Otter.ai
otter.ai
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- Vendor discloses an unfavourable answer: Will they train on your data?
- Otter.ai trains its own AI on user recordings and transcripts and shares data with human annotators
- Data retention window not stated
See Before you sign, with what to ask for ↓
Scanned Oct 5, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: Otter.ai's privacy policy states that it trains its proprietary AI technology on de-identified audio recordings and on transcriptions, and acknowledges the transcriptions may contain personal information; the legal basis given is consent or legitimate interests.
What to ask for: Resolve this directly with the vendor before proceeding — this is a confirmed disclosure, not a gap to fill in.
“Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)”
“Data labeling service providers who provide annotation services and use the data we share to create training and evaluation data for Otter’s product features.”
Why it matters: The privacy policy states Otter.ai trains its proprietary AI technology on de-identified audio recordings and on transcriptions that may contain personal information, on a consent or legitimate-interests basis. It also discloses sharing data with data labeling providers to create training and evaluation data, and the subprocessor page names Research Transcriptions as the annotation vendor. The third-party no-training statements apply only to Anthropic and OpenAI, not to Otter.ai's own models. The collected documents do not state whether Otter Business or enterprise customer data is excluded from training or annotation, or how an opt-out is exercised.
What to ask for: Is Customer Data from Otter Business and enterprise accounts excluded from training Otter.ai's proprietary models and from annotation by Research Transcriptions or other labeling providers? If exclusion is opt-in or opt-out, how is it exercised and where is it recorded contractually?
“Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)”
“Data labeling service providers who provide annotation services and use the data we share to create training and evaluation data for Otter’s product features.”
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
“Where we have an Otter Business or enterprise service agreement in place with an enterprise customer who is asking you to use our Services (for example your employer), we obtain and process your Personal Information on behalf of and at the instructions of that customer. In that context, such enterprise customers are the data controllers and their privacy policies will apply to the processing of your Personal Information.”
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“Otter.ai stores all Personal Information for as long as necessary to fulfill the purposes set out in this Policy, or for as long as we are required to do so by law or in order to comply with a regulatory obligation. When deleting Personal Information, we will take measures to render such Personal Information irrecoverable or irreproducible, and the electronic files which contain Personal Information will be permanently deleted.”
“When providing our Services as a data processor, we process and retain Personal Information as necessary to provide our Services as permitted in our agreements, or as required or permitted under applicable law.”
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✗Will they train on your data?Concern / gap
Otter.ai's privacy policy states that it trains its proprietary AI technology on de-identified audio recordings and on transcriptions, and acknowledges the transcriptions may contain personal information; the legal basis given is consent or legitimate interests.
Requires written confirmation — see Before you sign ↓
“Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)”
“Data labeling service providers who provide annotation services and use the data we share to create training and evaluation data for Otter’s product features.”
!How long do they keep your data?Ask the vendor
Retention is criteria-based: personal information is kept for as long as necessary for the policy's purposes or as required by law, with no defined retention windows stated; on deletion Otter.ai commits to rendering the data irrecoverable.
Requires written confirmation — see Before you sign ↓
“Otter.ai stores all Personal Information for as long as necessary to fulfill the purposes set out in this Policy, or for as long as we are required to do so by law or in order to comply with a regulatory obligation. When deleting Personal Information, we will take measures to render such Personal Information irrecoverable or irreproducible, and the electronic files which contain Personal Information will be permanently deleted.”
“When providing our Services as a data processor, we process and retain Personal Information as necessary to provide our Services as permitted in our agreements, or as required or permitted under applicable law.”
!Who else can access your data?Ask the vendor
Otter.ai publishes a dated subprocessor page (effective 31 March 2026) listing each third party's entity name, country and subprocessing role, split into core infrastructure and other subprocessors.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
“Provider for evaluating the effectiveness of our Large Language Models (LLM). The provider is used to provide input on whether product feature(s) may contain harmful information. No Customer Data will be used to train or improve OpenAI’s artificial intelligence models. OpenAI does not store Customer Data sent through the API on their platform.”
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”
!Where is your data processed?Ask the vendor
Compute and data storage rely on Amazon Web Services in the United States; data may be processed outside the user's country, with Standard Contractual Clauses cited as the safeguard for transfers out of the EEA or UK.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Cloud service providers who we rely on for compute and data storage, including Amazon Web Services, based in the United States.”
