Security and privacy
Recorded meetings are sensitive material, so this page states plainly who can see your evidence, what encryption covers, what happens to it during AI processing, and what deletion actually removes.
- Updated
- 26 August 2026
- Read
- 5 min
- For
- Anyone assessing Citesvue
Who can see what.
- Your workspace is the boundary
Recordings, documents, findings, and answers belong to the workspace, and only its members can reach them. There is no cross-workspace view, and no shared pool.
- Roles decide what a member can do
Owner, Admin, Member, and Viewer. A viewer can read everything and change nothing - including sending anything out through an integration.
- Sharing is explicit and revocable
A share link shows a read-only summary of one recording: its title, length, and status. It carries no transcript, no media, and no owner identity. Links expire on a schedule you choose, and regenerating one revokes the old one immediately.
How your content and credentials are protected.
Traffic uses modern TLS, and stored objects and databases are encrypted by the platform they sit on.
When you connect Jira, Linear, Notion, Slack, or a webhook, the credential is encrypted again at the application level before it is stored, and is never shown back to you in full.
Every delivery carries an HMAC signature your receiver can verify, so your endpoint can prove a request came from Citesvue and reject replays.
A meeting URL you paste is encrypted before storage - it is a credential to the meeting, and it is treated as one.
What the models do, and do not, do with your content.
- Your content is not training data
Recordings, documents, transcripts, and everything derived from them are never used to train models.
- Answers are grounded, not invented
Questions are answered from retrieved passages of your own material. When the evidence does not support an answer, the product declines instead of guessing.
- Processing is automated
Transcription, visual analysis, and extraction run automatically. No human at Citesvue reviews your recordings as part of normal processing.
Recording people is a responsibility.
- The assistant is visible
It joins as a named participant with a recording notice. It cannot be hidden, and that is deliberate.
- You confirm authorisation
Sending the assistant asks you to confirm you are authorised to record. Recording law varies by place and by who is in the room; that judgement stays with you.
- You can stop it
Stop the assistant at any point from the dashboard, and delete the recording afterwards if it should not have been made.
The full posture, including sub-processors and data location, is on the security page and in the privacy policy.
Security and privacy, answered.
- Processing is automated and nobody reviews your content as a matter of course. Access for support purposes is limited and requires a reason; if you would like the specifics in writing for a security review, ask through the contact page.
- The media and everything derived from it go together - transcript, analysed frames, extracted findings, and the search index entries. The library slot frees immediately. Deletion is not a hidden copy.
- Retention is set by plan and runs from 30 days on the free plan to two years on Business, with custom terms on Enterprise. Export anything you need to keep beyond your plan window.
- Not today, and we do not claim otherwise. The security page sets out the controls that do exist so you can assess them directly rather than take a badge on trust.
- Not yet. Sign-in is email and password, with sessions you can review and end from your profile.
- Only what you send it. Citesvue pushes the specific content you choose to the destination you picked, using the credential you connected - it does not grant a provider access to your workspace.