SOC 2 Type 2, ISO 27001, and HIPAA AI Note Takers (2026): Compliance and Security Guide
Compare AI note takers across SOC 2 Type 2, ISO 27001, HIPAA BAA availability, and GDPR compliance. See verified security standards, zero data retention policies, and enterprise criteria.

Key takeaways
- Tiro's audited baseline: Tiro holds SOC 2 Type 2 (2026-07 취득) (auditor Sensiba LLP, unqualified opinion) covering all five Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, and Privacy), and is certified to ISO/IEC 27001:2022. Reports are shared under NDA on request through the Tiro Trust Center. A DPA is available on request (partners@theplato.io), and healthcare or HIPAA requirements go to the same address.
- SOC 2 Type 2 and ISO 27001 evaluate distinct security controls: A SOC 2 Type 2 report verifies operational adherence to Trust Services Criteria across an observation period, whereas ISO/IEC 27001:2022 certifies an organizational Information Security Management System (ISMS). Holding one does not automatically imply the other.
- Enterprise compliance does not equal healthcare eligibility: General corporate security certifications like SOC 2 do not allow the ingestion of Protected Health Information (PHI). Regulated healthcare organizations require an executed Business Associate Agreement (BAA), which specialized medical tools like Freed AI and select enterprise tiers support, while tools like Granola explicitly state they cannot sign BAAs.
- Data retention and model training policies differ widely: Vendors implement varying data architectures, ranging from transient audio caching that deletes recordings immediately after transcription to indefinite transcript storage. Similarly, while third-party subprocessor training is commonly restricted contractually, first-party training on de-identified user data remains active by default on certain platforms unless configured otherwise.
- Infrastructure controls dictate enterprise readiness: Enterprise governance depends on organizational controls such as Single Sign-On (SSO), administrative workspace policies, password-protected share links, and token-scoped APIs or Model Context Protocol (MCP) servers.
Competitor details on this page reflect each vendor's official pages as of September 10, 2026.
Tiro's Security and Compliance Posture
Tiro is an AI meeting-notes product from ThePlato Inc. (Seoul). Its certifications and subprocessors are listed on the Tiro Trust Center.
| Area | Tiro |
|---|---|
| SOC 2 Type 2 | SOC 2 Type 2 (2026-07 취득). Auditor Sensiba LLP, unqualified opinion. Scope: all five Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy), including operating effectiveness over the audit period. |
| ISO/IEC 27001:2022 | ISO/IEC 27001:2022 certified (Stage 1 and Stage 2 complete). |
| Audit reports | The SOC 2 report and ISO documents are shared under NDA on request. |
| GDPR | DPA available on request (partners@theplato.io). |
| Healthcare and HIPAA | Send healthcare or HIPAA requirements to partners@theplato.io. |
| Subprocessors | Current list on the Tiro subprocessors page. |
| Audio retention | Audio files are irreversibly discarded right after transcription. If a customer explicitly opts into retention, audio is stored encrypted with a separate key and permanently destroyed on deletion. |
| Model training | No customer data, including conversations, is used for model training or fine-tuning on any plan. Every LLM and STT vendor is under a DPA that prohibits training and requires zero data retention. |
| Encryption and identity | AES-256 at rest and TLS 1.2+ in transit, with an additional per-user encryption layer for sensitive content. SAML 2.0 / OIDC SSO with Okta, Azure AD (Entra ID), and Google Workspace; MFA via the identity provider; SCIM 2.0 provisioning on Enterprise. |
Understanding AI Note Taker Compliance: What SOC 2, ISO 27001, GDPR, and HIPAA Actually Prove
Deploying an AI meeting assistant across corporate, legal, or healthcare environments introduces sensitive audio streams, proprietary transcripts, and customer records to cloud subprocessors. Security and compliance leaders must evaluate specific legal and operational frameworks rather than treating vendor security badges as interchangeable credentials.
| Operational Audits (SOC 2 Type 2) | Management Frameworks (ISO/IEC 27001:2022) | Statutory Regulation (GDPR DPA / HIPAA BAA) |
|---|---|---|
| Verifies operational controls (Security, Confidentiality, Privacy) over an audit window. | Standardizes organizational information security management systems and risk governance. | Imposes legal obligations for regional privacy (GDPR) and health data protection (PHI). |
SOC 2 Type 2 vs. ISO/IEC 27001
A SOC 2 Type 2 report evaluates how effectively a service organization's security controls operate over a defined audit window (typically 3 to 12 months) against the American Institute of CPAs (AICPA) Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Unlike a Type 1 audit, which only examines control design at a single moment, Type 2 tests historical enforcement.
