Information Management and Security Statement
How Nguma stores, protects and keeps sovereign the data entrusted to it. This statement applies to the Nguma meeting transcription service and is classified Public. All customer data, and all AI inference performed on it, remains within Australian infrastructure.
1. Overview
Nguma provides an AI meeting transcription service that converts meeting audio into accurate, searchable transcripts. It is built for organisations that need their meeting records processed and stored on Australian infrastructure, with data sovereignty and security treated as first-order requirements.
This statement describes how Nguma manages and protects the information entrusted to it, where that information resides, and the subprocessors and controls that underpin the service. It is written for the organisations that rely on Nguma to handle sensitive meeting content, and for the security and procurement teams who assess it.
Data sovereignty is central to Nguma’s design. All customer data, and all AI inference performed on it, remains within Australian infrastructure. The sections below set out how that commitment is met in practice.
2. Data sovereignty and residency
All customer data handled by Nguma, including meeting audio, transcripts and the records associated with them, is stored and processed within Australia. Nguma does not transfer customer content offshore in the course of delivering the service.
In practice this means:
- Meeting audio and transcription are processed and stored in the AWS Asia Pacific (Sydney) Region.
- The application database and authentication are hosted in the AWS Asia Pacific (Sydney) Region.
- File storage, the application edge, delivery and protection layer run on Cloudflare’s Australian infrastructure.
- AI transcription models run onshore; customer audio and transcripts are not used to train third-party models.
This matters because data-handling obligations vary across Nguma’s customers, but Australian residency is a baseline expectation and some require infrastructure assessed under the Information Security Registered Assessors Program (IRAP). The underlying AWS and Cloudflare infrastructure Nguma relies on has been IRAP assessed at the PROTECTED level, as set out in the subprocessor table.
3. Hosting and architecture
Nguma is delivered as a cloud application hosted on Cloudflare, which provides the edge network, DNS, web application firewall, DDoS protection, file storage and application delivery layer. Two managed services sit behind the application: Supabase for the database and authentication, and Deepgram for speech-to-text transcription. Both managed services run in the AWS Asia Pacific (Sydney) Region, keeping customer data onshore.
Each provider is a subprocessor operating under its own audited security program. Nguma configures each to keep data within Australia and to exclude customer content from model-improvement and training workflows.
4. Subprocessors
Nguma relies on the following subprocessors to deliver the service. Each holds current, independently audited security certifications; the certifications listed are held by the named subprocessor and are current as at the effective date of this statement.
| Subprocessor | Purpose | Data location | Certifications and controls |
|---|---|---|---|
| Deepgram | Speech-to-text transcription of meeting recordings. | AWS Asia Pacific (Sydney), ap-southeast-2, via the Deepgram Australia managed endpoint. | SOC 2 Type I and Type II. Audio, transcripts and speech output processed and stored onshore in Australia; model-improvement opt-out enabled so customer content is excluded from training. |
| Supabase | Application database and authentication. | AWS Asia Pacific (Sydney), ap-southeast-2. | SOC 2 Type II; ISO/IEC 27001:2022; HIPAA; PCI DSS; GDPR. Data encrypted at rest with AES-256 and in transit with TLS 1.2+. Daily backups with point-in-time recovery. |
| Amazon Web Services (AWS) | Underlying cloud infrastructure for the Deepgram and Supabase managed services. | Asia Pacific (Sydney) Region, ap-southeast-2. | IRAP assessed at the PROTECTED level (2026 assessment; 167 services in scope). ISO/IEC 27001; SOC 1, SOC 2 and SOC 3; PCI DSS Level 1; and further programs. |
| Cloudflare | Edge network, DNS, web application firewall, DDoS protection, file storage and application delivery. | Australia (Sydney). | IRAP assessed at the PROTECTED level (Cloudflare for Government, Australia). ISO/IEC 27001; SOC 2 Type II; PCI DSS. |
Source references for each provider’s certifications are listed in the References section at the end of this statement.
5. Encryption
Customer data is encrypted both in transit and at rest:
- In transit: connections between users and the application, and between Nguma and its subprocessors, are encrypted using TLS 1.2 or higher.
- At rest: data stored in the application database and object storage is encrypted using AES-256. Sensitive values such as tokens and keys receive additional application-level encryption before storage.
6. Access control and authentication
Access to Nguma is authenticated for every user, and access to customer data within the platform is limited to the authorised users within the customer’s organisation. Administrative access to production systems is restricted to authorised Nguma personnel on a least-privilege basis and is logged.
Nguma’s subprocessors maintain their own access controls, audit logging and monitoring as part of the SOC 2 and ISO/IEC 27001 programs referenced above.
7. AI and responsible data handling
Nguma’s role is to transcribe, not to interpret. The service converts meeting audio into text; it does not assess, judge or make decisions about the people or content in a meeting. The transcript is the customer’s record, to use as they see fit.
This is a data-handling commitment as well as a product one. Customer audio and transcripts are processed onshore for the sole purpose of delivering the service, and are excluded from any third-party model-training workflow. Nguma is working toward ISO/IEC 42001, the international standard for AI management systems, as part of the compliance program described below.
8. Resilience, backup and recovery
The application database is backed up daily, with point-in-time recovery available through the managed database service. Backups are retained within the AWS Asia Pacific (Sydney) Region, consistent with Nguma’s data-residency commitment. The edge and delivery layer provided by Cloudflare adds network resilience, including DDoS protection and web application firewall coverage.
9. Nguma’s compliance posture
Held. Nguma is Indigenous-owned and led, certified by the NSW Indigenous Chamber of Commerce (NSWICC), Yarpa, and Supply Nation.
In progress. Vanta is engaged to support certification against the ACSC Essential Eight (Maturity Level 2), ISO/IEC 27001 (information security management), and ISO/IEC 42001 (AI management systems).
These certifications are described accurately as their current status: the Indigenous-ownership certifications are confirmed and held; the Vanta-supported certifications are in progress. Nguma does not claim certifications it does not yet hold. Where a customer requires infrastructure assessed at a particular level, the IRAP PROTECTED assessment of the underlying AWS and Cloudflare infrastructure is available today, as set out in Section 4.
10. Data retention and deletion
Customer data is retained for the duration of the customer relationship and in line with the applicable agreement and the customer’s own records-management obligations. On request, or on termination of the agreement, customer data can be exported and deleted from Nguma’s production systems and from subprocessor storage, subject to the completion of routine backup-rotation cycles. Specific retention periods are agreed with each customer to align with their own recordkeeping requirements.
11. Customer responsibilities
Security is a shared responsibility. Nguma secures the platform, its infrastructure and its subprocessor configuration. Customers are responsible for the security of their own devices, networks and credentials, for managing which of their people have access to their meeting records, and for handling any exported data in accordance with their own obligations. Nguma’s controls do not extend to customer-side infrastructure.
12. Contact
Security, privacy and data-handling enquiries, including requests for a subprocessor’s audit reports where these can be shared, can be directed to:
This statement reflects Nguma’s information-management and security posture for meeting transcription as at 1 June 2026 and may be updated as the platform and its certifications evolve.