!What happens in a security incident?Ask the vendor
Otter.ai states it maintains physical, administrative and technical safeguards for personal information but disclaims the security of data in transit; the collected documents say nothing about security incident response, breach notification timelines or vulnerability disclosure.
Requires written confirmation — see Before you sign ↓
“Otter.ai maintains and implements physical, administrative, and technical safeguards to protect the confidentiality, integrity, and availability of personal information. However, the transfer of Personal Information through the internet will carry its own inherent risks and we do not guarantee the security of your data transmitted through the internet.”
Email to send the vendor9 items to confirm in writing
Hello Otter.ai team, We are assessing Otter.ai as part of our supplier review. Before we proceed, please confirm the following in writing: 1. Do you use our data (inputs, outputs or uploaded files) to train or improve your models? Please confirm in writing, including any opt-out and whether it applies to every plan. 2. What is your commitment to notify customers of a security incident affecting our data, including the timeframe? 3. How long do you retain our data, in days, for each type (inputs, outputs, logs and backups), and how is it deleted? 4. Please provide your current, dated subprocessor list and explain how you notify customers of changes. 5. In which countries and regions is our data processed and stored, and can processing be limited to a region we choose? 6. Which model providers and model families process meeting audio, transcripts and screenshots for each AI feature, on which cloud provider does inference run, and how are customers notified and able to evaluate changes to models or AI features? 7. Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data. 8. Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data. 9. Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data. A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date. Thank you,
Key findingsclick a row for the evidence
✓Published, dated subprocessor register names AI and infrastructure providersStrong
Otter.ai maintains a subprocessor page (effective 31 March 2026) listing entity, country and role for 17 third parties, including its AI providers. Anthropic is named as the backend for AI-enabled functionality and OpenAI for LLM evaluation and harmful-content checks, each with an explicit statement that Customer Data is not used to train the provider's models and is not stored via the API. Three cloud providers (AWS, Google Cloud Platform, Crusoe) are named, and Otter.ai commits to notify account owners of new subprocessors where the Agreement requires.
A buyer can see who sits in the data path for AI features and hold the vendor to specific no-training and no-storage statements about those providers, rather than relying on a generic 'we use AI service providers' disclosure.
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
“Provider for evaluating the effectiveness of our Large Language Models (LLM). The provider is used to provide input on whether product feature(s) may contain harmful information. No Customer Data will be used to train or improve OpenAI’s artificial intelligence models. OpenAI does not store Customer Data sent through the API on their platform.”
“We will endeavor to provide the owner of Customer’s account with notice of any new Subprocessors to the extent required under the Agreement, along with posting such updates here.”
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”
✗Otter.ai trains its own AI on user recordings and transcripts and shares data with human annotatorsGap
The privacy policy states Otter.ai trains its proprietary AI technology on de-identified audio recordings and on transcriptions that may contain personal information, on a consent or legitimate-interests basis. It also discloses sharing data with data labeling providers to create training and evaluation data, and the subprocessor page names Research Transcriptions as the annotation vendor. The third-party no-training statements apply only to Anthropic and OpenAI, not to Otter.ai's own models. The collected documents do not state whether Otter Business or enterprise customer data is excluded from training or annotation, or how an opt-out is exercised.
Meeting recordings are among the most sensitive data a workplace tool handles. Training and human annotation on that content, even de-identified, is a material disclosure for any buyer and needs to be settled contractually for enterprise plans.
Question for vendor: Is Customer Data from Otter Business and enterprise accounts excluded from training Otter.ai's proprietary models and from annotation by Research Transcriptions or other labeling providers? If exclusion is opt-in or opt-out, how is it exercised and where is it recorded contractually?
“Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)”
“Data labeling service providers who provide annotation services and use the data we share to create training and evaluation data for Otter’s product features.”
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
“Where we have an Otter Business or enterprise service agreement in place with an enterprise customer who is asking you to use our Services (for example your employer), we obtain and process your Personal Information on behalf of and at the instructions of that customer. In that context, such enterprise customers are the data controllers and their privacy policies will apply to the processing of your Personal Information.”
