Security
How Cleansig protects the data you entrust to it, written for IT teams and buyers who have to assess it. The legal detail is in the privacy policy, and the providers on the Subprocessors page.
Where the data lives
- The application and its database are hosted by Render, in the United States, and the website by Vercel. Our matching model runs on a dedicated server at OVHcloud, in France, and text analysis at Mistral AI, in the European Union.
- Meeting audio is captured by Recall.ai, which processes data in Frankfurt and deletes it within 72 hours. Transcription is done by Groq, which does not retain the files.
- The full list, with each provider's location and safeguards: https://www.cleansig.com/subprocessors/en
Encryption
- All traffic is encrypted in transit (HTTPS/TLS).
- The database is encrypted at rest by our host (AES-256), backups included.
- The tokens that give access to Google, Microsoft, Slack and Jira are additionally encrypted by the application itself (Fernet) before they are written. Passwords are hashed with bcrypt.
Access and isolation
- Every workspace is isolated: content is visible only to the members of its workspace, and membership is re-checked on every request. A workspace you do not belong to is not even reported as existing.
- Sessions are time-limited and renewed through a dedicated token. Session cookies are HTTP-only and sent over a secure connection only, and sensitive endpoints are rate-limited.
- Nobody at Cleansig reads your content, except at your explicit request as part of support.
Signing in with Google and Microsoft
- Sign-in follows OpenID Connect: Cleansig verifies the identity token's signature, issuer and audience before opening anything.
- On the Microsoft side, only work accounts are accepted. Every attempt uses PKCE, expires in ten minutes, can be used once, and must finish in the browser that started it: a callback link passed on by someone else opens nothing.
- A Microsoft account is recognised by the identifiers of its organisation and of its account, never by its email address alone. The address is only used to find an existing account when Microsoft guarantees that its domain belongs to the organisation.
- Cleansig authenticates to Microsoft with a certificate, without a shared secret, and its expiry is checked daily.
What the calendars allow
- Outlook calendar: delegated permissions only, granted by each person for their own account (openid, profile, email, offline_access, User.Read and Calendars.ReadBasic, which excludes the text and attachments of invitations). No application permission, no access to email or to OneDrive or SharePoint files, and nothing is written.
- Google Calendar: reading only the events the person owns (calendar.events.owned.readonly) and, for whoever files the minutes, drive.file, which only reaches the files Cleansig creates.
- Each member connects their own calendar, and nobody can connect a colleague's. Disconnecting erases the tokens immediately and calls off the meetings planned from that calendar.
For Microsoft 365 administrators
- If your organisation reserves consent to administrators, an administrator can approve Cleansig for the whole organisation, once: https://www.cleansig.com/microsoft/admin-consent
- Microsoft's screen then shows exactly the permissions listed above, and no other.
- The approval can be withdrawn at any time in the Microsoft Entra admin center, under Enterprise applications. Each person can also withdraw their own at myapps.microsoft.com.
Meeting recording
- The participant “Auris · Cleansig” joins meetings under its own name, visible to everyone. Only audio is captured: no video is recorded.
- Each person chooses the meetings Auris joins, and can exclude one at any time.
Artificial intelligence
- Transcripts are analysed by Mistral AI, in the European Union, which is contractually committed not to use them to train its models. Our own matching model compares signal statements on our server in France, keeping nothing.
- No data from Google or Microsoft calendars is sent to a model: what is analysed comes from Auris's recording or from the documents you upload.
- Our technical logs mask email addresses and never write an access token.
Deletion and portability
- A meeting, a signal or an account is deleted from the app, immediately and permanently. A deleted workspace is kept for 30 days, then erased.
- Everyone can download an archive of their data from their settings.
Compliance
- Cleansig is built for the GDPR. A data processing agreement (DPA) is available to our customers, and our list of subprocessors is public and kept up to date.
- Cleansig does not hold a SOC 2 or ISO 27001 certification yet. We answer our customers' security questionnaires: write to us at contact@cleansig.com.