Security

Last updated date: 2026-07-24

Access control

Access is controlled by organization, role, and meeting participation in both API and database. Personal memos and AI consultations use separate permissions and sync paths.

Data protection.

Protected by encryption, private storage, short-lived tokens, server-side management, and operation logs.

Deletion and audit.

Meeting deletion involves prior confirmation, waiting period, deletion target verification, and post-deletion residual check. Voice registration requires consent and revocation recording; after revocation, feature data and sample audio are deleted.

Report Vulnerability

Report suspected vulnerabilities with reproduction steps and impact to cto@iiwayo.tech. Do not perform unauthorized data access or service disruption.