Security and compliance FAQ

Last updated: July 13, 2026

Available on: Mac, Windows, iOS, Android, and the web Admin Portal

This FAQ answers the security, privacy, and compliance questions we hear most often from buyers, IT teams, and security reviewers. Most supporting reports are available through the Wispr Trust Center under NDA. For anything not covered here, contact security@wispr.ai.


Company and structure

Where is Wispr based, and what is the company's legal structure?

Wispr AI, Inc. is a Delaware C-corporation, founded in 2023 and privately held. Wispr operates the Wispr Flow product.

Headquarters: 444 Townsend Street, San Francisco, CA 94107, United States.

Who owns Wispr's security program?

Security is led by our Co-Founder/CTO/CISO and supported by a senior compliance engineer, our engineering and infrastructure leads, and an independent vCISO advisor. Day-to-day ownership sits with:

  • Sahaj Garg: Co-Founder, CTO, and CISO — overall accountability for security, compliance, and policy.

  • Tanay Kothari: Co-Founder and CEO — executive sponsorship.

  • Jason Scot: Senior Technical Support and Compliance Engineer — day-to-day execution of compliance, audits, and customer security inquiries.

  • Ethan Carlson: Engineering Lead — application security ownership.

  • Duncan McIsaac: Infrastructure Lead — cloud and database security.

  • Steve Dotson: vCISO — independent advisory.

Functional ownership is documented in the CISO Policy and the Risk and Governance Executive Committee Charter.

Is Wispr Flow run from your own data center, the cloud, or deployed on-premise?

Wispr Flow runs entirely in the cloud and is delivered as multi-tenant SaaS, hosted with a major US cloud provider. There is no on-premise deployment, and Wispr does not offer an on-premise version of the software.

Do you follow your cloud provider's security best practices?

Yes. Wispr follows its cloud provider's well-architected and security best practices, and reviews provider security attestations (such as SOC 2, ISO 27001, and PCI DSS) as part of our Vendor Management Program.


Product

What is Wispr Flow?

Wispr Flow is AI-powered voice-to-text dictation for macOS, Windows, iOS, and Android. Users speak, and formatted text is inserted into whatever application is active.

What platforms does Wispr Flow support?

Wispr Flow ships as native applications for:

  • macOS: primary desktop platform.

  • Windows: desktop.

  • iOS: mobile.

  • Android: mobile.

A web-based Admin Portal for enterprise organization configuration is available at admin.wisprflow.ai.

How many languages does Wispr Flow support?

Wispr Flow supports over 100 languages for voice dictation, and we continue to expand coverage. Quality varies by language; English has the most mature accuracy. Customers can validate language support during evaluation.


Certifications and audits

What security certifications and audits does Wispr have?

Current attestations:

  • SOC 2 Type I: Completed April 2026 by A-LIGN, clean unqualified opinion. Scope: Security. Report available under NDA.

  • ISO 27001:2022 Stage 1: Completed April 2026 by A-LIGN. Stage 2 scheduled June 2026.

  • HIPAA-aligned controls: Business Associate Agreement (BAA) available for healthcare customers.

  • Annual penetration testing: Most recent by BSK Security LLC (November 2025); next engagement with Doyensec planned after SOC 2 Type I.

In progress:

  • SOC 2 Type II: Observation period underway; report not yet issued.

Historical note: Wispr previously held a SOC 2 Type II (Accorp Partners) and ISO 27001 (Gradient) certification. Both were proactively invalidated in March 2026 due to platform integrity concerns at the original auditor. See our note on our compliance program for full context.

Not currently held: FedRAMP, PCI DSS (Wispr does not process payment card data; Stripe handles payments under PCI DSS Level 1), SOC 1 (not applicable — Wispr is not a financial reporting service), and SOC 3.

Can we get a copy of your SOC 2 report?

Yes, under NDA. Wispr's SOC 2 Type I report (A-LIGN, April 2026) is available via the Trust Center or through your account representative.

For interim periods, A-LIGN provides an Engagement Confirmation Letter as a standard alternative to a bridge letter.

What other certification reports can you provide?

Available under NDA via the Trust Center: the SOC 2 Type I report (A-LIGN, April 2026) and ISO 27001:2022 Stage 1 documentation. ISO 27001:2022 Stage 2 is in progress. Wispr is not PCI certified as a merchant — Stripe handles all payment processing under PCI DSS Level 1.

Is Wispr HIPAA compliant? Do you sign a BAA?

