed on your servers, and the Arabic and English summary is stored in your own database. Both options are quoted per organisation, with unlimited recording hours.

On-premise deployment in detail

Questions about meeting data security

Are AI notetakers safe to use for confidential meetings?

Yes, when the notetaker is designed to be visible and governed. Khulasa joins under a clear name that appears in the participant list and posts a notice in the meeting chat, in English and then in Arabic, as soon as it is admitted, so nobody is recorded without knowing. After the meeting, organisation roles, groups and per-recording sharing decide who sees the notes; recordings, transcripts and summaries are delivered over HTTPS and isolated per organisation, and they are never used to train models. For meetings whose audio may not leave your infrastructure at all, Khulasa can run on-premise.

Who can see our recordings, and where is the data kept?

Every recording belongs to your organisation and is visible according to the rules you set: private to its owner, shared with a group, or open to the whole workspace, plus explicit per-person shares. Media is never handed out through a public storage URL — it is streamed through the API behind your session. You can set a retention window after which recordings are erased everywhere, place a legal hold to exempt one, redact emails and phone numbers before analysis is stored, and delete anything permanently at any time. Public share links stay off until an admin enables them, and expire by default.

Where is my meeting data stored?

On the cloud plans, in Khulasa's cloud workspace: isolated per organisation, and streamed to you through the API behind your session rather than through a public storage URL. On Private Cloud, in a dedicated, isolated deployment we run for you, hosted where you need it — the location is agreed with you when we set it up. On-Premise keeps everything on your own hardware, with the option of no outbound connection at all. Whichever you choose, the data belongs to your organisation and follows the retention and deletion rules you set.

Is meeting content used to train AI models?

No. Your meeting content is processed to produce your transcript, summary and action items and to run and secure the service; we do not use it to train AI models. Private Cloud and On-Premise are built to run the models self-hosted inside your own environment, so your audio does not have to leave it; the model setup is confirmed with you when we size it.

How long are recordings kept, and can we delete them?

For as long as you decide. An admin can set a retention window after which recordings are erased everywhere, place a legal hold to exempt one recording from that window, and delete anything permanently at any time; emails and phone numbers can also be redacted before the analysis is stored. Encrypted backups of the database are kept for at most 14 days, as the Terms describe, so a deleted recording does not linger beyond that.

What is the difference between Private Cloud and On-Premise?

Both are built to run self-hosted speech and language models, so audio does not have to leave the deployment; the model setup is confirmed with you when we size it. Private Cloud is a dedicated, isolated deployment we run for you, hosted where you need it — the location is agreed with you when we set it up. On-Premise is the same system installed on your own hardware, able to run with no outbound connection at all. Both are quoted per organisation — talk to us and we will size it with you.

A security page that cannot point at its contracts is a brochure. These are the documents that bind us.

Bring your meetings under this posture

Start on the free plan and try the controls on a real meeting, or read what each plan includes before you commit.

Cookies on Khulasa

We use strictly necessary cookies to run the site. With your permission we also use Google Analytics to understand how the site is used. You can change your choice at any time from "Cookie settings" in the footer. Privacy Policy