Is this your company? Buyers are checking Fireflies AI here. Claim fireflies.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Claim free
Fireflies AI
Sourced from public information. Not yet verified by the company.
Fireflies AI is SOC 2 Type II compliant. Fireflies AI also holds GDPR, and HIPAA.
About
Fireflies is an AI meeting agent that helps you unlock the value buried inside your conversations. Fireflies transcribes, summarizes, and analyzes meetings in real-time. We understand that meetings contain your organization's most sensitive conversations and intellectual property. Our security-first approach is built on three core principles: ## Data Ownership & Privacy - You retain full ownership of your meeting data, explicitly stated in our [ToS](https://fireflies.ai/terms-of-service.pdf), Section 4. User Content - Strict zero-day retention policy with AI vendors - No training of AI models
Compliance & infrastructure
Documents
18- Terms of ServicePublic
- Privacy PolicyPublic
- SOC 2 Type 2 report 2025/2026Request
- GDPR Compliance Report 2025/2026Request
- HIPAA Compliance Policy (EN)Request
- FERPA Compliance Report 2025/2026Request
- Fireflies Penetration Test Report 2026Request
- Access Control PolicyRequest
- Secure Development Policy (EN)Request
- Data Breach Notification Procedure (EN)Request
- Data Deletion Policy (EN)Request
- Disaster Recovery Plan (EN)Request
- Cyber Security InsuranceRequest
- HackerOne Program Status Report 2024Request
Subprocessors
17- AAssembly.aiUS
- OOpenAIUS
- MMongoDB AtlasUS
- GGoogle Cloud Platform · gcpUS
- AAnthropicUS
- AAmazon Web Services · awsUS
- GGitHub · githubUS
- GGoogle Workspace · gsuiteadminUS
- NNew RelicUS
- HHeapUS
- PPerplexityUS
- tturbopufferUS
Show all 17 subprocessorsShow fewer
- EExaUS
- GGroqUS
- EElevenlabsUS
- SSonioxUS
- AApollo.io · Sales and AnalyticsUS
Compliance leadership
The person who leads Fireflies AI's SOC 2 isn't listed yet. Claim this profile to add it.
Penetration test
Unknown. Fireflies AI's penetration test vendor isn't listed yet.
Claim this profile to add it.
This listing is partial
7/11 details · 64%SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
- Auditorraises trustAdd the CPA firm that issued your SOC 2 so buyers can verify who signed it.
- Report dateraises trustAdd your most recent report period so buyers see how current your SOC 2 is.
- Renewal dateAdd your renewal window so buyers know your coverage is active.
- Security controlsConfirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Fireflies AI SOC 2 compliant?
Is Fireflies AI GDPR compliant?
Is Fireflies AI HIPAA compliant?
Is Fireflies AI SOC 2 Type I or Type II?
Can I use Fireflies AI's SOC 2 for a vendor risk assessment?
Is Fireflies AI penetration tested?
Can I get Fireflies AI's SOC 2 report?
Is Fireflies AI secure?
Does Fireflies AI have a bug bounty or vulnerability disclosure program?
Who are Fireflies AI's subprocessors?
Where does Fireflies AI host or store data?
Where is Fireflies AI's trust center or security page?
Answers published by Fireflies AI
Reproduced from Fireflies AI's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗
Who owns the data? Describe the circumstances in which customer data is allowed to leave your production systems? Who owns the rights to the content?
Where is data stored? Where are the servers located?
Does Fireflies access my data? Can I delete or remove my data?
Does Fireflies use my data for training purposes? Does Fireflies share my data with third parties?
Does Fireflies create or store voiceprints?
Is Fireflies HIPAA compliant? What other measures have been taken to safeguard health data?
Is Fireflies SOC 2 compliant?
How does Fireflies comply with UK/EU data protection requirements?
Is Fireflies subject to CIPA (California's biometric privacy law)?
What data is encrypted? What encryption is used?
How does Fireflies manage security vulnerabilities?
Are we able to turn Fireflies off for certain meetings or will Fireflies always be listening?
Legal & Government peers that completed SOC 2

Anthropic PBC
DirectMailers
Ruddr