Yes. Wispr offers a Business Associate Agreement (BAA) for healthcare customers requiring HIPAA-compliant data handling. Request the BAA through your account representative.

Supporting HIPAA-aligned controls:

  • HIPAA Internal Privacy Policy.

  • PHI De-identification Policy and Procedure.

  • HIPAA-aligned Breach Notification Policy.

  • Security Awareness Training with HIPAA-specific content.

  • Encryption of PHI at rest and in transit (see the Encryption section).

  • Audit logging across infrastructure and application layers.

Can a signed HIPAA BAA be revoked?

Yes, with platform-specific limitations:

  • Individual users can revoke their BAA on Desktop (macOS/Windows) from Settings → Data & Privacy → "Revoke BAA" (shown next to "View signed BAA"). iOS does not currently support revoking a signed BAA.

  • Enterprise admins manage and revoke the organization's BAA from the Admin Portal (admin.wisprflow.ai); the desktop settings screen only provides a link to that portal.

  • Non-admin enterprise members do not see revoke controls.

Warning: While the BAA is active, Privacy Mode is enforced — your data is not used for training and is not stored server-side. Revoking the BAA removes that enforcement, so review your Privacy Mode and Cloud Sync settings immediately after revoking.

Is Wispr PCI DSS compliant?

Not applicable. Wispr does not store, process, or transmit cardholder data directly. Stripe handles all payment processing under their PCI DSS Level 1 certification, so Wispr is out of scope for PCI DSS as a merchant beyond SAQ-A applicability.

Is Wispr FedRAMP authorized?

No. Wispr does not currently hold FedRAMP authorization.

What regulations does Wispr comply with?

Wispr operates in alignment with:

  • GDPR (EU): DPA incorporates Standard Contractual Clauses.

  • CCPA / CPRA (California): Privacy Policy aligned to consumer rights.

  • HIPAA (US): under signed BAA with healthcare customers.

  • SOC 2 and ISO 27001:2022 industry frameworks.

Our AI governance practices are aligned to ISO/IEC 42001:2023.

Not subject to: GLBA (not a financial institution), SOX (privately held), 21 CFR Part 11 (not FDA-regulated), CFTC, and SEC reporting.

How does Wispr handle UK GDPR and international data transfers?

All customer data is processed in the United States. For EU and UK customers, the cross-border transfer mechanism is documented in our Data Processing Addendum:

  • EU GDPR: EU Standard Contractual Clauses (June 2021) incorporated by reference.

  • UK GDPR: A UK Addendum to the EU SCCs is available.

Wispr does not produce a vendor-side Transfer Impact Assessment (TIA) as a standalone document. Under the SCC framework, the TIA is conducted by the data controller. We provide the materials needed to support that assessment: our DPA (which includes the EU SCCs and Annex 3 — Technical and Organizational Measures), our SOC 2 Type I report, and factual information about our security controls and data minimization architecture. EU and UK customers needing this material can request it via the Trust Center or their account representative.

How do you conduct internal and external audits?

Internal: Control testing runs continuously through our compliance automation platform, supplemented by an annual internal risk assessment and ISMS review.

External: Independent third parties perform our SOC 2 audit (Type I complete April 2026; Type II in progress) and ISO 27001:2022 assessment (Stage 2 in progress), plus an annual external penetration test.


Privacy and data handling

What data does Wispr require to provide the service, and is any of it sensitive?

To provide the service, Wispr handles:

  • Dictation content: the audio you dictate and the transcribed text.

  • Account data: name, email, and organization.

Wispr does not require financial data or government data, and payments are handled by Stripe. No sensitive data is required to use the product. Users may dictate any content at their discretion, and under Privacy Mode that dictation content is not retained server-side or used for training.

Does Wispr offer Privacy Mode and Zero Data Retention?

Yes. Wispr Flow uses two independent controls that together govern how your dictation data is handled:

  • Privacy Mode: controls whether your dictation data is used to evaluate, train, or improve AI models. When on, none of your data is used for training by Wispr or any third party.

  • Cloud Sync: controls whether your transcription data (transcripts, audio, dictation history) is stored on Wispr's servers to power features such as cross-device sync for Wispr Scratchpad.

As user-facing shorthand, Zero Data Retention (ZDR) is the combination of Privacy Mode on and Cloud Sync off: no training and no server-side storage of dictation data. ZDR is enforced at the enterprise level — when enabled for an organization, it overrides admin and user settings and forces both Cloud Sync and data sharing off for all members regardless of their individual preferences.

