Trust Center
Tiro
Security isn't a feature. It's how we operate.
Tiro is an AI meeting assistant, built for security from day one. Explore our certifications, controls, and policies — and request the documents your security team needs.
Security questionnaire & FAQ
Answers to the questions security teams ask most, grouped by assessment area.
Need a full CAIQ, SIG, or our security questionnaire? Request it Request access
Data ownership
Who owns the data and the rights to the content?
You do. Customer content remains yours under our Terms of Service; Tiro processes it solely to provide the service and claims no ownership.
When is customer data allowed to leave your production systems?
Only encrypted, and only to the subprocessors required to deliver the service (speech-to-text, LLM, storage), each under a Zero-Data-Retention DPA. Data is never exported for marketing or model training.
Data handling & retention
Where is data stored and where are your servers located?
In the AWS Seoul region (ap-northeast-2), Multi-AZ, encrypted at rest with AES-256 using per-user keys.
Do you offer data residency options?
Seoul is the default. Enterprise customers can request a dedicated region or VPC, and vendor routing can be restricted (for example, Korea-only).
What is your data retention policy?
Customers control retention. Audio is discarded after transcription; notes, transcripts, and summaries are kept until you delete them or your configured retention window closes (for example, 90/180/365 days for enterprise).
When data is deleted, is it still stored anywhere?
No. Deletion propagates to the operational database, vector indexes, and caches immediately; automatic backups roll off within their retention window; and on account closure the KMS keys protecting the data are scheduled for deletion, rendering any residual copies cryptographically inaccessible.
How is meeting audio handled?
In real time, audio streams through the speech-to-text engine and is discarded from memory immediately — never stored in plaintext. Uploaded files are discarded after processing. Optional opt-in retention stores audio in your own encrypted storage (off by default).
Access & personnel
Who at Tiro can access customer data?
By default only you and the people you share with. Operationally, plaintext access is restricted to a small set of explicitly authorized personnel, and every access is logged at the query and column level.
What controls apply to employees with access?
Mandatory security training at onboarding, least-privilege access enforced via RBAC/ABAC, and quarterly access reviews.
AI & subprocessors
Do you train AI models on customer data?
Never. No customer data — conversations, transcripts, or summaries — is used to train or fine-tune models, across all tiers. Every LLM and speech-to-text vendor is contractually bound to Zero Data Retention and no training.
Which AI subprocessors receive which data?
Speech-to-text vendors receive meeting audio for transcription; LLM vendors receive transcript and prompt text for summaries — all under Zero-Data-Retention contracts. See the Subprocessors page for the full list and what each receives.
Does any human review my content?
No routine human review. Plaintext access is restricted to a small set of authorized personnel for support and debugging only, with every access logged.
Resilience & incident response
What is your incident response process?
24×7 monitoring detects anomalies; confirmed incidents trigger a 4-hour first-response SLA (enterprise), customer notification within 24 hours, and a post-incident review. Report security issues to partners@theplato.io.
How and when are customers notified of a breach?
Affected enterprise customers are notified within a 24-hour breach-notification SLA, including scope, impact, and remediation steps.
What are your business continuity and disaster recovery measures?
Multi-AZ deployment, automatic KMS-encrypted backups with annual restore testing, RTO 24h and RPO 24h, and a 99.9% monthly uptime SLA.
How often do you conduct penetration testing?
We run a penetration-testing and vulnerability-assessment program; summaries are available under NDA once issued. Researchers can also report findings through our vulnerability disclosure policy.
Compliance & legal
Which certifications and audits do you hold?
ISO/IEC 27001:2022 (certified by Sensiba LLP), SOC 2 Type 1, and SOC 2 Type 2 — both SOC 2 reports attested by Sensiba LLP across all five Trust Services Criteria with an unqualified opinion. We also align to NIST CSF, NIST AI RMF, and CIS Controls 8.1. Reports are available under NDA.
Can I get a DPA and SCCs?
Yes — a Data Processing Agreement with EU Standard Contractual Clauses is available. Request it via partners@theplato.io.