Recording pipeline

Overview

When a recorded meeting is closed, the Veeting recording pipeline turns the raw media of its participants into finished files: a gallery video of the whole meeting and, if enabled, an MP4 copy, a transcription and a tamper-evident seal over all of it.

The pipeline is a sequence of steps. Some always run; others are enabled per installation or per customer. Several steps hand their work to an external service, a provider. Providers are interchangeable, so the pipeline does not depend on any one vendor. Transcription is not enabled in our standard Veeting Rooms offering.

How the pipeline works

The recording pipeline: raw per-participant streams are recorded, decoded and composed into a gallery video, optionally exported to MP4 and transcribed, optionally sealed with a manifest, a digital signature and a trusted timestamp, and announced with a web hook and an email

Steps with a solid border always run. Steps with a dashed border are optional. The hexagons are provider slots: they list the providers supported today and show where your own service can plug in.

  1. Recording. During the meeting, the media server records the audio and video of each participant as separate raw files. Optional: when processing starts, before anything else touches or moves them, these raw files are fingerprinted, signed and timestamped. This is the origin seal.
  2. Processing. The pipeline decodes the raw files and aligns them on a common timeline. It splits the meeting into sessions, separated by breaks: everyone leaving, or the recording being stopped and restarted. For each session it composes a gallery video that shows the participants side by side, with everyone's audio mixed in. Audio-only meetings skip the video steps. Large installations run this step on a dedicated recording server, so the media server keeps its resources for live meetings.
  3. Optional outputs. The pipeline can export an MP4 copy that plays in most players, and transcribe the whole meeting and each session as plain text, SRT subtitles and JSON, using the transcription provider you choose.
  4. Delivery seal. Optional: a manifest lists every delivered file with its SHA-256 fingerprint. The manifest is digitally signed, then timestamped by an independent timestamp authority. If a delivered file changes by a single byte afterward, verification fails and names the file.
  5. Completion. The platform calls the onMeetingRecordingCreated web hook, so your own system can copy the recording to permanent storage right away. The verification files sit next to the recording, in the same location as mergedRecordingUrl; copy them too. Depending on the meeting's settings, the organizer, and optionally every participant, receives an email with a link to the recording.

Providers

Each provider slot is open. Use one of the providers supported today, or have us connect yours.

StepProviders todayAdding another provider
TranscriptionOpenAI Whisper, DeepVAA REST API that accepts an audio file upload. Veeting adds a provider module for it
Digital signatureA key held by each Veeting serverYour own signing service, for example with a qualified certificate. Added by Veeting on request
Trusted timestampDigiCert (default), SwissSign, SigstoreAny timestamp authority that speaks RFC 3161. Configuration only, no new code needed

The steps are not fixed either: further steps can be added where an installation needs them. If you have something in mind, talk to us.

Verifying a sealed recording

A sealed recording carries its verification files next to the recording files. For a recording with the token <token>:

FileContainsProves
<token>.meta.jsonThe manifest: every delivered file with its size and SHA-256 fingerprintWhat
<token>.meta.sigA digital signature over the manifest (ECDSA P-256)Who
<token>.meta.tsrA trusted timestamp over the manifest (RFC 3161), from an independent authorityWhen
<token>.origin.meta.*The origin seal: the same three files for the raw files, made before any processingFrom what

The seal uses open standards throughout, so anyone can check it independently of Veeting with sha256sum and OpenSSL 3. Each platform publishes the public keys of its servers at https://<HOSTNAME>/api/v6/recording-integrity/signing-keys. Keep the verification files together with the recording when you archive it.

A successful verification shows that none of the files changed after the seal was made, that a Veeting server signed it, and that it existed no later than the time of the timestamp. It says nothing about the content before the seal was made. The origin seal moves that point back to the moment the raw files were fingerprinted. The seal is not a qualified electronic seal under Swiss (ZertES) or EU (eIDAS) law. A qualified timestamp authority can be configured today; a qualified signing service would be added by Veeting.

For step-by-step verification instructions and the Veeting verification tool, contact us.

Not sure how to best implement your project?

Contact our team to discuss the details.