Privacy Mode is locked on when either:

  • The user has an active HIPAA BAA, or

  • The enterprise enforces Zero Data Retention.

On enterprise plans, admins can enforce Privacy Mode on and Cloud Sync off at the organization level so individual users cannot change them. While a HIPAA BAA is active, Privacy Mode is locked on and Cloud Sync is locked off. Revoking the BAA removes this enforcement.

Enterprise defaults. For Enterprise customers, data-sharing defaults to off (Privacy Mode effectively on), but Cloud Sync defaults to on unless the enterprise has explicitly enabled ZDR or a HIPAA BAA is active.

Enterprise local-data policy. Separately from Cloud Sync, enterprise admins choose one of three local-data behaviors for data stored on the member's device:

  • Store normally: default.

  • Delete after 24 hours: local data cleared after 24 hours.

  • Never store: nothing written locally.

Enterprise admin-set policies act as a floor — individual users may choose a more restrictive setting but not a less restrictive one. When the org policy is set to "Never store," the user's choice is fully locked. Both "Delete after 24 hours" and "Never store" also clear locally stored Polish history and Instruct/command history, and hide voice-profile UI surfaces on the client.

What gets stripped when Cloud Sync is off (or under ZDR). All dictation-pipeline artifacts are kept off Wispr's servers — the audio, any associated screen context, the speech-to-text output, the formatted result, and any downstream variants produced by the AI formatting and rewrite layers. The server enforces this independently of the client.

Note: Screen context is stripped server-side when Privacy Mode is on / Cloud Sync is off. Under Cloud Sync on with Privacy Mode off, screen-context fields may be persisted alongside the transcript.

Feedback exception. If a user explicitly submits transcript feedback via the Report action, that record is uploaded in full. This is an intentional, user-triggered action.

Do you use customer data to train AI models?

Whether dictation data is used for model training depends on whether Privacy Mode is enabled:

  • With Privacy Mode enabled: Audio, transcripts, prompts, and derived content are not used for model training by Wispr or any subprocessor.

  • Without Privacy Mode (standard mode): Audio and transcription data may be used to evaluate, train, and improve Wispr's models. This is the default for trial and standard accounts.

Training is governed by Privacy Mode, independent of Cloud Sync — turning Privacy Mode on prevents training even when Cloud Sync is on. If you handle confidential or privileged information, enable Privacy Mode before dictating sensitive content.

Does Wispr seek a right to use or own customer-derived data for its own purposes?

Wispr claims no ownership of customer data. Whether dictation content is used to improve our models depends on Privacy Mode: with Privacy Mode enabled, dictation data is never used for training. Without Privacy Mode (the default for standard and trial accounts), audio and transcription data may be used to evaluate, train, and improve Wispr's models. Enterprise and HIPAA BAA customers run with Privacy Mode on by default, so their data is not used for training.

Do you anonymize customer data?

Under Privacy Mode, dictation content is not retained, so there is no dictation dataset to anonymize. Where dictation content is processed, the privacy controls are retention-based: the content is stripped from Wispr's servers entirely rather than stored in an anonymized form. Operational telemetry and product analytics exclude dictation content by design. Wispr does not maintain an anonymized dictation dataset for internal use.

Do you share customer data with, or enable direct access by, any third party?

No customer data is sold or shared for any third party's own purposes. Subprocessors access data only to provide the service, under written contract with confidentiality and data-protection obligations. The authoritative subprocessor list is Annex 2 of the DPA.

How do your subprocessors meet your data-protection standards?

All active subprocessors handling customer data are bound by written agreements covering confidentiality, data-protection terms equivalent to our customer commitments, breach notification, and subprocessor flow-down obligations. Where Privacy Mode applies, Wispr requires that dictation content not be retained by subprocessors. Subprocessor risk is re-reviewed annually under our Vendor Management Policy. The authoritative subprocessor list is Annex 2 of the DPA, available under NDA via the Trust Center.

What does the Wispr Flow client send outside the dictation path?

The Wispr Flow desktop client transmits the following outside the dictation upload path, grouped into three categories:

  • Operational logs: client error reports and diagnostic logs, with automatic PII scrubbing applied.

  • Product analytics: usage events and feature telemetry. No dictation content is included.

  • Health metrics: background reachability and latency probes, the auto-updater check, and account or subscription-state polling that powers the in-app word-usage UI.

