The evidence layer
your security team can sign off on.
Citesvue handles the recordings teams use to make the most consequential decisions in their week. We engineer it like that's true.
Your recordings are yours. Deleting them means deleting them.
Recordings are processed into a structured evidence layer: transcripts, frames, and artifacts. Everything stays inside your workspace, scoped to your account at every query. When you delete a recording, both the source media and the derived evidence are removed. When you delete your account, your data goes with it.
- Deletion that deletes
Removing a recording removes the uploaded media and every derived artifact. Account deletion is irreversible and removes workspace data across our systems.
- Tenancy isolation
Every query is scoped to your workspace at the data layer. Cross-tenant access is treated as a defect of the highest severity.
- Audit trail
Security-sensitive events such as sign-ins, password changes, and membership changes are recorded in an internal audit trail.
Encrypted in transit. Encrypted at rest. Least privilege throughout.
All traffic to and from Citesvue is encrypted in transit with modern TLS. Data at rest lives on infrastructure that encrypts every object and database with AES-256. The most sensitive secrets we hold, such as OAuth tokens for your connected calendar and Google account, carry an additional layer of application-level AES-256-GCM encryption with purpose-scoped keys.
- Transit
Modern TLS with strong cipher suites on every connection, including service-to-service traffic.
- At rest
AES-256 across storage and databases, with an extra application-level encryption layer on OAuth tokens and comparable secrets.
- Least scopes
Third-party access uses the narrowest scopes offered. Google export, for example, can only touch files it creates in your Drive.
We describe our controls. We do not claim certificates we do not hold.
Citesvue is built on GDPR-aligned practices: data minimisation, deletion on request, and a DPA available to any customer who needs one. Formal certification programmes are on our roadmap and will be announced here when a report actually exists, not before.
- GDPR
Deletion and export on request, a DPA available for signature, and standard contractual clauses where cross-border transfers require them.
- Payments
Card data is handled entirely by Stripe, a PCI DSS Level 1 provider. Citesvue never sees or stores card numbers.
- Certifications
SOC 2 and similar programmes are roadmap, not claims. If your requirements depend on a specific certification, talk to us before relying on Citesvue for regulated data.
For the security and legal teams who need to sign things.
Citesvue’s Enterprise track is where the sign-off conversations happen: contractual retention terms, DPAs, and the security roadmap with dates attached. We list what ships today and what is still roadmap, never the other way around.
- Access
Email and password sign-in with revocable sessions and role-based workspace membership today. SAML SSO with SCIM provisioning is on the Enterprise roadmap, not yet available.
- Residency
Data is stored on Cloudflare’s global network with encryption at rest and in transit. Regional pinning is on the roadmap.
- Deployment
Cloud-managed multi-tenant today. Single-tenant and self-hosted options are Enterprise-roadmap conversations, not shipping features.
DPA, sub-processor list, and security questions: all on request.
We'll answer your security questionnaire honestly, walk you through the controls described on this page, and send a DPA for signature. Expect a reply within one business day.