Secure Video Conferencing for Regulated Industries
Start free — no credit card. Enter your work email to get going:
Video Conferencing That Takes Security Seriously
Video conferencing has become the default mode of meeting for organisations worldwide. Board discussions, patient consultations, legal strategy sessions, financial reviews, and classified briefings all happen over video. Yet most organisations use the same consumer-grade platforms for these sensitive conversations that they use for casual team check-ins.
For regulated industries — healthcare, financial services, government, defence, and legal — this is not adequate. These sectors operate under specific regulatory frameworks that impose strict requirements on how communications are handled, where data is stored, who can access it, and how long it is retained.
Mandraki is built to meet these requirements without sacrificing the usability that drives adoption.
Architecture for Security
Selective Forwarding Unit (SFU)
Mandraki uses a modern SFU architecture based on mediasoup. Unlike peer-to-peer architectures that struggle with large groups, or multipoint control units that decode and re-encode media on the server, the SFU receives media streams from each participant and forwards them to the others without decoding.
This architecture provides two critical benefits for security:
- Scalability. The SFU can handle large meetings efficiently, routing only the streams each participant needs.
- E2EE compatibility. Because the SFU does not decode media, it can forward encrypted frames transparently. When end-to-end encryption is enabled via SFrame, the server handles only ciphertext.
NAT Traversal
Enterprise networks frequently use firewalls and NAT configurations that block direct peer-to-peer connections. Mandraki operates its own TURN relay servers within the EU to ensure connectivity in restrictive network environments. Media relayed through TURN servers remains encrypted in transit and, when E2EE is active, is encrypted end-to-end.
Encryption Layers
Video calls benefit from multiple encryption layers:
- Transport encryption (DTLS-SRTP). All media is encrypted in transit between clients and the SFU, regardless of other settings.
- End-to-end encryption (SFrame). When enabled, media frames are encrypted on the sender’s device and decrypted only on recipients’ devices. The SFU cannot access the media content.
- At-rest encryption. Call recordings, if enabled, are encrypted using the organisation’s data encryption key before storage.
Compliance by Sector
Healthcare
Patient consultations via video must comply with GDPR and, in many jurisdictions, sector-specific regulations such as Germany’s DiGAV or France’s HDS requirements. Mandraki’s EU data residency, encryption, and consent controls provide the technical foundations for compliant telemedicine.
Audit logging captures who joined each call, when, and what features were active, supporting the accountability requirements of healthcare data protection.
Financial Services
The Digital Operational Resilience Act (DORA) requires financial entities to manage ICT risk, including the resilience of communication tools. Mandraki’s European-only infrastructure, absence of US dependencies, and documented disaster recovery capabilities support DORA compliance.
MiFID II and similar regulations require that certain financial communications be recorded and retained. Mandraki’s call recording feature, with configurable retention periods and encrypted storage, supports these obligations.
Government and Defence
Public sector organisations increasingly require platforms that are hosted on sovereign infrastructure and certified under national or European cybersecurity schemes. Mandraki’s deployment on European hyperscale infrastructure and its end-to-end encryption capabilities position it for government use cases where classified or sensitive information is discussed.
Legal
Attorney-client privilege requires that legal communications are protected from disclosure. End-to-end encrypted video calls on Mandraki ensure that neither the platform operator nor the infrastructure provider can access the content of legal consultations.
Practical Features for Secure Meetings
Beyond architecture, Mandraki includes practical features that support secure meeting workflows:
- Meeting rooms with persistent links for recurring sessions, reducing the risk of misaddressed invitations.
- Participant controls allowing hosts to manage who can join, share screens, or record.
- Waiting rooms to vet participants before admitting them to sensitive discussions.
- In-call chat with the same encryption protections as the video stream.
- Screen sharing for document review without requiring file uploads to third-party services.
Security and usability are not in tension. Mandraki delivers both, for organisations where the stakes are too high for compromise.