Security & trust
Built to be trusted with your meetings
Sol reads meeting transcripts to extract decisions, actions, and summaries for you only. Your transcripts never train a shared model, and you keep full control over retention, model routing, and access.
Your transcripts, your outcomes, full stop
The core rules that govern how Sol handles the meeting transcripts you submit.
Your meeting transcripts are processed to produce your decisions, action items, and summaries only. They are never used to train or fine-tune a shared model.
Encryption in transit on all connections (TLS 1.2 minimum, TLS 1.3 preferred).
Encryption at rest for all stored transcripts and derived data.
Configurable retention windows. The default is 90 days; Team and Business plan customers can reduce it further.
Deletion on request, processed within 30 days.
Transcript data is never disclosed to other Sol customers or used to improve outputs for anyone other than you.
Transcripts used for your outcomes only
When you submit a meeting transcript, Sol uses it to extract the decisions made, the action items with owners and due dates, and a short summary. That is the extent of what we do with it. The transcript is not fed into training pipelines, not compared against other customers' data, and not retained beyond your configured window.
Model inference happens in-context at the moment of extraction. The transcript is passed to the model for that single request and is not persisted by the model provider for training.
The right people, with the least-privilege access
SSO and SCIM
SAML 2.0 single sign-on and SCIM automated provisioning are available on the Business plan, so your identity provider remains the source of truth for who has access to your workspace.
Role-based access
Three roles per workspace: viewer (read meeting outcomes), editor (submit transcripts and edit extracted items), and admin (manage members and billing). Roles are enforced at the data layer, not just the interface.
Audit log
Every workspace action is logged: who submitted a transcript, who edited an action item, who exported a summary. The log is available to workspace admins. Export is on the Business plan roadmap.
API token scoping
API tokens are scoped to a single workspace and carry the minimum permission needed. Tokens can be rotated or revoked at any time without opening a support ticket.
Keep transcripts inside your perimeter
On the Business plan, you control where your transcripts go and which models process them.
Self-host or run in your VPC
Business plan customers can deploy Sol inside their own cloud environment or virtual private cloud. Meeting transcripts never leave your perimeter. We provide a container image and a security review to support procurement requirements.
Model-agnostic routing
Sol routes each extraction step across frontier and open-weight models, selecting for quality and cost at each step. Business plan customers can pin specific providers, exclude external providers entirely, or route all inferences to open-weight models they host themselves, keeping transcripts within their own boundary.
Who touches your data, and why
We keep the list short and honest. Business plan customers can remove model providers from this list by routing to open-weight models they self-host.
Cloud infrastructure
Amazon Web Services (us-east-1)
Compute, storage, and networking for the hosted Sol service. Transcripts and derived data (decisions, actions, summaries) are stored here unless you route to self-hosted models.
Model providers
Multiple providers, model-agnostic
Language model inference for transcript extraction. Business plan customers can pin specific providers, exclude external providers entirely, or route all inferences to open-weight models they self-host, keeping transcripts inside their own boundary.
Payment processing
Stripe
Card and subscription billing for Team and Business plans. Sol shares only the billing details needed to complete a transaction. Stripe operates under its own privacy policy.
What is done and what is in progress
We report our posture honestly. A label that says in progress means exactly that.
SOC 2 Type II
In progressOur audit period is underway. The report will be available to Business plan customers under NDA once complete. We are happy to answer specific control questions during sales.
GDPR
ReadyA data processing agreement (DPA) is available on request. EU data residency controls and sub-processor documentation are available to Business plan customers.
CCPA
ReadyData subject rights requests are handled at hello@soltechnologies.org within 30 calendar days. We do not sell personal data.
Report a vulnerability
If you find a security issue in Sol, please report it to security@soltechnologies.org. We acknowledge every report within one business day and coordinate disclosure with you before going public. We do not pursue legal action against researchers who act in good faith and follow this process.
- Email a clear description of the issue and the steps to reproduce it.
- Give us reasonable time to investigate and patch before publishing your findings.
- Avoid accessing data that belongs to other customers.
- Do not run automated scanners against production endpoints.
Questions about security or data practices: email security@soltechnologies.org. See also the Privacy policy and Terms of Service.