There is no separate license-verification beacon and no standalone usage beacon outside of these three categories.

Does Wispr store voiceprints or biometric identifiers?

No. Wispr does not collect, derive, or store voiceprints, voice embeddings, or any other biometric identifier as defined under BIPA, GDPR Article 9, or CCPA "sensitive personal information."

Some Wispr Flow product features associate a user with logical groupings for organizational purposes. These groupings are referenced by opaque, arbitrary identifiers that carry no encoded measurement of the user's voice or any other biometric attribute.

Do you keep sensitive data in hard copy (for example, paper copies)?

No. No customer data is kept in hard copy. A Clean Desk Policy applies, and no production data is held at the office.

Do you have a data classification matrix?

Yes. Wispr maintains a four-tier data classification (Public, Internal, Confidential, Restricted) defined in our Data Classification Policy. Customer dictation content is classified as Restricted and receives the strictest controls. The policy is available under NDA via the Trust Center.

Can you provide a data flow diagram?

Yes. A data flow architecture diagram is available under NDA via the Trust Center.

Do you maintain an inventory of where personal data is stored, including cross-border flows?

Yes. Data flows are documented, and all storage is in the United States, so there is no cross-border storage. Subprocessor data flows are listed in Annex 2 of the DPA.

Does customer data ever leave your production systems?

Customer data stays within our US cloud production environment. Any egress to a subprocessor is TLS-encrypted, outbound-initiated, and limited to providing the service (for example, AI inference). No customer business data resides on employee endpoint devices.

Is a Data Protection Impact Assessment (DPIA) conducted for personal data processing?

Privacy risk is assessed as part of Wispr's risk program, and we provide the materials customers need to support their own DPIA (DPA with SCCs and Annex 3 Technical and Organizational Measures, SOC 2 Type I report, and details of our data-minimization architecture). For questions about a specific DPIA, contact security@wispr.ai.

How does Wispr respond to law-enforcement requests for customer data?

Wispr evaluates the legal validity of any law-enforcement request, narrows scope to what is legally required, and — unless legally prohibited (for example, where a confidentiality order applies to an active investigation) — notifies the affected customer before disclosing data. This is a description of our general approach, not legal advice.

What is your data retention policy?

Data retention is governed by Wispr's Data Retention and Disposal Policy. User dictation is not retained when Privacy Mode is enabled and Cloud Sync is off; when Cloud Sync is on, dictation data is stored on Wispr's servers and retained per the published Privacy Policy. Account and configuration data is retained for the duration of service plus a reasonable wind-down period. Automated database backups are retained for a short rolling window. Operational logs have automatic PII scrubbing applied to credentials, session metadata, and request payloads. Data destruction follows NIST 800-88 standards for physical media; cloud data is purged per contractual terms with our hosting provider and subprocessors.

What happens when a user requests account deletion?

Account deletion requests initiate a durable, asynchronous erasure workflow that runs across multiple systems automatically — the primary account database, usage/history storage, stored audio, and stored content. The workflow retries each step and typically completes within hours; some history-store updates may take up to an hour to verify. During processing, the account is marked as pending deletion.

The workflow is account-preserving of certain artifacts by design: aggregated stats, credits, referrals that reference the requester as the referrer, and scratchpad images tied to notes are retained. A separate compliance audit record notes the deletion outcome. For HIPAA BAA customers and enterprises with specific deletion-confirmation requirements, contact your account representative for written confirmation.

What happens to customer data when the contract terminates?

Under Zero Data Retention (Privacy Mode on, Cloud Sync off — enforced at the enterprise level): Dictation data is never stored server-side, so no dictation data persists after contract termination.

Account, configuration, and user data is available for export via the Admin Portal during the contract term and a reasonable wind-down period, then deleted within a defined window per the Data Retention and Disposal Policy. Customers may request data export and confirmation of deletion via their account representative.

Can customers export their data?

Yes. Customers can request a GDPR data export, which includes:

  • User account information and preferences.

  • Subscriptions, credits, and referrals.

  • Notes.

  • Team memberships.

  • Dictionaries.

  • Usage stats.

  • HIPAA BAA records and enterprise records.

  • Full dictation history (transcripts and associated metadata) when stored on Wispr's servers (Cloud Sync on).

  • SMS/notification event records.

  • Promo-code records.

  • Mobile-store subscription events (App Store / Play Store).

  • Enterprise-scoped records including cost centers and invitations.

