Recapora
Security and trust

Controls customers can verify.

This page distinguishes controls already implemented in the application from operational work that must be completed before general availability.

Implemented in the application

Identity and multi-factor authentication

OIDC authorization-code flow with PKCE, nonce and state validation, verified-email enforcement, opaque server-side sessions, and signed multi-factor authentication evidence required in production.

Authorization

Organization membership, role-based permissions, tenant-scoped repositories, PostgreSQL row-level security, and explicit approval boundaries.

Data protection

Source audio and transcripts are processed transiently. Structured history is retained for 30 days by default. OAuth credentials are encrypted, and HTTPS plus restrictive browser security headers are enforced.

Billing isolation

Payment details are collected on Stripe-hosted pages, webhooks are signed and idempotent, prices are selected server-side, and entitlements are enforced at organization level.

Production status

Multi-factor authentication policy
Required
Google Calendar + Gmail
Configured
Billing
Disabled
Certification
Recapora does not claim SOC 2 or ISO 27001 certification.

Responsible disclosure

Report suspected vulnerabilities privately to brianalam81@gmail.com. Do not include real customer data unless requested through a secure channel.