Security

Built to be trusted

Noots handles your most sensitive conversations, so security is foundational, not an add-on. For a formal review or DPA, reach security@cartexdata.com.

Encryption everywhere

Data is encrypted in transit (TLS) and at rest. Session tokens are signed and httpOnly.

Least-privilege access

Role-based permissions (owner / admin / member / viewer) gate every sensitive action.

Your data stays yours

We never train third-party models on your private meeting content, it's processed only to produce your summaries.

Granular deletion

Deleted items sit in a recoverable bin and are permanently purged on a schedule. Delete your org anytime.

Enterprise

Controls for regulated teams

  • SSO / SAML
  • SCIM provisioning
  • Audit logs
  • Data-residency policy
  • IP allowlisting
  • Custom retention
  • Append-only compliance log
Request a security review

What we don’t claim

Noots holds no SOC 2, ISO 27001, HIPAA or FedRAMP certification, and we will never imply one on this site. The controls above are real and you are welcome to assess them; the certification is not something we have. If a formal attestation is a requirement for you, tell us where you are in your process and we will be straight with you about what we can and cannot sign today.

We also publish no uptime SLA. A data-residency policy is recorded per workspace and written to the audit log; moving data already at rest to another region is a migration our team schedules with you.