SOC2C

Is this your company? Buyers are checking Fireflies AI here. Claim fireflies.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Fireflies AI logo

Fireflies AI

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Fireflies AI is SOC 2 Type II compliant. Fireflies AI also holds GDPR, and HIPAA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Fireflies is an AI meeting agent that helps you unlock the value buried inside your conversations. Fireflies transcribes, summarizes, and analyzes meetings in real-time. We understand that meetings contain your organization's most sensitive conversations and intellectual property. Our security-first approach is built on three core principles: ## Data Ownership & Privacy - You retain full ownership of your meeting data, explicitly stated in our [ToS](https://fireflies.ai/terms-of-service.pdf), Section 4. User Content - Strict zero-day retention policy with AI vendors - No training of AI models

Compliance & infrastructure

Hosting
AWSGCP

Documents

18

Subprocessors

17
  • A
    Assembly.ai
    US
  • O
    OpenAI
    US
  • M
    MongoDB Atlas
    US
  • G
    Google Cloud Platform · gcp
    US
  • A
    Anthropic
    US
  • A
    Amazon Web Services · aws
    US
  • G
    GitHub · github
    US
  • G
    Google Workspace · gsuiteadmin
    US
  • N
    New Relic
    US
  • H
    Heap
    US
  • P
    Perplexity
    US
  • t
    turbopuffer
    US
Show all 17 subprocessors
  • E
    Exa
    US
  • G
    Groq
    US
  • E
    Elevenlabs
    US
  • S
    Soniox
    US
  • A
    Apollo.io · Sales and Analytics
    US

Compliance leadership

The person who leads Fireflies AI's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Fireflies AI's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Fireflies AI SOC 2 compliant?
Fireflies AI is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Fireflies AI GDPR compliant?
According to Fireflies AI's public trust center, Fireflies AI is GDPR compliant. On SOC2C this listing is Listed.
Is Fireflies AI HIPAA compliant?
According to Fireflies AI's public trust center, Fireflies AI is HIPAA compliant. On SOC2C this listing is Listed.
Is Fireflies AI SOC 2 Type I or Type II?
Fireflies AI is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Fireflies AI's SOC 2 for a vendor risk assessment?
Yes. Fireflies AI's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.

Answers published by Fireflies AI

Reproduced from Fireflies AI's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Who owns the data? Describe the circumstances in which customer data is allowed to leave your production systems? Who owns the rights to the content?
At Fireflies.ai, you retain complete ownership of your data. While your information is securely stored in the cloud, you have full control over it. At your authenticated request, we can immediately purge and permanently delete your data from our systems. In alignment with our terms of service, you remain the sole owner of your content, ensuring your rights and privacy are fully protected.
Where is data stored? Where are the servers located?
At Fireflies.ai, we provide flexible and secure data management options tailored to your organization’s needs, ensuring the highest levels of security, compliance, and performance: Default Data Management By default, your data is securely stored and processed in our US-based cloud infrastructure, designed for reliability and adherence to industry standards: - Servers: Hosted on the Google Cloud Platform (GCP), known for its robust security features and scalability. - Database: Managed within a Virtual Private Cloud (VPC) on AWS, offering enhanced isolation and data protection. This setup ensures that your data is protected and optimized for performance throughout the storage and processing lifecycle. Flexible Storage Options 1. Fireflies Managed Storage: - Infrastructure: Data is stored on a dedicated cloud storage solution managed by Fireflies, providing secure and seamless access. - Data Locality: - Processing: All data processing occurs within the United States. - Storage: Data is stored in your preferred geographic location, ensuring compliance with regional data residency requirements. 2. Bring Your Own Storage (BYOS): - Infrastructure: You have the option to store your data in your own AWS or GCP storage bucket, giving you full control over your storage environment. - Data Locality: - Processing: All data processing is conducted within the United States. - Storage: Data resides in your chosen storage location, as configured in your AWS or GCP infrastructure. This flexibility allows organizations to customize their data management to align with specific compliance, security, and operational requirements, providing you with complete confidence and peace of mind.
Does Fireflies access my data? Can I delete or remove my data?
No. We follow the principle of least privilege, strictly granting access to sensitive data on a need-to-know basis, with monitoring and auditing. If greater access is needed, for example, during a support request, you must first grant permission. Yes. You can delete the data from the user dashboard or by contacting the support team. Once deleted, it is impossible to recover the meeting data.
Does Fireflies use my data for training purposes? Does Fireflies share my data with third parties?
No. We don’t use your data for training purposes. No, Fireflies does not share your data with third parties.We prioritize your privacy and have signed a Business Associate Agreement (BAA) with OpenAI and other third-party ASR (Automatic Speech Recognition) vendors. The BAA enforces: - Zero Data Retention Policy: Vendors cannot store or retain your data. - Restricted Access: Vendors are prohibited from accessing or using your data for any purpose beyond the agreed services. - No Training on Your Data: Your data will not be used to train AI models.
Does Fireflies create or store voiceprints?
No. Fireflies does not create, store, or process voiceprints or biometric identifiers. Fireflies uses a vendor for transcription & speaker diarization, which returns generic speaker labels “Speaker 1”, “Speaker 2", etc. Vendor has a zero data retention policy and does not train on voice data. When available, Fireflies labels speakers using conference metadata.

Legal & Government peers that completed SOC 2