SOC2C

Is this your company? Buyers are checking Fathom here. Claim fathom.video free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Fathom logo

Fathom

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Fathom is SOC 2 Type II compliant. Fathom also holds HIPAA, GDPR, and CCPA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

If you have any questions check out our FAQ at the bottom of the page or contact [trust@fathom.video](mailto:trust@fathom.video) For system status please visit [status.fathom.video](https://status.fathom.video)

Compliance & infrastructure

Hosting
GCP
Data handled
Calendar Data: Meetings & Attendee EmailsMeeting Content Data: Recording (Audio & Video), TranscriptUser Data: Name, Email, IP, Job Title, Role

Subprocessors

22
  • G
    Google Cloud Platform · Primary Cloud Provider
    USA
  • A
    Anthropic · AI Provider
    USA
  • O
    OpenAI · AI Provider
    USA
  • E
    ElevenLabs · AI Provider
    USA
  • E
    Elastic · Search Provider
    USA
  • M
    Modal · AI Provider
    USA
  • V
    Voyage AI · AI Provider
    USA
  • B
    Brandfetch · Brand & Logo API
    USA
  • C
    Census · Data Analytics & ETL
    USA
  • C
    Courier · Email Provider
    USA
  • C
    Cloudflare · CDN
    USA
  • F
    FiveTran · Data Analytics & ETL
    USA
Show all 22 subprocessors
  • F
    Front · Helpdesk Provider
    USA
  • H
    HubSpot · CRM
    USA
  • N
    New Relic · Application Monitoring
    USA
  • P
    Postmark · Email Provider
    USA
  • P
    Pusher · In-App Communication
    USA
  • R
    Retool · Data Analytics & ETL
    USA
  • R
    Reveal · Partnership Marketing Platform
    Belgium
  • S
    Sentry · Application Monitoring
    USA
  • S
    Stripe · Payment Processor
    USA
  • U
    UserVoice · Feedback Tracking Platform
    USA

Compliance leadership

The person who leads Fathom's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Fathom's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Subprocessor UpdatesSep 2025

We will use this section to notify customers of any changes to our subprocessors. By subscribing to Trust Center updates, you will automatically receive notifications whenever we add, remove, or modify subprocessors that process customer data.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Fathom SOC 2 compliant?
Fathom is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Fathom HIPAA compliant?
According to Fathom's public trust center, Fathom is HIPAA compliant. On SOC2C this listing is Listed.
Is Fathom GDPR compliant?
According to Fathom's public trust center, Fathom is GDPR compliant. On SOC2C this listing is Listed.
Is Fathom CCPA compliant?
According to Fathom's public trust center, Fathom is CCPA compliant. On SOC2C this listing is Listed.
Is Fathom SOC 2 Type I or Type II?
Fathom is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Answers published by Fathom

Reproduced from Fathom's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Do you let AI providers train on customer data?
NO. None of our AI sub-processors (Anthropic, OpenAI, or Google) are contractually permitted to use our users’ data to train their AI models. Fathom uses de-identified customer data to improve the accuracy of our proprietary AI models in order to improve our service for all users. You can opt out of this anytime in your User Settings, and Organizations on Team Edition can opt out all users on their account by going to Organization Settings.
Is data in your platform encrypted both in transit and at rest?
YES, all application data, including recorded, are encrypted both at rest and in transit.
Where do you store data?
All data is stored in the United States. For those customers located in the EU/UK we are GDPR compliant and are happy to sign a DPA. Contact [trust@fathom.video](mailto:trust@fathom.video)
How is Fathom free? Do you sell our data to third parties?
NO, we do not and will never sell your data to third parties. We provide the Fathom app free of charge because it drives usage and brand awareness which generates leads for our Team Edition product.
How long do you store meeting recordings and other customer data?
One key feature of Fathom is that it will retain your recordings and other data indefinitely unless you manually delete individual recordings or your account. Specific retention requirements (e.g. purge all recordings after 2 years) are supported on the Pro plan of our Team Edition product. Sign up for a free trial at https://fathom.video/for/teams