Security
No recording. Stored in London. Plainly stated.
Corrobly never records a call and never stores audio. Your notes and, when live transcript is on, the transcript text are stored in your workspace under your retention settings, where you can export or delete them. Data is stored in London and text is sent to the Anthropic API for analysis. This page describes exactly what that means.
Architecture
What we store
- Your notes, as typed, with the time into the call each line was written.
- Derived work: question coverage states, evidence snippets linking answers to notes, expert quality scores, suggestions, reports and action items.
- Deal context you enter: question guides, short fact one-liners, expert labels and ratings.
- Account details: name, email, workspace membership and role.
Data is stored in a Supabase Postgres database in London. The application runs on Vercel functions pinned to London (lhr1).
Encryption at rest and in transit is provided by our hosting providers.DRAFT - verify
What we never capture
- No audio and no video is ever sent to us, written to disk, or stored, with or without live transcript.
- No meeting bot: nothing joins your call, bridge line or conference.
- No document ingestion: no CIMs, data rooms or PDFs are uploaded or parsed.
Live transcript, if you turn it on
A call can be set up for notes only, or for notes plus a live transcript. With the transcript on, your own browser listens to the call audio you share and to your microphone, and streams that audio directly to a transcription provider using a short-lived token. The audio does not pass through our servers and is not stored by us at any point. Nothing joins the call.
The text that comes back moves the coverage board and, by default, is stored with the call's notes: deletable, exportable, and removed by the same retention job. The engine also derives question states, scores, signals and short quotes capped at 200 characters. A quote taken from speech is marked as heard rather than typed, so you can always tell the two apart. A workspace can turn transcript storage off, in which case the text is never written down: recent speech sits in memory only long enough to give the model context, and only what the engine derived is kept.
Two switches guard this, both off by default and both admin-only: whether expert calls may be transcribed at all, and whether transcripts are retained. Expert-network terms commonly forbid recording, so the person running the call must confirm consent before each capture, and that confirmation is written to the audit log.DRAFT - verify
AI processing
To map notes to your guide and score the call, note text, the question guide and related context are sent to the Anthropic API. Anthropic is not UK-hosted, so this processing happens outside the UK. We do not claim UK-only processing.
AI outputs are treated as proposals: they are validated before they are shown, and you can override any state.
No training
Customer data is never used to train models. We do not build or tune models on your notes, transcripts or reports.DRAFT - verify
Note text sent for analysis goes through Anthropic’s commercial API, whose terms govern how it handles API inputs, including retention, and do not permit training on them.DRAFT - verify
Retention and deletion
- Retention window. Admins set how many days raw notes and transcripts are kept. A daily job deletes anything older and records the purge in the audit log.
- Delete a meeting. Any call or meeting can be deleted with its notes, board, evidence and report. The audit trail is kept.
- Purge a deal. Admins can purge a deal’s raw notes manually, with typed confirmation. Derived work such as reports is kept.
- Delete all workspace data. An owner can delete every meeting in the workspace, with its notes, transcripts and reports, in one step with typed confirmation.DRAFT - verify
- Export first. Calls and deals export in Word, Excel, Markdown and JSON, so you keep a copy before anything is deleted.DRAFT - verify
Backups held by our database provider follow the provider’s own schedule.DRAFT - verify
Access control and roles
- Every record belongs to a workspace. Every server query is scoped to the signed-in member’s workspace, and row-level security is enabled on every table as a second layer.
- Roles: owner, admin and member. Admin actions such as invites, role changes and purge need admin.
- Sign-in is by email magic link or single sign-on with Google, or Microsoft where enabled. There are no passwords.
- Invites are single-use tokens, stored hashed and expiring after seven days.
Audit log
An append-only log records sensitive actions: signing in to a workspace, invites sent and accepted, role changes, purges, exports, settings changes and MNPI flags. Admins can view it and export it as CSV.
MNPI flagging
When switched on, notes that look like material non-public information raise a banner on the live screen and an entry in the audit log. It is a prompt for your judgement, not a guarantee of detection.
Subprocessors
| Provider | Purpose | Location | Data |
|---|---|---|---|
| Vercel | Application hosting and functions | London, UK (lhr1) for functions | Requests in transit and function logs |
| Supabase | Postgres database and sign-in | London, UK | All stored workspace data and account details |
| Anthropic | AI analysis of note text (Claude API) | Outside the UK | Note text, question guide and related context sent per request |
| Deepgram | Live transcription of call audio, streamed from your browser | Outside the UKDRAFT - verify | Call audio in transit only, never stored; transcript text returned |
| Resend | Transactional email (invites, pilot and DPA requests) | Outside the UKDRAFT - verify | Recipient email address and message content |
Each provider’s own security and data processing terms apply.DRAFT - verify
Certifications and agreements
We do not hold independent security certifications today.DRAFT - verify
A data processing agreement is available on request.DRAFT - verify Request our DPA.
Security questions are answered within two working days.DRAFT - verify