Skip to content

Device security and encryption

Synthezia encrypts its meeting database with SQLCipher and stores retained managed audio in authenticated encrypted vault files. The database key and the audio key are separately derived in memory from a root secret held in macOS Keychain. Search indexes, transcript chunks, summaries, templates, and privacy settings are part of the encrypted database.

This does not encrypt every file related to a meeting. Imported originals and user-selected exports remain at the locations you choose. Downloaded models are also outside the meeting-data vault. Active processing can create short-lived private workspace files before cleanup and startup recovery remove them.

The protection of local Synthezia data depends in part on the signed-in macOS account and the device controls your organization chooses, such as a strong account password, screen lock, managed device access, backups, and FileVault. This page does not assert that any of those controls are enabled, sufficient, or compliant for a particular deployment.

Use a separate macOS or organization security review to decide whether the device, account, backup, endpoint-management, and remote-provider controls meet your requirements.

  • Limit access to the macOS account that can unlock the Synthezia Keychain items.
  • Treat transcripts, summaries, managed audio, imported originals, and exports as potentially sensitive.
  • Review the export destination before saving a summary; exports are outside Synthezia’s deletion actions.
  • Prefer Strict Local Mode when external AI processing is not acceptable for the content.
  • Use a provider-specific secret-management and access-control process before configuring a production credential.