Your trust is paramount. We implement enterprise-grade security measures to protect your data and privacy.
Last updated: August 25, 2026
All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Your audio files and transcriptions are protected with industry-standard encryption protocols.
Production audio storage uses Google Cloud Storage, and persisted application data uses a managed PostgreSQL database. Access to both is controlled by server-side credentials and application authorization.
We only retain your data as long as necessary. You can delete your recordings and transcriptions at any time through your account settings.
We follow privacy-by-design principles. We collect only the minimum information necessary to provide our services. We disclose the third-party providers used for transcription, AI features, storage, payments, email, and analytics in our Privacy Policy.
We've implemented key GDPR features including:
Production file storage runs on Google Cloud infrastructure. Managed services are combined with application-level access controls, secure headers, and encrypted connections.
Uploaded files are transcribed through AssemblyAI. OpenAI is used for real-time transcription and AI-powered transcript features. Files remain available for playback alongside their transcriptions until you choose to delete them.
Production audio files are stored in Google Cloud Storage. Legacy recordings may remain in Replit Object Storage. Transcriptions are saved in PostgreSQL databases with access controls and encrypted connections.
Only you can access your data. Our engineering team follows strict access protocols and can only access your data for technical support with your explicit consent.
WhisperAI aligns its security program with SOC 2 standards and guidelines. This is an alignment statement, not a claim that WhisperAI is SOC 2 certified. We also follow OWASP security guidance and NIST cybersecurity framework principles.
WhisperAI's Data Processing Agreement documents the terms governing our processing of customer personal data.
Download the Data Processing Agreement (PDF)TAC Security, an App Defense Alliance-authorized lab, completed a CASA AL1 assessment of WhisperAI Cloud Sync. The report was issued August 13, 2026, and expires August 14, 2027.
Download the TAC Security CASA report (PDF)Our Privacy Policy contains the canonical list of subprocessors, the purpose of each service, the data shared, region, and legal basis.
Review the subprocessor listWe continuously update our security measures and stay current with the latest security best practices and threats.
Your data is yours alone. We never access your recordings or transcriptions unless you explicitly request support.
We're transparent about our security practices, data handling, and any third-party services we use.
Built on Google Cloud's secure infrastructure, ensuring enterprise-grade reliability.
We take security seriously. If you have questions about our security practices, need security documentation for your institution, or want to report a vulnerability, please contact us.
We typically respond within 24 business hours