Trust Center

Tiro

Security isn't a feature. It's how we operate.

Tiro is an AI meeting assistant, built for security from day one. Explore our certifications, controls, and policies — and request the documents your security team needs.

partners@theplato.ioPrivacy PolicyLast updated July 25, 2026

Controls

Security controls operating across our infrastructure and organization, grouped by area.

42 controls · last reviewed July 25, 2026

Data security & encryption

6 controls
  • Audio discarded after transcription
    Audio is irreversibly discarded right after transcription and is never stored on disk in plaintext.
    Active
  • Encryption at rest and in transit
    Data is encrypted at rest with AES-256 and in transit with TLS 1.2+.
    Active
  • Per-user encryption keys
    Sensitive content is encrypted with a separate per-user key, so even an operator with direct database access cannot read it in plaintext.
    Active
  • Managed key custody (KMS / HSM)
    Keys are protected by AWS KMS using FIPS 140-2 Level 3 validated HSMs and rotated automatically every 12 months.
    Active
  • No customer data used for AI training
    No customer data, including conversations, is used to train or fine-tune AI models — across all tiers.
    Active
  • Irreversible deletion
    Deletion covers the operational database, backups, vector indexes, and caches; on account closure, KMS keys are scheduled for deletion.
    Active

Access control & authentication

7 controls
  • Least-privilege access (RBAC / ABAC)
    Role- and attribute-based access controls enforce least-privilege access to systems and data.
    Active
  • Restricted plaintext access
    Plaintext content access is restricted to a small set of explicitly authorized personnel under least-privilege controls, and every access is logged at the query and column level.
    Active
  • Single sign-on (SAML 2.0)
    Enterprise SSO via Okta, Azure AD, Google Workspace and other IdPs keeps access in sync with your policies.
    Active
  • Multi-factor authentication
    OTP, authenticator apps, or hardware keys add a second factor and block logins even if a password leaks.
    Active
  • IP allowlisting
    Access can be restricted to approved IP ranges so only office or VPN traffic is permitted.
    Active
  • SCIM provisioning
    User onboarding and offboarding in your IdP sync to Tiro automatically via SCIM.
    Active
  • Session & device controls
    A default 30-minute idle timeout (configurable for enterprise) plus policy controls over concurrent sessions and device registration.
    Active

Infrastructure & availability

5 controls
  • Korean data residency (AWS Seoul)
    Data is hosted in the AWS Seoul region (ap-northeast-2); enterprise customers can choose a dedicated VPC or another region.
    Active
  • Multi-AZ resilience
    A Multi-AZ deployment keeps the service available through single-AZ failures.
    Active
  • Encrypted automated backups
    Databases are backed up automatically under KMS encryption, with annual restore testing.
    Active
  • Tested recovery objectives
    Recovery objectives are RTO 24h and RPO 24h, validated by annual restore tests.
    Active
  • 99.9% uptime SLA
    A 99.9% monthly availability SLA applies, with service credits if we miss it.
    Active

Monitoring & threat detection

6 controls
  • 24×7 threat detection
    AWS GuardDuty continuously monitors the environment for threats.
    Active
  • Vulnerability scanning
    AWS Inspector continuously scans workloads for vulnerabilities.
    Active
  • Web attack protection
    A WAF together with Cloudflare protects against common web attacks.
    Active
  • Tamper-resistant logging
    Audit and infrastructure logs are delivered to isolated, tamper-resistant storage, protected from modification by operational systems.
    Active
  • Audit logs
    User and admin activity is logged with configurable retention and can be exported or streamed to your SIEM.
    Active
  • Penetration testing
    We run penetration testing and vulnerability assessments to identify and remediate risks proactively.
    Active

AI security & data privacy

5 controls
  • No model training on customer data
    Customer conversations, transcripts, and summaries are never used to train or fine-tune models.
    Active
  • Zero-Data-Retention vendor terms
    Every LLM and STT vendor is bound by a DPA that prohibits training and requires Zero Data Retention.
    Active
  • PII auto-masking
    Personally identifiable information in meeting notes can be detected and masked automatically.
    Active
  • Configurable data retention
    Retention windows can be set by domain, with automatic deletion when the window closes.
    Active
  • Vendor routing controls
    Choose which LLM and STT vendors are available to your tenant, including Korea-only routing.
    Active

Data governance & sharing

5 controls
  • External sharing controls
    Note sharing can be limited to an allowlist of trusted domains.
    Active
  • Mobile screen-capture protection
    Screenshots inside the mobile app can be blocked, with every attempt logged.
    Active
  • Organization retention policy
    Enterprise admins can enforce organization-wide retention windows centrally.
    Active
  • Complete deletion on closure
    When an account is closed, related personal data is deleted within 14 days and the encryption keys protecting it are scheduled for deletion, rendering any residual copies cryptographically inaccessible.
    Active
  • Deletion logging
    Each deletion request, execution, and completion is logged, and an erasure record can be provided to enterprise customers on request.
    Active

Corporate & organizational

4 controls
  • Security training
    Employees complete mandatory security training at onboarding.
    Active
  • Quarterly access reviews
    Access rights are reviewed every quarter to keep least-privilege current.
    Active
  • Information security policies
    A full information security policy set is maintained and operated on the dedicated GRC platform.
    Active
  • Vendor due diligence
    Subprocessors are bound by DPAs that prohibit training and require Zero Data Retention.
    Active

Incident response & continuity

4 controls
  • Incident response
    Enterprise customers are covered by a 4-hour first-response SLA for security incidents.
    Active
  • Breach notification SLA
    Affected customers are notified of security incidents within a 24-hour notification SLA.
    Active
  • Business continuity & DR
    Backups, Multi-AZ deployment, and tested recovery objectives underpin business continuity and disaster recovery.
    Active
  • Change management
    Production changes follow controlled review and deployment processes.
    Active