All systems operational View status page

How to Submit a Vendor Security Assessment or Questionnaire

Available on: Web (Wispr Trust Center)

Need Wispr to complete a vendor security assessment, security questionnaire, or third-party risk review? All submissions go through the Wispr Trust Center, where you request access and sign an NDA before we share security documentation.


How to submit your questionnaire

  1. Go to the Wispr Trust Center and follow the prompts to request access. Signing an NDA is part of this flow.

  2. Submit your questionnaire or vendor portal link once access is granted.

  3. Review the SOC 2 report and Data Processing Addendum in the Trust Center — they often answer questionnaire items without a manual response.

Note: Enterprise-plan admins can also reach the Trust Center in the app at Settings → Organization → SOC 2, or on the Privacy page → SOC 2 and HIPAA compliance card; both are disabled with an Enterprise tag on other plans. The enterprise Privacy page also links the Privacy policy, Terms of service, Data controls, and Data Processing Addendum.


Enterprise controls commonly referenced in assessments

These controls are available to Enterprise plan admins unless noted. Org policies are managed in the web admin portal; the desktop app links out to it rather than editing org settings in-app.

  • Audit log: the Events viewer (Audit Logs → Events) lists events by actor, action, and target with plain-language labels (e.g. "removed member"), including member added, member removed, and join request approved or rejected. Filter by date range and event type, set page size to 20, 50, or 100, load more pages, refresh manually or automatically, and export as CSV or JSON. Audit-log streaming is configured in a separate tab for eligible enterprises.

  • Improve the model for everyone: controls whether Wispr may use audio, transcripts, and edits to evaluate and improve AI models; admins can set it to "Disabled for everyone" org-wide.

  • Dictation cloud storage: controls whether dictation data is stored on Wispr servers for personalization features that need cross-device access; can be restricted org-wide. Available to admins on Team (Pro Teams) and Enterprise plans with an active or trialing subscription, and disabled without one.

  • Enforce zero data retention: org-wide policy that turns data sharing (Privacy Mode) off for every member and locks the setting so users cannot re-enable it. Dictation cloud storage is a separate org setting.

  • Local data storage policy: admins choose Managed individually, auto-delete local data every 24 hours, or never store data locally. The org setting is a floor: "never store data locally" locks out every other choice and keeps no local dictation history on the device; "auto-delete every 24 hours" still lets members pick the stricter "never store" but not "managed individually"; "managed individually" or unset leaves all three available. Effective policy is always the stricter of the org floor and the user's choice.

  • Context awareness: admins can disable it org-wide on desktop. On Android it is controlled only by the per-user setting (on by default) and never applies in banking/financial apps or in Wispr Flow's own UI; there is no org-level control on Android or iOS.

  • SSO/SAML: available with SCIM provisioning.

  • HIPAA Business Associate Agreement (BAA): Enterprise admins sign it at Settings → Organization → Org-wide HIPAA → View and accept BAA. While active, data sharing is disabled for all users and transcription data is not used to train or improve models. Individual BAA holders can view or revoke their signed BAA.

  • Data retention and deletion: transcripts are stored locally per device and do not sync across devices. iOS offers an "Auto-delete transcripts" toggle (Settings → Data & Privacy, default off) that clears history older than the current day on launch, and org policy can force it on and lock it. Users can delete their account and all associated data from the app.

  • Policy propagation and fail-closed behavior: running desktop clients re-fetch org policy changes automatically. If the app cannot confirm your organization's policy — at launch before settings load, right after sign-out, or if a refresh fails — it applies the strictest settings (auto-delete on, data sharing off, cloud storage off) rather than stale ones, until the policy is confirmed. Signing out clears cached org policy immediately.

  • Restricted cloud storage: when cloud storage is blocked by org policy or a signed HIPAA BAA, members see an explanatory dialog with a privacy-policy link instead of a toggle, shown as a modal or a dismissible inline banner. Non-admin members can tap Request access, which records the request and shows a one-time confirmation toast rather than opening a support ticket; dismissing the dialog does not unblock the feature. A user who disabled cloud storage themselves, with no org or HIPAA lock, sees a card that re-enables it directly.

  • Page-level lockout (desktop): when org policy blocks dictation features, Flow shows a full-screen locked overlay over Dictation, Insights, Style, Dictionary, My Voice, Snippets and Transforms; the page underneath cannot be used and its keyboard shortcuts are disabled.

  • Plan labels: Enterprise orgs display as either Growth (self-serve business billing) or Enterprise (sales-led/legacy); both map to the same feature set — security & compliance, IT admin seats, audit logs, SSO & SCIM, dedicated support, volume discounts, usage analytics, and team opt-out. Users with no organization show as Pro.

  • External link handling (desktop): the desktop app only opens external links using http, https, or mailto; all other URL schemes are blocked, with a single macOS-only exception for the system Sound settings pane.

Note: Android has no Data & Privacy section — no Privacy Mode or cloud-storage toggle — and surfaces only the plan label rather than full enterprise controls.


FAQs

Can I email my questionnaire instead?

Submit it through the Trust Center. That keeps the NDA, your documentation access, and your assessment in one place.

Do I have to sign an NDA?

Yes. It is built into the Trust Center access flow.

Can you complete our assessment in our own vendor portal?

Yes. Share your portal or assessment link when submitting through the Trust Center, and our security team will work from there.

Can I get a Transfer Impact Assessment (TIA)?

Under the Standard Contractual Clauses framework, the data controller — your organization — completes the TIA. Wispr provides the Data Processing Addendum and security documentation through the Trust Center as supporting material.

How quickly do policy changes take effect for users after an admin updates them?

See Policy propagation and fail-closed behavior above. Signed-out users receive updated policies as soon as they sign back in.


Still need help?

Include your platform, plan, and what you have already submitted:

Need a hand?

Reach the Flow team and we’ll help you get unblocked.