Trust & SecurityLast reviewed · June 2026

Security isn't a feature. It's how the platform is built.

We've built the platform so your information stays private and protected at every step. Your data travels through a locked connection, your password is never stored in a form anyone can read, and your organisation's data is sealed off from every other's, including from us. Below is exactly how that works, in plain terms and in technical detail.

01How we keep your data safe

A plain guide, for everyone using the platform.

Your connection is locked

Everything you send and everything we send back travels through an encrypted connection, the same kind your bank uses, so it can't be read along the way.

We never keep your password

We don't store your actual password. We keep a scrambled version that can't be turned back into the original, so even we can't see it. We just ask you to choose a strong one.

Your data is kept completely separate

Your organisation's information is walled off from every other organisation's. The system won't allow anyone, including our own team, to wander into someone else's data.

Everyone sees only what they should

What a person can view or change depends on their role. If someone is given extra access temporarily, it switches off again on its own.

You're signed out when you step away

Leave the screen idle for a while and it logs you out, so a forgotten open tab can't be misused.

Invite and reset links are single-use

Links for joining or resetting a password work once and then stop. After you've used one, or after it expires, it's just a dead link.

We keep a record of what happens

Logins, permission changes, exports, and edits are all written down in a log, so there's always a clear account of who did what.

We block spam and attacks

The system automatically slows down and blocks anything that looks like flooding or automated abuse before it reaches your data.

We share as little as possible

We pass along only what's strictly needed, to a small set of trusted partners. Your organisation's identity and project details stay with us.

02For your security & IT team

The same protections, in technical detail.

We publish a non-proprietary technical overview for security and IT reviewers, covering how each control works under the hood, from transport and authentication to isolation, tokens, and auditing.

  • Transport
  • Authentication & sessions
  • Credentials
  • Tenant isolation
  • Access control
  • Application security
  • One-time links
  • Abuse prevention
  • Auditing
Read the technical overview
03Who we share data with

A short, deliberate list of trusted partners.

We only involve outside services where they're needed to deliver a feature you use. In each case we share the minimum required, never your organisation's identity or project details for their own purposes.

Meeting transcription
Meeting audio/video and the resulting transcript.
Only when you use the meeting note-taker
Email delivery
Recipient address and message content for transactional and notification emails.
When an email is sent on your behalf
AI assistant
Your prompts and the specific documents they reference, to generate a response.
Only when you use the assistant
Calendar
The event details needed to schedule and join meetings.
Only if you connect a calendar
04Responsible disclosure

Found something? Tell us.

We welcome reports from security researchers and customers, and we won't pursue action against anyone acting in good faith to help us keep the platform safe. Our policy covers scope, what to include, and what to expect.

Read our disclosure policy
Security contact
[email protected]

Prefer a form? Use the report form , it reaches the same team.

Machine-readable details: /.well-known/security.txt

05Common questions

Questions clients ask us.

Is my data safe while I'm using the app?

Yes. Everything you send and receive travels through a locked, encrypted connection, the same kind banks use, so it can't be read by anyone in between.

Can anyone see my password?

No, not even us. We don't store your real password. We keep a scrambled version that can't be reversed. We just ask you to choose a strong one: at least 12 characters with a mix of letter cases, numbers, and symbols.

Could another organisation see my data by accident?

No. Each organisation's data is completely walled off. You log in at your own web address, and the system refuses any attempt to reach another organisation's information, even from our own team. Every save, edit, and export is checked first.

Why can't I do certain things in the app?

Access depends on your role, so people only see and do what they're meant to. If someone needs extra access for a short time, it's granted temporarily and switches off on its own.

What happens if I leave my screen open?

You're automatically signed out after a period of inactivity, so an unattended screen doesn't stay logged in.

Are invite and reset links safe to use?

Yes. They work only once and expire on a timer. Once a link has been used or has timed out, it stops working.

Do you keep track of what happens in the account?

Yes. Logins, permission changes, exports, and edits are recorded in a log for accountability and compliance.

What stops someone from attacking or spamming the system?

Built-in limits automatically detect and block flooding and automated abuse.

Do you share my information with anyone else?

Only the minimum needed, and only with trusted partners, for example a transcription service for meetings and an email-delivery service for notifications. Your organisation's identity and project details are never handed over.

This page describes how the platform works today and is updated as the platform evolves. It's a description of our practices, not a contract or warranty. For contractual data-protection terms, see your agreement with The Change Agency.