Skip to main content
Home›Security
Trust & Security

Security, by design.

Perceive8 processes sensitive audio — meeting recordings, conversations, and real-time streams — that our customers trust us to protect. Our approach is defense in depth, least privilege, and honesty about where we still have work to do.

How we protect your data

Multiple overlapping controls at every layer — network, application, data, and operational.

Encryption in transit

TLS 1.2+ is enforced on every connection — REST APIs, WebSocket streams, webhooks, and database traffic. Plaintext HTTP is rejected and HSTS is enabled.

Encryption at rest

AES-256 protects the PostgreSQL database and object storage. API keys are stored only as bcrypt hashes (cost 12) — plaintext keys are never kept.

Least-privilege access

Workspace-scoped roles, Supabase row-level security, and scope-limited API keys. Every resource request verifies ownership before returning data.

Isolated infrastructure

Services communicate over private networks, database access has no public endpoint, and a managed gateway is the single public entry point.

Rate limiting & DDoS

Layered limits at the gateway and per-endpoint/application level, pagination caps, and per-user concurrent stream limits prevent resource abuse.

Audit logging

Every /v1 API route is covered by audit logging — user, action, IP, and timestamp — with API-key last-used tracking for activity monitoring.

Signed webhooks

Outbound webhooks are signed with HMAC-SHA256, delivered over HTTPS only, and destination domains are verified before delivery begins.

Secure development

Peer review on every change, secrets only in managed environment variables, and Pydantic-validated payloads with strict type enforcement.

Your data is never training data.

Audio sent to AI providers for transcription and analysis travels over TLS-encrypted connections, is processed under data processing agreements that prohibit training on customer data, and is not retained by providers beyond the processing window. Provider API keys live in environment variables — never in source code or databases — and every subprocessor is vetted and listed in our subprocessor registry.

Compliance posture

Where we stand today — including the honest status of certifications we haven't started yet.

GDPR
Readiness assessed

Data inventory, retention schedule, and deletion/export workflows documented.

CCPA / CPRA
Readiness assessed

Consumer rights workflows covered by the same export and deletion pipeline.

HIPAA
Reviewed · BAA workflow

BAA workflow defined for covered teams. HIPAA has no certification — we support BAAs.

COPPA / FERPA
Reviewed

Product and data flows reviewed against child-privacy and education requirements.

SOC 2 Type II
On the roadmap

Planned — not yet initiated. We don't claim it until the audit says so.

ISO 27001
On the roadmap

Planned alongside the SOC 2 program.

A standard Data Processing Agreement (DPA) is available for customers who require one — email [email protected].

Responsible disclosure

We welcome security researchers. If you discover a vulnerability, report it privately to [email protected]— please don't disclose it publicly until we've had a reasonable opportunity to fix it, and don't access or modify other users' data.

We acknowledge reports within 2 business days, provide an initial assessment within 5 business days, remediate confirmed issues promptly, and won't pursue legal action against good-faith researchers.

In scope

  • Perceive8 API (api.perceive8.com)
  • Perceive8 MCP Server (mcp.perceive8.com)
  • Perceive8 Dashboard (app.perceive8.com)
  • Perceive8 SDKs (Python, JavaScript)

Out of scope

  • Third-party services (Supabase, Stripe, AI providers)
  • Social engineering or phishing attacks
  • Denial of service attacks
  • Physical security

Talk to us about security

Security vulnerabilities

[email protected]

Privacy inquiries

[email protected]

DPA requests

[email protected]