Otter.ai

otter.ai

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
52 / 100D
Procurement decision
Do not approve on current evidence
3 conditions outstanding
  • Vendor discloses an unfavourable answer: Will they train on your data?
  • Otter.ai trains its own AI on user recordings and transcripts and shares data with human annotators
  • Data retention window not stated

See Before you sign, with what to ask for ↓

Evidence MediumFreshness CurrentVerification Partial

Scanned Oct 5, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

Vendor discloses an unfavourable answer: Will they train on your data?Blocking

Why it matters: Otter.ai's privacy policy states that it trains its proprietary AI technology on de-identified audio recordings and on transcriptions, and acknowledges the transcriptions may contain personal information; the legal basis given is consent or legitimate interests.

What to ask for: Resolve this directly with the vendor before proceeding — this is a confirmed disclosure, not a gap to fill in.

Evidence
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Data labeling service providers who provide annotation services and use the data we share to create training and evaluation data for Otter’s product features.”
Otter.ai trains its own AI on user recordings and transcripts and shares data with human annotatorsBlocking

Why it matters: The privacy policy states Otter.ai trains its proprietary AI technology on de-identified audio recordings and on transcriptions that may contain personal information, on a consent or legitimate-interests basis. It also discloses sharing data with data labeling providers to create training and evaluation data, and the subprocessor page names Research Transcriptions as the annotation vendor. The third-party no-training statements apply only to Anthropic and OpenAI, not to Otter.ai's own models. The collected documents do not state whether Otter Business or enterprise customer data is excluded from training or annotation, or how an opt-out is exercised.

What to ask for: Is Customer Data from Otter Business and enterprise accounts excluded from training Otter.ai's proprietary models and from annotation by Research Transcriptions or other labeling providers? If exclusion is opt-in or opt-out, how is it exercised and where is it recorded contractually?

Evidence
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Data labeling service providers who provide annotation services and use the data we share to create training and evaluation data for Otter’s product features.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Where we have an Otter Business or enterprise service agreement in place with an enterprise customer who is asking you to use our Services (for example your employer), we obtain and process your Personal Information on behalf of and at the instructions of that customer.  In that context, such enterprise customers are the data controllers and their privacy policies will apply to the processing of your Personal Information.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai stores all Personal Information for as long as necessary to fulfill the purposes set out in this Policy, or for as long as we are required to do so by law or in order to comply with a regulatory obligation.  When deleting Personal Information, we will take measures to render such Personal Information irrecoverable or irreproducible, and the electronic files which contain Personal Information will be permanently deleted.”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“When providing our Services as a data processor, we process and retain Personal Information as necessary to provide our Services as permitted in our agreements, or as required or permitted under applicable law.”

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

✗Will they train on your data?Concern / gap

Otter.ai's privacy policy states that it trains its proprietary AI technology on de-identified audio recordings and on transcriptions, and acknowledges the transcriptions may contain personal information; the legal basis given is consent or legitimate interests.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Data labeling service providers who provide annotation services and use the data we share to create training and evaluation data for Otter’s product features.”
!How long do they keep your data?Ask the vendor

Retention is criteria-based: personal information is kept for as long as necessary for the policy's purposes or as required by law, with no defined retention windows stated; on deletion Otter.ai commits to rendering the data irrecoverable.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai stores all Personal Information for as long as necessary to fulfill the purposes set out in this Policy, or for as long as we are required to do so by law or in order to comply with a regulatory obligation.  When deleting Personal Information, we will take measures to render such Personal Information irrecoverable or irreproducible, and the electronic files which contain Personal Information will be permanently deleted.”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“When providing our Services as a data processor, we process and retain Personal Information as necessary to provide our Services as permitted in our agreements, or as required or permitted under applicable law.”
!Who else can access your data?Ask the vendor

