Security

Your security review will be a short one

The product's architecture removes most of the questions before they're asked: nothing about your meetings ever reaches us.

SOC 2 Type II

Audited annually. Report available under NDA.

GDPR + DPA

EU data residency available on enterprise plans.

SSO + SCIM

SAML and OIDC with automated provisioning and deprovisioning.

No meeting data

Nametags renders on the device. We never join, record, or store calls.

How rendering works

Nametags installs as a native meeting app or a virtual camera. Either way, the composite happens locally: the video frame never leaves the device on its way to us, because it never comes to us at all.

  • No bot account joins the meeting.
  • No video or audio is transmitted to Nametags infrastructure.
  • No recordings, transcripts, or participant lists are stored.
  • Template definitions and directory attributes sync over TLS and are encrypted at rest.

Access and identity

Admin access to Control Center is gated by your IdP. Roles separate who can edit a template from who can publish one, and every publish is attributed in an audit log you can export.

Subprocessors

A current subprocessor list is maintained for Enterprise customers and updated with 30 days' notice before any addition takes effect.

Questions from security reviews

Does Nametags join our meetings?

No. There is no bot and no participant. The nametag is composited into the outgoing camera feed on the employee's own machine.

What data do you store?

Directory attributes needed to render a tag — name, title, team, region — plus template definitions and usage counts. No video, no audio, no transcripts, no participant lists.

Where is data hosted?

US regions by default. Enterprise agreements can pin all storage and processing to the EU.

How do you handle offboarding?

SCIM deprovisioning revokes the template immediately. The next call renders without a nametag.

Do you support penetration test reports?

Yes. Annual third-party test summaries are available under NDA alongside the SOC 2 report.

Send us your questionnaire

We'll return it completed, with the SOC 2 report and DPA attached, usually within two business days.