BriefVox
Home

BriefVox AI

Security Policy

Last updated: 2026-07-14

BriefVox AI Security Policy

Operator details

The operator of BriefVox AI is: Filip Ogonowski, a natural person conducting unregistered business activity within the meaning of Art. 5 of the Polish Act of 6 March 2018 – Entrepreneurs' Law, Generała Dezyderego Chłapowskiego 12, 05-825 Grodzisk Mazowiecki, Poland.

Customer support contact: support@briefvox.com.

Privacy and data protection contact: privacy@briefvox.com.

1. Purpose of this document

This document describes the security measures currently used by BriefVox AI and how to report vulnerabilities. It is not a security certification or a guarantee that all risk can be eliminated.

2. File security

Audio files, video files, and linked media imports are stored in a private, non-public data store.

Files are accessed through temporary, expiring links.

Traffic between the browser, API, and file storage is protected with TLS. Storage is private, and object access is controlled through authorization and short-lived signed URLs.

Files are not publicly indexed and are not made available without User authorization or another valid basis described in the Privacy Policy.

3. Administrative access

Administrative access is role-restricted and granted only to the extent needed to operate the Service.

Administrative accounts and sessions require authentication; access to external production services is protected using the controls offered by the relevant provider.

Material administrative actions are recorded in an audit log.

Service staff and technical personnel do not have standard access to the contents of user recordings or transcriptions. Emergency access, if technically provided for, may only be used in exceptional circumstances, must require authorization, must be recorded in logs, and must be limited to the minimum scope necessary to resolve the issue.

4. Application security

passwords stored only as secure hashes,

sessions in secure HTTP-only cookies,

rate limiting on login and password reset,

file validation and 2 GB size limit,

server-side audio-track duration verification,

Stripe webhooks with signature verification and idempotency,

protection against concurrent minute-limit bypass,

regular dependency updates.

5. Transcription and AI providers

Audio and video transcription is performed on the Operator's own infrastructure in the European Union; source files are not sent to an external transcription provider. When the User selects AI Notes, transcript text is sent to the AI provider listed in the Subprocessors Registry solely to generate the selected note.

6. Backups and recovery

disaster-recovery copies of the database and metadata are created for recovery purposes and before higher-risk production changes,

access to copies is restricted to the Operator, and they are not used for ordinary review of User content,

copies follow the period stated in the Data Retention Policy and are deleted or overwritten after that period,

restoration is performed only after a failure, security incident, or justified recovery test; deletion requests are reapplied after restoration unless the law requires retention.

7. Vulnerability reporting

Security issues can be reported to: privacy@briefvox.com. A report should include a description of the vulnerability, reproduction steps, and the potential impact. The Operator will not penalize good-faith disclosures that do not involve accessing other users' data or disrupting the Service.