Vendor security assessments and questionnaires

Last updated: September 28, 2026

Available on: Web (Wispr Trust Center)

Need Wispr to complete a vendor security assessment, security questionnaire, or third-party risk review? Completed assessments are reserved for Enterprise customers and prospects, and require a signed NDA. On other plans, the Wispr Trust Center answers most assessment questions directly.


Who can request a completed assessment

  • Enterprise customers and Enterprise prospects working with our sales team: Wispr's security team completes assessments and questionnaires after Trust Center access is granted and the NDA is signed.

  • Pro, Pro for Teams, and Growth: Use the published Trust Center documentation to answer assessment items. Wispr does not complete assessments on these plans.

Without a Wispr sales contact, reach the Enterprise team through Talk to Sales.


Get access to the Trust Center

Note: Anyone with a work email can request access, and our security team reviews every request. Access to documentation is separate from eligibility for a completed assessment.

  1. Go to the Wispr Trust Center.

  2. Click Request Access and enter your work email.

  3. Sign the NDA when prompted. It is built into the access flow, with no separate paperwork.

  4. Review the published security documentation once your request is approved.


Submit a questionnaire (Enterprise)

  1. Sign in to the Wispr Trust Center with your approved account.

  2. Click Submit a Questionnaire in the top-right.

  3. Upload your file, or paste your vendor portal or assessment link.

  4. Wait for our security team to follow up once your completed assessment is ready.


What the Trust Center already answers

Once access is granted, this documentation often covers questionnaire items without a manual response.

Attestations and certifications

  • SOC 2 Type II report (A-LIGN), covering the Security, Availability, and Confidentiality Trust Services Criteria together with HIPAA and HITECH requirements. Unqualified opinion, with no exceptions noted in the tests of controls.

  • ISO/IEC 27001:2022 certificate (A-LIGN) for Wispr's information security management system, maintained through annual surveillance audits with recertification on a three-year cycle. The Statement of Applicability is available under NDA.

  • SOC 2 Type I report (A-LIGN, Security criterion, unqualified opinion), the earlier report, still available.

  • Penetration test executive summary and remediation report from an independent third party, performed at least annually.

Legal and data protection

  • Data Processing Addendum (DPA), including the EU Standard Contractual Clauses, the UK Addendum, and Annex III subprocessors.

  • Business Associate Agreement (BAA) for healthcare customers.

  • Records of Processing Activities (ROPA).

Policies and architecture

  • ISMS policy suite, including Information Security, Access Control, Business Continuity and Disaster Recovery, Incident Response, and SDLC.

  • AI Policy, Data Classification Policy, Data Handling Policy, and Data Retention and Disposal Policy.

  • Data flow architecture.

The Privacy Policy, the current subprocessor list, and public security disclosures are published without an access request.

Note: Wispr Flow dictation is the in-scope system for the SOC 2 examinations and the service assessed in the ISO 27001 certification audit. Meeting Notetaker launched after those audit periods and was not assessed in the SOC 2 Type I, the SOC 2 Type II, or the ISO 27001 certification audit.


FAQs

Can I email my questionnaire to Support instead?

No. Support cannot complete or return assessment documents. Use the Trust Center for documentation, and Talk to Sales if you need a formal assessment and do not have a sales contact.

Can I get a Transfer Impact Assessment (TIA)?

Under the Standard Contractual Clauses framework, the data controller, which is your organization, completes the TIA. Wispr provides supporting materials through the Trust Center: the DPA with the EU SCCs and Annex III, the SOC 2 Type II report, and factual detail on our security controls and data minimization.


Still need help?

Email security@wispr.ai with your organization name and the assessment you are working through if:

  • You cannot create or sign in to your Trust Center account. Include the error message and the step where you are blocked.

  • Your assessment covers something not addressed in our documentation.