Otter.ai publishes a dated subprocessor page (effective 31 March 2026) listing each third party's entity name, country and subprocessing role, split into core infrastructure and other subprocessors.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for evaluating the effectiveness of our Large Language Models (LLM). The provider is used to provide input on whether product feature(s) may contain harmful information. No Customer Data will be used to train or improve OpenAI’s artificial intelligence models. OpenAI does not store Customer Data sent through the API on their platform.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
Externally corroboratedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”
!Where is your data processed?Ask the vendor

Compute and data storage rely on Amazon Web Services in the United States; data may be processed outside the user's country, with Standard Contractual Clauses cited as the safeguard for transfers out of the EEA or UK.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Cloud service providers who we rely on for compute and data storage, including Amazon Web Services, based in the United States.”
!What happens in a security incident?Ask the vendor

Otter.ai states it maintains physical, administrative and technical safeguards for personal information but disclaims the security of data in transit; the collected documents say nothing about security incident response, breach notification timelines or vulnerability disclosure.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai maintains and implements physical, administrative, and technical safeguards to protect the confidentiality, integrity, and availability of personal information.  However, the transfer of Personal Information through the internet will carry its own inherent risks and we do not guarantee the security of your data transmitted through the internet.”

Email to send the vendor9 items to confirm in writing

Subject: Supplier assessment: written confirmation requested
Hello Otter.ai team,

We are assessing Otter.ai as part of our supplier review. Before we proceed, please confirm the following in writing:

1. Do you use our data (inputs, outputs or uploaded files) to train or improve your models? Please confirm in writing, including any opt-out and whether it applies to every plan.
2. What is your commitment to notify customers of a security incident affecting our data, including the timeframe?
3. How long do you retain our data, in days, for each type (inputs, outputs, logs and backups), and how is it deleted?
4. Please provide your current, dated subprocessor list and explain how you notify customers of changes.
5. In which countries and regions is our data processed and stored, and can processing be limited to a region we choose?
6. Which model providers and model families process meeting audio, transcripts and screenshots for each AI feature, on which cloud provider does inference run, and how are customers notified and able to evaluate changes to models or AI features?
7. Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
8. Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
9. Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

A written reply to each point, or a link to where it is documented, is enough. Where a point is covered by a certification or independent report, please include the certificate number or the report and its date.

Thank you,
Audit evidence: a verified report maps its findings to ISO/IEC 27001 supplier controls, ISO/IEC 42001 third-party controls and APRA CPS 230. See verified reports →

Key findingsclick a row for the evidence

✓Published, dated subprocessor register names AI and infrastructure providersStrong

Otter.ai maintains a subprocessor page (effective 31 March 2026) listing entity, country and role for 17 third parties, including its AI providers. Anthropic is named as the backend for AI-enabled functionality and OpenAI for LLM evaluation and harmful-content checks, each with an explicit statement that Customer Data is not used to train the provider's models and is not stored via the API. Three cloud providers (AWS, Google Cloud Platform, Crusoe) are named, and Otter.ai commits to notify account owners of new subprocessors where the Agreement requires.

A buyer can see who sits in the data path for AI features and hold the vendor to specific no-training and no-storage statements about those providers, rather than relying on a generic 'we use AI service providers' disclosure.

Evidence
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for evaluating the effectiveness of our Large Language Models (LLM). The provider is used to provide input on whether product feature(s) may contain harmful information. No Customer Data will be used to train or improve OpenAI’s artificial intelligence models. OpenAI does not store Customer Data sent through the API on their platform.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“We will endeavor to provide the owner of Customer’s account with notice of any new Subprocessors to the extent required under the Agreement, along with posting such updates here.”
Externally corroboratedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”
✗Otter.ai trains its own AI on user recordings and transcripts and shares data with human annotatorsGap

The privacy policy states Otter.ai trains its proprietary AI technology on de-identified audio recordings and on transcriptions that may contain personal information, on a consent or legitimate-interests basis. It also discloses sharing data with data labeling providers to create training and evaluation data, and the subprocessor page names Research Transcriptions as the annotation vendor. The third-party no-training statements apply only to Anthropic and OpenAI, not to Otter.ai's own models. The collected documents do not state whether Otter Business or enterprise customer data is excluded from training or annotation, or how an opt-out is exercised.

