Security
How we look after your transcripts.
Depositions hold medical records, finances and other people’s private lives. Here is what we do today, and what we have not done yet.
- US only
- Google Cloud, us-central1 (Iowa)
- Encrypted
- In transit and at rest
- 90 days
- Deleted after the last render
- Never trained on
- We never train AI on your transcripts
Where your data lives
One region, in the United States
- Transcripts, PDFs and our database are stored only in the US, on Google Cloud in us-central1.
- Sign-in data and accounts live in our own database, not a third-party identity provider.
- Contact requests are stored in our own database, not a third-party CRM.
- The subprocessors below handle payments, email, error reports and analytics under their own terms.
Encrypted in transit and at rest
- Every connection to the site, app and storage uses HTTPS.
- Google Cloud encrypts the database and file storage at rest.
Who can reach it
Your organization only
- Every query runs as your organization; row-level security is a second line of defence.
- Files sit under your organization’s own path, reached only through short-lived signed links.
- Share links expire within 30 days and can be revoked any time.
Your accounts
- Two-factor sign-in with an authenticator app and backup codes.
- New passwords are checked against known breaches.
- Bot protection on sign-up. No SMS codes, which can be intercepted.
Our staff
- Staff reach customer data through a separate system role; every access is logged.
- An audit trail of sign-ins, uploads, downloads, shares and deletions.
Kept out of side channels
- Logs and error reports record identifiers and codes, never transcript text.
- No AI model reads your transcripts, and we never use them to train one. Building the PDFs is deterministic software.
How long we keep it
- A transcript’s files are deleted 90 days after its last render, with the caption and witness name on its cover.
- Delete a transcript any time: files are purged at once and storage is swept again afterwards.
- An order you start but never submit is deleted after 7 days.
Subprocessors
Pending review by counsel; will be part of our data processing addendum.
| Service | What it does |
|---|---|
| Google Cloud | Hosting, database and file storage (United States) |
| Stripe | Payments and invoices |
| Postmark | Account and notification emails, and contact-sales requests |
| Sentry | Error reports: identifiers and error codes, no transcript text |
| PostHog | Website analytics, without cookies |
| Google reCAPTCHA | Bot protection on sign-up and forms |
Roadmap
Planned, not done. Dates only once committed.
- SOC 2 Type I, then Type IIComing
- An independent penetration testComing
- Customer-managed encryption keysComing
- Passkeys, and required two-factor for a whole organizationComing
- Single sign-on (SAML and OIDC) and SCIM for EnterpriseComing
- A signed data processing addendumComing
Report a vulnerability
Email security@readbackhq.com and give us a chance to fix it before telling anyone else. For a questionnaire or a call, contact us.