Security and compliance FAQ

Last updated: September 4, 2026

Available on: Mac, Windows, iOS, Android, and the web Admin Portal

Answers to the security, privacy, and compliance questions buyers, IT teams, and security reviewers ask most. Supporting reports are available under NDA through the Wispr Trust Center. For anything not covered here, contact security@wispr.ai.


Company and structure

Where is Wispr based, and what is the company's legal structure?

Wispr AI, Inc. is a privately held Delaware C-corporation, founded in 2023, and operates Wispr Flow. Headquarters: 444 Townsend Street, San Francisco, CA 94107, United States.

Who owns Wispr's security program?

Our Co-Founder/CTO/CISO is accountable for security, compliance, and policy, sponsored by the Co-Founder/CEO. Day-to-day ownership:

  • Senior Technical Support and Compliance Engineer: compliance execution, audits, and customer security inquiries.

  • Engineering Lead: application security.

  • Infrastructure Lead: cloud and database security.

  • vCISO: independent advisory.

Functional ownership is documented in the CISO Policy and the Risk and Governance Executive Committee Charter.

Is Wispr Flow run from your own data center, the cloud, or deployed on-premise?

Wispr Flow is multi-tenant SaaS hosted entirely with a major US cloud provider. There is no on-premise version.

Do you follow your cloud provider's security best practices?

Yes. Wispr follows its cloud provider's well-architected and security best practices, and reviews provider security attestations (SOC 2, ISO 27001, PCI DSS) under our Vendor Management Program.


Product

What is Wispr Flow?

Wispr Flow is AI-powered voice-to-text dictation with native apps for macOS, Windows, iOS, and Android. You speak, and formatted text is inserted into the active application.

A web-based Admin Portal for enterprise organization configuration is available at admin.wisprflow.ai.

How many languages does Wispr Flow support?

Over 100 languages, with coverage still expanding. Quality varies by language; English is the most mature. Customers can validate language support during evaluation.


Certifications and audits

What security certifications and audits does Wispr have?

Current attestations:

  • SOC 2 Type I: completed April 2026 by A-LIGN, clean unqualified opinion, Security scope. Report available under NDA.

  • ISO 27001:2022 Stage 1: completed April 2026 by A-LIGN. Stage 2 scheduled June 2026.

  • HIPAA-aligned controls: Business Associate Agreement (BAA) available for healthcare customers.

  • Annual penetration testing: most recent by BSK Security LLC (November 2025); next engagement with Doyensec planned after SOC 2 Type I.

  • SOC 2 Type II: observation period underway; report not yet issued.

Historical note: Wispr previously held a SOC 2 Type II (Accorp Partners) and ISO 27001 (Gradient) certification. Both were proactively invalidated in March 2026 due to platform integrity concerns at the original auditor. See Our path to a new, independent audit.

Not currently held: FedRAMP, PCI DSS (Stripe handles payments under PCI DSS Level 1; Wispr does not process card data), SOC 1 (Wispr is not a financial reporting service), and SOC 3.

Which certification reports can you share?

Under NDA via the Trust Center or your account representative: the SOC 2 Type I report (A-LIGN, April 2026) and ISO 27001:2022 Stage 1 documentation. For interim periods, A-LIGN provides an Engagement Confirmation Letter as a standard alternative to a bridge letter.

Is Wispr HIPAA compliant? Do you sign a BAA?

Yes. Request a Business Associate Agreement (BAA) through your account representative. Supporting HIPAA-aligned controls:

  • HIPAA Internal Privacy Policy, PHI De-identification Policy and Procedure, and HIPAA-aligned Breach Notification Policy.

  • Security Awareness Training with HIPAA-specific content.

  • Encryption of PHI at rest and in transit (see Encryption).

  • Audit logging across infrastructure and application layers.

Enterprise admins manage the organization's BAA from the Admin Portal (admin.wisprflow.ai).

Can a signed HIPAA BAA be revoked?

Yes, with platform-specific limitations:

  • Individual users: revoke on Desktop (macOS/Windows) from Settings → Data & Privacy → "Revoke BAA", next to "Download signed BAA", which appears only when a signer name is on record. Revoking takes effect immediately, with no confirmation dialog. A personally signed BAA takes precedence over an organization-level lock for that user.

