Security at Punkto
What actually happens to a meeting. Written for a DPO, not for a landing page.
The audio promise
The audio file is stored temporarily on our EU server, sent to Mistral in France for the transcript, then deleted once the transcript and the summary are saved. If transcription fails, it is deleted within 24 hours. The account keeps the text, encrypted with AES-256-GCM, not the audio.
Encryption
Audio and transcript
Infrastructure
Access
Compliance
Zero audio retention — what that means
The audio file is stored temporarily on our EU server, then deleted. It does not stay in the account.
- The host starts the recording. On a Direct call, our own LiveKit server in the EU writes an audio-only file. The camera is not in it.
- That file stays on our server. It is not sent to a LiveKit cloud account.
- We send it over TLS to Mistral Voxtral in France. Mistral returns text. Their API terms say this content is not used to train models.
- The transcript and the summary are encrypted (AES-256-GCM) and stored. The audio-path column stays empty.
- The file is deleted. If transcription fails, it can remain for up to 24 hours so the job can be retried, then it is purged.
There is no audio player and no download. The temporary file is a buffer on our EU disk, not a recording we hand back.
Questions
Reports and DPAs
Security reports and DPA requests go to contact@punkto.app. We answer a security report within 24 hours.