Trust Center

Tiro

Security isn't a feature. It's how we operate.

Tiro is an AI meeting assistant, built for security from day one. Explore our certifications, controls, and policies — and request the documents your security team needs.

partners@theplato.ioPrivacy PolicyLast updated July 25, 2026

Start your security review

Welcome to Tiro's Trust Center. Use this portal to review our security posture, browse our certifications and controls, and request the documents your security team needs.

Compliance

Independently audited certifications, plus the frameworks our security program aligns to.

Certified

ISO/IEC 27001:2022

Certified June 4, 2026 · Sensiba LLP

The international standard for an information security management system (ISMS), confirmed by an independent, accredited audit.

Attested

SOC 2 Type 1

5 Trust Services Criteria

Attests that our security controls are suitably designed at a point in time across five Trust Services Criteria.

Attested

SOC 2 Type 2

Attested July 24, 2026 · Sensiba LLP

Evaluates how those controls actually operated over the audit period, across the same five Trust Services Criteria. Unqualified opinion.

Frameworks & self-attestations

Frameworks our information security program aligns to. Self-attested unless an audit is noted.

  • NIST CSF
  • NIST AI RMF
  • CIS Controls 8.1
  • GDPR
  • CCPA / CPRA

Controls

View all

Data security & encryption

  • Audio discarded after transcription
  • Encryption at rest and in transit
  • Per-user encryption keys
View 3 more controls

Access control & authentication

  • Least-privilege access (RBAC / ABAC)
  • Restricted plaintext access
  • Single sign-on (SAML 2.0)
View 4 more controls

Infrastructure & availability

  • Korean data residency (AWS Seoul)
  • Multi-AZ resilience
  • Encrypted automated backups
View 2 more controls

AI security & data privacy

  • No model training on customer data
  • Zero-Data-Retention vendor terms
  • PII auto-masking
View 2 more controls

How your data flows

What happens to a meeting from capture to deletion, and which providers see what.

  1. 1
    Capture

    Meeting audio is captured and streamed over TLS 1.2+ — never written to disk in plaintext.

  2. 2
    Transcribe

    Audio is sent to a speech-to-text provider under a Zero-Data-Retention contract, converted to text, then discarded.

  3. 3
    Summarize

    Transcript text is sent to an LLM provider (Zero Data Retention, no training) to generate summaries and answers.

  4. 4
    Store

    Notes, transcripts, and summaries are encrypted at rest with AES-256 in the AWS Seoul region, isolated by per-user keys.

  5. 5
    Delete

    On deletion, content is removed from the database, backups, vector indexes, and caches; KMS keys are scheduled for deletion on account closure.

Data ownership & privacy

Your data is yours. Here is how we handle ownership, processing terms, and where your data lives.

You own your data

Customer content belongs to you. We process it only to provide the service, never sell it, and never use it to train AI models.

DPA & SCCs

A Data Processing Agreement is available, incorporating EU Standard Contractual Clauses for international transfers.

Data residency

Data is stored in the AWS Seoul region (ap-northeast-2) by default. Enterprise customers can request a dedicated region or VPC.

Data subject rights

We support access, correction, export, and deletion requests in line with GDPR and CCPA.

VDI & closed-network environments

Tiro runs in locked-down VDI and closed-network environments with no client to install — finance, public-sector, and enterprise teams use it through their in-house virtual desktops.

No client to install

A standard HTTPS web app — it works in Chrome, Edge, and Safari inside a VDI, with no native client or agent to deploy.

Gateway & CASB friendly

All traffic stays on the *.tiro.ooo domain, so VDI gateways and CASBs (Prisma Access, Netskope, Zscaler, and others) can apply domain- and IP-based policy. Fixed egress IPs and domain allowlists are available for enterprise.

Admin-controlled export

Note export (PDF/Markdown/DOCX) is governed at the admin level, and every download and export is written to the audit log — so your VDI data-loss controls extend to Tiro.

Doesn't rely on the endpoint

Confidentiality comes from server-side per-user encryption, not the device — the database is never exposed in plaintext, even to operators.

Incident response & availability

How we detect, respond to, and communicate security incidents — and where to check live status.

1

Detect

24×7 monitoring (AWS GuardDuty, Inspector, WAF, CloudTrail) surfaces anomalies in real time.

2

Respond

Confirmed security incidents trigger a 4-hour first-response SLA for enterprise customers.

3

Notify

Affected customers are notified within a 24-hour breach-notification SLA, with scope, impact, and remediation.

4

Review

Every incident is followed by a post-incident review and corrective actions.

Vulnerability disclosure

We welcome reports from security researchers and handle them responsibly.

We acknowledge reports within 3 business days and keep you updated through remediation.

Good-faith research conducted under this policy is authorized — we will not pursue legal action against researchers who follow it.

Data we handle

What Tiro processes, and how each category is protected.

  • Meeting audio — discarded immediately after transcription
  • Transcripts & summaries — encrypted at rest with AES-256
  • Account & organization information
  • Usage & diagnostic logs