Built to be trusted
Noots handles your most sensitive conversations, so security is foundational, not an add-on. For a formal review or DPA, reach security@cartexdata.com.
Encryption everywhere
Data is encrypted in transit (TLS) and at rest. Session tokens are signed and httpOnly.
Least-privilege access
Role-based permissions (owner / admin / member / viewer) gate every sensitive action.
Your data stays yours
We never train third-party models on your private meeting content, it's processed only to produce your summaries.
Granular deletion
Deleted items sit in a recoverable bin and are permanently purged on a schedule. Delete your org anytime.
Controls for regulated teams
- SSO / SAML
- SCIM provisioning
- Audit logs
- Data-residency policy
- IP allowlisting
- Custom retention
- Append-only compliance log
What we don’t claim
Noots holds no SOC 2, ISO 27001, HIPAA or FedRAMP certification, and we will never imply one on this site. The controls above are real and you are welcome to assess them; the certification is not something we have. If a formal attestation is a requirement for you, tell us where you are in your process and we will be straight with you about what we can and cannot sign today.
We also publish no uptime SLA. A data-residency policy is recorded per workspace and written to the audit log; moving data already at rest to another region is a migration our team schedules with you.