Account and configuration data plus snippets can be retrieved through the Admin Portal, and API-based export is available. Dictation content is not exportable when it is not stored server-side (Cloud Sync off or ZDR).

Do you support interoperability and data portability?

Yes. Wispr Flow uses standard data formats, and account/configuration data and snippets are retrievable through the Admin Portal and via API export, supporting interoperability and portability. Dictation content is not retained under Privacy Mode and therefore is not part of an export in that mode.

Where is customer data stored geographically?

Wispr's infrastructure is hosted in the United States. All customer data is processed and stored in the US, regardless of where the user is located. Wispr does not operate a European or other regional processing location for customer data.

International data transfers from customers in the EU and UK are governed by the EU Standard Contractual Clauses (June 2021) incorporated into our DPA, with a UK Addendum available.

What data does Wispr Flow store locally on the user's device?

Note: The Data & Privacy controls described here are available on Desktop and iOS. Android's Data & Privacy Settings section, Privacy Mode toggle, and Cloud Sync are being rolled out and may not yet be visible to all Android users.

Wispr Flow stores the following locally on the user's device:

  • Application binary and resources.

  • User preferences and settings: Privacy Mode state, Cloud Sync state, activation shortcut, and similar.

  • Authentication tokens: stored in the application's standard private storage area, isolated to Wispr Flow.

  • Snippets and dictionaries: synced from the backend, regardless of Privacy Mode or Cloud Sync.

  • Local logs: application errors and telemetry, sanitized of dictation content.

Not stored locally (subject to your local data storage setting):

  • Past dictation content or transcripts, when local storage is set to "Never store data locally."

  • Audio recordings (audio is streamed to the backend and not persisted locally).

  • Customer business data.

Uninstalling the app removes the binary. Cached preferences may remain in standard OS application support directories and can be cleared by the user.

Does sensitive or private data ever reside on endpoint devices?

No production customer data resides on employee endpoints. Dictation content is processed server-side, and under Privacy Mode no transcripts are stored locally. This is enforced through least-privilege access, managed-device controls, and endpoint protection on all managed devices.

Are user snippets and dictionaries stored regardless of Privacy Mode?

Yes. User-created snippets (saved text expansions) and custom dictionaries (custom vocabulary) are stored in Wispr's backend and synced across the user's devices regardless of Privacy Mode or Cloud Sync status. These are user-authored productivity assets, not dictation content.

They are stored with the same protections as other account and configuration data: encrypted at rest, encrypted in transit (TLS 1.2+), and access-controlled. Privacy Mode specifically covers whether the dictation content pipeline is used for training; Cloud Sync covers whether that content (captured audio, any screen context taken for Context Awareness, the speech-to-text output, the formatted result, and any downstream AI-rewritten variants) is stored on Wispr's servers.

Personal snippets and dictionary share a single backend endpoint. Team-shared snippets and dictionary entries are available on Team, Business, and Enterprise plans through separate endpoints.

Does Wispr capture screenshots?

Wispr Flow's Context Awareness feature has two separately-toggled components:

  • Accessibility-text context (default on): Reads text from the active application's accessibility tree to improve AI formatting.

  • Screen OCR (default off): Captures a full-display screenshot to extract proper nouns. This is opt-in.

Screenshots only flow when both toggles are on. Screen OCR captures the display containing the mouse cursor. If the Accessibility-text context toggle is off, Screen OCR is automatically disabled even if its own toggle is on. Any captured screenshot is stripped on upload when Privacy Mode is on / Cloud Sync is off, and is not persisted server-side in that mode. Enterprise admins manage Context Awareness settings via admin.wisprflow.ai.

Is your Privacy Policy publicly available?

Yes. Our Privacy Policy is public at wisprflow.ai/privacy and is also linked from the Trust Center.


Encryption

How is data encrypted in transit?

All confidential data in transit is encrypted using TLS 1.2 or higher with forward-secrecy cipher suites. There are no plaintext connections over public networks to our production infrastructure. Internal traffic uses our cloud provider's encrypted channels. Certificates are issued by trusted public CAs with automated renewal.

How is data encrypted at rest?

Stored data is encrypted at rest using AES-256 at the database and object-storage layers, backed by our cloud provider's managed key service using FIPS 140-2 validated HSMs. Sensitive OAuth and SSO credentials are additionally encrypted at the application layer using authenticated symmetric encryption, on top of the underlying disk encryption. This application-layer encryption applies to server-side database storage of OAuth credentials. Local auth tokens on the desktop client are stored in the app's private storage area and rely on OS-level disk encryption (FileVault/BitLocker) for at-rest protection.

