SANDBOX ENVIRONMENT - This is a testing environment. Data may be reset at any time.

Security and Privacy
at Neurameet

Your trust is everything. We've made security non-negotiable, and it shapes every decision we make. Your school's information is protected from the moment you record a meeting to when you share a report.

Compliant by design, not as an afterthought.

Neurameet acts as your data processor under UK GDPR and the Data Protection Act 2018. Your data protection team gets the documentation and controls they need before you ever go live.

View our Trust Centre

Data Processing Agreement

Clear, documented processing purposes and retention periods for every category of data.

Data subject rights

Access, rectification and erasure requests handled within statutory timescales.

Sub-processors disclosed

Full list with processing locations and advance notice of any change.

Breach notification

Any qualifying breach reported to you within 72 hours, as UK GDPR requires.

Your data is stored in the UK, with
transparent processing.

Every recording, transcript and action item is stored exclusively in ISO 27001-certified UK data centres. When AI services process your data, they're protected by Standard Contractual Clauses and security safeguards. You can see which partners are involved and review them anytime in our Trust Centre.

Governance

We establish security policies and controls across every layer of our platform, then continuously monitor adherence to ensure they remain effective. Our security governance is not a one-time effort. It's an ongoing commitment to protect your data. Our approach is guided by foundational principles:

Access to systems and data is limited to those with legitimate business need, following the principle of least privilege.

Security controls are implemented in layers. No single control is relied upon; we use defence in depth throughout our platform.

Security practices are applied consistently across all of our systems and operations. There are no exceptions.

Controls are continuously reviewed and improved. Our approach evolves as new threats and technologies emerge.

Security and Compliance

We maintain Cyber Essentials certification, a government-backed scheme covering fundamental security controls.

View our certification · ICO Registration

You decide what we keep and for how long.

No lock-in, no surprises. Export or erase your data on demand.

Clear retention periods

Recordings are automatically deleted once your minutes are generated. Transcripts, minutes and action items are retained for the period your school sets.

Delete on demand

Permanently delete any meeting in a click. Deleted data is purged from live systems and backups.

Export anytime

Download minutes and action items as PDF or CSV whenever you need them. Your records are always portable, no lock-in.

Account closure

If you decide to leave, we erase all your data and can issue a certificate of deletion for your records.

Data Protection

Data at rest

All data at rest is encrypted using AES-256 encryption across our storage systems. This includes data stored in object storage, databases, and backups, providing multiple layers of protection for your information.

Data in transit

We use TLS 1.2 or higher to protect data transmitted between your browser and our servers. We also employ HSTS (HTTP Strict Transport Security) across all endpoints to maximise the security of data in transit.

Secret management

Encryption keys and sensitive secrets are securely managed and encrypted at rest. Access is strictly restricted and monitored to ensure only authorised systems can retrieve and use these credentials.

Product Security

Role-based permissions

Access to meetings, minutes, and reports is controlled by configurable roles. Staff only see what they need. Each school account is fully isolated with no cross-account data access.

Session management

Sessions are short-lived and invalidated on sign-out. We support two-factor authentication for all accounts. Encryption keys are rotated regularly per security best practices.

Vulnerability scanning

We continuously scan our codebase and infrastructure for known vulnerabilities using automated security tools. All dependencies are monitored for security updates and we patch identified issues promptly.

Dependency management

We maintain a strict inventory of all third-party dependencies and regularly review them for security and maintenance. Known vulnerable packages are identified and updated immediately.

Enterprise Security

Hosting & Backups

Neurameet is hosted on dedicated servers within the United Kingdom. Data is backed up daily and encrypted separately. Uptime is monitored continuously with formal incident response processes.

Incident Response

In the event of a data breach, we notify affected schools promptly and report to the ICO where required by UK GDPR. We maintain formal incident response procedures to investigate and resolve breaches quickly.

ICO Registration: ZB966092 (Data Processor)

Endpoint Protection

All devices accessing Neurameet internal systems are required to meet security standards including up-to-date operating systems, antivirus protection, and encryption. Remote access is restricted to authenticated, authorised users only.

Security Education

Our team participates in ongoing security training and awareness programmes. We stay current with emerging threats and security best practices to continuously improve our defences.

Identity & Access Management

Access to Neurameet internal systems is controlled using role-based access management. We enforce multi-factor authentication across all accounts and require strong authentication methods.

Responsible Disclosure

If you discover a security vulnerability, please email security@neurameet.com rather than disclosing it publicly. We'll work with you to resolve it promptly and fairly.

AI Security

Meeting audio is processed by AI services to generate transcripts and minutes. These services operate under data processing agreements with equivalent protection standards.

Your meeting content is never used to train AI models.

Data Privacy

Neurameet is committed to protecting your data under UK GDPR. Our privacy and data protection agreements are available below.

Privacy Policy

Our privacy policy outlines how we collect, use, and protect your personal data in accordance with UK GDPR and UK Data Protection Act 2018.

View our Privacy Policy

Data Protection Policy

Detailed policy on our compliance with UK GDPR principles, data subject rights, sub-processors, and breach management procedures.

View our Data Protection Policy

Subprocessors

We maintain a complete list of subprocessors authorised to process data on your behalf. Changes are notified in advance.

View our Subprocessors

Trust Centre

Overview of our security controls, compliance certifications, and detailed information about how we protect your data.

View our Trust Centre