Fireflies.ai

fireflies.ai

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
44 / 100D
Procurement decision
Approve with conditions
2 conditions outstanding
  • No formal subprocessor register disclosed
  • No clear commitment that your data will not train their models

See Before you sign, with what to ask for ↓

Evidence MediumFreshness CurrentVerification None

Scanned Oct 5, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

No formal subprocessor register disclosedCondition

Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.

What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.

No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Evidence
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We do not use personal information for AI model training and we contractually prohibit our vendors from using this information for their own model training.”
“You own your data. We don’t train on it by default unlike other AI companies.”

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

The Privacy Policy states Fireflies does not use personal information for AI model training and contractually prohibits its vendors from using it for their own model training.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We do not use personal information for AI model training and we contractually prohibit our vendors from using this information for their own model training.”
“You own your data. We don’t train on it by default unlike other AI companies.”
✓How long do they keep your data?Clear

Meeting content (audio, video, transcripts, summaries) and Fireflies Talk data are subject to a Zero Data Retention policy: third-party vendors must not store it after processing, access it after the service is complete, or use it to train internal or external AI models.

Evidence
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We also impose a Zero Data Retention policy for meeting content, which includes audio, video, transcripts, and summaries of the meeting, and Fireflies Talk data. This means that your meeting content and Fireflies Talk data is not: (1) stored by any third-party vendor after processing; (2) accessed by any third-party vendor once the service is completed; or (3) used for training internal or external AI models.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We store personal information associated with your account for as long as your account remains active. If you close your account, we will delete personal information related to your account within 30 days.”
“Users can delete a recording and its transcript at any time , and that deletion is a control inside the product.”
“Enterprise plans add custom data retention , the Super Admin role for workspace wide governance, and the Rules Engine , which applies recording, transcription, and retention policies across an organization automatically, plus Private Storage for holding meeting data in dedicated infrastructure.”
“Organizations on the Enterprise plan that cannot retain audio can switch to a transcript only or summary only recording format, and participants who want a recording deleted can ask the meeting host or Fireflies support.”
!Who else can access your data?Ask the vendor

Fireflies names OpenAI and Anthropic as transcription providers and model suppliers it uses, states that its zero-data-retention agreements extend to them, and refers to a full list on its Trust Center (not included in this scan).

Requires written confirmation — see Before you sign ↓

Evidence
“Those agreements extend to the transcription providers and model suppliers Fireflies actually uses, including OpenAI and Anthropic. You can check the full list on Fireflies’ Trust Center page.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“Voice Data may be considered “biometric identifiers” or “biometric information” in some jurisdictions. Our service providers do not use Voice Data to identify or authenticate individuals, and we never receive or process this information on our own servers.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“More information about our subprocessors is available at https://trust.fireflies.ai/subprocessors .”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We make personal information available to our vendors, service providers, contractors and consultants who perform services on our behalf, such as companies that assist us with analyzing meeting recordings, transcribing and formatting Fireflies Talk dictations (speech-to-text providers receive dictation audio; text-formatting providers receive the transcribed text and Screen Context), web hosting and cloud infrastructure, payment processing, fraud prevention, security, customer service, analytics, and marketing.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“If you choose to use integrations we offer on our Services, such as collaboration tools or external AI connectors, we will provide or make available certain information to those partners as needed to enable the integration. Information provided to integration partners will be handled in accordance with their own privacy policy and terms, which you should review carefully.”
!Where is your data processed?Ask the vendor

Fireflies is US-based and, with its service providers, processes and stores personal information in the United States and unspecified other countries, relying on contractual safeguards or derogations for restricted international transfers.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“Fireflies.ai is based in the United States, and we and our service providers process and store personal information on servers located in the United States and other countries.”
“Private Storage on Enterprise to store your meeting data at your preferred location.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“For personal information about EEA, Swiss, and UK individuals, Fireflies.ai complies with the EU-U.S. and Swiss-U.S. Data Privacy Frameworks and the UK Extension to the EU-U.S. Data Privacy Framework (collectively, the “Frameworks”), each as set forth by the U.S. Department of Commerce.”
!What happens in a security incident?Ask the vendor

Fireflies runs continuous vulnerability scanning and a bug bounty programme on HackerOne; backups exclude meeting content.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
“Vulnerability scanning runs continuously alongside a bug bounty program on HackerOne, and system backups cover configuration and metadata while excluding meeting content itself.”
“If you have security questions or have found a vulnerability, please disclose it via our bug bounty program .”

