Janus / Security & Privacy
Security and data handling
Access controls, tenant separation, document permissions, and the data lifecycle.
Last updated
This overview explains application access controls and the handling requirements for customer information. Available workflows and permitted inputs depend on the customer’s agreement.
Supported inputs and integrations
Janus can receive an authorized meeting transcript or use a meeting transcription participant, depending on the agreed meeting setup. The base transcript workflow does not require an integration with, or credentials for, a customer’s internal applications, databases, or file systems. The optional extension has a separate browser-permission and capture scope described in the browser extension section. Meeting participation depends on the selected platform and approved transcription setup.
Supported inputs include meeting transcripts, project information entered by the project lead, and selected documentation uploaded with the client's approval to help organize information more quickly. Approval must identify the documents, their permitted uses, and any AI-provider processing. Screenshots and screen recordings are outside the initial transcript/document workflow unless the optional extension or another capture method is separately approved. Unapproved internal system files, patient information, credentials, and other protected data remain outside scope. Transcripts and requirements can still contain confidential or personal information; meeting discussions and manual entries must stay within the agreed scope. This is an operating restriction, not an automatic detection or redaction guarantee.
How information is protected
- Encryption: Supabase protects hosted customer data with AES-256 encryption at rest and TLS in transit. Vercel provides HTTPS/TLS for connections to its platform and AES-256 encryption for data stored on disk. These are provider-managed protections; access to project records and files is controlled separately.
- Signed-in access: Normal application requests use the signed-in user's session to access project records.
- Database permissions: Organization and role-based permissions, enforced through row-level security (RLS), restrict who can view or change project information in shared infrastructure.
- Document access: Organization membership and document-level access rules control who can view document records in Janus.
- Controlled service access: AI processing uses protected service credentials. Authorized staff and service providers may access customer information to deliver and support the agreed services.
- Human review: The project lead reviews AI-drafted requirements and documentation before relying on them as deliverables. AI-generated text and schedules can be incomplete or incorrect.
Approved documents: Client approval defines which documents may be provided, their intended use, any AI processing, and retention. Confidential documents must be shared through an agreed, access-controlled channel.
Retention and deletion
Full transcripts are retained in the client's own environment and provided to the project lead manually, or retained in Zoom. Supplied transcripts and temporary processing copies are covered by the engagement’s storage and retention requirements.
Each engagement must specify retention for audio if captured, full transcripts and supplied copies, approved documents, project records, generated content, embeddings, logs, and backups in the engagement’s written retention schedule. Zoom retention and region depend on the relevant account configuration. Deletion periods and provider retention are governed by the written schedule.
Requests to access, correct, export, or delete client information go to the project lead through the existing engagement contact channel. Deletion must account for upstream copies and derived records, not just the visible Janus record. Provider retention and backup expiry must be included in the deletion process.