  • iOS: the BAA can only be viewed and signed (with a typed legal name); signing cannot be undone, and model improvement and dictation cloud storage are turned off for the account. Revoke from Desktop or, for organizations, the Admin Portal.

  • Enterprise admins: manage and revoke the organization's BAA in the Admin Portal (admin.wisprflow.ai); desktop settings only link to the portal.

  • Non-admin enterprise members: see only a "Request access" button, which records the request in-app but does not notify the admin — contact your admin directly.

Warning: While the BAA is active, Privacy Mode is enforced — your data is not used for training and is not stored server-side. Revoking removes that enforcement, so review your Privacy Mode and Dictation cloud storage settings immediately afterward.

Is Wispr PCI DSS compliant?

Not applicable. Wispr does not store, process, or transmit cardholder data. Stripe handles all payment processing under its PCI DSS Level 1 certification, so Wispr is out of scope as a merchant beyond SAQ-A applicability.

Is Wispr FedRAMP authorized?

No. Wispr does not currently hold FedRAMP authorization.

What regulations does Wispr comply with?

Wispr operates in alignment with:

  • GDPR (EU): DPA incorporates Standard Contractual Clauses.

  • CCPA / CPRA (California): Privacy Policy aligned to consumer rights.

  • HIPAA (US): under signed BAA with healthcare customers.

  • SOC 2 and ISO 27001:2022 frameworks; AI governance aligned to ISO/IEC 42001:2023.

Not subject to: GLBA (not a financial institution), SOX (privately held), 21 CFR Part 11 (not FDA-regulated), CFTC, and SEC reporting.

How does Wispr handle UK GDPR and international data transfers?

All customer data is processed in the United States. Cross-border transfer mechanisms are documented in our Data Processing Addendum:

  • EU GDPR: EU Standard Contractual Clauses (June 2021) incorporated by reference.

  • UK GDPR: a UK Addendum to the EU SCCs is available.

Wispr does not produce a standalone vendor-side Transfer Impact Assessment (TIA); under the SCC framework the TIA is conducted by the data controller. We supply the supporting materials — the DPA (including the EU SCCs and Annex 3 Technical and Organizational Measures), the SOC 2 Type I report, and factual detail on our security controls and data-minimization architecture — via the Trust Center or your account representative.

How do you conduct internal and external audits?

Internal: continuous control testing, plus an annual internal risk assessment and ISMS review.

External: independent third parties perform our SOC 2 audit (Type I complete April 2026; Type II in progress), ISO 27001:2022 assessment (Stage 2 in progress), and an annual penetration test.


Privacy and data handling

What data does Wispr require to provide the service, and is any of it sensitive?

Wispr handles two categories:

  • Dictation content: the audio you dictate and the transcribed text.

  • Account data: name, email, and organization.

No financial or government data is required, and Stripe handles payments. No sensitive data is required; users may dictate any content at their discretion.

Does Wispr offer Privacy Mode and Zero Data Retention?

Yes. Two independent controls govern dictation data:

  • Privacy Mode (labeled "Improve the model for everyone" in settings, inverted): controls whether your dictation data is used to evaluate, train, or improve AI models. When on, none of your data is used for training by Wispr or any third party.

  • Dictation cloud storage: controls whether transcripts, audio, and dictation history are stored on Wispr's servers to power features such as cross-device sync for Wispr Scratchpad.

Zero Data Retention (ZDR) is shorthand for Privacy Mode on plus Dictation cloud storage off: no training and no server-side storage of dictation data. Enabling ZDR for an organization forces Privacy Mode on and Dictation cloud storage off for all members regardless of individual preferences, and outranks any org-level "allow Dictation cloud storage" setting.

Locks. Privacy Mode is locked on when the user has an active HIPAA BAA or the enterprise enforces ZDR. Dictation cloud storage is locked off only when the enterprise explicitly disables it or a HIPAA BAA is in force. Lock messages differ: "Dictation Cloud Storage is locked off because HIPAA BAA is signed." and "This setting is managed by your organization." If both apply, the HIPAA message takes precedence.

