Is this your company?Buyers are checking Fireflies AI here. Claim fireflies.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Fireflies is an AI meeting agent that helps you unlock the value buried inside your conversations. Fireflies transcribes, summarizes, and analyzes meetings in real-time. We understand that meetings contain your organization's most sensitive conversations and intellectual property. Our security-first approach is built on three core principles: ## Data Ownership & Privacy - You retain full ownership of your meeting data, explicitly stated in our [ToS](https://fireflies.ai/terms-of-service.pdf), Section 4. User Content - Strict zero-day retention policy with AI vendors - No training of AI models
SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Fireflies AI SOC 2 compliant?
Fireflies AI is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Fireflies AI GDPR compliant?
According to Fireflies AI's public trust center, Fireflies AI is GDPR compliant. On SOC2C this listing is Listed.
Is Fireflies AI HIPAA compliant?
According to Fireflies AI's public trust center, Fireflies AI is HIPAA compliant. On SOC2C this listing is Listed.
Is Fireflies AI SOC 2 Type I or Type II?
Fireflies AI is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Fireflies AI's SOC 2 for a vendor risk assessment?
Yes. Fireflies AI's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Fireflies AI penetration tested?
Fireflies AI hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Can I get Fireflies AI's SOC 2 report?
Fireflies AI's SOC 2 report is available on request. Request access through SOC2C and we coordinate the company-side NDA and delivery.
Is Fireflies AI secure?
Security isn't a single yes/no, but Fireflies AI is SOC 2 Type II compliant and holds GDPR, HIPAA, SOC 2 Type II. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Fireflies AI have a bug bounty or vulnerability disclosure program?
Fireflies AI hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@fireflies.ai or via a /security page (Fireflies AI lists a security contact).
Who are Fireflies AI's subprocessors?
Fireflies AI lists 17 subprocessors on its trust center, including Assembly.ai, OpenAI, MongoDB Atlas, Google Cloud Platform, Anthropic. Buyers use this for fourth-party risk review.
Where does Fireflies AI host or store data?
Fireflies AI hosts on AWS, GCP. Data residency details are on its trust center.
Where is Fireflies AI's trust center or security page?
Fireflies AI's trust center is at https://trust.fireflies.ai. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Who owns the data? Describe the circumstances in which customer data is allowed to leave your production systems? Who owns the rights to the content?
At Fireflies.ai, you retain complete ownership of your data. While your information is securely stored in the cloud, you have full control over it. At your authenticated request, we can immediately purge and permanently delete your data from our systems. In alignment with our terms of service, you remain the sole owner of your content, ensuring your rights and privacy are fully protected.
Where is data stored? Where are the servers located?
At Fireflies.ai, we provide flexible and secure data management options tailored to your organization’s needs, ensuring the highest levels of security, compliance, and performance: Default Data Management By default, your data is securely stored and processed in our US-based cloud infrastructure, designed for reliability and adherence to industry standards: - Servers: Hosted on the Google Cloud Platform (GCP), known for its robust security features and scalability. - Database: Managed within a Virtual Private Cloud (VPC) on AWS, offering enhanced isolation and data protection. This setup ensures that your data is protected and optimized for performance throughout the storage and processing lifecycle. Flexible Storage Options 1. Fireflies Managed Storage: - Infrastructure: Data is stored on a dedicated cloud storage solution managed by Fireflies, providing secure and seamless access. - Data Locality: - Processing: All data processing occurs within the United States. - Storage: Data is stored in your preferred geographic location, ensuring compliance with regional data residency requirements. 2. Bring Your Own Storage (BYOS): - Infrastructure: You have the option to store your data in your own AWS or GCP storage bucket, giving you full control over your storage environment. - Data Locality: - Processing: All data processing is conducted within the United States. - Storage: Data resides in your chosen storage location, as configured in your AWS or GCP infrastructure. This flexibility allows organizations to customize their data management to align with specific compliance, security, and operational requirements, providing you with complete confidence and peace of mind.
Does Fireflies access my data? Can I delete or remove my data?
No. We follow the principle of least privilege, strictly granting access to sensitive data on a need-to-know basis, with monitoring and auditing. If greater access is needed, for example, during a support request, you must first grant permission. Yes. You can delete the data from the user dashboard or by contacting the support team. Once deleted, it is impossible to recover the meeting data.
