Security
Version 2026.10.02.1
This page describes the security practices that actually run in YOTEXT today. We do not show claims we have not achieved.
Data separated per workspace
Every meeting, task, and usage record can only be accessed by members of the workspace it belongs to. Members who are removed lose access to the organization's meetings right away.
Accounts and sessions
Sign in uses Google accounts with verified email addresses. Sign in sessions are protected, and requests from other sites are rejected.
Encryption in transit
All data travels over encrypted connections. Links to play or download audio are only valid for a short time.
Audit log
Sensitive actions such as sign in, sharing, meeting deletion, member changes, data export, and admin actions are recorded. Workspace owners and admins can view the workspace activity log. Logs are kept for 365 days without meeting content and with pseudonymized IP addresses.
Retention and deletion
Users can download all their data and delete their account themselves. Workspaces can set a retention limit, and meetings older than that limit are deleted automatically together with their audio.
Secure development
Every change is tested automatically before release, including tests for data separation and sharing pages. A release is stopped when a critical security issue is found.
Reporting a vulnerability
Send reports to support@yotext.app. Do not access other users' data or run destructive tests. We respond to valid reports as quickly as we can.
Certification status
YOTEXT does not yet have a SOC 2 report or an ISO/IEC 27001 certificate. Our controls are designed with reference to those frameworks and to UU PDP, GDPR, and PIPL. We will update this page when an independent audit is complete.