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
!No incident response, breach notification or security assurance disclosure in the collected materialGap
Only three documents were collected (subprocessor page, privacy policy, blog index), so this assessment is narrow. Within them, security is covered by a one-paragraph safeguards statement that disclaims transit security, with nothing on incident response, breach notification timelines or vulnerability disclosure. No SOC 2, ISO/IEC 27001 or ISO/IEC 42001 report is named. Retention is criteria-based with no defined windows for recordings or transcripts. vulnerability_and_incident_handling is marked not_evidenced rather than not_applicable: a hosted SaaS meeting-notes vendor can and ordinarily does publish these commitments, so their absence here is a gap to close, not a domain that does not arise.
A buyer cannot assess breach-notification obligations, deletion timelines or audited security controls from the public material collected; a trust centre or DPA may exist but was not in scope of this scan.
Question for vendor: Please provide your security incident and breach notification commitments (including notification timelines to customers), your current SOC 2 Type II or ISO/IEC 27001 report, and defined retention and deletion windows for recordings, transcripts and derived data after account or workspace deletion.
“Otter.ai maintains and implements physical, administrative, and technical safeguards to protect the confidentiality, integrity, and availability of personal information. However, the transfer of Personal Information through the internet will carry its own inherent risks and we do not guarantee the security of your data transmitted through the internet.”
“Otter.ai stores all Personal Information for as long as necessary to fulfill the purposes set out in this Policy, or for as long as we are required to do so by law or in order to comply with a regulatory obligation. When deleting Personal Information, we will take measures to render such Personal Information irrecoverable or irreproducible, and the electronic files which contain Personal Information will be permanently deleted.”
“When providing our Services as a data processor, we process and retain Personal Information as necessary to provide our Services as permitted in our agreements, or as required or permitted under applicable law.”
“Otter.ai has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with respect to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.”
!Data Privacy Framework participation is a self-certification, not an independent auditGap
The only assurance mechanism named is Otter.ai's self-certification to the U.S. Department of Commerce under the EU-U.S. DPF, UK Extension and Swiss-U.S. DPF, backed by an annual self-assessment and FTC enforceability. It is scoped to personal data received from the EU, UK and Switzerland and is not a third-party audit of security or AI controls. The registry record at dataprivacyframework.gov was not checked in this scan.
DPF supports lawful transfer for European data but says nothing about audited security or AI governance; buyers outside Europe gain little from it and should not read it as a security certification.
“Otter.ai has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with respect to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.”
“We conduct an annual self-assessment of our practices regarding Personal Information intended to verify that the assertions we make about our practices are true and that such practices have been implemented as represented.”
!Which models run where is not disclosedGap
The documents describe inputs (audio, OtterPilot screenshots, speaker identification) and name Anthropic as the AI backend and OpenAI as an evaluation provider, but do not name model families or versions, say whether Otter.ai's proprietary models run on AWS, Google Cloud Platform or Crusoe, or describe how model or feature changes are evaluated and communicated. The only change-notice commitment is for new subprocessors. This is why ai_system_description, model_provider_transparency, testing_and_evaluation and change_management are marked partial.
Without knowing which models process meeting content and where inference runs, a buyer cannot complete a data-flow assessment or judge the impact of a provider or model swap.
Question for vendor: Which model providers and model families process meeting audio, transcripts and screenshots for each AI feature, on which cloud provider does inference run, and how are customers notified and able to evaluate changes to models or AI features?
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
“Provider for evaluating the effectiveness of our Large Language Models (LLM). The provider is used to provide input on whether product feature(s) may contain harmful information. No Customer Data will be used to train or improve OpenAI’s artificial intelligence models. OpenAI does not store Customer Data sent through the API on their platform.”
“When you use the Services, you may provide us with your audio recordings (“Audio Recordings”), automatic OtterPilot TM screenshots and any text, images or videos that you upload or provide to us in the context of the Services. OtterPilot may take automatic screenshots which are available meeting transcripts to add value to the meetings by extracting useful visual information. The automatic screenshots will only take place in virtual meetings.”
“When you use the Services, you may record and annotate spoken conversations, such as calls or meetings, from which we generate speaker identification information. We use this information to help you recognize speakers in recorded conversations and automatically tag their name within the transcript.”