Email to send the vendor7 items to confirm in writing

Subject: Supplier assessment: written confirmation requested
Hello Fireflies.ai team,

We are assessing Fireflies.ai as part of our supplier review. Before we proceed, please confirm the following in writing:

1. Please provide your current, dated subprocessor list and explain how you notify customers of changes.
2. Do you use our data (inputs, outputs or uploaded files) to train or improve your models? Please confirm in writing, including any opt-out and whether it applies to every plan.
3. In which countries and regions is our data processed and stored, and can processing be limited to a region we choose?
4. What is your commitment to notify customers of a security incident affecting our data, including the timeframe?
5. Please share the current SOC 2 Type II report (auditor, period, in-scope systems) and confirm whether any HIPAA or FERPA coverage is available below the Enterprise tier.
6. Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
7. Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date.

Thank you,
Audit evidence: a verified report maps its findings to ISO/IEC 27001 supplier controls, ISO/IEC 42001 third-party controls and APRA CPS 230. See verified reports →

Key findingsclick a row for the evidence

✓No-training and zero-retention commitments flow down to named AI suppliersStrong

Fireflies publishes a clear commitment that customer and personal data are not used to train AI models, backed by a Zero Data Retention policy for meeting content with third-party vendors (no storage after processing, no post-service access, no training). It names OpenAI and Anthropic as model and transcription suppliers covered by those agreements, and states SOC 2 Type II is audited annually and applies on every plan.

For a tool that routes meeting audio to outside model providers, the training and retention position of those providers is the main data-handling risk. A flow-down commitment with named suppliers is stronger than most meeting-notes vendors publish, though it remains vendor-asserted until the DPA and SOC 2 report are reviewed.

Evidence
“Those agreements extend to the transcription providers and model suppliers Fireflies actually uses, including OpenAI and Anthropic. You can check the full list on Fireflies’ Trust Center page.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We do not use personal information for AI model training and we contractually prohibit our vendors from using this information for their own model training.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We also impose a Zero Data Retention policy for meeting content, which includes audio, video, transcripts, and summaries of the meeting, and Fireflies Talk data. This means that your meeting content and Fireflies Talk data is not: (1) stored by any third-party vendor after processing; (2) accessed by any third-party vendor once the service is completed; or (3) used for training internal or external AI models.”
“Fireflies holds SOC 2 Type II certification, audited independently every year. GDPR compliance covers EU data protection requirements. Both apply on every plan including the free one, which matters because compliance that begins at the paid tier leaves your smallest teams uncovered.”
!Security page says 'we don't train on it by default' while other pages say neverGap

The Security page states Fireflies does not train on customer data 'by default', which implies a non-default or opt-in training path. The Privacy Policy and the vendor's own safety article state unconditionally that customer and personal data are never used to train AI models and that vendors are contractually barred from doing so.

A buyer relying on the headline Security page could read a carve-out that the Privacy Policy does not contain, or vice versa. The commitment that governs is the one in the signed Terms of Service and DPA, which were not in this scan.

Question for vendor: Is there any setting, plan or programme under which customer meeting content or transcripts are used to train or fine-tune Fireflies or supplier models? Please confirm in writing which contractual document contains the binding no-training commitment.

Evidence
“You own your data. We don’t train on it by default unlike other AI companies.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We do not use personal information for AI model training and we contractually prohibit our vendors from using this information for their own model training.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We also impose a Zero Data Retention policy for meeting content, which includes audio, video, transcripts, and summaries of the meeting, and Fireflies Talk data. This means that your meeting content and Fireflies Talk data is not: (1) stored by any third-party vendor after processing; (2) accessed by any third-party vendor once the service is completed; or (3) used for training internal or external AI models.”
!Supply chain beyond OpenAI and Anthropic is described only by categoryGap

Apart from OpenAI and Anthropic, recipients are disclosed by category only: unnamed providers analyse recordings, generate potentially biometric Voice Data, receive Fireflies Talk dictation audio and Screen Context, and supply cloud hosting. The subprocessor list is referenced at trust.fireflies.ai but was not collected. Data passed to customer-enabled integrations and external AI connectors falls under the partner's terms, outside Fireflies' commitments. Processing occurs in the US and unspecified other countries unless Enterprise Private Storage is used.

