Security & Privacy

Audio never leaves your machine.
Local engines run fully offline.

For lawyers, doctors, therapists, cross-border M&A teams — anyone whose conversations demand absolute privacy. A complete local pipeline (ASR + TTS + LLM) with no telemetry, no cloud upload, and the option to run fully air-gapped.

Data flow

Three privacy modes — you choose per session

Mode 1 · Fully local Air-gapped capable · zero network
Microphone
Local ASR
(Whisper-faster)
Local LLM
(Ollama)
Local TTS
(CosyVoice / VoxCPM)
Virtual mic / screen

Whisper-faster + Ollama + CosyVoice / VoxCPM all run on your GPU/CPU. Yank the cable — it still works.

Mode 2 · Hybrid Local ASR + cloud LLM · transcript stays local
Microphone
Local ASR
Cloud LLM
(direct, your API key)
Local TTS
Virtual mic / screen

Audio never leaves the device. Only the transcript text reaches the LLM provider via your own API key — never through CrossMeet servers.

Mode 3 · Cloud Fastest, lowest hardware bar · audio crosses borders
Microphone
Cloud ASR + LLM + TTS
(direct, your API key)
Virtual mic / screen

Even here, requests still go directly from you to OpenAI / Aliyun / Anthropic — never through CrossMeet servers. We never see your audio or transcripts.

Industry scenarios

Where absolute privacy isn't a feature — it's a job requirement.

Law firms

Attorney-client privileged conversations with international clients. Local engines mean no third party — not even us — can subpoena audio that never existed on a server.

Hospitals & telemedicine

Cross-language consultations with overseas patients. Air-gapped mode keeps protected health information (PHI) inside your network — architecture aligned with HIPAA principles, BAA available.

Therapists & counselors

Cross-language clients sharing their most sensitive material. Therapeutic trust requires that the conversation truly stops at the office door — no third-party transcription, no cloud retention.

Cross-border investment banking

M&A negotiations, deal calls, due diligence interviews. NDAs are easy; an architecture that mechanically cannot retain the conversation is the differentiator.

What we collect

  • • Email + license key (for activation)
  • • Device fingerprint (license binding, no PII)
  • • Crash reports (opt-in, stack trace only)
  • • Payment metadata (transaction ID + amount; cards handled by Stripe / Alipay / WeChat)

What we never collect

  • • Your audio
  • • Your transcripts
  • • Your translations
  • • Your RAG knowledge base files
  • • Your glossary entries
  • • Mic / screen / filesystem listings
Audit commitments

No telemetry. No analytics SDK. No phone-home.

No third-party analytics

No Google Analytics. No Sentry. No Mixpanel. No Amplitude. No PostHog. The desktop client embeds none of them.

Updates check version only

The auto-updater contacts a versioned manifest URL with no usage data, no user ID, no feature flags. Nothing about what you did inside the app.

License heartbeat: device_id + license_key only

The activation server receives an opaque device fingerprint hash + your license key. No business content, no transcripts, no metadata about your sessions.

Source code auditability

The CrossMeet adapter layer (audio capture, virtual mic, engine routing) is on the roadmap to open-source so enterprise customers can verify the no-telemetry claim themselves.

Compliance roadmap

Architecture-ready today. Formal certifications, plotted on a public timeline.

We do not claim certifications we have not earned. Every line below is either signed today, in audit, or scheduled — honestly labeled.

AVAILABLE NOW

DPA (Data Processing Agreement)

Both legal entities can execute a GDPR-aligned DPA. China mainland customers contract with [CN_COMPANY_NAME]; international with [HK_COMPANY_NAME].

AVAILABLE NOW

BAA (Business Associate Agreement)

For healthcare customers handling PHI. Issued by [HK_COMPANY_NAME]. Air-gapped deployment recommended for full HIPAA-aligned operation.

AVAILABLE NOW

Enterprise NDA / MSA

Standard or custom NDAs. Either legal entity, or both. Counter-signed within 5 business days.

AVAILABLE NOW

GDPR data subject rights

Access / rectify / erase / export / restrict / object. 30-day response. See Privacy Policy §6.

PLANNED 2027

SOC 2 Type II

Formal audit scheduled for 2027. Today's architecture is already designed against SOC 2 trust services criteria (security, availability, confidentiality, processing integrity, privacy).

PLANNED 2028

ISO 27001

ISMS implementation underway. Formal certification scheduled for 2028. We will not display ISO 27001 logos until the certificate is in hand.

We list certifications only when we hold them. "Planned 2027" never becomes "certified" in marketing copy without the audit being complete first.

Transport & storage

  • TLS 1.3 · AES-256 at rest
    All license / payment traffic; databases encrypted at rest.
  • Regional data residency
    China mainland user data stays in mainland (Aliyun East China). International data on AWS Hong Kong / North America.
  • RBAC + audit logs
    Least-privilege internal access; every read is logged.

Report a vulnerability

Found a security issue? Please email security@crossmeet.com. We commit to:

  • Acknowledge within 48 hours
  • Patch critical issues within 7 days
  • Public disclosure (with credit) after fix

Need a private deployment, signed DPA / BAA, or industry customization?

We work with law firms, hospitals, M&A teams and other privacy-critical buyers on custom contracts.

Get started

Ready to make every conversation feel native?

NO CREDIT CARD CANCEL ANYTIME LOCAL-FIRST
~100ms
End-to-end latency
30+
Languages
4
ASR engines
WIN 10/11
Native platform