Does Fireflies use my data for training purposes? Does Fireflies share my data with third parties?
No. We don’t use your data for training purposes. No, Fireflies does not share your data with third parties.We prioritize your privacy and have signed a Business Associate Agreement (BAA) with OpenAI and other third-party ASR (Automatic Speech Recognition) vendors. The BAA enforces: - Zero Data Retention Policy: Vendors cannot store or retain your data. - Restricted Access: Vendors are prohibited from accessing or using your data for any purpose beyond the agreed services. - No Training on Your Data: Your data will not be used to train AI models.
Does Fireflies create or store voiceprints?
No. Fireflies does not create, store, or process voiceprints or biometric identifiers. Fireflies uses a vendor for transcription & speaker diarization, which returns generic speaker labels “Speaker 1”, “Speaker 2", etc. Vendor has a zero data retention policy and does not train on voice data. When available, Fireflies labels speakers using conference metadata.
Is Fireflies HIPAA compliant? What other measures have been taken to safeguard health data?
Yes, Fireflies.ai is HIPAA compliant, ensuring the protection of patient health information in the United States. You can view and sign the BAA here for HIPAA compliance. We prioritize safeguarding your data through the following measures: Private Storage for HIPAA Compliance: We maintain a secure infrastructure designed to meet the stringent requirements of HIPAA, ensuring sensitive information is stored and processed safely. Business Associate Agreements (BAAs): We have established BAAs with vendors like OpenAI and ASR providers, guaranteeing they do not trade, store, or use your data for any purpose other than those explicitly authorized. Zero-Day Retention Policy: Our specialized workflow ensures that neither OpenAI nor other third-party vendors retain or use Fireflies data to train their AI algorithms. This policy provides an additional layer of protection for your content
Is Fireflies SOC 2 compliant?
Yes. Fireflies maintains annual compliance with SOC 2 Type 2 requirements. You can access our reports after requesting access here in Vanta.
How does Fireflies comply with UK/EU data protection requirements?
Fireflies is compliant with GDPR, and, therefore, complies with data protection and data subject rights for EU residents. Corporate organizations can use the Private Storage option to store their data within the EU and meet your compliance requirements. Note: - Your data will be stored in the EU but processed in the US. - In the future, we will offer you the ability to process data in the EU or your region of choice via Private Cloud. - Private Cloud will allow you to deploy the entire Fireflies platform in your cloud. To see more details about how we comply, please email security@fireflies.ai to get our GDPR report
Is Fireflies subject to CIPA (California's biometric privacy law)?
Fireflies' architecture falls outside CIPA's scope. No voice-based biometric profiles are created, stored, or maintained at any point in the processing chain.
What data is encrypted? What encryption is used?
All user data, including meeting transcripts, audio recordings, calendar events, emails, and user settings, are encrypted end-to-end both at rest and in transit using industry-standard encryption. We take snapshots of User Metadata (calendar events, emails, user settings) every 4 hours for backup purposes but not for User Content - transcripts, audio recordings, and derivatives. Metadata snapshots are retained for one year to comply with our customer data availability agreements. No transcript or audio data is included in these snapshots or backups. To secure your data during transit, storage, and processing, we use 256-bit AES encryption for data at rest and TLS 1.2 encryption for data in transit. At Fireflies.ai, we implement robust security practices to protect the integrity and confidentiality of all the data we collect and share with our service providers. Related: Fireflies Security FAQ’s
How does Fireflies manage security vulnerabilities?
Fireflies.ai is continuously scanned with industry-standard scanning tools for monitoring and detecting vulnerabilities. We also host an ongoing bug bounty program with HackerOne to continuously detect vulnerabilities. However, no security system is impenetrable, and we cannot 100% guarantee the security of our systems. If any information under our control is compromised because of a breach of security, we will take reasonable steps to investigate the situation and, when appropriate, notify those individuals whose information may have been compromised and take other steps by any applicable laws and regulations.
Are we able to turn Fireflies off for certain meetings or will Fireflies always be listening?
Yes, users can decide not to invite Fireflies to the meeting, or ban Fireflies from entering certain meetings. See the guide here.