Voice Data may be regulated as biometric information, and Screen Context can carry sensitive content; the buyer cannot assess those recipients or their jurisdictions from the pages scanned. The Trust Center subprocessor list should be obtained before relying on the model_provider_transparency and subprocessor assessments here, which are marked partial for that reason.

Question for vendor: Please provide the current subprocessor list naming the speech-to-text, speaker-identification (Voice Data), text-formatting and cloud infrastructure providers, the countries in which each processes customer data, and how customers are notified of additions.

Evidence
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“Voice Data may be considered “biometric identifiers” or “biometric information” in some jurisdictions. Our service providers do not use Voice Data to identify or authenticate individuals, and we never receive or process this information on our own servers.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“More information about our subprocessors is available at https://trust.fireflies.ai/subprocessors .”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We make personal information available to our vendors, service providers, contractors and consultants who perform services on our behalf, such as companies that assist us with analyzing meeting recordings, transcribing and formatting Fireflies Talk dictations (speech-to-text providers receive dictation audio; text-formatting providers receive the transcribed text and Screen Context), web hosting and cloud infrastructure, payment processing, fraud prevention, security, customer service, analytics, and marketing.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“If you choose to use integrations we offer on our Services, such as collaboration tools or external AI connectors, we will provide or make available certain information to those partners as needed to enable the integration. Information provided to integration partners will be handled in accordance with their own privacy policy and terms, which you should review carefully.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“Fireflies.ai is based in the United States, and we and our service providers process and store personal information on servers located in the United States and other countries.”
!Compliance claims need qualification: GDPR and HIPAA are not certifications, and HIPAA/FERPA are Enterprise-onlyGap

The Security page describes Fireflies as 'certified' for GDPR, SOC 2 Type II and HIPAA. Only SOC 2 Type II is an attestation; GDPR and HIPAA are legal regimes. HIPAA and FERPA coverage applies only on Enterprise with Private Storage plus a signed BAA or Data Sharing Agreement. The SOC 2 auditor, report period and system scope are not stated. The Data Privacy Framework participation is a self-certification.

Buyers on Free, Pro or Business tiers should not read the badges as regulated-data coverage, and the SOC 2 claim remains vendor-asserted until the report is obtained under NDA.

Question for vendor: Please share the current SOC 2 Type II report (auditor, period, in-scope systems) and confirm whether any HIPAA or FERPA coverage is available below the Enterprise tier.

Evidence
“Certified for GDPR, SOC 2 Type II, and HIPAA compliance, ensuring top security and privacy standards.”
“Fireflies holds SOC 2 Type II certification, audited independently every year. GDPR compliance covers EU data protection requirements. Both apply on every plan including the free one, which matters because compliance that begins at the paid tier leaves your smallest teams uncovered.”
“HIPAA compliance is Enterprise only and takes two things together, Private Storage enabled and a signed Business Associate Agreement. Removing either one disables it automatically. FERPA compliance works the same way for student education records, Enterprise only, requiring Private Storage and a signed Data Sharing Agreement.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“For personal information about EEA, Swiss, and UK individuals, Fireflies.ai complies with the EU-U.S. and Swiss-U.S. Data Privacy Frameworks and the UK Extension to the EU-U.S. Data Privacy Framework (collectively, the “Frameworks”), each as set forth by the U.S. Department of Commerce.”
!No published AI evaluation, model change notice or incident response commitmentGap

Nothing in the scanned pages describes how transcription or summarisation quality is tested, how model or supplier changes are communicated to customers, or how security incidents and breaches are handled and notified. testing_and_evaluation and change_management are marked not_evidenced rather than not_applicable: this is a hosted SaaS in the request path whose suppliers (OpenAI, Anthropic) can change, so the vendor could publish both and comparable vendors do. The only change notice found concerns the Privacy Policy itself, and the only incident-related disclosure is the bug bounty channel, so vulnerability_and_incident_handling is partial.