Enterprise defaults. Data sharing defaults to off (Privacy Mode effectively on); Dictation cloud storage defaults to on unless the enterprise has enabled ZDR or a HIPAA BAA is active. On iOS, turning Dictation cloud storage off requires confirming a destructive prompt; turning it on is immediate.

Enterprise local-data policy. Separately from Dictation cloud storage, admins choose one of three behaviors for data on the member's device: Store normally (default), Delete after 24 hours, or Never store (nothing written locally). Admin-set policies act as a floor — users may choose a more restrictive setting but not a less restrictive one, and "Never store" locks the user's choice entirely.

Not stored when Dictation cloud storage is off (or under ZDR): your audio, any associated screen context, the transcribed text, the formatted result, and any AI-rewritten variants.

Note: With Dictation cloud storage on and Privacy Mode off, screen-context fields may be persisted alongside the transcript.

Feedback exception. Submitting transcript feedback via the Report action uploads that record in full — an intentional, user-triggered action.

Do you use customer data to train AI models?

Training is governed by Privacy Mode, independent of Dictation cloud storage:

  • Privacy Mode on: audio, transcripts, prompts, and derived content are not used for model training by Wispr or any subprocessor, even when Dictation cloud storage is on.

  • Privacy Mode off (standard mode): audio and transcription data may be used to evaluate, train, and improve Wispr's models. This is the default for trial and standard accounts.

Enterprise and HIPAA BAA customers run with Privacy Mode on by default. If you handle confidential or privileged information, enable Privacy Mode before dictating.

Does Wispr claim ownership of customer data?

No. Whether dictation content improves our models depends on Privacy Mode — see "Do you use customer data to train AI models?"

Do you anonymize customer data?

Privacy controls are retention-based rather than anonymization-based: under Privacy Mode dictation content is not kept, so there is no dictation dataset to anonymize. Operational telemetry and product analytics exclude dictation content by design, and Wispr maintains no anonymized dictation dataset for internal use.

Do you share customer data with third parties?

No customer data is sold or shared for any third party's own purposes. Subprocessors access data only to provide the service, under written agreements covering confidentiality, data-protection terms equivalent to our customer commitments, breach notification, and subprocessor flow-down. Where Privacy Mode applies, subprocessors may not retain dictation content. Subprocessor risk is re-reviewed annually under our Vendor Management Policy, and the authoritative list is Annex 2 of the DPA, available under NDA via the Trust Center.

What does the Wispr Flow client send outside the dictation path?

The desktop client transmits three categories outside the dictation upload path:

  • Operational logs: client error reports and diagnostic information, with automatic PII scrubbing.

  • Product analytics: usage events and feature telemetry, excluding dictation content.

  • Health metrics: service availability checks, the update check, and account and subscription state for the in-app word-usage display.

There is no separate license-verification or usage beacon outside these categories.

Does Wispr store voiceprints or biometric identifiers?

No. Wispr does not collect, derive, or store voiceprints, voice embeddings, or any other biometric identifier as defined under BIPA, GDPR Article 9, or CCPA "sensitive personal information."

Some features associate a user with logical groupings for organizational purposes, referenced by identifiers that encode no measurement of the user's voice or any other biometric attribute.

Do you keep sensitive data in hard copy?

No customer data is kept in hard copy. A Clean Desk Policy applies, and no production data is held at the office.

Do you have a data classification matrix?

Yes. A four-tier classification (Public, Internal, Confidential, Restricted) is defined in our Data Classification Policy, available under NDA via the Trust Center. Customer dictation content is classified Restricted and receives the strictest controls.

Can you provide a data flow diagram?

Yes, under NDA via the Trust Center.

Do you maintain an inventory of where personal data is stored?

Yes. Data flows are documented and all storage is in the United States, so there is no cross-border storage. Subprocessor data flows are listed in Annex 2 of the DPA.

Does customer data ever leave your production systems?

Customer data stays within our US cloud production environment. Any transfer to a subprocessor is encrypted in transit and limited to providing the service (for example, AI inference). No customer business data resides on employee endpoint devices.

Is a Data Protection Impact Assessment (DPIA) conducted?

