Noota Trust Center

We prioritize system security and customer privacy at every stage of the engineering process. Noota runs on enterprise-grade infrastructure with security, performance, and reliability at its core. We apply a security-by-design approach and encrypt all customer data — recordings, transcripts, emails, and metadata — at rest and in transit. Our systems are continuously monitored and updated to ensure full data protection.

Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.

Skip to main content
Noota Trust Center

Noota Trust Center

We prioritize system security and customer privacy at every stage of the engineering process.

Noota runs on enterprise-grade infrastructure with security, performance, and reliability at its core.

We apply a security-by-design approach and encrypt all customer data — recordings, transcripts, emails, and metadata — at rest and in transit.

Our systems are continuously monitored and updated to ensure full data protection.

Data security

Protects customer information through strong encryption and logical separation measures.

Encryption in transit

Every connection to the service is secured with tls 1.2/1.3, preventing eavesdropping or tampering as data moves between users and the platform.

Data isolation

Each customer’s transcripts, audio and metadata are fully segregated from other tenants, preventing cross-tenant access and strengthening confidentiality.

Customer data ownership

Customers retain full legal ownership of their content and can require its removal at any time, reinforcing control and compliance with contractual obligations.

Restricted internal access

Internal staff may view customer data only when explicitly authorised by the client, with all access logged for accountability.

Encryption at rest

All stored customer data is protected using aes-256 encryption, reducing the risk of unauthorized disclosure if physical media are compromised.

Data lifecycle management

Gives customers granular control over how long data is kept and how it is permanently removed.

Customisable data retention periods

Enterprise administrators can set retention from 1 day to 3 years, aligning storage practices with internal policies and regulations.

Permanent deletion within 24 hours

When a meeting is deleted, all copies in production and backups are irreversibly erased in under 24 hours, minimising residual risk.

Default 30-day archive for free accounts

Free plans automatically archive content after 30 days, ensuring data is not kept longer than necessary.

Contract-termination purge

Upon contract end, all customer data is purged unless otherwise agreed, preventing unnecessary retention.

Zero-retention post-deletion policy

No cold storage or delayed deletion is performed once data is removed, eliminating lingering copies.

Access control

Ensures only authorised users and organisations can reach sensitive resources.

Role-based access control

Owner, admin and member roles provide least-privilege permissions that match job responsibilities across the organisation.

Single sign-on integration

Enterprise customers can connect corporate identity providers for centralised user authentication and streamlined off-boarding.

Private workspaces by default

Each user’s recordings remain private unless they choose to share, protecting confidentiality out of the box.

Meeting-level recording control

Users or admins can disable the service for specific meetings, preventing accidental capture of sensitive conversations.

Explicit internal access approval

Support or devops staff may only access content when clients share a secret identifier, ensuring oversight of privileged actions.

Privacy and compliance

Demonstrates alignment with european privacy law and transparent personal-data handling.

GDPR compliance

The platform meets eu data protection obligations, including eu-only hosting, lawful processing and support for all data-subject rights.

Appointed data protection officer

A designated dpo oversees privacy governance and serves as a point of contact for regulators and customers.

Data protection impact assessments

DPIAs are conducted for sensitive use cases, ensuring risks are identified and mitigated before processing begins.

Data-subject rights fulfilment within 30 days

Requests for access, deletion, portability or objection are honoured in no more than 30 days, helping customers meet legal timelines.

No customer data used for AI training

Transcripts, audio and metadata are never fed into internal models, preventing unintended reuse of personal information.

Infrastructure security

Leverages certified cloud environments and strict geographic controls to safeguard operations.

EU-only hosting for EU customers

European user data is stored exclusively in belgian and dutch data centres, supporting regional sovereignty requirements.

Regional hosting options for global users

The service can deploy data locally to satisfy regulations such as ccpa, offering flexible residency choices.

Certified cloud provider

Production runs on a cloud platform that maintains iso 27001 and soc 2 attestations, adding independent validation of foundational controls.

Separated backup storage

Backups are held in physically and logically distinct locations from production systems, reducing correlated failure risk.

Incident response

Provides a structured approach to detect, contain and communicate security events.

Documented incident response plan

Clear procedures guide investigation, containment and remediation activities to minimise business impact.

Regulatory breach notification

Affected customers are informed in accordance with laws such as GDPR, supporting transparency and legal compliance.

Post-incident review process

Every incident is audited and lessons learned are fed back into controls, driving continuous improvement.

Backup and recovery

Maintains resilient copies of critical metadata while limiting unnecessary replication of sensitive content.

Four-hour backup frequency

Metadata is backed up every four hours, limiting potential data loss in the event of system failure.

Encrypted backup storage

All backup files are encrypted and isolated, preventing compromise if backup repositories are accessed.

One-year metadata retention limit

Backed-up metadata is retained for up to a year, balancing recovery needs with privacy obligations.

No content data in backups by default

Audio and transcript files are excluded from routine snapshots unless contractually agreed, reducing exposure of sensitive material.

Third-party management

Controls how service providers handle customer information and limits downstream risk.

Data processing agreements

All subprocessors operate under strict dpas that define security and privacy obligations, extending protections beyond the core platform.

Zero-retention requirement for processors

Third-party services are contractually barred from storing customer data longer than necessary, lowering residual exposure.

Quarterly review of third-party access logs

Access by processors is logged and reviewed every quarter, ensuring continued compliance with contractual terms.

Audit and assurance

Provides independent verification and continuous oversight of the security programme.

Semi-annual internal security audits

Comprehensive internal reviews are performed every six months to evaluate control effectiveness.

Annual third-party penetration testing

External specialists test the platform each year, identifying vulnerabilities before they can be exploited.

ISO 27001 and SOC 2 type II certification roadmap

Formal certification efforts are underway, signalling commitment to widely recognised security standards.

Centralised audit logging

All user and administrator actions are captured for forensic analysis and compliance reporting.

User privacy controls

Empowers customers to tailor privacy-sensitive features to their organisational policies.

Automated recording notifications

Participants are automatically informed that a session is being recorded, supporting transparency and consent requirements.

Organisation-wide sentiment analysis toggle

Administrators can disable sentiment analysis across all workspaces, limiting processing of potentially sensitive insights.

On-demand anonymised reporting

Users may request anonymised versions of transcripts, enabling safer information sharing with broader audiences.