exma Try exma free

Security

Is your AI transcription tool safe for confidential audio? A 12-point checklist

By the exma team · July 28, 2026 · 10 min read

TL;DR: "Is this tool secure?" is the wrong question, because the answer is almost always it depends on the plan tier. Twelve things decide whether privileged, protected, or otherwise regulated audio can go through a transcription vendor: model training rights, retention and deletion, subprocessors, encryption at rest, access logging, data residency, SOC 2 Type II evidence, BAA availability and tier, bot-free capture, sharing defaults, chain of custody, and contract terms. Ask all twelve in writing. Several of them have embarrassing answers.

Why the default answer is "no"

Most AI transcription products were designed for a sales team recapping a customer call. Their defaults reflect that: recordings persist indefinitely because users want their history, transcripts auto-share with everyone on the calendar invite because that's convenient, and the terms of service reserve broad rights to use content to "improve the service" because training data is valuable.

Every one of those defaults is a liability when the audio is a client interview, a clinical consult, an internal investigation, a claims call, or a closed hearing. Nothing about the technology is inherently unsafe — but the configuration you get by signing up with a work email usually is, and the gap between what a vendor's security page implies and what its contract obliges is where procurement earns its keep.

The tier trap: compliance features are routinely gated behind the top plan. Otter.ai, for example, announced HIPAA compliance in July 2025 and offers a business associate agreement — to Enterprise customers. Fireflies.ai makes its HIPAA BAA available on its Enterprise tier as well. A HIPAA-capable product used on a free or mid-tier plan is not a HIPAA-covered deployment.

The 12 questions

Send these to the vendor and require written answers. The point isn't to disqualify everyone — it's that the answers are cheap to give when they're good and conspicuously slow to arrive when they aren't.

1Will you use our audio or transcripts to train any model?

The most consequential question, and the one most often answered in a terms-of-service clause rather than a conversation. Some services train on customer content by default; the practice has drawn legal scrutiny, including a 2025 class action alleging a major transcription provider used customer data for model training without adequate consent.

Ask it in three parts: do you train on our content, do your subprocessors train on our content, and can we get "no" in the contract rather than on a webpage. The third part is what matters — marketing pages are revised silently, contracts are not.

What a good answer sounds like "No, for any tier. Customer audio and transcripts are contractually excluded from training for us and for every subprocessor, and that term is in the DPA."
Red flag "We use aggregated and de-identified data to improve our services." De-identification of a verbatim transcript is not a solved problem — testimony identifies people by describing what they did.

2How long do you keep our audio after the transcript is delivered?

There is no operational reason to retain source audio indefinitely once a transcript has been produced and delivered — unless it's being used for something else. Get the default retention window, whether it's configurable, whether deletion is real deletion or a soft flag, and how long backups take to purge.

What a good answer sounds like A specific number of days, a customer-configurable window, deletion on request with a stated backup-purge lag, and confirmation that deletion propagates to subprocessors.

3Who else touches the data? Show me the subprocessor list.

Almost no transcription vendor runs every component itself. Behind the interface there is typically a cloud host, a speech recognition engine, sometimes a separate model provider for summaries, occasionally human transcriptionists or contractors, plus analytics and support tooling that may see transcript content. Each one is a place your audio exists.

Ask for the current subprocessor list, whether you're notified before it changes, and whether you can object. If human contractors ever review content, ask where they are, how they're vetted, and what they've signed.

4Is data encrypted at rest, not just in transit?

Every vendor has TLS — that's table stakes and not what's being asked. The question is what happens to the file sitting in object storage afterward: encryption at rest, key management, and whether anyone at the vendor can read stored content in the clear.

5Who at your company can access our transcripts, and is it logged?

Support engineers frequently can read customer content — sometimes for legitimate debugging. What separates a mature vendor is that such access is role-restricted, justified, logged, and reviewable. Ask whether you can see the access log for your own content.

6Where does the data physically live?

Data residency is a hard requirement for many government, healthcare, and EU engagements, and it applies to the whole pipeline rather than the primary datastore. Confirm residency at the infrastructure level, including where inference runs — a US-hosted database in front of a model endpoint in another region does not satisfy a residency commitment.

7Can I see your SOC 2 Type II report — not the badge?

SOC 2 Type II means an independent auditor tested the vendor's controls over an observation window, typically three to twelve months. That's real evidence, and it is also routinely oversold. Request the report under NDA and check three things: the observation period, the scope (which systems and which trust criteria), and the exceptions section — where the auditor records what didn't work as described.

Red flag A SOC 2 logo with no report available, a Type I passed off as Type II, or a scope that excludes the transcription pipeline itself.

8Will you sign a BAA — and on which plan?

