Trust

Security & architecture

Current as of July 2026 · Questions? [email protected]

Like everything in Vogata: not declared, demonstrated.

We ask your team for evidence, not promises. It would be odd if our security worked the other way around. So this page doesn't say "your data is safe": it explains how the platform is built and what is impossible inside it, so your technical team can judge it, not your good faith.

01

Your notes are yours, period

What you write privately during a 1:1 isn't seen by your manager, the administrator, or any aggregate report. It lives in a separate space, under your name, and the shared agenda only gets what you decide to move there.

02

Your team's voice doesn't travel

The Notetaker listens, transcribes and lets go: the audio is processed locally, inside the same container that recorded it, and that container is destroyed when the meeting ends. No external provider ever receives a recording. The bot also only joins if manager and report both said yes, and that yes is stored with date, author and the version they accepted.

03

Every organization in its own space

Your company's data doesn't live alongside anyone else's. Each organization has its own space, and the platform checks identity and role before every read and every write. There is no query capable of crossing that boundary.

04

Encrypted across the whole journey

From the browser to the database and back, your data travels and lives encrypted. The access you entrust to us, like your Google Calendar, carries an extra layer with managed keys (AWS KMS) that rotate on their own.

05

Nothing left running

We don't keep servers on 24/7 with your information inside: the platform spins up to answer you and shuts down. Fewer live pieces means fewer places where something of yours could be exposed. And access keys are never written into the code.

06

Everything remembered, nothing lost

Every change to a plan, a cycle or a 1:1 leaves a mark in a log that can't be edited, including consents: who accepted what, and when. And the database can return to an exact moment in the past: a human mistake doesn't erase your team's work.

The platform

For technical teams, the layers at a high level:

FrontendNext.js · served via Amazon CloudFront
APIServerless on AWS Lambda
DataAmazon DynamoDB · encrypted at rest · point-in-time recovery
IdentityAWS Cognito · optional Google sign-in
AIModels from the leading providers, via paid business APIs · server-side keys only · your data doesn't train models
NotetakerEphemeral container · local transcription · no audio persisted
RegionAWS us-east-2 (Ohio)

Your data and AI

Vogata's AI runs on models from the market's leading providers, contracted through their paid business tier. That contract carries the clause we care about most: what your organization sends can't be used to train their models. The keys for those services never touch your browser either: they live server-side. Who are they, exactly? Name, purpose and country for each one are in the subprocessors table of our Privacy Policy.

Certifications

We'd rather be straight with you than impressive: we are not SOC 2 certified today. We build SOC 2‑aligned, and our infrastructure runs on AWS, a provider with mature security programs and its own independent audits. As we grow, formal certification is on the roadmap. Until then, we won't claim a badge we haven't earned.

Responsible disclosure

If you believe you've found a security vulnerability in Vogata, please tell us before disclosing it publicly. Email [email protected] with enough detail to reproduce the issue. We'll acknowledge your report, work with you to understand and fix it, and we won't pursue action against good-faith research that respects our users' privacy and avoids degrading the service. We genuinely appreciate the help.

Does your company need more paperwork?

Audits, security questionnaires, tailored agreements: write to us and we'll go through them together. Straight answers, from the person who built this.