Back to Blog
Privacy & Security
Aug 19, 2026
12 min read

Do You Need a SOC 2 Compliant AI Note Taker? What the Badge Proves, and What It Cannot

Otter, Fireflies, Fathom and Notta all wave SOC 2 badges. Here is what that audit actually proves, what it cannot tell you, and when you truly need it.

I. M.

Blank golden compliance seal beside a smartphone with an on-device shield of circuit traces and the MeetingsAI icon
#Privacy#Private Mode#Security#Meeting Tips

Introduction

Sometimes, but less often than the badges suggest. A SOC 2 compliant AI note taker has passed an independent audit of how the vendor protects data on its own systems. That matters when your meeting audio lives on their servers. When it never gets there, as with on-device processing, there is far less for that audit to cover.

When we read the privacy policies of 7 AI note takers, one line got quoted back to us more than any other: a SOC 2 report tells you a company follows its own procedures, the privacy policy tells you what those procedures allow. This post is the full version of that sentence. What SOC 2 actually audits, what it cannot tell you, who advertises it today, and a fast way to check any vendor before you press record.

Key Takeaways

Tip callout:
  • SOC 2 is an independent attestation that a vendor's security controls work, defined by the AICPA and audited by a CPA firm. It is not a legal requirement and not a certification in the strict sense.
  • Type II is the one that counts: it tests whether controls actually operated over a period of months, not whether they existed on paper for one day.
  • SOC 2 says nothing about whether your recordings train AI models, how long they are kept, or who can read them. That is privacy policy territory.
  • You should insist on SOC 2 Type II when a cloud vendor stores your company's recordings. For on-device processing, there is no vendor-side copy to audit in the first place.

What SOC 2 Actually Is (and What It Is Not)

An attestation, not a certification

SOC 2 comes from the AICPA, the US body for certified public accountants. An independent CPA firm examines a vendor's controls against the Trust Services Criteria: security is mandatory, and availability, processing integrity, confidentiality, and privacy are optional add-ons the vendor chooses.

The output is an attestation report, not a pass or fail certificate. The auditor describes the controls, tests them, and writes down what they found, including exceptions. Two companies can both "have SOC 2" while one report is spotless and the other lists a page of control failures. The badge on the website looks identical either way.

Type I vs Type II

A Type I report checks that controls were designed properly at a single point in time. A Type II report tests whether those controls actually operated effectively over a review period, usually 3 to 12 months.

Type I is a photograph. Type II is security camera footage. If a vendor says "SOC 2" without specifying, ask which one, because the difference in assurance is large and vendors know most buyers never ask.

The report is the product, not the badge

The actual SOC 2 report is a confidential document, typically shared under NDA with prospects and customers. It contains the part that matters most and that no badge can show: the scope. Which systems were audited, over what period, with which criteria, and what exceptions the auditor found.

A badge that is not backed by a report you can request is marketing. Every serious vendor will share the report or a summary letter when asked.

What a SOC 2 Badge Cannot Tell You

SOC 2 audits whether the vendor follows its own stated procedures. It does not judge whether those procedures are good for you. Specifically, a SOC 2 badge cannot tell you:

  • Whether your recordings train AI models. Training rights live in the privacy policy and data processing agreement, not in the audit.
  • How long your audio and transcripts are retained. A vendor can retain recordings indefinitely and still pass SOC 2, as long as retention matches its own policy.
  • Who can read your transcripts. Human review for quality or abuse handling can be entirely SOC 2 compatible.
  • What the scope actually covered. An audit can cover a subset of systems. The product feature you use may sit outside it.
  • What subprocessors do downstream. Your audio may flow to third-party AI providers whose commitments are separate from the vendor's audit.
Warning callout: "SOC 2 compliant" and "your data is private" are different claims. The first is about the vendor's discipline. The second is about the vendor's permissions. You need to check both.

Do You Need a SOC 2 Compliant AI Note Taker?

When you should insist on it

If meeting recordings from your whole team will sit on a vendor's cloud, SOC 2 Type II should be table stakes. That covers you if:

  1. You are rolling a cloud note taker out across a company, not just your own phone.
  2. You work in a regulated or client-confidential field: finance, healthcare, legal, anything with NDAs as a way of life.
  3. Your security or procurement team runs vendor risk reviews. They will ask for the report, so ask first.
  4. The vendor stores recordings long-term, which makes their infrastructure the custodian of your most sensitive conversations.

In those cases, request the current Type II report under NDA, check the period it covers, and read the exceptions section before you sign.

When it matters less

If you are an individual or a small team, no procurement process is involved, and recordings are personal working notes, a SOC 2 report is a nice signal but not the deciding factor. The privacy policy, training rights, and retention terms will affect you far more directly.

And there is a third case the compliance listicles skip entirely: when the audio never reaches a vendor at all.

The question behind the question

What you actually want is confidence that nothing bad happens to your recordings. There are two ways to get it. Audit the custodian, which is the SOC 2 route. Or remove the custodian, which is the on-device route. Both are legitimate answers, and they suit different situations. The mistake is treating the badge as the only form the answer can take.

Who Advertises SOC 2 Today

We checked each vendor's own pages on August 19, 2026. Treat these as claims to verify against a current report, not as endorsements. The Sanity comparison rule applies here: one vendor per heading, no table needed.