For protected health information, a business associate agreement isn't optional and "we're HIPAA compliant" is not the same as "we have signed a BAA with you." Ask explicitly which tier includes it, how long execution takes, and what the vendor's obligations are on breach notification. Then confirm which tier your organization is actually on — this is where teams discover their department has been on the professional plan for eighteen months.

Adjacent regimes deserve the same treatment: CJIS for criminal justice data, GLBA and SEC recordkeeping in finance, FERPA in education, GDPR for EU personal data.

9Does anything join the meeting?

A note-taker that dials into a call as a participant creates a disclosure event. Everyone present sees that a third-party service is recording, the bot shows up in the participant list and often on the calendar invite, and in privileged or regulated settings its presence may itself require consent or draw an objection. It also introduces a dependency on the meeting platform and a second copy of the audio inside the bot vendor's infrastructure.

Direct capture — the microphone in the room, the computer's system audio for anything remote — avoids the whole category, because nothing joins anything. This is covered in more depth in exma vs. consumer AI note-takers.

10What are the default sharing settings?

Consumer note-takers optimize for distribution: transcripts auto-share with meeting participants, sync to workspace channels, get indexed into a searchable org-wide history, and in some products propagate to people who were merely invited but never attended. For confidential work the default must be the opposite — private to the creator, shared deliberately, with no automatic distribution to anyone.

Ask whether restrictive defaults can be enforced organization-wide by policy, or whether they're a per-user toggle that one person will inevitably flip.

11Can you prove chain of custody?

For evidentiary and investigative work, the transcript's value depends on being able to show what happened to the recording between capture and delivery: who accessed it, what changed, when, and whether the text still ties to the audio. Ask for chain-of-custody tracking, timestamped transcripts synced to the recording, and an audit trail of edits. See What makes a transcript court-admissible? for why this is the difference between a document and evidence.

12What does the contract actually oblige you to do?

Everything above is a promise until it's a term. The paperwork to insist on: a data processing agreement, contractual data-use restrictions covering training, a stated breach-notification window, advance notice of subprocessor changes, deletion and export rights on termination, and confirmation that the vendor claims no license to your content beyond what's needed to deliver the service.

Red flag A terms-of-service clause granting a "perpetual, worldwide, royalty-free license" to user content. It's boilerplate copied from consumer social products, and it has no business anywhere near privileged material.

The pattern to watch for

Across consumer AI note-takers the shape is consistent, and it's worth naming plainly because it's the single most common way teams end up out of compliance without noticing:

Control Typical free / pro tier Typical enterprise tier
Training on your content Permitted by ToS Contractually excluded
BAA / HIPAA coverage Not available Available on request
Retention control Vendor default, indefinite Configurable
Audit logs None exposed Admin console
Sharing defaults Open, auto-distribute Policy-enforceable

The lesson isn't that these products are bad — it's that the security posture you evaluated is not necessarily the one you deployed. If compliance lives on a tier, verify the tier.

How exma answers these

exma is built for regulated, data-sensitive fields, so several of these are structural rather than optional:

Procurement paperwork — DPAs, compliance documentation, security review, and deployment requirements specific to your regime — goes through sales, where you'll get direct answers to all twelve of the questions above rather than a link to a trust page.

Frequently asked questions

Is AI transcription safe for confidential or privileged audio?

It can be, but safety is a property of the vendor and the plan tier, not of AI transcription in general. Model training rights, retention, subprocessors, encryption at rest, access logging, and contract terms decide it — and those frequently differ between the tier you evaluated and the tier you're on.

Do transcription services train their models on customer recordings?

Some do by default, with permission granted through the terms of service rather than requested explicitly. Ask in writing whether the vendor and its subprocessors train on your content, and require the answer in the contract.

Is Otter.ai HIPAA compliant?

Otter.ai announced HIPAA compliance in July 2025 and offers a business associate agreement to Enterprise customers; Fireflies.ai similarly offers its BAA on the Enterprise tier. Both are examples of the broader pattern: compliance features exist but sit behind the top plan, so verify your organization's actual tier and confirm a signed BAA before uploading PHI.

What does SOC 2 Type II prove?

That an auditor tested the vendor's stated controls over an observation window and reported how they operated. It's evidence of process, not a guarantee about your data, and it says nothing about data-use rights. Read the report — especially the scope and the exceptions — rather than trusting the badge.

Why is a meeting bot a security problem?

Because it's visible. It announces to everyone present that a third-party service is recording, appears in participant lists and calendar invites, may require consent, and places a second copy of the audio in another vendor's systems. Direct microphone and system-audio capture avoids all of it.

What's the single most important question on this list?

Number one. Retention, residency, and access controls are all recoverable failures — you can delete data, migrate regions, and tighten permissions. Content absorbed into someone else's model weights cannot be retrieved.

Put your hardest question to us

Bring the checklist to a 15-minute call and we'll answer all twelve on the record — or try exma free first and read the terms before you upload anything.

Talk to sales