Built to pass your security review.
Disclosure, watermarking, data residency, and governance aren't settings to hunt for — they are how MeetCrew is built. This is the short version — the full security overview (PDF) is the long one.
Every disclosure, opt-out, and deletion is written to a hash-chained log. A nightly integrity check re-verifies it end to end — a failure raises an alert and is never silently overwritten.
It can't quietly be in the room.
Every teammate makes itself known — and can't switch its own disclosure off.
In the participant list
It appears as a named participant with an AI badge — not a hidden background bot.
On screen, every frame
An "AI colleague" banner is composited into every frame it sends, for the whole meeting. It ships on and can't be turned off by end users.
It says so, out loud
When it joins, it introduces itself audibly as an AI participant.
Anyone can opt out, live
Say "[Name], please leave" or "don't remember this conversation" and it is honored immediately — and logged.
Only where an admin allowed it
A teammate joins only the meetings a tenant admin has authorized — no self-service crashing of calls.
No voice biometrics. By design.
The biometric-privacy lawsuits hitting meeting AI are about voiceprints. MeetCrew is architected to remove the most common basis for these claims: it recognizes people the way your directory already does, and stores no voice-derived biometrics anywhere.
Cross-meeting recognition uses Microsoft Entra platform identity — email and display name — never voice characteristics.
No voice-derived biometric identifier is created or stored in the schema, for anyone in the meeting.
Speakers without a durable identifier stay anonymous by label; named attribution is off by default in v1.
The consent-gated attribution controls stay dormant unless named attribution is ever switched on.
Meeting memory your agent can read — and act on.
MeetCrew exposes structured meeting memory to your own agent over an MCP server or API — under your identity, inside your tenant. Your agent reads what was decided and acts on it: close an action item, resolve an open question, update a decision.
It’s your agent, not ours
Access runs under a Microsoft Entra service principal your admin grants in the console — and can revoke. No shared keys, no MeetCrew back door.
Scoped to your tenant, enforced by us
Every call is locked to a single tenant and enforced server-side. Another customer’s agent can’t reach your memory — not even by guessing IDs.
Down to a single teammate
Reads and actions are scoped to one named deployment by default. Reaching across deployments takes an explicit admin opt-in.
Actionable, within hard limits
Your agent reads decisions, action items, open questions, statements, and topics — and acts on the workflow ones: close an action item, resolve an open question, update a decision. It can’t delete records, rewrite transcripts, or touch provenance or the audit trail.
No voiceprints exposed
Attribution comes from Microsoft Entra identity, not voice. The interface exposes no voiceprints and no speaker audio, and content stays in the Azure boundary.
Every read and write is logged
Every read and every action over the MCP server and API is logged and attributable to the Entra identity that made it — you can see who did what, and when.
Everything it says is watermarked and provable.
Watermarked speech
Its synthesized voice carries an audio watermark, sealed at the moment of synthesis.
C2PA content credentials
Stored artifacts carry C2PA-style origin metadata — what was generated, when, and by which teammate.
A tamper-evident audit chain
Disclosures, opt-outs, and deletions are hash-chained and re-verified nightly. Fail-closed: a broken link alerts, it is not quietly rewritten.
Your data, your region, your keys.
Language inference runs on in-region Azure OpenAI — meeting content stays inside the Azure boundary.
Each deployment is pinned to its region, with no cross-region replication of your data.
The meeting bot runs Zero Data Retention by default — the vendor keeps no recording at any point — so your durable memory exists only in your MeetCrew tenant.
A teammate will not join if the organizer's tenant is out of scope. Illinois, the EU, and the UK are excluded in v1.
Retention is enforced to the jurisdiction's statutory ceiling; expired records are cryptographically shredded.
On a data-subject deletion request, the person is regenerated out of the memory your agents query and search — not merely hidden — and a durable marker stops any later re-extraction from reintroducing them. The source transcript is a bounded, non-queryable residual, deleted on request.
On Enterprise, your memory is encrypted at rest under a key held in your own Azure Key Vault or Managed HSM — across all three memory tiers. Rotate or revoke it whenever you need; revoke, and the data goes dark.
Exports are encrypted twice — a tenant key plus your own recipient key — so data leaving the boundary stays yours.
Your meeting content is not used to train any model — ours or anyone else's.
Governed by your admins. Isolated by tenant.
Microsoft Entra, end to end
Teammates authenticate through Entra; access follows your existing identity and conditional-access policies.
Tenant-admin authorization
Admins decide which teammates exist, where they may join, and who can configure them — per deployment.
Every action attributed
Administrative actions are recorded against the real administrator, distinct from the anonymized meeting record.
Hard tenant isolation
One MeetCrew tenant maps to one Entra tenant, with hard isolation between customers by construction.
We built for the law meeting AI is running into.
AI in meetings is under real legal pressure — biometric-privacy law like Illinois' BIPA (740 ILCS 14) and data-protection rules like GDPR Article 4(11). We did not bolt compliance on afterward; we architected MeetCrew so the most aggressive theories have far less to attach to: no voiceprints, disclosure that ships on, and geo-fencing out of the regions where the rules bite hardest. This describes how the product is built and is not legal advice.
Bring your security team to the demo.
We like those meetings. We will walk your controls, share the security overview, and answer the hard questions.
These are architecture commitments, not third-party certifications — MeetCrew is not SOC 2 certified yet (it is on the roadmap), so today we walk your team through the controls directly. You remain responsible for obtaining any recording or participation consent your jurisdiction requires. Availability is limited to supported regions (US excluding Illinois, and Canada, in v1). Microsoft, Teams, Entra, and Azure are trademarks of Microsoft; MeetCrew is an independent Microsoft Partner. Found a security issue? Report a vulnerability.