Meeting recordings are among the most sensitive data a workplace tool handles. Training and human annotation on that content, even de-identified, is a material disclosure for any buyer and needs to be settled contractually for enterprise plans.

Question for vendor: Is Customer Data from Otter Business and enterprise accounts excluded from training Otter.ai's proprietary models and from annotation by Research Transcriptions or other labeling providers? If exclusion is opt-in or opt-out, how is it exercised and where is it recorded contractually?

Evidence
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Data labeling service providers who provide annotation services and use the data we share to create training and evaluation data for Otter’s product features.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Where we have an Otter Business or enterprise service agreement in place with an enterprise customer who is asking you to use our Services (for example your employer), we obtain and process your Personal Information on behalf of and at the instructions of that customer.  In that context, such enterprise customers are the data controllers and their privacy policies will apply to the processing of your Personal Information.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
!No incident response, breach notification or security assurance disclosure in the collected materialGap

Only three documents were collected (subprocessor page, privacy policy, blog index), so this assessment is narrow. Within them, security is covered by a one-paragraph safeguards statement that disclaims transit security, with nothing on incident response, breach notification timelines or vulnerability disclosure. No SOC 2, ISO/IEC 27001 or ISO/IEC 42001 report is named. Retention is criteria-based with no defined windows for recordings or transcripts. vulnerability_and_incident_handling is marked not_evidenced rather than not_applicable: a hosted SaaS meeting-notes vendor can and ordinarily does publish these commitments, so their absence here is a gap to close, not a domain that does not arise.

A buyer cannot assess breach-notification obligations, deletion timelines or audited security controls from the public material collected; a trust centre or DPA may exist but was not in scope of this scan.

Question for vendor: Please provide your security incident and breach notification commitments (including notification timelines to customers), your current SOC 2 Type II or ISO/IEC 27001 report, and defined retention and deletion windows for recordings, transcripts and derived data after account or workspace deletion.

Evidence
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai maintains and implements physical, administrative, and technical safeguards to protect the confidentiality, integrity, and availability of personal information.  However, the transfer of Personal Information through the internet will carry its own inherent risks and we do not guarantee the security of your data transmitted through the internet.”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai stores all Personal Information for as long as necessary to fulfill the purposes set out in this Policy, or for as long as we are required to do so by law or in order to comply with a regulatory obligation.  When deleting Personal Information, we will take measures to render such Personal Information irrecoverable or irreproducible, and the electronic files which contain Personal Information will be permanently deleted.”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“When providing our Services as a data processor, we process and retain Personal Information as necessary to provide our Services as permitted in our agreements, or as required or permitted under applicable law.”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with respect to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.”
!Data Privacy Framework participation is a self-certification, not an independent auditGap

The only assurance mechanism named is Otter.ai's self-certification to the U.S. Department of Commerce under the EU-U.S. DPF, UK Extension and Swiss-U.S. DPF, backed by an annual self-assessment and FTC enforceability. It is scoped to personal data received from the EU, UK and Switzerland and is not a third-party audit of security or AI controls. The registry record at dataprivacyframework.gov was not checked in this scan.

DPF supports lawful transfer for European data but says nothing about audited security or AI governance; buyers outside Europe gain little from it and should not read it as a security certification.

Evidence
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with respect to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“We conduct an annual self-assessment of our practices regarding Personal Information intended to verify that the assertions we make about our practices are true and that such practices have been implemented as represented.”
!Which models run where is not disclosedGap

The documents describe inputs (audio, OtterPilot screenshots, speaker identification) and name Anthropic as the AI backend and OpenAI as an evaluation provider, but do not name model families or versions, say whether Otter.ai's proprietary models run on AWS, Google Cloud Platform or Crusoe, or describe how model or feature changes are evaluated and communicated. The only change-notice commitment is for new subprocessors. This is why ai_system_description, model_provider_transparency, testing_and_evaluation and change_management are marked partial.