How are cryptographic keys managed?

Encryption keys are managed in our cloud provider's HSM-backed key management service, with access controlled by IAM and key usage logged in our audit trail. Application secrets (credentials, API keys) are held in a dedicated managed secrets store, and there are no hardcoded secrets in source. Keys are authorized for use only when active.

Is Wispr Flow end-to-end encrypted? Can Wispr decrypt customer data?

Wispr Flow does not provide end-to-end encryption in the strict cryptographic sense (where the service provider cannot decrypt content). The service is encrypted in transit (TLS 1.2+) and at rest, but Wispr's backend must decrypt audio to perform transcription.

Under Zero Data Retention (Privacy Mode on, Cloud Sync off), the architectural mitigation is that decrypted audio and transcripts are not persisted. Dictation content is stripped at both client and server layers, and flows through processing without storage. For customers requiring true E2E encryption where the provider cannot read content, Wispr Flow's transcription model does not support that architecture.

How are passwords hashed?

Authentication is delegated to managed identity providers. Passwords are hashed by those providers using industry-standard algorithms and are never stored or logged by Wispr in plaintext.

Can customers manage their own encryption keys (BYOK)?

Customer-managed keys (BYOK) are not currently supported. Encryption keys are managed by Wispr, and key lifecycle events are logged and auditable.


Identity and access

Does Wispr support Single Sign-On (SSO)?

Yes. SSO supports SAML 2.0 and OIDC connections to major identity providers (Okta, Microsoft Entra ID, Google Workspace, JumpCloud, OneLogin, Ping Identity, and generic SAML/OIDC). Admins configure their SSO connection through a hosted admin portal linked from the enterprise settings. Both SP-initiated and IdP-initiated flows are supported.

SSO enforcement (blocking password login) requires the SSO-enforcement setting to be enabled and live enterprise billing. If SCIM directory sync is configured, new user provisioning is delegated entirely to the identity provider and email sign-ups on that domain are blocked. SSO is Enterprise-plan only.

Is MFA enforced?

For Wispr's internal access (employees): MFA is required for all production system access, administrative cloud access, SSO, and all sensitive SaaS tools.

For enterprise customer access: MFA is enforced via the customer's own identity provider through SAML/OIDC SSO (delegated to the IdP).

How do you manage role provisioning, deprovisioning, and recertification?

Access is governed by our Access Control and Termination Policy: provisioning requires manager approval, access is revoked the same business day on termination or role change, and access is recertified on a quarterly basis. Access follows least-privilege principles throughout.

How do you control privileged accounts?

Privileged access follows least-privilege IAM with no permanent standing admin credentials. Administrative access is granted through time-bound, MFA-gated sessions and is logged in our audit trail. Administrative access is brokered through authenticated, audited cloud sessions under a zero-trust model.

Which staff have access to personal and sensitive data?

Under Privacy Mode (default for Enterprise and HIPAA BAA customers), no dictation content is accessible to anyone, since it is not retained. A limited number of engineering and infrastructure personnel hold read-only, MFA-gated, logged production access for troubleshooting. Support and customer success have read-only, logged access to account-level data only (subscription, user list, organization settings).

Can employees or contractors remotely connect to production (for example, via VPN)?

There is no corporate VPN and no directly exposed SSH or RDP to production. Administrative access is brokered through authenticated, audited cloud sessions with MFA under a zero-trust model. There is no remote access to customer environments or customer machines.

Does Wispr staff access customer data or environments?

Wispr support and customer success personnel do not have access to customer dictation content when it is not stored server-side (Cloud Sync off or ZDR). Account-level data access (subscription, user list, organization settings) is read-only for support and requires authenticated, logged access. Production database access for engineering troubleshooting is read-only, MFA-protected, and logged. There is no remote access to customer environments or customer machines. For incidents requiring deeper data access, customer authorization is sought first.

Are employees and contractors subject to background checks?

Yes. Background checks are performed for personnel with access to production systems or customer data, where legally permitted, per the Personnel Security Policy.

Do personnel sign confidentiality and acceptable use agreements?

Yes. All personnel sign confidentiality/NDA agreements as a condition of employment, and acknowledge the Acceptable Use Policy at onboarding and annually. A formal disciplinary process applies to security policy violations under the Personnel Security Policy and Code of Conduct.

