Trust Center · Reviewed September 17, 2026

    Honest posture, not a badge wall.

    This page is maintained by the Instaconnect team to describe the current review scope. It is not an independent certification — and we mark clearly what we do not claim.

    Deployment review

    What to verify for your intended workflow.

    Authentication & access

    JWT-based session auth with bcrypt password hashing. Optional Auth0, Firebase Auth and Cognito identity hooks. RBAC: permission codes gate the sidebar and route guards today. Verify resolver-level enforcement, provisioning and offboarding behavior for the selected workflow before rollout.

    Multi-tenant isolation

    The product uses tenant and Space concepts. Validate the deployed data boundaries and access permissions with test roles before introducing customer or client data; a workspace label is not independent evidence of isolation.

    Data in transit & at rest

    Review transport, storage and key-management evidence for the actual platform deployment. The marketing website and application are separate surfaces; the website hosting provider alone does not establish the application architecture. Customer-managed keys are not currently advertised.

    Recordings & transcripts

    Recordings are scoped to the originating Space and gated by role. Per-tenant meeting allowance and usage counters govern volume. Transcripts (Whisper) and AI summaries (GPT) inherit the same Space-scope and role gates.

    Subprocessors

    The marketing website uses Lovable hosting and a connected database for enquiry records. Application features may involve video, AI, realtime and voice providers. The Service Providers page identifies the marketing-site providers. Request the application deployment schedule before entering a processing agreement.

    Privacy & deletion

    Customers can request data export and deletion through the Contact channel. Standard DPA terms are available for incorporation into a written agreement with an agreed deployment schedule. We do not currently expose self-serve in-product export/deletion.

    What we don't claim

    The honest section.

    If a future buyer or auditor reads this page, here is what we explicitly do not assert.

    • No SOC 2 report, ISO 27001 certification, PCI-DSS validation or FedRAMP authorization is claimed here. Instaconnect does not offer a BAA today; do not use it for protected health information or clinical workflows.
    • We do not currently publish a public penetration-test summary, sub-processor change log, or status-page incident history.
    • Confirm data residency, retention and processing requirements for the intended deployment before enabling recordings, transcripts or other sensitive workflows.

    Security questionnaire or DPA?

    For data deletion, subprocessor details or a deployment-specific review, contact the team with your requirements.