When a recorded meeting is closed, the Veeting recording pipeline turns the raw media of its participants into finished files: a gallery video of the whole meeting and, if enabled, an MP4 copy, a transcription and a tamper-evident seal over all of it.
The pipeline is a sequence of steps. Some always run; others are enabled per installation or per customer. Several steps hand their work to an external service, a provider. Providers are interchangeable, so the pipeline does not depend on any one vendor. Transcription is not enabled in our standard Veeting Rooms offering.
Steps with a solid border always run. Steps with a dashed border are optional. The hexagons are provider slots: they list the providers supported today and show where your own service can plug in.
onMeetingRecordingCreated web hook, so your own system can copy the recording to permanent storage right away. The verification files sit next to the recording, in the same location as mergedRecordingUrl; copy them too. Depending on the meeting's settings, the organizer, and optionally every participant, receives an email with a link to the recording.Each provider slot is open. Use one of the providers supported today, or have us connect yours.
| Step | Providers today | Adding another provider |
|---|---|---|
| Transcription | OpenAI Whisper, DeepVA | A REST API that accepts an audio file upload. Veeting adds a provider module for it |
| Digital signature | A key held by each Veeting server | Your own signing service, for example with a qualified certificate. Added by Veeting on request |
| Trusted timestamp | DigiCert (default), SwissSign, Sigstore | Any timestamp authority that speaks RFC 3161. Configuration only, no new code needed |
The steps are not fixed either: further steps can be added where an installation needs them. If you have something in mind, talk to us.
A sealed recording carries its verification files next to the recording files. For a recording with the token <token>:
| File | Contains | Proves |
|---|---|---|
<token>.meta.json | The manifest: every delivered file with its size and SHA-256 fingerprint | What |
<token>.meta.sig | A digital signature over the manifest (ECDSA P-256) | Who |
<token>.meta.tsr | A trusted timestamp over the manifest (RFC 3161), from an independent authority | When |
<token>.origin.meta.* | The origin seal: the same three files for the raw files, made before any processing | From what |
The seal uses open standards throughout, so anyone can check it independently of Veeting with sha256sum and OpenSSL 3. Each platform publishes the public keys of its servers at https://<HOSTNAME>/api/v6/recording-integrity/signing-keys. Keep the verification files together with the recording when you archive it.
A successful verification shows that none of the files changed after the seal was made, that a Veeting server signed it, and that it existed no later than the time of the timestamp. It says nothing about the content before the seal was made. The origin seal moves that point back to the moment the raw files were fingerprinted. The seal is not a qualified electronic seal under Swiss (ZertES) or EU (eIDAS) law. A qualified timestamp authority can be configured today; a qualified signing service would be added by Veeting.
For step-by-step verification instructions and the Veeting verification tool, contact us.
Contact our team to discuss the details.