How is access handled when someone leaves or changes role?

The Access Control and Termination Policy governs employment changes. Access is revoked the same business day on termination or role change, managed devices are remotely wiped, and assets are recovered at offboarding.

Are employee laptops encrypted and centrally managed?

Yes. All employee endpoints are enrolled in centralized mobile device management (MDM) with full-disk encryption enforced (FileVault on macOS, BitLocker on Windows). Devices that connect to production do so via authenticated, audited sessions with MFA, not a direct laptop-to-production network connection. Lost or stolen managed devices can be remotely wiped.

What is the standard security configuration on employee devices?

Managed endpoints are configured with full-disk encryption (FileVault/BitLocker), a login password, anti-malware via endpoint detection and response, an auto-lock timer, a software firewall, USB mass-storage blocking, and restricted administrative privileges. Configuration is enforced centrally through MDM.

How do you prevent data loss from endpoint devices?

Email DLP and endpoint DLP (including USB mass-storage blocking) are in place on managed systems, alongside endpoint detection and response, least-privilege access, and the fact that no production customer data resides on endpoints in the first place. Content-aware cloud-storage DLP is not currently deployed; this is a risk-accepted decision.

Do you require removable media to be encrypted?

USB mass storage is blocked on managed endpoints, and removable media is not used for organizational data.

Do you enforce managed devices for mobile access to organizational data?

Yes. Access to corporate data requires a managed device, with mobile devices managed through MDM. Personal (BYOD) devices are not permitted for production access.

Do you use equipment identification for connection authentication?

Yes. Device posture (MDM enrollment plus endpoint protection) is required for access under our zero-trust model.

Are there additional enterprise access controls available?

Additional enterprise controls (IP allowlist, application deny list, browser URL deny list, Notetaker transcript retention) are available on request and are progressively rolled out by Wispr to enterprises that require them.


Secure development and testing

When was your most recent penetration test, and does it follow an industry methodology?

Wispr performs an annual external penetration test by an independent third party; the most recent test was completed in November 2025. It follows an OWASP-based methodology covering the OWASP Top 10, web application, infrastructure, and authentication/session testing. The remediation report is available under NDA via the Trust Center.

How do you ensure code is developed securely?

Our Secure SDLC Policy requires mandatory peer review (authors cannot approve their own changes), static application security testing (SAST) and secret scanning in CI, automated dependency scanning, CI/CD security gates, and segregated development, staging, and production environments. Core development is in-house; open-source dependencies are continuously scanned and patched.

Is threat modeling part of the design phase?

Yes. Security-sensitive changes receive a security review by the Engineering Lead/CISO, and threat considerations are incorporated into the design of higher-risk features.

Do you outsource development, and how is third-party software reviewed?

Core development is in-house. Open-source dependencies are managed and scanned through automated dependency scanning and SAST. Third parties with access to data undergo a security assessment under our Vendor Management Policy.

Do you maintain a software bill of materials (SBOM)?

Yes. We maintain an internal SBOM derived from our package manifests, and a customer-shareable CycloneDX SBOM is available under NDA via the Trust Center.

How do you manage vulnerabilities and patching?

Vulnerabilities are detected through automated dependency scanning, cloud vulnerability assessment, continuous threat detection, endpoint detection and response, and the annual penetration test. We continuously monitor vendor bulletins and CVE feeds and remediate on risk-based timelines, with dependency fixes automated where possible and re-scanned in CI on remediation. Managed endpoints are patched through MDM.

How do you stay aware of new vulnerabilities and threats?

We monitor security advisories, CVE feeds, cloud-provider security bulletins, and other vendor bulletins, and act on findings from our cloud vulnerability assessment and threat-detection tooling. Our vCISO also participates in the broader security community.

What mitigates web application vulnerabilities?

A web application firewall (WAF) and an edge security layer sit in front of the application, complemented by input validation, output encoding, and Content-Security-Policy headers. These are reinforced by the secure-SDLC controls above.

How do you manage secrets (tokens, passwords, API credentials, certificates)?

Credentials and API keys are stored in a managed secrets store, encryption keys are held in an HSM-backed key management service, and there are no hardcoded secrets in source. Automated secret scanning runs in our repositories.

What is the process for changing network configuration?

Network changes are made through infrastructure-as-code with peer review. Changes are version-controlled and logged.

Do you have a vulnerability disclosure or bug bounty program?