Privacy risk is assessed within Wispr's risk program, and we provide the materials customers need for their own DPIA: the DPA with SCCs and Annex 3 Technical and Organizational Measures, the SOC 2 Type I report, and details of our data-minimization architecture. For DPIA-specific questions, contact security@wispr.ai.

How does Wispr respond to law-enforcement requests?

Wispr evaluates the legal validity of any request, narrows scope to what is legally required, and notifies the affected customer before disclosing data unless legally prohibited (for example, under a confidentiality order covering an active investigation). This describes our general approach and is not legal advice.

What is your data retention policy?

Retention is governed by our Data Retention and Disposal Policy. Dictation is not retained when Privacy Mode is on and Dictation cloud storage is off; when Dictation cloud storage is on, dictation data is stored on Wispr's servers and retained per the published Privacy Policy. Account and configuration data is retained for the duration of service plus a reasonable wind-down period, and automated database backups for a short rolling window. Operational logs have PII scrubbed from credentials, session metadata, and request payloads. Destruction follows NIST 800-88 for physical media; cloud data is purged per contractual terms with our hosting provider and subprocessors.

Transcription history is stored locally per device and does not sync across devices, so history on one device is not a complete record. Free-plan word limits are enforced client-side only.

What happens when a user requests account deletion?

Deletion requests erase account data, usage history, stored audio, and stored content. The account is marked pending deletion while the request is processed.

By design, certain artifacts are retained: aggregated stats, credits, referrals that reference the requester as the referrer, and scratchpad images tied to notes. A separate compliance audit record notes the outcome. HIPAA BAA customers and enterprises needing written deletion confirmation should contact their account representative.

What happens to customer data when the contract terminates?

Under Zero Data Retention, dictation data is never stored server-side, so none persists after termination.

Account, configuration, and user data can be exported via the Admin Portal during the contract term and a reasonable wind-down period, then is deleted within a defined window per the Data Retention and Disposal Policy. Request export or confirmation of deletion through your account representative.

Can customers export their data?

Yes. A GDPR data export includes:

  • User account information and preferences; subscriptions, credits, and referrals; promo-code records.

  • Notes, dictionaries, and team memberships.

  • Usage stats and SMS/notification event records.

  • HIPAA BAA records and enterprise-scoped records including cost centers and invitations.

  • Mobile-store subscription events (App Store / Play Store).

  • Full dictation history (transcripts and associated metadata) when stored on Wispr's servers (Dictation cloud storage on).

Wispr Flow uses standard data formats. Account and configuration data plus snippets can be retrieved through the Admin Portal. API-based export is no longer available; the API has been sunsetted. Dictation content is not exportable when it is not stored server-side (Dictation cloud storage off or ZDR).

Where is customer data stored geographically?

All customer data is processed and stored in the United States regardless of user location; Wispr operates no European or other regional processing location. EU and UK transfers are governed by the EU Standard Contractual Clauses (June 2021) in our DPA, with a UK Addendum available.

What data does Wispr Flow store locally on the device?

Note: The full set of Data & Privacy controls (HIPAA BAA signing, local-data policy, auto-delete transcripts) exists on Desktop (macOS/Windows) and iOS. Android has no Data & Privacy settings section — it offers no model-improvement or cloud-storage toggle.

Stored locally:

  • Application binary and resources.

  • User preferences and settings: Privacy Mode state, Dictation cloud storage state, activation shortcut, and similar.

  • Authentication tokens: on Android, login sessions and OAuth tokens are encrypted at rest using hardware-backed encryption and are excluded from device backups and device-to-device transfers. On other platforms, tokens sit in the application's standard private storage area, isolated to Wispr Flow.

  • Snippets and dictionaries: kept in sync across your devices regardless of Privacy Mode or Dictation cloud storage.

Not stored locally: customer business data; audio recordings; and past dictation content or transcripts when local storage is set to "Never store data locally."

Changing local-data policy on Desktop. Moving to a more restrictive local-data setting requires confirming a destructive dialog: "Never store data locally" immediately deletes all transcripts and polish history; "Auto-delete local data every 24hrs" deletes transcripts and polish history older than 24 hours. Reverting to a less restrictive setting applies without confirmation. Where an admin restricts options, the dropdown reads "Some options are restricted by your organization."

