Security and compliance
ācta is in beta. This guide will change as the product changes.
This page is for IT and InfoSec reviewers, vendor and procurement coordinators, and compliance or legal teams. It explains how ācta protects your records. It also states where ācta stands on each compliance standard today, with no claim that is ahead of the facts.
How ācta protects your records
- No bot joins your meeting. You record in ācta or upload audio that you already have.
- ācta is built so that sensitive content stays out of the AI pipeline. Mark a segment off the record, and ācta removes it from the transcript.
- Approval seals the minutes with a SHA-256 hash. After that, a change needs a change request, and each approved change creates a new version.
- Approvals and changes to minutes go into a tamper-evident audit trail. Anyone with the PDF can check that it matches the sealed record.
- Each organization's data is kept separate from every other organization's. Every request is checked against workspace access.
- An external auditor needs no account. Every action by an external auditor is logged.
- Your organization sets how long ācta keeps its data. The page Access your data explains the retention policy.
We use analytics and error tracking only to improve ācta. We never sell your data or use it for advertising.
Compliance status
Limitation
No certification today
ācta holds no compliance certification or audit report today. The statements below describe work in progress. They are not claims of compliance.
- SOC 2 Type II: ācta is preparing for a SOC 2 Type II audit. The Security and Confidentiality criteria are in scope. ācta does not hold a SOC 2 report today.
- GDPR: ācta works to meet the requirements of the GDPR. The work covers consent, the rights of data subjects, and data transfers. It is not complete today.
- HIPAA: support for HIPAA is on the ācta roadmap, and the work starts after launch. Today, ācta does not support protected health information and does not sign business associate agreements.
Limitation
Do not record patient information
Do not use ācta for meetings that contain protected health information. If your organization needs HIPAA support, tell us at support@actaminutes.com. If we see strong demand, this work moves higher on our list.
Consent to record
The rules for recording a meeting differ by country, state, governing body, and organization. You are responsible for any notice and consent that your laws or policies require. ācta does not collect consent from participants for you. Your organization can require the person who records to confirm consent before each recording. The page Consent to record explains this in full.
Questions from your review team
If your team has a security questionnaire, a vendor assessment form, or needs more detail, send it to support@actaminutes.com. We answer each question with what is true today.
Last updated