ISO/IEC 27001:2022 is an internationally recognized standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). While SOC 2 is standard in North America for SaaS vendor evaluation, ISO 27001 is often preferred globally. Importantly, having internal security policies modeled after ISO 27001/2 (as noted by Otter.ai) is distinct from holding an accredited third-party ISO/IEC 27001:2022 certification.
GDPR and Cross-Border Data Transfers
The General Data Protection Regulation (GDPR) governs personal data processing for European Union and UK data subjects. AI transcription tools handling corporate calls often process identifiers, voiceprints, and proprietary business discussions. Compliance requires executing a Data Processing Agreement (DPA) containing Standard Contractual Clauses (SCCs) or reliance on frameworks such as the EU-U.S. Data Privacy Framework (DPF).
SaaS tools frequently host data primarily on United States cloud infrastructure (such as Amazon Web Services). For example, Granola and Fathom host user data in the US while offering signed DPAs and Standard Contractual Clauses to support lawful international data transfers.
HIPAA and Business Associate Agreements (BAAs)
The Health Insurance Portability and Accountability Act (HIPAA) governs Protected Health Information (PHI) in the United States. Under HIPAA, a software provider that processes, transmits, or stores PHI on behalf of a covered entity is legally classified as a Business Associate and must execute a formal Business Associate Agreement (BAA).
General corporate AI note takers holding SOC 2 Type 2 reports are not legally permitted to process PHI unless the vendor explicitly signs a BAA and maintains HIPAA-compliant administrative, physical, and technical safeguards.
Comparison Matrix: Verified Security Certifications, HIPAA Support, and Data Retention
The following matrix compares documented compliance postures, healthcare agreements, regional data protection frameworks, and audio retention architectures across five AI meeting tools. Tiro's own posture is summarized at the top of this page.
| Provider | Documented SOC 2 Status | ISO 27001 Status | HIPAA Alignment / BAA | GDPR / DPA Support | Audio & Transcript Retention Baseline |
|---|---|---|---|---|---|
| Fireflies.ai | SOC 2 Type II documented | Not established in published record | HIPAA compliance listed on Enterprise plan | Signed DPA, EU-U.S. DPF, and SCCs supported | 0-day vendor retention; dashboard deletion wipes records; custom retention on Enterprise |
| Otter.ai | Achieved SOC 2 Type 2 report | Policies based on ISO 27001/2 framework (not certified) | HIPAA compliance add-on listed on Enterprise plan | Incorporated GDPR standards into data practices | Trash auto-deleted after 30 days; Enterprise custom retention & audio removal |
| Granola | Holds SOC 2 Type II report (available under NDA) | ISO 27001 not yet available | Explicitly not HIPAA compliant; cannot sign BAAs | Complies with GDPR/UK GDPR via signed DPA with SCCs; US hosting | Real-time audio deleted after transcription; transcripts retained indefinitely unless retention set |
| Fathom | Holds SOC 2 Type II report | Does not hold ISO 27001 | States HIPAA compliance | Offers signed DPA for EU/UK users; US hosting | Unlimited storage; account deletion removes data and purges backups in 7 days |
| Freed AI | SOC 2 Type II certified | Not established in published record | Dedicated clinical scribe; provides Organization-wide BAA | Not established in published record | Does not store patient recordings; custom note retention settings on Admin plan |
Where a signed BAA must be in place before any PHI is recorded, the official pages above document that specification today: Freed AI provides an organization-wide BAA, Fireflies.ai and Otter.ai list HIPAA options on their Enterprise plans, and Fathom states HIPAA compliance. For Tiro, send healthcare or HIPAA requirements to partners@theplato.io.
Model Training Policies and Audio Retention Architecture
Security reviews of generative AI meeting tools must separate two distinct technical operations: how raw audio streams are stored and whether customer transcripts or metadata are utilized for model training.
Audio Storage vs. Transient Caching
AI note takers differ in how they capture and store audio:
- Ephemeral Audio Caching: Granola captures audio locally from device system sound and microphones, caches it temporarily during transcription, and deletes the audio once transcription completes. It stores only the resulting transcript and user notes. Similarly, clinical scribe Freed AI notes that its system does not store patient recordings.