On iOS, Settings → Data & Privacy also offers Auto-delete transcripts (default off; forced on when enterprise policy enforces auto-delete) and Refresh notes from cloud. The Desktop equivalent is Hard refresh all notes (labeled "Sync notes") in Settings → Data & Privacy: "Force a full one-time sync to rescan and retrieve all your notes from the cloud." It is disabled while a sync is running, briefly after a successful sync, and when Dictation cloud storage is off ("Turn on Dictation Cloud Storage to sync notes.").

Uninstalling removes the binary. Cached preferences may remain in standard OS application support directories and can be cleared by the user.

For full details, see wisprflow.ai/data-usage.

Does sensitive data ever reside on employee endpoint devices?

No production customer data resides on employee endpoints. Dictation content is processed server-side, and under Privacy Mode no transcripts are stored locally. This is enforced through least-privilege access, managed-device controls, and endpoint protection.

Are snippets and dictionaries stored regardless of Privacy Mode?

Yes. User-created snippets (saved text expansions) and custom dictionaries (custom vocabulary) are stored by Wispr and synced across your devices regardless of Privacy Mode or Dictation cloud storage — they are user-authored productivity assets, not dictation content. They carry the same protections as other account and configuration data: encrypted at rest, encrypted in transit (TLS 1.2+), and access-controlled.

Limits: custom dictionary entries 30 characters; snippet triggers 60 characters; snippet expansions 4,000 characters.

Team-shared snippets and dictionary entries are available on Team, Business, and Enterprise plans. Sharing is org/home-team wide; department-scoped sharing is not available.

Does Wispr capture screenshots?

Wispr Flow's Context Awareness feature, toggled in Settings → Data & Privacy, lets Flow use limited, relevant text content from the app you're dictating in to spell names correctly and better understand you. Enterprise admins can lock the setting, which then shows "This setting is managed by your organization," and manage it via admin.wisprflow.ai.

Captured screen context is not retained by Wispr when Privacy Mode is on / Dictation cloud storage is off.

What privacy effects does enabling Privacy Mode have on iOS?

On iOS, enabling Privacy Mode immediately purges buffered keyboard telemetry and redacts stored edit-history content, with no confirmation. A signed BAA or Privacy Mode both put the account into a "data restricted" state that also stops telemetry collection in the Flow Keyboard extension.

Is your Privacy Policy publicly available?

Yes, at wisprflow.ai/privacy and linked from the Trust Center.


Encryption

How is data encrypted in transit?

All confidential data in transit uses TLS 1.2 or higher with forward-secrecy cipher suites. There are no plaintext connections over public networks to production, internal traffic uses our cloud provider's encrypted channels, and certificates are issued by trusted public CAs with automated renewal.

How is data encrypted at rest?

Stored data is encrypted with AES-256. Sensitive OAuth and SSO credentials receive an additional layer of authenticated encryption. On Android, login sessions and OAuth tokens are encrypted at rest using hardware-backed encryption on the device. On other platforms, local auth tokens sit in the app's private storage area and rely on OS-level disk encryption (FileVault/BitLocker).

How are cryptographic keys managed?

Wispr manages encryption keys and application secrets under restricted access, with key usage logged and auditable.

Is Wispr Flow end-to-end encrypted? Can Wispr decrypt customer data?

Wispr Flow is not end-to-end encrypted in the strict cryptographic sense. The service is encrypted in transit (TLS 1.2+) and at rest, but audio must be decrypted to produce a transcription, so true E2E encryption is not possible.

Under Zero Data Retention (Privacy Mode on, Dictation cloud storage off), decrypted audio and transcripts are never persisted.

How are passwords hashed?

Passwords are hashed using industry-standard algorithms. Wispr never stores or logs passwords in plaintext.

Can customers manage their own encryption keys (BYOK)?

BYOK is not currently supported. Wispr manages encryption keys, and key lifecycle events are logged and auditable.


Identity and access

Does Wispr support Single Sign-On (SSO)?

Yes, on the Enterprise plan. SSO supports SAML 2.0 and OIDC connections to major identity providers (Okta, Microsoft Entra ID, Google Workspace, JumpCloud, OneLogin, Ping Identity, and generic SAML/OIDC), in both SP-initiated and IdP-initiated flows. Admins configure the connection from enterprise settings.

