Skip to main content
The first questions a compliance or security review asks, answered for a self-hosted install. Each answer links to the page that documents it. Where something is not built, this page says so. The hosted service at vexa.ai is a different deployment, and it does not run the agent plane (Architecture review).

Where do recordings and transcripts land?

On infrastructure you run. Transcripts and meeting records are rows in your Postgres; recordings and agent workspaces are objects in your own storage (Where the audio goes, Recordings). Encryption at rest is planned, not shipped: today you bring your own disk or volume encryption (Known gaps).

Which model reads them?

One you run, if you set it up that way. Point transcription at the bundled unit or any OpenAI-compatible endpoint you host (Transcription), and point agents at your own LLM endpoint (Agent inference). The quickstart as written uses hosted transcription, so self-hosting the rest does not by itself remove egress (The egress answer). On Kubernetes, one setting still goes through extraEnv (No-egress clusters). These docs describe no consent or notice feature. The bot joins the call like any participant, under the name you configure (Bot participant name), and on Meet and Teams a host may have to admit it from the lobby (Send a bot). Telling participants, and recording their consent, is up to your firm.

Single sign-on

Sign-in to the Terminal is Google or Microsoft OAuth (Kubernetes). SAML is not built. SSO with Okta or Entra, with SCIM, is listed as planned (Identity).

Retention

Today: No. There is no retention policy. Deletion is per recording or per meeting, by API (Delete a recording). Roadmap: Retention and deletion controls.

Read audit log

Not built. There is no log of who read a transcript or a recording.

What is not captured

The bot captures Google Meet, Microsoft Teams and Zoom calls. Not captured today:

Certifications

None claimed (Known gaps).