We operate a coordinated disclosure process via security@wispr.ai and the Trust Center, and we recognize researchers for impactful findings. We do not currently run a public paid bounty platform.


Logging, monitoring, and incident response

Which audit trails and logs do you keep for systems with access to customer data?

We maintain multi-layer logging across the infrastructure, network, and application layers — including cloud API/audit logs, network flow logs, WAF logs, threat-detection findings, application logs, and endpoint logs.

The enterprise-facing audit log surfaces membership events (member added, member removed, join request approved, join request rejected) with a rolling query window, filterable by actor, target, and event type. Infrastructure and application logs are retained separately for security monitoring.

How do you log and alert on security events?

Security events from across the network and application layers are aggregated centrally with severity-based alerting routed to on-call, supported by cloud-native threat detection and correlation. We do not currently operate a traditional SIEM; customer-facing log export is on our roadmap.

Are forensic investigations conducted as part of incident response?

Yes. Forensic capability is available through our endpoint detection and response provider and our cyber-insurance incident-response panel. We do not maintain a standing forensic retainer.

Is remediation of application vulnerabilities automated where possible?

Yes. Dependency fixes are proposed automatically, and CI re-scans on remediation to confirm the fix.


Security awareness and training

Do you have a security awareness training program?

Yes. Security awareness training is mandatory at onboarding and annually, with role-specific content for engineering (secure coding) and for personnel with PHI access (HIPAA). Training includes phishing awareness. Completion is tracked and verified through our compliance automation platform. We do not currently run a standalone simulated-phishing campaign platform.

Do you engage with the wider security community?

Yes. We track security advisories and engage with the security community, and our vCISO participates in relevant industry groups.


Network controls

Do you filter employee web browsing by URL category?

Wispr does not currently operate web content or URL-category filtering; this is a risk-accepted decision. Endpoint protection is provided by managed detection and response across all managed devices.

Is all public-network traffic to production encrypted?

Yes. All traffic over public networks to our production infrastructure uses TLS 1.2 or higher. There are no plaintext connections, and internal traffic uses our cloud provider's encrypted channels.

Do you segregate office and guest Wi-Fi from production?

Yes. Office Wi-Fi (WPA2/WPA3) is segregated from production. Production has no wireless access and is reached only through authenticated cloud sessions.


Physical and environmental security

Note: Wispr operates no data centers of its own. Production infrastructure runs with a major US cloud provider whose data centers are independently attested (SOC 2, ISO 27001, PCI DSS). The Wispr office holds no production customer data.

Are physical security perimeter controls in place around data centers?

Yes, at the cloud provider level. Our cloud provider's data centers implement physical perimeter controls, surveillance at ingress/egress points, access logging, and trained on-site personnel, all covered by their independent SOC 2, ISO 27001, and PCI DSS attestations. The Wispr office uses building-managed perimeter controls and badge access with escorted visitors, and holds no production data.

Is physical access to facilities logged and monitored?

Yes. Data-center physical access is logged and monitored by our cloud provider (attested under their certifications). Office access uses badge entry logged by the building, with visitors escorted.

Are data-center environmental and utility controls in place?

Yes — these are managed by our cloud provider and covered by their attestations. Environmental control systems (temperature and humidity), utility services, power and telecommunication cabling protection, and redundant equipment across multiple availability zones and regions are the provider's responsibility. Wispr owns no data-center equipment.

How is business-critical equipment made redundant and protected from environmental risk?

Our cloud provider's multi-availability-zone and multi-region architecture provides geographic redundancy, and the provider selects sites to account for environmental risk. Wispr owns no physical data-center equipment.

Do you transport physical media or relocate data-bearing hardware?

No. Wispr has no data-center hardware to relocate and does not transport physical media containing customer data. Employee endpoints are managed through MDM, and cloud data remains within our US cloud provider environment.


Service changes and availability

How are service changes communicated, and can tenants authorize them?

Wispr Flow is multi-tenant SaaS, so changes are not authorized per individual tenant. Material changes are communicated through our status page, and breaking changes receive advance notice per the MSA.


Still need help?

If your question isn't answered above, reach out and we'll get you what you need:

  • Email security@wispr.ai for security and compliance questions, including bespoke documentation requests.

  • Request reports (SOC 2 Type I, ISO 27001, DPA, subprocessor list) via the Wispr Trust Center.

  • Enterprise customers can contact their account representative for contract-specific items (BAA, regional hosting confirmation, SIEM streaming timing).