Like everything in Vogata: not declared, demonstrated.
We ask your team for evidence, not promises. It would be odd if our security worked the other way around. So this page doesn't say "your data is safe": it explains how the platform is built and what is impossible inside it, so your technical team can judge it, not your good faith.
Your notes are yours, period
What you write privately during a 1:1 isn't seen by your manager, the administrator, or any aggregate report. It lives in a separate space, under your name, and the shared agenda only gets what you decide to move there.
Your team's voice doesn't travel
The Notetaker listens, transcribes and lets go: the audio is processed locally, inside the same container that recorded it, and that container is destroyed when the meeting ends. No external provider ever receives a recording. The bot also only joins if manager and report both said yes, and that yes is stored with date, author and the version they accepted.
Every organization in its own space
Your company's data doesn't live alongside anyone else's. Each organization has its own space, and the platform checks identity and role before every read and every write. There is no query capable of crossing that boundary.
Encrypted across the whole journey
From the browser to the database and back, your data travels and lives encrypted. The access you entrust to us, like your Google Calendar, carries an extra layer with managed keys (AWS KMS) that rotate on their own.
Nothing left running
We don't keep servers on 24/7 with your information inside: the platform spins up to answer you and shuts down. Fewer live pieces means fewer places where something of yours could be exposed. And access keys are never written into the code.
Everything remembered, nothing lost
Every change to a plan, a cycle or a 1:1 leaves a mark in a log that can't be edited, including consents: who accepted what, and when. And the database can return to an exact moment in the past: a human mistake doesn't erase your team's work.
The platform
For technical teams, the layers at a high level:
Your data and AI
Vogata's AI runs on models from the market's leading providers, contracted through their paid business tier. That contract carries the clause we care about most: what your organization sends can't be used to train their models. The keys for those services never touch your browser either: they live server-side. Who are they, exactly? Name, purpose and country for each one are in the subprocessors table of our Privacy Policy.
Certifications
We'd rather be straight with you than impressive: we are not SOC 2 certified today. We build SOC 2‑aligned, and our infrastructure runs on AWS, a provider with mature security programs and its own independent audits. As we grow, formal certification is on the roadmap. Until then, we won't claim a badge we haven't earned.
Responsible disclosure
If you believe you've found a security vulnerability in Vogata, please tell us before disclosing it publicly. Email [email protected] with enough detail to reproduce the issue. We'll acknowledge your report, work with you to understand and fix it, and we won't pursue action against good-faith research that respects our users' privacy and avoids degrading the service. We genuinely appreciate the help.
Does your company need more paperwork?
Audits, security questionnaires, tailored agreements: write to us and we'll go through them together. Straight answers, from the person who built this.