# Recording pipeline

Source: https://www.veeting.com/en/developer-documentation/recording-pipeline

## Overview

When a recorded meeting is closed, the Veeting recording pipeline turns the raw media of its participants into finished files: a gallery video of the whole meeting and, if enabled, an MP4 copy, a transcription and a tamper-evident seal over all of it.

The pipeline is a sequence of steps. Some always run; others are enabled per installation or per customer. Several steps hand their work to an external service, a *provider*. Providers are interchangeable, so the pipeline does not depend on any one vendor. Transcription is *not* enabled in our standard Veeting Rooms offering.

## How the pipeline works

![The recording pipeline: raw per-participant streams are recorded, decoded and composed into a gallery video, optionally exported to MP4 and transcribed, optionally sealed with a manifest, a digital signature and a trusted timestamp, and announced with a web hook and an email](/assets/img/documentation/recording-pipeline.en.svg)

```mermaid
flowchart TB
    classDef core fill:#ffffff,stroke:#000000,stroke-width:2px,color:#000000
    classDef optional fill:#ffffff,stroke:#000000,stroke-dasharray:5 4,color:#000000
    classDef provider fill:#ffffff,stroke:#000000,color:#000000

    subgraph S1["Recording"]
        direction LR
        REC["Separate audio and video streams<br/>for each participant"]:::core
        ORIGIN["Fingerprints of the raw files,<br/>digitally signed and timestamped"]:::optional
        REC -.-> ORIGIN
    end

    subgraph S2["Processing"]
        direction LR
        PREP["Decode and align the individual<br/>audio and video files"]:::core
        COMPOSE["Detect breaks and interruptions,<br/>compose the gallery video"]:::core
        AUDIO["Audio-only meetings:<br/>mixed audio of all participants"]:::core
        PREP --> COMPOSE
    end

    subgraph S3["Optional outputs"]
        direction LR
        MP4["MP4 export"]:::optional
        TRANSCRIPT["Transcription<br/>text, SRT, JSON"]:::optional
        TP{{"OpenAI Whisper, DeepVA,<br/>your own transcription service"}}:::provider
        TP --- TRANSCRIPT
    end

    subgraph S4["Delivery seal"]
        direction LR
        MANIFEST["Integrity manifest<br/>SHA-256 of every file"]:::optional
        SIGNATURE["Digital signature"]:::optional
        TIMESTAMP["Timestamp service<br/>RFC 3161"]:::optional
        SP{{"Veeting private key,<br/>your own signing service,<br/>e.g. with a qualified certificate"}}:::provider
        TSP{{"DigiCert, SwissSign, Sigstore,<br/>your own RFC 3161 timestamp service"}}:::provider
        MANIFEST -.-> SIGNATURE
        MANIFEST -.-> TIMESTAMP
        SP --- SIGNATURE
        TSP --- TIMESTAMP
    end

    OUT[("Finished recording<br/>video and audio, separate videos per session<br/>and per participant, manifest, signatures and timestamps")]:::core
    READY["Recording is ready<br/>web hook, email"]:::core

    REC --> PREP
    REC --> AUDIO
    ORIGIN -.-> PREP
    COMPOSE --> OUT
    AUDIO --> OUT
    COMPOSE -.-> MP4
    COMPOSE -.-> TRANSCRIPT
    AUDIO -.-> TRANSCRIPT
    COMPOSE -.-> MANIFEST
    AUDIO -.-> MANIFEST
    MP4 -.-> MANIFEST
    TRANSCRIPT -.-> MANIFEST
    SIGNATURE -.-> OUT
    TIMESTAMP -.-> OUT
    OUT --> READY

    style S1 fill:#ffffff,stroke:#000000
    style S2 fill:#ffffff,stroke:#000000
    style S3 fill:#ffffff,stroke:#000000
    style S4 fill:#ffffff,stroke:#000000
```

Steps with a solid border always run. Steps with a dashed border are optional. The hexagons are provider slots: they list the providers supported today and show where your own service can plug in.