- Persistent Audio Storage with Retention Controls: Platforms such as Fathom offer unlimited recording and storage on both Free and Premium tiers. Fireflies.ai wipes meeting records from its system when deleted from the dashboard and provides private storage options and custom retention controls on Enterprise plans. Otter.ai moves deleted conversations to a Trash folder that auto-deletes after 30 days, while offering custom data retention policies and audio removal options for Enterprise subscribers.
Subprocessor Prohibitions and Proprietary Model Training
A key enterprise concern is whether call data is ingested into public large language models (LLMs). Most enterprise AI assistants contractually bar third-party foundation model vendors from training on customer data:
- Third-Party LLM Vendor Prohibitions: Fathom contractually prohibits its AI subprocessors (Anthropic, OpenAI, Google) from using customer data to train their models. Granola and Fireflies.ai also contractually restrict external vendors from retaining or training on meeting transcripts and summaries.
- First-Party Internal Training and Opt-Outs: Policies regarding a vendor's own proprietary models vary. Otter.ai uses a proprietary method to de-identify user data prior to training internal models, and commits that imported customer data (such as Google Workspace files) is not used for model training. Fathom states that it uses de-identified customer data to improve the accuracy of its proprietary models. Granola notes that anonymized data on Free and Basic tiers may be used for product improvements, while allowing individual opt-outs and providing org-wide training opt-out controls for Enterprise workspace administrators.
Access Governance, Developer Tooling, and Integration Security
Enterprise security requires managing how meeting summaries are shared, accessed, and automated across corporate systems. Organizations standardizing on meeting workflows, from initial recording to summary generation, contextual querying, and team sharing, rely on granular identity controls and secure programmatic interfaces.
Identity Management and Workspace Governance
Access governance begins with identity authentication and permission boundaries:
- Single Sign-On (SSO): Granola provides SSO on Enterprise plans for organizations with 50+ seats. Freed AI lists SSO under its Groups and Admin tiers. Otter.ai offers SSO on its Enterprise plan with a minimum 100-user license requirement.
- Automated Provisioning (SCIM): User lifecycle management through SCIM ensures prompt deprovisioning when employees leave. Otter.ai supports SCIM provisioning on Enterprise tiers (100-seat minimum).
- Administrative Access Controls: Fireflies.ai provides automated workflows via its Rules Engine and includes Super Admin roles on its Enterprise plan. Granola defaults notes to private, offering three sharing tiers: Private, Only your company, or Public links.
Secure Sharing and Developer Interfaces
AI meeting notes often need to be shared across distributed teams or integrated into developer workflows:
- Password-Protected Share Links: Unauthenticated public links present data leakage risks. Meeting notes platforms such as Tiro enable public share links that can be protected with passwords to ensure only authorized recipients access meeting records without requiring a full account login.
- Token-Scoped REST APIs and Webhooks: Programmatic data extraction must adhere to scoped authorization. Tiro's REST API supports workspace-scoped and organization-scoped API keys with rate-limiting thresholds (600 requests per 60 seconds per key) and Bearer token authentication. Tiro webhooks deliver event notifications (such as
note_document.generatedornote_document.deleted) authenticated with a pre-shared secret key sent in theAuthorizationheader. Otter.ai similarly provides API and Webhook access for Enterprise customers. - Model Context Protocol (MCP) Integrations: Connecting AI agents directly to meeting notes requires scoped read permissions. Tiro provides an MCP Server and CLI tools for AI clients to search and read meeting notes, including a
get_share_linktool (scopemcp:note:read) that verifies access to password-protected links. Granola offers MCP integrations utilizing browser-based OAuth restricted to notes the user has permission to view.
Multilingual Workflows Across Online and In-Person Meetings
Global organizations frequently require meeting documentation that bridges language barriers across diverse meeting formats. Tiro, developed around the slogan "Perfectly crafted meeting notes — beyond language barriers", structures meeting intelligence across 15 supported languages in four phases:
- Recording: Capturing online video conferences or in-person discussions across desktop and mobile environments.
- Documentation & Translation: Generating synchronized transcripts, summaries, and action items across 15 supported languages.
- Search & Inquiry: Allowing teams to query past meetings, surface decisions, and retrieve contextual details.
- Collaboration: Sharing structured meeting notes across team workspaces or external stakeholders via password-protected links.