Otter

Otter announced its SOC 2 Type II attestation report back in January 2022 and also advertises HIPAA compliance. If you evaluate Otter, ask for the current report, since a 2022 announcement says nothing about the latest audit period. We covered its broader privacy posture in our Otter alternatives for privacy-conscious users post.

Fireflies

The Fireflies security page lists SOC 2 Type II, GDPR alignment, and HIPAA with a Business Associate Agreement on the Enterprise plan.

Fathom

Fathom advertises SOC 2 Type II, GDPR, and HIPAA with a signed BAA on Enterprise, per its help center, and states that its AI subprocessors are not permitted to train on customer data. Those training commitments come from policy documents, which is exactly the point of this post: the audit badge and the data-use promise are separate things.

Notta

The Notta security page claims SOC 2 Type II, ISO 27001, GDPR, CCPA, and HIPAA. The certification stack is broad; the same "request the actual report and check the scope" advice applies.

Granola

Granola states it obtained SOC 2 Type 2 in July 2025 and credits its fast audit to storing minimal audio. That is a useful pattern to notice: the less data a vendor holds, the easier compliance gets. On-device processing is that pattern taken to its logical end.

How On-Device Processing Changes the Question

SOC 2 exists because a vendor holds your data and you need assurance about what happens on their side. Private Mode removes that side. Recording, transcription, and summarization run locally on your phone, your conversations are not visible to us, and the whole flow works offline. There is no server-side archive of your meetings to audit, breach, subpoena, or train on. We explain the mechanics in how Private Mode keeps your data on your device.

And since this post is about honest badges, here is ours: MeetingsAI is not SOC 2 audited today. Our compliance posture is GDPR and CCPA alignment. MeetingsAI also has a cloud mode, clearly labeled, which processes audio on servers for speed and wider language support; in cloud mode you should hold us to the same policy questions we raised about everyone else. The difference is that with MeetingsAI you can choose, per conversation, to keep the data on your device entirely.

We think that is the right shape for the trust question: not "trust our badge," but "here is a mode where trust is not required."

The 10-Minute Vendor Check

Before you adopt any AI note taker for sensitive conversations, run this:

  1. Ask for the SOC 2 report, not the badge. A vendor that will not share it under NDA has answered your question.
  2. Confirm it is Type II and check the audit period is recent, ideally within the last 12 months.
  3. Read the scope section. Make sure the product you actually use was inside it.
  4. Open the privacy policy and search for "train," "improve," and "retain." This is where the real answers live.
  5. Check the subprocessor list. Know which third-party AI providers touch your audio and what they are allowed to do.
  6. Ask about deletion. How fast, how complete, and whether backups are included.
  7. Ask whether an on-device or no-storage option exists. The strongest control is the data that was never collected.

Frequently Asked Questions

Is SOC 2 legally required for AI note takers?

No. SOC 2 is a voluntary attestation framework created by the AICPA, not a law. No regulation forces an AI note taker to have it. It has become a de facto requirement in enterprise procurement because security teams use it as a baseline signal, but a vendor without SOC 2 is not breaking any rule, and a vendor with it is not automatically privacy-friendly.

What is the difference between SOC 2 Type I and Type II?

Type I assesses whether a vendor's security controls were suitably designed at a single point in time. Type II tests whether those controls operated effectively over a review period, usually 3 to 12 months, which makes it much stronger evidence. When an AI note taker says "SOC 2 compliant" without specifying, ask for Type II and the date of the most recent report.

Does SOC 2 mean a note taker is GDPR compliant?

No. SOC 2 and GDPR answer different questions. SOC 2 is a US attestation about whether a vendor follows its own security procedures. GDPR is European law about lawful basis, user rights, retention, and transfers. A vendor can hold a clean SOC 2 report and still process personal data in ways GDPR does not allow, so check both separately.

Are Otter, Fireflies, and Fathom SOC 2 compliant?

All three advertise SOC 2 Type II: Otter announced its attestation report in January 2022, and Fireflies and Fathom list SOC 2 Type II alongside GDPR and enterprise HIPAA options on their security pages, as checked in August 2026. For any of them, request the current report under NDA and read its scope and exceptions rather than relying on the website badge.

Does an on-device AI note taker need SOC 2?

For the on-device processing itself, there is nothing for SOC 2 to audit, because the audio and transcripts stay on your phone instead of a vendor's servers. SOC 2 exists to give assurance about vendor-held data. If the same app also offers a cloud mode, judge that mode the way you would judge any cloud vendor: report, policy, retention, and subprocessors.

How do I verify a vendor's SOC 2 claim?

Ask their sales or security contact for the most recent SOC 2 Type II report, which is normally shared under NDA. Check the audit period, the scope of systems covered, and the exceptions the auditor noted. If a vendor only offers a badge, a press release, or a Type I report from years ago, treat the claim as unverified marketing.

Conclusion

SOC 2 is a real signal with a specific job: it tells you a cloud vendor's security controls were independently tested. It was never designed to tell you what a vendor may do with your recordings, and it cannot. Insist on a current Type II report whenever a company will hold your meetings on its servers, read the privacy policy for the promises the audit does not make, and remember there is a second way to settle the trust question: keep the conversation on your own device.

See what the trust question looks like when there is no server in the middle: try Private Mode in MeetingsAI, free to start, no credit card. And if you have not read it yet, start with what 7 AI note takers' privacy policies actually say.

Share this article

I. M.

Related Articles