1. **Recording.** During the meeting, the media server records the audio and video of each participant as separate raw files. *Optional:* when processing starts, before anything else touches or moves them, these raw files are fingerprinted, signed and timestamped. This is the *origin seal*.
2. **Processing.** The pipeline decodes the raw files and aligns them on a common timeline. It splits the meeting into *sessions*, separated by breaks: everyone leaving, or the recording being stopped and restarted. For each session it composes a gallery video that shows the participants side by side, with everyone's audio mixed in. Audio-only meetings skip the video steps. Large installations run this step on a dedicated recording server, so the media server keeps its resources for live meetings.
3. **Optional outputs.** The pipeline can export an MP4 copy that plays in most players, and transcribe the whole meeting and each session as plain text, SRT subtitles and JSON, using the transcription provider you choose.
4. **Delivery seal.** *Optional:* a manifest lists every delivered file with its SHA-256 fingerprint. The manifest is digitally signed, then timestamped by an independent timestamp authority. If a delivered file changes by a single byte afterward, verification fails and names the file.
5. **Completion.** The platform calls the `onMeetingRecordingCreated` [web hook](/en/developer-documentation/web-hooks), so your own system can copy the recording to permanent storage right away. The verification files sit next to the recording, in the same location as `mergedRecordingUrl`; copy them too. Depending on the meeting's settings, the organizer, and optionally every participant, receives an email with a link to the recording.

## Providers

Each provider slot is open. Use one of the providers supported today, or have us connect yours.

| Step              | Providers today                         | Adding another provider                                                                         |
| ----------------- | --------------------------------------- | ----------------------------------------------------------------------------------------------- |
| Transcription     | OpenAI Whisper, DeepVA                  | A REST API that accepts an audio file upload. Veeting adds a provider module for it             |
| Digital signature | A key held by each Veeting server       | Your own signing service, for example with a qualified certificate. Added by Veeting on request |
| Trusted timestamp | DigiCert (default), SwissSign, Sigstore | Any timestamp authority that speaks RFC 3161. Configuration only, no new code needed            |

The steps are not fixed either: further steps can be added where an installation needs them. If you have something in mind, [talk to us](mailto:info@veeting.com).

## Verifying a sealed recording

A sealed recording carries its verification files next to the recording files. For a recording with the token `<token>`:

| File                    | Contains                                                                            | Proves    |
| ----------------------- | ----------------------------------------------------------------------------------- | --------- |
| `<token>.meta.json`     | The manifest: every delivered file with its size and SHA-256 fingerprint            | What      |
| `<token>.meta.sig`      | A digital signature over the manifest (ECDSA P-256)                                 | Who       |
| `<token>.meta.tsr`      | A trusted timestamp over the manifest (RFC 3161), from an independent authority     | When      |
| `<token>.origin.meta.*` | The origin seal: the same three files for the raw files, made before any processing | From what |

The seal uses open standards throughout, so anyone can check it independently of Veeting with `sha256sum` and OpenSSL 3. Each platform publishes the public keys of its servers at `https://<HOSTNAME>/api/v6/recording-integrity/signing-keys`. Keep the verification files together with the recording when you archive it.

A successful verification shows that none of the files changed after the seal was made, that a Veeting server signed it, and that it existed no later than the time of the timestamp. It says nothing about the content before the seal was made. The origin seal moves that point back to the moment the raw files were fingerprinted. The seal is not a qualified electronic seal under Swiss (ZertES) or EU (eIDAS) law. A qualified timestamp authority can be configured today; a qualified signing service would be added by Veeting.

For step-by-step verification instructions and the Veeting verification tool, [contact us](mailto:info@veeting.com).

---

## The rest of this documentation

- [Custom tools](https://www.veeting.com/en/developer-documentation/custom-tools)
- [External meeting authorization service](https://www.veeting.com/en/developer-documentation/external-meeting-authorization-service)
- [iFrame and Web Components](https://www.veeting.com/en/developer-documentation/iframe-and-web-components)
- [JavaScript APIs](https://www.veeting.com/en/developer-documentation/javascript-apis)
- [Query parameters](https://www.veeting.com/en/developer-documentation/query-parameters)
- [Room system control](https://www.veeting.com/en/developer-documentation/room-system-control)
- [Veeting Blocks - Components](https://www.veeting.com/en/veeting-blocks/components)
- [Veeting Blocks - Introduction](https://www.veeting.com/en/veeting-blocks/introduction)
- [Veeting Blocks - JavaScript and Typescript APIs](https://www.veeting.com/en/veeting-blocks/apis)
- [Veeting Rooms REST APIs](https://www.veeting.com/en/developer-documentation/api-usage)
- [Video display calculator](https://www.veeting.com/en/developer-documentation/video-display-calculator)
- [Web hooks](https://www.veeting.com/en/developer-documentation/web-hooks)

All of it in one file: https://www.veeting.com/llms-full.txt
