All-party consent
Meeting capture is consent-first and visible to participants. Raw audio and transcripts follow configurable retention.
Security and privacy
Cadence is designed around visible capture, current flat Admin/Member access, human approval, no model training on customer data, and an honestly labeled security maturity roadmap.
Meeting capture is consent-first and visible to participants. Raw audio and transcripts follow configurable retention.
AI drafts summaries and coaching, but humans approve memorialized meeting records and own outbound communication.
Encryption, current flat Admin/Member access, audit trails, DPA process, and SOC 2 Type II roadmap are stated honestly.
Security architecture
Cadence holds sensitive workforce data: 1:1 conversations, performance context, ER cases, recognition, goals, and survey signal. The trust model keeps current controls explicit and roadmap controls clearly labeled.
Customer data is encrypted in transit and at rest. Per-tenant key management remains roadmap-labeled until it is production-ready.
Production workloads run on Google Cloud Platform with containerized services, managed PostgreSQL, and Redis used for cache-only paths.
Current access uses flat Admin/Member permissions. Granular manager, employee, HR, and CHRO access controls remain roadmap work.
Administrative actions, exports, and sensitive-record access generate audit records designed for review and export workflows.
Customer workforce data is processed for tenant-specific summaries, coaching, and signal. It is not used to train AI models.
Dependency and container scanning are part of the build path; SOC 2 Type II readiness is described as roadmap until complete.
Meeting consent
Meeting content is inherently sensitive. Cadence is designed so recording and AI processing are visible, opt-in, revocable, and fail-closed.
Compliance posture
| Area | Cadence posture | Status |
|---|---|---|
| GDPR | Processor posture for customer workforce data; EU employee recording requires lawful-basis mapping, DPIA, and non-recording fallback. | In progress |
| CCPA / CPRA | Service-provider posture; no sale or sharing of workforce data. | Ready for customer DPA review |
| SOC 2 Type II | Controls and evidence collection are roadmap/readiness work, not a completed certification claim. | Roadmap |
| AI governance | AI drafts, summarizes, and coaches; humans own judgment and outbound communication. | Current design principle |