Without evaluation evidence a buyer cannot judge summary accuracy or hallucination risk for decisions taken from meeting notes; without change notice a supplier swap could alter data flows silently; without an incident commitment the buyer has no contractual breach-notification baseline.

Question for vendor: What testing is performed on transcription and summary accuracy, how and when are customers notified of changes to AI models or model suppliers, and what are your security incident response and customer breach notification commitments and timeframes?

Evidence
“Vulnerability scanning runs continuously alongside a bug bounty program on HackerOne, and system backups cover configuration and metadata while excluding meeting content itself.”
“If you have security questions or have found a vulnerability, please disclose it via our bug bounty program .”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We may change this Privacy Policy from time to time. If we make changes, we will notify you by revising the date at the top of this policy. If we make material changes, we will provide you with additional notice (such as by adding a statement to the Services or sending you a notification).”
“Those agreements extend to the transcription providers and model suppliers Fireflies actually uses, including OpenAI and Anthropic. You can check the full list on Fireflies’ Trust Center page.”
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
“Those agreements extend to the transcription providers and model suppliers Fireflies actually uses, including OpenAI and Anthropic. You can check the full list on Fireflies’ Trust Center page.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“Voice Data may be considered “biometric identifiers” or “biometric information” in some jurisdictions. Our service providers do not use Voice Data to identify or authenticate individuals, and we never receive or process this information on our own servers.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“More information about our subprocessors is available at https://trust.fireflies.ai/subprocessors .”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We make personal information available to our vendors, service providers, contractors and consultants who perform services on our behalf, such as companies that assist us with analyzing meeting recordings, transcribing and formatting Fireflies Talk dictations (speech-to-text providers receive dictation audio; text-formatting providers receive the transcribed text and Screen Context), web hosting and cloud infrastructure, payment processing, fraud prevention, security, customer service, analytics, and marketing.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“If you choose to use integrations we offer on our Services, such as collaboration tools or external AI connectors, we will provide or make available certain information to those partners as needed to enable the integration. Information provided to integration partners will be handled in accordance with their own privacy policy and terms, which you should review carefully.”
?Technical dependency observed: GoogleObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
“Those agreements extend to the transcription providers and model suppliers Fireflies actually uses, including OpenAI and Anthropic. You can check the full list on Fireflies’ Trust Center page.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“Voice Data may be considered “biometric identifiers” or “biometric information” in some jurisdictions. Our service providers do not use Voice Data to identify or authenticate individuals, and we never receive or process this information on our own servers.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“More information about our subprocessors is available at https://trust.fireflies.ai/subprocessors .”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We make personal information available to our vendors, service providers, contractors and consultants who perform services on our behalf, such as companies that assist us with analyzing meeting recordings, transcribing and formatting Fireflies Talk dictations (speech-to-text providers receive dictation audio; text-formatting providers receive the transcribed text and Screen Context), web hosting and cloud infrastructure, payment processing, fraud prevention, security, customer service, analytics, and marketing.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“If you choose to use integrations we offer on our Services, such as collaboration tools or external AI connectors, we will provide or make available certain information to those partners as needed to enable the integration. Information provided to integration partners will be handled in accordance with their own privacy policy and terms, which you should review carefully.”

