Platform security controls
All transport encrypted (TLS 1.3, DTLS-SRTP). Recordings encrypted at rest with AES-256. Signed-URL playback only. SSO via SAML 2.0 / OIDC. Per-tenant key isolation. Tamper-evident audit log.
- TLS 1.3 + DTLS-SRTP on every transport
- AES-256 at rest (KMS or per-tenant keys)
- Signed-URL playback (no public recording URLs)
- SSO via SAML / OIDC
- Role-based access control with deny-by-default
- Per-tenant data isolation enforced at API and storage layer