๐Ÿ”

Legal

Security

How GlobeMeet protects your operations

Security posture across the marketing site, the platform, and our internal operations. Email security@globemeet.in to disclose vulnerabilities โ€” we respond within 24 hours.

TLS 1.3

Required on every transport

AES-256

Recordings at rest

Quarterly

Third-party pentests

24h

Vulnerability response

01

Platform security controls

All transport encrypted (TLS 1.3, DTLS-SRTP). Recordings encrypted at rest with AES-256. Signed-URL playback only. SSO via SAML 2.0 / OIDC. Per-tenant key isolation. Tamper-evident audit log.

  • TLS 1.3 + DTLS-SRTP on every transport
  • AES-256 at rest (KMS or per-tenant keys)
  • Signed-URL playback (no public recording URLs)
  • SSO via SAML / OIDC
  • Role-based access control with deny-by-default
  • Per-tenant data isolation enforced at API and storage layer
02

Operational security

Quarterly third-party penetration testing. Dependency CVE monitoring with automated weekly alerts. Reproducible Docker builds with signed manifests. Pre-shared signed releases. Internal security training for every team member, refreshed annually.

03

Incident response

Documented IR playbook covering detection, containment, eradication, recovery, and post-mortem. Ours and yours connect at the contract โ€” we agree in writing on roles and notification timing for incidents that affect your data.

04

Vulnerability disclosure

Email security@globemeet.in. We respond within 24 hours, triage within 72 hours, and credit responsible disclosure publicly (with your permission). We do not pursue legal action against good-faith researchers.

05

Roadmap

ISO 27001 certification (in progress, target Q4 2026). SOC 2 Type II for the managed cloud (planning stage). Bug-bounty program (under evaluation).

SPEC

Technical specifications

Transport
TLS 1.3 + DTLS-SRTP
At rest
AES-256 with per-tenant or KMS keys
Auth
SAML 2.0 ยท OIDC ยท OAuth 2.0
Audit log
Hash-chained, tamper-evident, exportable
Pen test
Quarterly, third-party (CERT-In empanelled)
CVE monitoring
Weekly automated scans on all dependencies
FAQ

Frequently asked questions

Not yet for the platform. We're targeting SOC 2 Type II for the managed cloud during 2026. ISO 27001 is further along โ€” currently in audit phase.

Yes โ€” for self-hosted deployments you can pentest your own instance freely. For managed cloud, request a pentest window via security@globemeet.in.

Customer-affecting advisories go to a private mailing list of named contacts at every customer. Public advisories (post-fix) go on globemeet.in/security.