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score40
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
“Fireflies acts as a data custodian. Internal teams have no access to meeting content by default, and any access requires the user's explicit permission, usually for support.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“If you have a concern about our processing of personal data, we encourage you to contact us in the first instance by emailing us at [email protected] .”
AI system15% of the score20
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
“Fireflies joins as a visible participant named Fireflies.ai Notetaker. Attendees see it in the participant list, and participants can remove it, subject to the platform's own permission rules.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We use the information we collect to provide, operate, and improve our Services, including to capture audio and visual recordings of meetings, generate transcripts and summaries, transcribe and format dictations you create with Fireflies Talk, and enable other integrations you select.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“Fireflies Talk is off until you turn it on in the desktop application under Settings › Dictation, and you can turn it off there at any time. You can also turn off Screen Context in the same place; with Screen Context off, Fireflies Talk transcribes your dictation without reading the application you are using.”
Vendor publishedIntroduction - Fireflies.ai API Documentation ↗retrieved Oct 5, 2026
“Our API covers various functionalities, including queries for fetching data as well as uploading meeting audio.”
“It supports 100+ languages and gives you 20 one-time AI credits for features like AskFred, which lets you ask questions about your transcript to find specific information.”
“That name matters, because these are settings rather than defaults. Once an account or workspace owner enables them, participants receive an email an hour before the meeting telling them it will be recorded, with a link to decline that keeps Fireflies out, and a pinned message posts in the meeting chat when Fireflies joins.”
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Not Evidenced
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

AI system description: vendor-evidenced, not yet independently corroborated.

Testing & evaluation: not publicly evidenced.

Change management: not publicly evidenced.

Model10% of the score40
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
“Those agreements extend to the transcription providers and model suppliers Fireflies actually uses, including OpenAI and Anthropic. You can check the full list on Fireflies’ Trust Center page.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“Voice Data may be considered “biometric identifiers” or “biometric information” in some jurisdictions. Our service providers do not use Voice Data to identify or authenticate individuals, and we never receive or process this information on our own servers.”
Customer data15% of the score65
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We do not use personal information for AI model training and we contractually prohibit our vendors from using this information for their own model training.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We also impose a Zero Data Retention policy for meeting content, which includes audio, video, transcripts, and summaries of the meeting, and Fireflies Talk data. This means that your meeting content and Fireflies Talk data is not: (1) stored by any third-party vendor after processing; (2) accessed by any third-party vendor once the service is completed; or (3) used for training internal or external AI models.”
“You own your data. We don’t train on it by default unlike other AI companies.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We store personal information associated with your account for as long as your account remains active. If you close your account, we will delete personal information related to your account within 30 days.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“Fireflies.ai is based in the United States, and we and our service providers process and store personal information on servers located in the United States and other countries.”
“Private Storage on Enterprise to store your meeting data at your preferred location.”
“Users can delete a recording and its transcript at any time , and that deletion is a control inside the product.”
“Enterprise plans add custom data retention , the Super Admin role for workspace wide governance, and the Rules Engine , which applies recording, transcription, and retention policies across an organization automatically, plus Private Storage for holding meeting data in dedicated infrastructure.”
“Organizations on the Enterprise plan that cannot retain audio can switch to a transcript only or summary only recording format, and participants who want a recording deleted can ask the meeting host or Fireflies support.”
“Meeting content is encrypted with AES at 256 bits while stored and TLS 1.2 or higher while moving.”

Customer data treatment: vendor-evidenced, not yet independently corroborated.

AI supply chain10% of the score40
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“More information about our subprocessors is available at https://trust.fireflies.ai/subprocessors .”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We make personal information available to our vendors, service providers, contractors and consultants who perform services on our behalf, such as companies that assist us with analyzing meeting recordings, transcribing and formatting Fireflies Talk dictations (speech-to-text providers receive dictation audio; text-formatting providers receive the transcribed text and Screen Context), web hosting and cloud infrastructure, payment processing, fraud prevention, security, customer service, analytics, and marketing.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“If you choose to use integrations we offer on our Services, such as collaboration tools or external AI connectors, we will provide or make available certain information to those partners as needed to enable the integration. Information provided to integration partners will be handled in accordance with their own privacy policy and terms, which you should review carefully.”
“Those agreements extend to the transcription providers and model suppliers Fireflies actually uses, including OpenAI and Anthropic. You can check the full list on Fireflies’ Trust Center page.”
Security foundation15% of the score45
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
“Vulnerability scanning runs continuously alongside a bug bounty program on HackerOne, and system backups cover configuration and metadata while excluding meeting content itself.”
“If you have security questions or have found a vulnerability, please disclose it via our bug bounty program .”
Independent assurance evidence10% of the score44
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Partial
Evidence — Independent assurance
“Fireflies holds SOC 2 Type II certification, audited independently every year. GDPR compliance covers EU data protection requirements. Both apply on every plan including the free one, which matters because compliance that begins at the paid tier leaves your smallest teams uncovered.”
“Certified for GDPR, SOC 2 Type II, and HIPAA compliance, ensuring top security and privacy standards.”
“HIPAA compliance is Enterprise only and takes two things together, Private Storage enabled and a signed Business Associate Agreement. Removing either one disables it automatically. FERPA compliance works the same way for student education records, Enterprise only, requiring Private Storage and a signed Data Sharing Agreement.”

