← Trust Directory

Fireflies.ai

fireflies.ai · 1 assessment

Fireflies.ai - organisation
Approve with conditions
2 items to confirm in writing
Assessed Oct 5, 2026 · public evidence coverage 43% · evidence confidence medium · methodology 0.7.0

Certifications

What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.

SOC 2 Type II
Vendor claimed only

Vendor states annual independent audit covering all plans including free; auditor, report period and in-scope systems not stated on scanned pages.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
HIPAA (Business Associate Agreement)
Vendor claimed only

Compliance claim, not a certification. Enterprise only; requires Private Storage enabled and a signed BAA.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
FERPA
Vendor claimed only

Compliance claim, not a certification. Enterprise only; requires Private Storage and a signed Data Sharing Agreement.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF)
Vendor claimed only

Self-certification transfer mechanism administered by the U.S. Department of Commerce, not an independent audit; verifiable against the public DPF list.

  • ✓ Vendor claimed
  • ✓ Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current
ISO/IEC 42001
Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

  • — Vendor claimed
  • — Evidence cited
  • — Registry corroborated
  • — Scope verified
  • — Current

Supply chain

Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.

AI providers: OpenAI, Anthropic

How to read this

This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. Where too little was found to characterise a product at all, no score or grade is published rather than a low one: absence of evidence is not a number, and a letter grade would read as a verdict on the vendor when it would only be a verdict on what we could collect. This record reflects the evidence available on Oct 5, 2026.