SSO can be enforced to block password login. Enforcement is contingent on active enterprise billing — if the subscription lapses, enforced SSO is automatically disabled even if the setting remains on. Sign-in attempts from a domain not linked to an enterprise, or an enterprise without an active SSO connection, return dedicated error pages. With SCIM directory sync configured, new users are provisioned by your identity provider and email sign-ups on that domain are blocked.

Is MFA enforced?

Internally: MFA is required for all production system access, administrative cloud access, SSO, and all sensitive SaaS tools.

For enterprise customers: MFA is enforced through the customer's own identity provider via SAML/OIDC SSO.

How do you manage provisioning, deprovisioning, and recertification?

Under our Access Control and Termination Policy, provisioning requires manager approval, access is revoked the same business day on termination or role change, and access is recertified quarterly. Managed devices are remotely wiped and assets recovered at offboarding. Access follows least-privilege principles throughout.

How do you control privileged accounts and remote access to production?

Privileged access follows least-privilege principles with no permanent standing admin credentials. Administrative access is time-bound, MFA-gated, and audited under a zero-trust model. There is no remote access to customer environments or machines.

Which staff can access customer data?

Under Privacy Mode (default for Enterprise and HIPAA BAA customers), no dictation content is accessible to anyone because it is not retained; the same applies whenever Dictation cloud storage is off. A limited number of engineering and infrastructure personnel hold read-only, MFA-gated, logged production access for troubleshooting. Support and customer success have read-only, logged access to account-level data only (subscription, user list, organization settings). For incidents requiring deeper data access, customer authorization is sought first.

Signing out of the desktop app clears the departing user's BAA signature metadata (signer name, email, date) so a subsequent user on the same machine cannot download another person's signed BAA receipt.

Are personnel screened and bound by security agreements?

Yes. Background checks are performed for personnel with access to production systems or customer data, where legally permitted, per the Personnel Security Policy. All personnel sign confidentiality/NDA agreements as a condition of employment and acknowledge the Acceptable Use Policy at onboarding and annually. A formal disciplinary process applies to security policy violations under the Personnel Security Policy and Code of Conduct.

How are employee devices secured and managed?

All employee endpoints are enrolled in centralized mobile device management (MDM), which enforces full-disk encryption (FileVault on macOS, BitLocker on Windows), a login password, anti-malware via endpoint detection and response, an auto-lock timer, a software firewall, USB mass-storage blocking, and restricted administrative privileges. Lost or stolen managed devices can be remotely wiped. Devices reach production only through authenticated, audited MFA sessions, never a direct laptop-to-production network connection.

A managed device is required for access to corporate data, including mobile; personal (BYOD) devices are not permitted for production access, and device posture (MDM enrollment plus endpoint protection) is required under our zero-trust model.

How do you prevent data loss from endpoints and removable media?

Email DLP and endpoint DLP (including USB mass-storage blocking) run on managed systems alongside endpoint detection and response and least-privilege access, and no production customer data resides on endpoints in the first place. Removable media is not used for organizational data. Content-aware cloud-storage DLP is not currently deployed — a risk-accepted decision.

Are there additional enterprise access controls available?

Additional enterprise controls may be discussed with your account representative.


Secure development and testing

When was your most recent penetration test, and what methodology does it follow?

Wispr commissions an annual external penetration test by an independent third party; the most recent completed in November 2025. It follows an OWASP-based methodology covering the OWASP Top 10, web application, infrastructure, and authentication/session testing. The remediation report is available under NDA via the Trust Center.

How do you ensure code is developed securely?

Our Secure SDLC Policy requires mandatory peer review, automated security and dependency testing, and separation of development, staging, and production environments. Security-sensitive changes receive a security review by the Engineering Lead/CISO, and threat considerations are built into the design of higher-risk features.

Do you outsource development, and how is third-party software reviewed?

Core development is in-house. Open-source dependencies are continuously scanned and patched. Third parties with access to data undergo a security assessment under our Vendor Management Policy.

Do you maintain a software bill of materials (SBOM)?

Yes. We maintain an internal SBOM, and a customer-shareable CycloneDX SBOM is available under NDA via the Trust Center.

