Security and trust

Security should be visible, understandable, and enforced.

OnadaMeet combines identity controls, meeting-scoped permissions, rate limiting, browser security policy, and protected account routes without hiding behind vague claims.

Scoped meeting access

Workspace membership, meeting-specific guest credentials, PINs, and server-issued LiveKit permissions limit who can enter and what they can publish.

Least-privilege roles

Hosts and authorized administrators receive moderation controls. Ordinary members, attendees, and guests do not inherit host privileges.

Hardened web surface

Sensitive routes are authenticated and non-cacheable. Security headers block framing, MIME sniffing, unsafe object embeds, unnecessary browser capabilities, and insecure transport.

Abuse and anomaly controls

Public and sensitive endpoints use rate limits, CSP violations are monitored, and support inputs are bounded and sanitized before processing.

Security controls in the product

Browser access with meeting-specific guest links
Workspace roles and server-controlled room permissions
Meeting PINs and controlled participant admission
Encrypted transport for live audio and video
Attendance and meeting records tied to the workspace
Rate limiting on sensitive public and account endpoints
Security headers, anti-framing controls, and CSP monitoring
Human review recommended for generated meeting notes
We do not claim certifications that have not been independently verified. For security questions or responsible disclosure, use the contact form or email support@onadameet.com.