A QST platform
ع

Security and compliance

Meeting information — protected, and under your control.

Protocol is self-hosted, runs its AI locally and records every material action. This page is written for the IT, security and procurement teams who evaluate it.

Defense in depth

Seven layers on every request

Each request passes seven independent layers of control. A weakness in any one of them is contained by the others.

  1. 01

    Network

    Deployed inside your perimeter and air-gapped capable, with no dependency on external AI, conferencing or push services.

  2. 02

    Identity

    Password policy, account lockout, idle-session timeout, multi-factor authentication, single sign-on (SAML and OIDC) and biometric app lock.

  3. 03

    Authorization

    Fine-grained, role-based permissions resolved per meeting, and deny-by-default, per-file access in the document library.

  4. 04

    Tenant isolation

    In multi-company deployments each company is hard-isolated, with group oversight only through an audited grant.

  5. 05

    Data

    Meeting material stays on your servers, offline packs on mobile are encrypted per user, and distributed documents carry dynamic watermarks.

  6. 06

    Device

    A device registry with new-device approval, remote sign-out and remote wipe for lost or stolen devices.

  7. 07

    Assurance

    A full audit trail of material changes, approvals, votes and signatures, reviewable by administrators.

Security

Meeting information stays protected — and in your hands

Meetings carry an organization’s most sensitive information. Protocol is built so that it never leaves your control.

Self-hosted

Runs entirely in your infrastructure; your data never leaves your perimeter.

Local AI

All AI processing happens on your servers — nothing goes to third-party AI services.

Granular permissions

Fine-grained, role-based access to every meeting, document and action.

Full audit trail

Every material change is recorded and reviewable.

Device security

A device registry with remote sign-out and remote wipe for lost or stolen devices.

Document protection

Dynamic watermarking and controlled export of meeting material.

Strong authentication

Password policy, lockout, idle-session timeout, biometric app lock, single sign-on and multi-factor.

Qualified e-signatures

Accredited signing through Nafath or Sadq for legally recognized decisions.

Tenant isolation

In multi-company deployments, companies are hard-isolated from one another.

Deployment

Deployed your way

The same software scales from a one-server pilot to a full, resilient estate — always inside your own infrastructure.

Single-, two- or three-tier

With high availability and disaster recovery, sized to your estate.

Fully air-gapped

Every capability — including AI, audio and video — works on an isolated network.

Offline licence

A signed licence bound to your server, activated without calling home.

Integrations on your terms

Optional Microsoft Teams, SharePoint and OneDrive connectors — none are required.

Compliance evidence

The record your auditors ask for

Governance rules are enforced by the workflow, and every step leaves evidence behind.

Full audit trail

Every material change, approval, vote and signature is recorded — who, what and when.

Approval chains

Agendas and packs pass through defined approvers before they are published.

Versioned review

Every agenda version is kept and commented on, with a complete timeline.

Quorum and voting rules

Attendance, quorum and six voting methods are captured against every decision.

Legally sound signatures

Qualified e-signature through Nafath or Sadq, and a certificate of completion for signed minutes.

Controlled access

Role-based permissions per meeting, view-only delegation and guests scoped to one meeting.

Planning a security review?

We will walk your security and IT teams through the architecture, deployment and controls — on a call or on site.