For regulated European teams
Meetings you can bring to your DPO.
Punkto is built for European organisations where compliance is not optional — healthcare, legal, finance, public sector, research. Meeting data stays in the EU. Audio is not kept in the account. Signed DPA. Card payments go through Stripe.
Why Punkto for compliance-driven teams
EU data residency
Meeting data stays on European infrastructure (Hetzner). No AWS, no Google Cloud, no Azure on that path.
No US parent
Punkto has no US parent. Meeting content is processed in the EU. Stripe charges the card in the US under standard contractual clauses and does not receive the meeting. Google is contacted only if someone chooses Google sign-in.
Signed DPA
Signed Data Processing Agreement available on Enterprise plans. Article 28 GDPR–compliant, negotiated with your legal team.
Audit logs
Full audit trail on every board, recording and action item. Exportable JSON / CSV via webhook or API.
Audio not kept in the account
Stored temporarily on our EU server, sent to Mistral in France, then deleted. Within 24 hours if transcription fails. The account keeps the text, not the audio.
Ephemeral & zero-knowledge modes
Run sessions that leave no trace in the database, or ones where shared files are encrypted client-side with a key that never touches our servers.
How Punkto compares
Versus typical US-hosted meeting-AI tools (Otter.ai, Fireflies, Tactiq, Fathom).
Full subprocessor transparency
Every third-party service we use, where they're based, what they do. No hidden vendors.
Enterprise compliance roadmap
Available
- •EU hosting
- •Signed DPA
- •Private recordings
- •Ephemeral mode
- •E2E files
In progress
- •SSO (SAML / OIDC)
- •Audit log export (webhook)
- •Self-hosted deployment
Roadmap
- •ISO 27001
- •SOC 2 Type II
- •HIPAA BAA
- •Fine-grained retention policies
Talk to us before you send us an RFP.
Fifteen minutes is usually enough to confirm Punkto fits your compliance profile. Bring your DPO, bring your questions.
Book a call →