Accurate transcription and summary generation depend heavily on audio quality and situational context; organizations should verify meeting configurations to maintain documentation integrity.
Enterprise Procurement Checklist for AI Note Takers
Before approving an AI meeting assistant for organizational deployment, Information Security (InfoSec) and procurement teams should execute this 6-point verification process:
- Inspect the Full SOC 2 Type 2 Report: Do not accept marketing badges alone. Request the full auditor report under NDA to evaluate the testing window, the specific Trust Services Criteria covered, and whether any testing exceptions were noted.
- Verify ISO 27001 Certification Authenticity: Confirm whether the vendor holds an accredited ISO/IEC 27001:2022 certificate covering their specific SaaS application and infrastructure, or merely bases internal policies on the ISO framework.
- Mandate a BAA for Healthcare Workloads: If meeting content touches patient health records, confirm that the vendor explicitly signs a Business Associate Agreement (such as Freed AI or designated enterprise tiers) and enforce appropriate user access policies.
- Execute DPAs and Review Data Residency: For EU/UK operations, ensure the vendor provides a standard DPA with Standard Contractual Clauses or DPF adherence. Confirm whether transcript and audio data reside on US or regional cloud infrastructure.
- Audit Subprocessor and Model Training Terms: Check contracts to ensure third-party LLM providers (e.g., OpenAI, Anthropic) cannot train foundational models on your data. Check whether the vendor trains its own internal models on customer data and ensure org-wide opt-out switches are available.
- Evaluate Identity Governance and API Scopes: Verify whether SSO and SCIM require specific seat minimums (e.g., 50 or 100 seats) and ensure external sharing links support password protection or workspace-only restrictions.
FAQS
Frequently Asked Questions
Which AI note takers have SOC 2 Type 2 and ISO 27001?
Verified compliance statuses differ by vendor. Granola, Otter.ai, Fathom, and Freed AI document SOC 2 Type II reports or certifications. Tiro holds SOC 2 Type 2 (2026-07 취득) (Sensiba LLP, all five Trust Services Criteria) and is certified to ISO/IEC 27001:2022; both are listed on the Tiro Trust Center, and reports are shared under NDA on request. Regarding ISO 27001, Otter.ai notes its security policies are based on the ISO 27001/2 framework rather than holding an accredited certificate, and Fathom and Granola state that ISO 27001 is not currently held.
Does a SOC 2 Type 2 report make an AI note taker HIPAA compliant?
No. A SOC 2 Type 2 report verifies operational security controls against AICPA criteria, but it does not satisfy the statutory requirements of the Health Insurance Portability and Accountability Act (HIPAA). Processing Protected Health Information (PHI) requires technical and administrative safeguards alongside a signed Business Associate Agreement (BAA).
Can enterprise AI note takers sign a HIPAA Business Associate Agreement (BAA)?
BAA availability varies by vendor and plan. Dedicated clinical documentation tools like Freed AI offer organization-wide BAAs. General enterprise note takers like Fireflies.ai and Otter.ai offer HIPAA compliance on Enterprise tiers. Conversely, tools like Granola explicitly state they are not HIPAA compliant and cannot sign BAAs. For Tiro, send healthcare or HIPAA requirements to partners@theplato.io.
How do AI note takers comply with GDPR when data is hosted in the US?
AI note takers storing data on US cloud infrastructure (such as AWS) comply with GDPR by signing Data Processing Agreements (DPAs) that incorporate European Commission Standard Contractual Clauses (SCCs) or by participating in the EU-U.S. Data Privacy Framework (DPF). Vendors like Granola, Fireflies.ai, and Fathom offer signed DPAs to establish lawful data transfer mechanisms for EU/UK customers. Tiro's DPA is available on request (partners@theplato.io).
Do AI note takers train AI models on customer meeting audio and transcripts?
Most enterprise providers contractually prohibit third-party model providers (such as OpenAI or Anthropic) from training on customer transcripts. However, policies regarding first-party internal model improvements differ: some vendors use de-identified customer data by default on lower-tier plans while offering organization-wide model training opt-outs on Enterprise plans. Security teams should review individual vendor DPAs and workspace settings to configure training opt-outs.
Evaluate Tiro for Secure Enterprise Meeting Notes
Review Tiro's SOC 2 Type 2 and ISO/IEC 27001:2022 posture, access controls, and multilingual meeting documentation, and request reports under NDA.
Related reading