Independent assurance: vendor-evidenced, not yet independently corroborated.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
“To ensure compliance with GDPR regulations, we invite you to sign our Data Processing Agreement (DPA). Please follow these simple steps:”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“This Privacy Policy does not apply to User Content we process on behalf of our business customers, which is governed by our Terms of Service , Data Processing Agreement , and other applicable agreements covering business customers' access to and use of our Services.”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“For personal information about EEA, Swiss, and UK individuals, Fireflies.ai complies with the EU-U.S. and Swiss-U.S. Data Privacy Frameworks and the UK Extension to the EU-U.S. Data Privacy Framework (collectively, the “Frameworks”), each as set forth by the U.S. Department of Commerce.”
“You maintain full control and ownership of your data, explicitly stated in our Term of Service”
Vendor publishedPrivacy Policy | Fireflies.ai ↗retrieved Oct 5, 2026
“We may change this Privacy Policy from time to time. If we make changes, we will notify you by revising the date at the top of this policy. If we make material changes, we will provide you with additional notice (such as by adding a statement to the Services or sending you a notification).”

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Publish Change management evidenceAI System 20 → 40
+3Complete the Governance & accountability disclosureOrganisation 40 → 60
+3Publish Testing & evaluation evidenceAI System 20 → 40
+3Complete the Vulnerability & incident handling disclosureSecurity Foundation 45 → 65
+3Publish independently corroborated ISO/IEC 42001 (AI management system) certificationIndependent Assurance 44 → 59

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 44 → up to 71 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSFireflies.ai Corp.Fireflies.ai Corp.Fireflies.ai NotetakerFireflies.ai NotetakerFireflies TalkFireflies TalkFireflies APIFireflies APIAskFredAskFredOpenAIOpenAIAnthropicAnthropic
View as list
Fireflies.ai Corp. Uses AI Service OpenAI
Fireflies.ai Corp. Uses AI Service Anthropic

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 5 — registry checks and verification ladders, click to view
SOC 2 Type IIVendor claimed only

Vendor states annual independent audit covering all plans including free; auditor, report period and in-scope systems not stated on scanned pages.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

HIPAA (Business Associate Agreement)Vendor claimed only

Compliance claim, not a certification. Enterprise only; requires Private Storage enabled and a signed BAA.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

FERPAVendor claimed only

Compliance claim, not a certification. Enterprise only; requires Private Storage and a signed Data Sharing Agreement.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

EU-U.S. Data Privacy Framework (incl. UK Extension and Swiss-U.S. DPF)Vendor claimed only

Self-certification transfer mechanism administered by the U.S. Department of Commerce, not an independent audit; verifiable against the public DPF list.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

Sources 12 — click to view
Fireflies Trust Center
Subprocessor List · Vendor · retrieved Oct 5, 2026
Privacy Policy | Fireflies.ai
Privacy Notice · Vendor · retrieved Oct 5, 2026
Vanta
Certification Or Compliance Page · Vendor · retrieved Oct 5, 2026
Introduction - Fireflies.ai API Documentation
Product Documentation · Vendor · retrieved Oct 5, 2026
Fireflies.ai Blog
Technical Article · Vendor · retrieved Oct 5, 2026
Fireflies Trust Center
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Explore with Fireflies AI Assistant - Fireflies.ai API Documentation
Product Documentation · Vendor · retrieved Oct 5, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Fireflies.ai at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.

Monitor for changes

Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.