
Learn about Commonplace · two of four
Security that respects the room
Commonplace uses authenticated access, organization-scoped permissions, encryption in transit and at rest, and a timestamped consent ledger.
What is in place
Authenticated sign-in
Consumer sign-in is the launch path. SAML, OIDC, SCIM, and institutional provisioning are not part of the launch offer.
Access scoped by role
Members, hosts, and organizers receive different permissions. The API enforces those permissions; the interface alone is not the security boundary.
Encryption and a consent ledger
Connections use TLS, and recordings and application data are encrypted at rest by their storage providers. Consent decisions are stored in a timestamped ledger.
A precise boundary
These controls reduce risk; they do not make any system invulnerable. Security and privacy claims should stay no broader than the evidence behind them.