“We will endeavor to provide the owner of Customer’s account with notice of any new Subprocessors to the extent required under the Agreement, along with posting such updates here.”
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”
?Technical dependency observed: AtlassianObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”
?Technical dependency observed: StripeObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score40
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“We conduct an annual self-assessment of our practices regarding Personal Information intended to verify that the assertions we make about our practices are true and that such practices have been implemented as represented.”
AI system15% of the score40
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“When you use the Services, you may provide us with your audio recordings (“Audio Recordings”), automatic OtterPilot TM screenshots and any text, images or videos that you upload or provide to us in the context of the Services. OtterPilot may take automatic screenshots which are available meeting transcripts to add value to the meetings by extracting useful visual information. The automatic screenshots will only take place in virtual meetings.”
“When you use the Services, you may record and annotate spoken conversations, such as calls or meetings, from which we generate speaker identification information. We use this information to help you recognize speakers in recorded conversations and automatically tag their name within the transcript.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“Provider for evaluating the effectiveness of our Large Language Models (LLM). The provider is used to provide input on whether product feature(s) may contain harmful information. No Customer Data will be used to train or improve OpenAI’s artificial intelligence models. OpenAI does not store Customer Data sent through the API on their platform.”
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
“We will endeavor to provide the owner of Customer’s account with notice of any new Subprocessors to the extent required under the Agreement, along with posting such updates here.”
Model10% of the score40
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
“Provider for evaluating the effectiveness of our Large Language Models (LLM). The provider is used to provide input on whether product feature(s) may contain harmful information. No Customer Data will be used to train or improve OpenAI’s artificial intelligence models. OpenAI does not store Customer Data sent through the API on their platform.”
Customer data15% of the score77
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)”
“Otter.ai stores all Personal Information for as long as necessary to fulfill the purposes set out in this Policy, or for as long as we are required to do so by law or in order to comply with a regulatory obligation. When deleting Personal Information, we will take measures to render such Personal Information irrecoverable or irreproducible, and the electronic files which contain Personal Information will be permanently deleted.”
“Cloud service providers who we rely on for compute and data storage, including Amazon Web Services, based in the United States.”
“Data labeling service providers who provide annotation services and use the data we share to create training and evaluation data for Otter’s product features.”
“When providing our Services as a data processor, we process and retain Personal Information as necessary to provide our Services as permitted in our agreements, or as required or permitted under applicable law.”
Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI supply chain10% of the score75
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
“Provider for evaluating the effectiveness of our Large Language Models (LLM). The provider is used to provide input on whether product feature(s) may contain harmful information. No Customer Data will be used to train or improve OpenAI’s artificial intelligence models. OpenAI does not store Customer Data sent through the API on their platform.”
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
“We will endeavor to provide the owner of Customer’s account with notice of any new Subprocessors to the extent required under the Agreement, along with posting such updates here.”
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”
Security foundation15% of the score0
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“Otter.ai maintains and implements physical, administrative, and technical safeguards to protect the confidentiality, integrity, and availability of personal information. However, the transfer of Personal Information through the internet will carry its own inherent risks and we do not guarantee the security of your data transmitted through the internet.”
Vulnerability & incident handling: not publicly evidenced.
Independent assurance evidence10% of the score55
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“Otter.ai has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with respect to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.”
Read from the registry record above — cited, not reproduced.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the score40
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“Where we have an Otter Business or enterprise service agreement in place with an enterprise customer who is asking you to use our Services (for example your employer), we obtain and process your Personal Information on behalf of and at the instructions of that customer. In that context, such enterprise customers are the data controllers and their privacy policies will apply to the processing of your Personal Information.”
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 52 → up to 73 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 3 — registry checks and verification ladders, click to view
Self-certification to the U.S. Department of Commerce covering personal data received from the EU, UK (and Gibraltar) and Switzerland; not an independent audit. The privacy policy points to dataprivacyframework.gov; the registry was not checked in this scan.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
Checked against Data Privacy Framework (dataprivacyframework.gov), Oct 5, 2026: Verified on the registry
Sources 13 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
Want to go further?
This scan assesses Otter.ai at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.
Scan a specific product →This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
Monitor for changes
Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.
