Shield with book

Learn about Commonplace · two of four

Security that respects the room

Commonplace uses authenticated access, organization-scoped permissions, encryption in transit and at rest, and a timestamped consent ledger.

What is in place

  1. Authenticated sign-in

    Consumer sign-in is the launch path. SAML, OIDC, SCIM, and institutional provisioning are not part of the launch offer.

  2. Access scoped by role

    Members, hosts, and organizers receive different permissions. The API enforces those permissions; the interface alone is not the security boundary.

  3. Encryption and a consent ledger

    Connections use TLS, and recordings and application data are encrypted at rest by their storage providers. Consent decisions are stored in a timestamped ledger.

A precise boundary

These controls reduce risk; they do not make any system invulnerable. Security and privacy claims should stay no broader than the evidence behind them.