Trust & Security
Private by design — and easy to verify.
Sending meeting transcripts to an AI is a reasonable thing to be careful about. Myc was built to keep your data both private and secure — and wherever we can, we let you verify for yourself rather than take our word for it. For everything else, we document exactly how it works — and where our posture has limits, we say so plainly.
The short version
No bot ever joins your meetings — Myc works from transcripts you upload, or auto-imports them from your own meeting tool’s cloud recordings after a one-time connection you control. Before the AI sees a word, every transcript is stripped of names and personal details — and you can see exactly what was sent. We don’t train on your data, and we don’t sell it. If your security team wants even more control, Myc supports BYO-LLM, or you can self-host the whole system for true vendor-zero-knowledge.
This page is our security overview. For exactly what we redact and how each piece of your data is handled, see our Privacy Policy.
How your transcript flows
- 1
Transcript
Upload a transcript you already have, or auto-import from your own Zoom or Google Meet recordings. No bot ever joins the meeting — text only, never audio.
- 2
Redaction
Names and personal details are stripped out — Microsoft Presidio plus our own recognizers — before anything is sent to the AI.
- 3
Analysis
Only the redacted text is sent for analysis, and it isn’t used to train any model.
- 4
Report
You get your coaching — plus a panel showing exactly what was sent to the AI.
- 5
Retention
We don’t train on or sell your data. Zero data retention is available on request for Enterprise clients (per-contract) — and with self-host, analysis runs entirely in your own infrastructure, for true vendor-zero-knowledge.
How we protect your data
Personal details redacted before AI analysis
Before a transcript reaches the AI, Microsoft Presidio plus our own recognizers reduce every person’s name to bare initials, and replace contact info, government IDs, card numbers, employee IDs, and credentials with opaque tokens. Organizations can dial redaction up further — a Conservative level that also removes locations and IP addresses, plus optional redaction of company and organization names.
See exactly what was sent
Every analysis includes a “view what was sent to the AI” panel — so you’re never guessing what left your system; you can see the redacted text verbatim.
No training, storage off, and we never sell your data
Requests are sent with LLM-side storage off (store=false on OpenAI), and the AI provider does not train on API data. The default tier carries the AI provider’s standard 30-day abuse-monitoring retention; zero data retention is available on request for Enterprise clients on a per-contract basis. We never sell or share your data.
Role-scoped access & multi-tenant isolation
Content is isolated at the API layer — every endpoint authorizes the caller against a record's owner before returning data, and a cross-organization probe returns 404 (not 403) so records can't be enumerated. Elevated roles inherit MFA from your identity provider.
Your organization sees participation, not your content
On a team or organization plan, your individual analyses — the reports, quotes, and scores — stay private to you unless you choose to share them. Your organization sees who’s taking part and program-level activity (for example, how many meetings each person has analyzed); an assigned coach sees only your name until you share. This is coaching, not monitoring.
Encrypted in transit and at rest
TLS 1.2+ for traffic between you and Myc, and between Myc and the AI provider. Customer content is encrypted at the application layer with AES-256-GCM under per-organization keys, with the root key held in AWS KMS (HSM-backed); beneath that, the hosting provider (Railway) encrypts the stored data and backups at rest at the storage level. Every administrative action is recorded to an append-only audit log.
A Data Processing Agreement is available
A Data Processing Agreement (DPA) is available for your legal team to review — download it below.
Want more than the default? You can run analysis through your own AI provider, or self-host the whole stack — see “Choose your privacy posture” below.
Choose your privacy posture
Three deployment options to satisfy your security and legal teams.
Option 1
Standard SaaS
We host the application, the database, and provide the AI, with the full redaction pipeline, encryption-at-rest, and per-organization isolation. The right default for most customers.
Option 2
Bring your own AI provider
Configure your own provider endpoint (Azure OpenAI, an enterprise OpenAI key, an OpenAI-compatible proxy, or Anthropic-direct), so data retention is governed by your API contract instead of ours. Your API key is encrypted at rest (AES-256-GCM) and never shown in plaintext.
Option 3
Turnkey self-hosting
Run the full Myc stack inside your own infrastructure via our turnkey self-serve installer — for true vendor-zero-knowledge. For the strictest data boundaries, point Myc at a Private LLM Deployment via VPC or Managed Private Endpoint.
What we don’t claim (yet)
- SOC 2 Type II is in progress, not yet certified.
- Under Option 1 (SaaS with vendor-supplied AI), our AI provider’s standard 30-day abuse-monitoring data retention applies. Zero data retention (ZDR) is available on request for Enterprise clients on a per-contract basis (an enterprise provider agreement), or via Options 2 or 3 if your own API contract includes a ZDR agreement.
- Under Options 1 and 2 (SaaS), Myc’s worker service handles transcript text momentarily to pass to the AI for analysis — true vendor-zero-knowledge requires Option 3 (self-hosting).
- We don’t support PHI and aren’t HIPAA-compliant (no Business Associate Agreement).
- We don’t offer customer-managed encryption keys (CMEK/BYOK) or a choice of data region (US West only).
- An independent penetration test is planned, not yet completed.
For your security & legal teams
Free to download and share with your team — no email or NDA required.
Try Myc for yourself.
Analyze a meeting transcript, or bring your security team to a walkthrough.
Questions from your security team?
Email us and we’ll route it to the right person.