Lamka LabsTranscription

Security

Confidentiality by design

Depositions contain medical records, financial detail, minors' names and material under protective order. Healthcare work involves PHI. Corporate work involves strategy and personnel matters. We built our process around all of it.

Encryption in transit and at rest

TLS on every connection. AES-256 at rest for audio files and transcripts. Signed, short-lived, single-use download URLs.

Your audio is never used to train any model

This is a hard policy, not a setting. We do not send customer audio or transcript content to any provider for model improvement.

Customer-controlled retention

Default 30-day auto-delete from our systems after delivery. Configurable to 7 days or immediate deletion after download. Hard-delete verified, including backups.

Access logging

We keep an audit log of who accessed which artifact, when, and from where. Available on request during procurement.

NDA, DPA and BAA

Mutual NDA on request. Data Processing Addendum for enterprise. Business Associate Agreement available for healthcare work.

Subprocessor transparency

We maintain a current subprocessor list for cloud infrastructure, email and payment providers. Notify us if you need it.

Operational controls

Rate-limited public forms
File type and size validation
No transcript content in logs or analytics
Secrets stored in a secrets manager, never in code
Regular dependency and security updates
Incident response plan on file
Role-based access to production data
Background checks for transcription staff
Secure equipment and clean-desk policy

Have a procurement questionnaire?

We answer security reviews and supply NDAs, DPAs and subprocessor lists directly.

Email support@lamkalabs.com