How do you manage vulnerabilities, patching, and threat awareness?

Vulnerabilities surface through automated dependency scanning, cloud vulnerability assessment, continuous threat detection, endpoint detection and response, and the annual penetration test. We monitor security advisories, CVE feeds, and cloud-provider and vendor bulletins, and remediate on risk-based timelines, verifying each fix. Managed endpoints are patched through MDM, and our vCISO participates in the broader security community.

What mitigates web application vulnerabilities?

Input validation, output encoding, and Content-Security-Policy headers protect the application, reinforced by our secure-SDLC controls.

How do you manage secrets and network configuration changes?

Credentials, API keys, and encryption keys are held in managed, access-controlled key and secret stores, with automated scanning to catch exposed secrets. Network changes require peer review and are version-controlled and logged.

Do you have a vulnerability disclosure or bug bounty program?

We operate a coordinated disclosure process via security@wispr.ai and the Trust Center, and recognize researchers for impactful findings. We do not currently run a public paid bounty platform.


Logging, monitoring, and incident response

Which audit trails and logs do you keep?

We maintain multi-layer logging across infrastructure, network, and application layers, retained for security monitoring.

The enterprise-facing audit log surfaces membership events (member added, member removed, join request approved, join request rejected) with a rolling query window, filterable by actor, target, and event type. Enterprise admins can export audit logs from the Audit Logs page in the enterprise admin dashboard.

How do you alert on security events?

Security events are monitored centrally with severity-based alerting routed to on-call staff.

Are forensic investigations part of incident response?

Yes. Forensic capability is available through our endpoint detection and response provider and our cyber-insurance incident-response panel. We do not maintain a standing forensic retainer.


Security awareness and training

Do you have a security awareness training program?

Yes. Training is mandatory at onboarding and annually, with role-specific content for engineering (secure coding) and personnel with PHI access (HIPAA), and includes phishing awareness. Completion is tracked centrally. We do not currently run a standalone simulated-phishing campaign platform.

Do you engage with the wider security community?

Yes. We track security advisories, and our vCISO participates in relevant industry groups.


Network controls

Do you filter employee web browsing by URL category?

Wispr does not operate web content or URL-category filtering — a risk-accepted decision. Endpoint protection is provided by managed detection and response across all managed devices.

Is all public-network traffic to production encrypted?

Yes — see "How is data encrypted in transit?" under Encryption.

Do you segregate office and guest Wi-Fi from production?

Yes. Office Wi-Fi (WPA2/WPA3) is fully separated from production systems.


Physical and environmental security

Note: Wispr operates no data centers of its own. Production infrastructure runs with a major US cloud provider whose data centers are independently attested (SOC 2, ISO 27001, PCI DSS). The Wispr office holds no production customer data.

Are physical perimeter controls in place, and is access logged?

Yes, at the cloud provider level: physical perimeter controls, surveillance at ingress/egress points, logged and monitored access, and trained on-site personnel, all covered by their independent attestations. The Wispr office uses building-managed perimeter controls and badge access logged by the building, with visitors escorted.

Are environmental, utility, and redundancy controls in place?

Yes, managed by our cloud provider and covered by their attestations: temperature and humidity control, utility services, power and telecommunication cabling protection, and redundant equipment. The provider supplies geographic redundancy and selects sites accounting for environmental risk. Wispr owns no data-center equipment.

Do you transport physical media or relocate data-bearing hardware?

No. Wispr has no data-center hardware to relocate and does not transport physical media containing customer data. Employee endpoints are managed through MDM, and cloud data remains within our US cloud provider environment.


Service changes and availability

How are service changes communicated, and can tenants authorize them?

Wispr Flow is multi-tenant SaaS, so changes are not authorized per tenant. Material changes are communicated through our status page, and breaking changes receive advance notice per the MSA.


Still need help?

  • Email security@wispr.ai for security and compliance questions, including bespoke documentation requests. Include your platform and plan.

  • Request reports (SOC 2 Type I, ISO 27001, DPA, subprocessor list) via the Wispr Trust Center.

  • Enterprise customers: contact your account representative for contract-specific items (BAA, regional hosting confirmation).