Legal
Security Overview
Trust Center
Effective 22 June 2026 · Last updated 22 June 2026
Security architecture and controls for MagMeet.
Architecture
- Multi-tier web application on hardened Linux infrastructure with reverse proxy and WAF protections.
- Real-time media routed through LiveKit SFU infrastructure with DTLS-SRTP encryption.
- S3-compatible object storage for recordings and files in EU-capable regions.
- Relational databases for metadata with restricted network access.
Encryption
TLS 1.2+ for all HTTPS and WSS connections. Media encrypted via SRTP. AES-256 at rest for recordings, transcripts, and backups.
Identity and access
- Email/password, Google OAuth, and phone OTP authentication.
- JWT access and refresh tokens with HttpOnly cookies.
- Role-based access control, meeting passwords, waiting rooms, and host moderation.
- Least-privilege production access with MFA for administrators.
Data residency
Primary operations are based in Republic of South Africa with media and storage options in EU-capable regions. Enterprise customers may discuss residency with [email protected].
Subprocessors
Magoven (Pty) Ltd engages the following categories of subprocessors that may process customer data on our behalf:
- Cloud infrastructure: Application hosting, networking, CDN (ZA / EU / US)
- LiveKit: Real-time audio/video media routing (Customer region)
- Wasabi / S3-compatible storage: Recordings, files, backups (EU-capable)
- Google Firebase: Authentication, app security services (Global)
- Telnyx: MagPhone PSTN/SMS telephony (ZA / US / EU)
- Payment gateway: Subscription billing (ZA)
- Email provider: Transactional email (ZA)
- Ollama (optional): Self-hosted AI inference (On-premise / ZA)
Incident response
Security incidents are triaged by our security team. Personal data breaches are notified per our DPA timelines. Report issues to [email protected].
Vulnerability disclosure
Responsible disclosure: [email protected]. We acknowledge valid reports and coordinate remediation.