Legal

Security

Last updated: 6 July 2026

Protokol handles sensitive client conversations, so security is built into how the product works. This page summarises our main controls.

Encryption

Data is encrypted in transit (HTTPS/TLS) and at rest in our database and file storage.

Account isolation

Each account’s data is isolated using row-level security, so one customer can never read another customer’s meetings, transcripts, clients, or settings.

Access control

Access to production data is restricted to the minimum necessary and protected by authentication. Server-only credentials are never exposed to the browser.

Data location

Our primary database and recording storage are hosted in the EU. See Privacy for the full list of sub-processors.

Recording transparency

No bot ever joins your meetings to record them. Recording happens on your own device through our desktop app, and we give you copy-paste disclosure text so participants know a recording is being made.

Quote verification

Every “exact quote” in an answer sheet is checked in code against the real transcript. If a quote cannot be found, it is removed and the answer is downgraded — the system cannot invent evidence to inflate a compliance score.

Data deletion

You can delete individual meetings at any time and request full account deletion by emailing support@getprotokol.app.

Reporting a vulnerability

If you believe you have found a security issue, please email support@getprotokol.app and we will respond promptly.

© 2026 Protokol. All rights reserved.