For regulated European teams

Meetings you can bring to your DPO.

Punkto is built for European organisations where compliance is not optional — healthcare, legal, finance, public sector, research. Meeting data stays in the EU. Audio is not kept in the account. Signed DPA. Card payments go through Stripe.

Why Punkto for compliance-driven teams

EU data residency

Meeting data stays on European infrastructure (Hetzner). No AWS, no Google Cloud, no Azure on that path.

No US parent

Punkto has no US parent. Meeting content is processed in the EU. Stripe charges the card in the US under standard contractual clauses and does not receive the meeting. Google is contacted only if someone chooses Google sign-in.

Signed DPA

Signed Data Processing Agreement available on Enterprise plans. Article 28 GDPR–compliant, negotiated with your legal team.

Audit logs

Full audit trail on every board, recording and action item. Exportable JSON / CSV via webhook or API.

Audio not kept in the account

Stored temporarily on our EU server, sent to Mistral in France, then deleted. Within 24 hours if transcription fails. The account keeps the text, not the audio.

Ephemeral & zero-knowledge modes

Run sessions that leave no trace in the database, or ones where shared files are encrypted client-side with a key that never touches our servers.

How Punkto compares

Versus typical US-hosted meeting-AI tools (Otter.ai, Fireflies, Tactiq, Fathom).

Hosting region
Typical US tool: 🇺🇸 AWS / GCP (various)
Punkto: 🇪🇺 European Union
CLOUD Act on meeting content
Typical US tool: Yes
Punkto: No
Signed DPA
Typical US tool: Usually
Punkto: Yes
AI model training on your data
Typical US tool: Often opt-out only
Punkto: Not under Mistral API terms
Third-party analytics
Typical US tool: Common
Punkto: None
Who operates the stack
Typical US tool: A US cloud
Punkto: Punkto, in the EU

Full subprocessor transparency

Every third-party service we use, where they're based, what they do. No hidden vendors.

Infrastructure
European hosting (EU)
Database & Storage
Self-hosted, EU region
AI transcription
Mistral, France
Real-time sync
Self-hosted CRDT
Audio/video rooms
Self-hosted, EU region
Email delivery
Brevo, France, transactional only
Analytics
First-party counter on our server. No ad pixels.

Enterprise compliance roadmap

Available

  • •EU hosting
  • •Signed DPA
  • •Private recordings
  • •Ephemeral mode
  • •E2E files

In progress

  • •SSO (SAML / OIDC)
  • •Audit log export (webhook)
  • •Self-hosted deployment

Roadmap

  • •ISO 27001
  • •SOC 2 Type II
  • •HIPAA BAA
  • •Fine-grained retention policies

Talk to us before you send us an RFP.

Fifteen minutes is usually enough to confirm Punkto fits your compliance profile. Bring your DPO, bring your questions.

Book a call →