> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vexa.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Regulated deployment

> The first questions a compliance review asks about a self-hosted Vexa, answered in one place: where records land, which model reads them, and what is not built yet.

The first questions a compliance or security review asks, answered for a self-hosted install.
Each answer links to the page that documents it. Where something is not built, this page says so.

The hosted service at vexa.ai is a different deployment, and it does not run the agent plane
([Architecture review](/architecture/evaluation#1-what-runs-where)).

## Where do recordings and transcripts land?

On infrastructure you run. Transcripts and meeting records are rows in your Postgres; recordings
and agent workspaces are objects in your own storage
([Where the audio goes](/architecture/evaluation#2-where-the-audio-goes),
[Recordings](/how-to/recordings)). Encryption at rest is planned, not shipped: today you bring
your own disk or volume encryption ([Known gaps](/security-compliance#known-gaps-honest)).

## Which model reads them?

One you run, if you set it up that way. Point transcription at the bundled unit or any
OpenAI-compatible endpoint you host ([Transcription](/deployment#transcription-the-separate-gpu-unit)),
and point agents at your own LLM endpoint ([Agent inference](/configuration#agent-inference-bring-your-own)).
The quickstart as written uses hosted transcription, so self-hosting the rest does not by itself
remove egress ([The egress answer](/architecture/evaluation#the-egress-answer-precisely)). On
Kubernetes, one setting still goes through `extraEnv`
([No-egress clusters](/deployment-kubernetes#no-egress-clusters)).

## Consent

These docs describe no consent or notice feature. The bot joins the call like any participant,
under the name you configure ([Bot participant name](/configuration#bot-participant-name)),
and on Meet and Teams a host may have to admit it from the lobby
([Send a bot](/how-to/send-a-bot)). Telling participants, and recording their consent, is up to
your firm.

## Single sign-on

Sign-in to the Terminal is Google or Microsoft OAuth ([Kubernetes](/deployment-kubernetes)).
SAML is not built. SSO with Okta or Entra, with SCIM, is listed as planned
([Identity](/core/identity#where-we-are)).

## Retention

**Today: No.** There is no retention policy. Deletion is per recording or per meeting, by API
([Delete a recording](/how-to/recordings#delete-a-recording)). Roadmap:
[Retention and deletion controls](/roadmap/items/retention-deletion-controls).

## Read audit log

Not built. There is no log of who read a transcript or a recording.

## What is not captured

The bot captures Google Meet, Microsoft Teams and Zoom calls. Not captured today:

* in-person meetings ([roadmap](/roadmap/items/in-person-upload));
* phone dial-in ([roadmap](/roadmap/items/dial-in-capture));
* Webex ([roadmap](/roadmap/items/webex-attendance)).

## Certifications

None claimed ([Known gaps](/architecture/evaluation#7-known-gaps-in-one-place)).

## Read next

* [Security & compliance](/security-compliance): deployment posture, trust model and the audit
  artifacts in the repo.
* [Kubernetes](/deployment-kubernetes): the Helm install.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.