Trust Centre · Version 1.0

See what Groundnote controls, what you configure, and where data can go.

Groundnote is self-hosted software. This document distinguishes built product controls, deployment responsibilities, optional external providers, tested operating procedures, and current limitations.

Document control

Owner: Groundnote · Effective: 4 September 2026 · Last reviewed: 4 September 2026 · Next scheduled review: 4 December 2026

Change history: Version 1.0 publishes the initial deployment, provider, data-flow, backup, incident-response, and feature-status account.

Data-flow overview

Text equivalent: Meeting content first enters a customer-operated Groundnote instance. Local processing paths are available. If an operator enables an external capture, transcription, AI, calendar, notification, email, billing, or work-tracking service, the selected data leaves the deployment for that provider. Groundnote stores and presents the resulting records, while users review outcomes and initiate supported outbound actions.

Hosting and storage responsibilities

Responsibilities by deployment component
ComponentGroundnote providesOperator is responsible for
ApplicationSelf-hosted web server and desktop application optionsHost security, updates, availability, capacity, and network controls
TransportApplication endpointsTLS termination and reverse-proxy configuration
DatabaseSQLite default or PostgreSQL configurationStorage location, access, backup, restore, and infrastructure encryption
Fortress profilePostgreSQL, local Whisper, local Ollama, and cloud-transcription refusal configurationExplicit deployment and verification; it is not the default mode
DesktopWindows and macOS application buildsEndpoint security and acceptance of current unsigned-build warnings

Groundnote does not currently publish a high-availability or clustered deployment claim. Bring-your-own cloud object storage is excluded from this public matrix until end-to-end support is verified.

AI model and processing matrix

Configurable AI processing paths
ProviderPathData and responsibility
OllamaLocal analysisPrompts and outputs stay on operator infrastructure when Ollama is local.
Local WhisperLocal transcriptionAudio is processed by the installed local binary and model.
OpenAIOptional cloud analysis or transcriptionSelected content leaves the deployment under the customer's account and provider terms.
AnthropicOptional cloud analysisSelected prompts leave the deployment under the customer's account and provider terms.
Google GeminiOptional cloud analysisSelected prompts leave the deployment under the customer's account and provider terms.
AWS BedrockOptional cloud analysisSelected prompts use the customer's AWS configuration, region, and provider terms.

Customer-data training statement: Groundnote does not currently publish a contractual promise covering every configured provider's model-training behavior. Local models avoid external AI-provider transfer. For cloud providers, customers must review and configure the provider account, product terms, retention, and data-use controls appropriate to their deployment.

External provider register

Optional external services and data categories
Provider or servicePurpose and dataOptionality and caveat
Microsoft GraphUser identity, calendar events, meeting metadata, and available Teams transcriptsOptional per-user OAuth; transcript permissions may require tenant approval.
Google CalendarCalendar events and meeting contextOptional per-user OAuth; no direct transcript import.
Recall.aiMeeting URL, bot configuration, capture, and processed transcriptOptional external bot; provider region and terms apply.
Slack or Teams webhooksSelected meeting digestOptional outbound notification to a configured webhook.
Jira, Asana, Linear, ClickUpSelected task details and returned external referenceOptional outbound work tracking; capabilities vary by connector.
SMTP serverSelected outbound email content and recipientsOptional; operator supplies and governs the mail service.
StripeSubscription and payment-related dataOptional billing configuration; not required for core self-hosted use.
Hugging FaceModel download credentials for optional diarizationOptional model acquisition path; meeting content need not be sent for inference.

Processing region, retention, and subprocessor details can vary with customer-selected accounts and provider configuration. Request the current deployment-specific data-flow review before procurement.

Backup, recovery, and incidents

Groundnote includes deployment and scheduled backup scripts for the documented production pattern. The restore runbook validates backup contents, stops the application, replaces data, restarts services, and verifies application identity and health. Actual recovery point depends on the operator's backup schedule; actual recovery time depends on infrastructure, data size, and testing.

Health endpoints, a public status view, application error logs, and hash-chained audit records support operational review. Operators remain responsible for monitoring, escalation, incident handling, notification duties, and credential rotation in their environment. Suspected Groundnote vulnerabilities can be reported through support@groundnote.com.au without including secrets or private meeting content in the initial message.

Feature-status legend

  • Available: implemented and suitable for current product description.
  • Requires configuration: implemented, but an operator, account, credential, provider, or deployment setting is needed.
  • Beta or verification pending: implemented code exists, but production workflow testing or assurance is incomplete.
  • Planned: not available and not suitable for current capability claims.

Available: source-linked outcomes, confidence states, hash-chained audit records, legal hold, retention controls.

Requires configuration: OIDC, MFA per account, cloud AI, local Whisper, Recall.ai, webhooks, SMTP, calendars, work trackers, fortress profile, SQLite encryption.

Beta or verification pending: evidence attachments, approval workflow, timeline and audit-pack UI, live identity-provider testing.

Planned or unavailable: SCIM auto-deprovisioning, organisation-enforced MFA, independent certification, and public high-availability architecture.

Assurance limitations

Groundnote is not SOC 2 certified, ISO 27001 certified, HIPAA certified, or independently penetration-tested as of this review. Controls do not make a customer deployment compliant by themselves. Verify product behavior, infrastructure, contracts, provider terms, and operating procedures against your requirements.