Security at Punkto

What actually happens to a meeting. Written for a DPO, not for a landing page.

The audio promise

The audio file is stored temporarily on our EU server, sent to Mistral in France for the transcript, then deleted once the transcript and the summary are saved. If transcription fails, it is deleted within 24 hours. The account keeps the text, encrypted with AES-256-GCM, not the audio.

Encryption

Transcripts at restAES-256-GCMEncrypted in the application before they are stored
In transitTLS 1.2+Every connection
Confidential filesAES-256-GCMKey generated in the browser, kept in the URL fragment, never sent
PasswordsArgon2idBetter Auth. Never stored in clear text

Audio and transcript

Kept in the accountNothingNo player, no download, audio path stays empty
While processingEU diskDeleted after success. Up to 24 hours if the job fails, then purged
TranscriptEncryptedAES-256-GCM, EU database
SummaryEncryptedSame encryption as the transcript

Infrastructure

HostingEUHetzner, European Union
DatabaseSelf-hostedPostgreSQL on our EU server
Real-time syncSelf-hostedYjs WebSocket server, same EU machine
Video and audioSelf-hostedLiveKit and coturn on our server. Not LiveKit Cloud
TranscriptionFranceMistral Voxtral. No US fallback

Access

AuthenticationEmail + TOTPBetter Auth. Two-factor is available to every account
Session dataOwnerChecked in the application, not by database row-level security
Board modesThreeStandard, ephemeral (nothing saved), confidential (files encrypted in the browser)
Board contentTextCards and chat are not end-to-end encrypted

Compliance

GDPRYesEU controller, EU processing of meeting data. DPA on Enterprise
Data processing agreementEnterpriseArticle 28, on request
ResidencyEUCard payments are the exception: Stripe, Inc. (US), standard contractual clauses
ProcessorsListedPrivacy policy names Hetzner, Mistral, Brevo, Stripe, and optional Google sign-in
Breach notice72 hArticle 33

Zero audio retention — what that means

The audio file is stored temporarily on our EU server, then deleted. It does not stay in the account.

  1. The host starts the recording. On a Direct call, our own LiveKit server in the EU writes an audio-only file. The camera is not in it.
  2. That file stays on our server. It is not sent to a LiveKit cloud account.
  3. We send it over TLS to Mistral Voxtral in France. Mistral returns text. Their API terms say this content is not used to train models.
  4. The transcript and the summary are encrypted (AES-256-GCM) and stored. The audio-path column stays empty.
  5. The file is deleted. If transcription fails, it can remain for up to 24 hours so the job can be retried, then it is purged.

There is no audio player and no download. The temporary file is a buffer on our EU disk, not a recording we hand back.

Questions

Can Punkto staff read a transcript?

Transcripts are stored encrypted. Decryption is for the product paths that deliver the summary to the host. Reading a customer transcript for support needs the customer’s agreement.

What is deleted with the account?

Boards, transcripts, and summaries. Deletion is not a soft hide. Backups roll for 7 days. After that window, we have no copy to restore.

Are cards and chat encrypted end to end?

No. Cards, chat, and action items are text in our EU database, limited to the owner and the people in the session. Confidential mode encrypts files in the browser. It does not encrypt the board.

How do confidential files work?

The browser generates an AES-256-GCM key and puts it in the URL fragment (#k=). Browsers do not send that fragment to the server. Files are encrypted before upload. The server stores ciphertext.

What happens in an incident?

We triage a security incident within 4 hours of detecting it. Affected customers are told within 72 hours under article 33, sooner if confidentiality is at stake.

Reports and DPAs

Security reports and DPA requests go to contact@punkto.app. We answer a security report within 24 hours.

Enterprise and complianceHow the audio is handled