Employees know when capture is happening
Meeting capture is designed to be consent-first and visible to participants. Confirm retention terms in the current approved agreement before relying on them.
Security and privacy
Cadence is designed around visible capture, human review, and an honestly labeled security maturity roadmap.
Last updated: June 2026
Meeting capture is designed to be consent-first and visible to participants. Confirm retention terms in the current approved agreement before relying on them.
AI can draft summaries and coaching, but humans approve memorialized meeting records and own any external communication.
Production capabilities and roadmap items are labeled separately, so buyers can distinguish current access from future work.
Security architecture
Cadence holds sensitive workforce data: 1:1 conversations, performance context, ER cases, recognition, goals, and survey signal. The trust model keeps current controls explicit and roadmap controls clearly labeled.
Production workloads run on Google Cloud Platform with containerized services, managed PostgreSQL, and Redis used for cache-only paths.
Current workspace access is role/entitlement scoped; deeper persona policy surfaces are not a current purchase promise.
Administrative actions, exports, and sensitive-record access generate audit records designed for review and export workflows.
AI drafts, summarizes, and coaches; humans own judgment and outbound communication.
Dependency and container scanning are part of the build path; SOC 2 Type II readiness is roadmap until complete.
Meeting consent
Meeting content is inherently sensitive. Cadence is designed so recording and AI processing are visible, opt-in, revocable, and fail-closed.
Compliance posture
| Area | Cadence posture | Status |
|---|---|---|
| GDPR | Processor posture for customer workforce data; EU employee recording requires lawful-basis mapping, DPIA, and non-recording fallback. | In review |
| CCPA / CPRA | Service-provider posture for customer workforce data. | In review |
| SOC 2 Type II | Controls and evidence collection are roadmap/readiness work, not a completed certification claim. | Roadmap |
| AI governance | AI drafts, summarizes, and coaches; humans own judgment and outbound communication. | Current design principle |
Responsible disclosure
Cadence welcomes good-faith vulnerability reports for the web application, API, and MCP server. Please avoid accessing, changing, or retaining customer or employee data beyond what is strictly necessary to demonstrate the issue.
Cadence Legal owns intake with Security as technical DRI. Sarah Mitchell, General Counsel, is accountable for disclosure governance and launch gating.
Send reports to security@cadencehr.ai with affected host, endpoint, tenant context, reproduction steps, impact, and any proof-of-concept material.
Cadence acknowledges credible submissions within 2 business days and provides an initial severity assessment or follow-up questions within 5 business days.
Critical issues involving authentication bypass, tenant isolation, regulated data exposure, or write access are escalated immediately to Security, Legal, and the executive incident channel.
Cadence will not pursue legal action for good-faith research that avoids privacy harm, data destruction, service disruption, social engineering, extortion, or access beyond what is necessary to prove the issue.
Public Cadence web surfaces, the customer-approved REST API, and the MCP server are in scope. Customer data exfiltration, employee impersonation, and physical attacks are out of scope.
Email security@cadencehr.ai with a concise report. Cadence may request coordinated disclosure timing for issues that could expose customer environments, employee data, authentication controls, or tenant isolation boundaries.