Without knowing which models process meeting content and where inference runs, a buyer cannot complete a data-flow assessment or judge the impact of a provider or model swap.

Question for vendor: Which model providers and model families process meeting audio, transcripts and screenshots for each AI feature, on which cloud provider does inference run, and how are customers notified and able to evaluate changes to models or AI features?

Evidence
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for evaluating the effectiveness of our Large Language Models (LLM). The provider is used to provide input on whether product feature(s) may contain harmful information. No Customer Data will be used to train or improve OpenAI’s artificial intelligence models. OpenAI does not store Customer Data sent through the API on their platform.”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“When you use the Services, you may provide us with your audio recordings (“Audio Recordings”), automatic OtterPilot TM screenshots and any text, images or videos that you upload or provide to us in the context of the Services.  OtterPilot may take automatic screenshots which are available meeting transcripts to add value to the meetings by extracting useful visual information.  The automatic screenshots will only take place in virtual meetings.”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“When you use the Services, you may record and annotate spoken conversations, such as calls or meetings, from which we generate speaker identification information. We use this information to help you recognize speakers in recorded conversations and automatically tag their name within the transcript.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“We will endeavor to provide the owner of Customer’s account with notice of any new Subprocessors to the extent required under the Agreement, along with posting such updates here.”
Externally corroboratedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
Externally corroboratedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”
?Technical dependency observed: AtlassianObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Atlassian as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Atlassian appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
Externally corroboratedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
Externally corroboratedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score40
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“We conduct an annual self-assessment of our practices regarding Personal Information intended to verify that the assertions we make about our practices are true and that such practices have been implemented as represented.”
AI system15% of the score40
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“When you use the Services, you may provide us with your audio recordings (“Audio Recordings”), automatic OtterPilot TM screenshots and any text, images or videos that you upload or provide to us in the context of the Services.  OtterPilot may take automatic screenshots which are available meeting transcripts to add value to the meetings by extracting useful visual information.  The automatic screenshots will only take place in virtual meetings.”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“When you use the Services, you may record and annotate spoken conversations, such as calls or meetings, from which we generate speaker identification information. We use this information to help you recognize speakers in recorded conversations and automatically tag their name within the transcript.”
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for evaluating the effectiveness of our Large Language Models (LLM). The provider is used to provide input on whether product feature(s) may contain harmful information. No Customer Data will be used to train or improve OpenAI’s artificial intelligence models. OpenAI does not store Customer Data sent through the API on their platform.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Partial
Evidence — Change management
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“We will endeavor to provide the owner of Customer’s account with notice of any new Subprocessors to the extent required under the Agreement, along with posting such updates here.”
Model10% of the score40
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for evaluating the effectiveness of our Large Language Models (LLM). The provider is used to provide input on whether product feature(s) may contain harmful information. No Customer Data will be used to train or improve OpenAI’s artificial intelligence models. OpenAI does not store Customer Data sent through the API on their platform.”
Customer data15% of the score77
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai stores all Personal Information for as long as necessary to fulfill the purposes set out in this Policy, or for as long as we are required to do so by law or in order to comply with a regulatory obligation.  When deleting Personal Information, we will take measures to render such Personal Information irrecoverable or irreproducible, and the electronic files which contain Personal Information will be permanently deleted.”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Cloud service providers who we rely on for compute and data storage, including Amazon Web Services, based in the United States.”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Data labeling service providers who provide annotation services and use the data we share to create training and evaluation data for Otter’s product features.”
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“When providing our Services as a data processor, we process and retain Personal Information as necessary to provide our Services as permitted in our agreements, or as required or permitted under applicable law.”

Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI supply chain10% of the score75
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Covered
Evidence — Subprocessors & supply chain
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for backend support of AI-enabled functionality. No Customer Data will be used to train or improve Anthropic’s artificial intelligence models. Anthropic does not store Customer Data sent through the API on their platform.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Provider for evaluating the effectiveness of our Large Language Models (LLM). The provider is used to provide input on whether product feature(s) may contain harmful information. No Customer Data will be used to train or improve OpenAI’s artificial intelligence models. OpenAI does not store Customer Data sent through the API on their platform.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Research Transcriptions Provider for annotating training and evaluation data for our product features. United States”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“We will endeavor to provide the owner of Customer’s account with notice of any new Subprocessors to the extent required under the Agreement, along with posting such updates here.”
Externally corroboratedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Google Cloud Platform Cloud service provider United States Crusoe Cloud service provider United States”
Security foundation15% of the score0
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Not Evidenced
Evidence — Vulnerability & incident handling
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai maintains and implements physical, administrative, and technical safeguards to protect the confidentiality, integrity, and availability of personal information.  However, the transfer of Personal Information through the internet will carry its own inherent risks and we do not guarantee the security of your data transmitted through the internet.”

Vulnerability & incident handling: not publicly evidenced.

Independent assurance evidence10% of the score55
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with respect to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.”

Read from the registry record above — cited, not reproduced.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the score40
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedOtter.ai Privacy Policy | Otter.ai ↗retrieved Oct 5, 2026
“Where we have an Otter Business or enterprise service agreement in place with an enterprise customer who is asking you to use our Services (for example your employer), we obtain and process your Personal Information on behalf of and at the instructions of that customer.  In that context, such enterprise customers are the data controllers and their privacy policies will apply to the processing of your Personal Information.”
Vendor publishedSubprocessors | Otter.ai ↗retrieved Oct 5, 2026
“Otter.ai engages the third-party entities in the table below to perform limited activities in connection with the Services provided. This page provides important information about the entity name, location and role of each subprocessor.”

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+4Complete the Governance & accountability disclosureOrganisation 40 → 60
+4Verify EU-U.S. Data Privacy Framework scope covers this assessmentIndependent Assurance 55 → 78
+3Have Customer data treatment disclosures independently corroboratedData 77 → 92
+3Complete the Legal & contractual transparency disclosureLegal Contractual 40 → 60
+3Complete the Model provider transparency disclosureModel 40 → 60

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 52 → up to 73 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSINFRASTRUCTURESUBPROCESSORSOtter.ai, Inc.Otter.ai, Inc.Otter meeting assistant appOtter meeting assistant a…Otter BusinessOtter BusinessOtterPilotOtterPilotAnthropicAnthropicOpenAIOpenAIAmazon Web Services, Inc.Amazon Web Services, Inc.Google Cloud PlatformGoogle Cloud PlatformCrusoeCrusoeResearch TranscriptionsResearch TranscriptionsZendeskZendeskOneSignalOneSignalStripeStripeZuoraZuoraSlackSlackIntercomIntercomWorkatoWorkatoCrescendo (formerly PartnerHero)Crescendo (formerly Partn…WorkOSWorkOSPlanHatPlanHatOn24On24
View as list
Otter.ai, Inc. Uses AI Service Anthropic
Otter.ai, Inc. Uses AI Service OpenAI
Otter.ai, Inc. Uses Infrastructure Amazon Web Services, Inc.
Otter.ai, Inc. Uses Infrastructure Google Cloud Platform
Otter.ai, Inc. Uses Infrastructure Crusoe
Otter.ai, Inc. Contracted Subprocessor Research Transcriptions
Otter.ai, Inc. Contracted Subprocessor Zendesk
Otter.ai, Inc. Contracted Subprocessor OneSignal
Otter.ai, Inc. Contracted Subprocessor Stripe
Otter.ai, Inc. Contracted Subprocessor Zuora
Otter.ai, Inc. Contracted Subprocessor Slack
Otter.ai, Inc. Contracted Subprocessor Intercom
Otter.ai, Inc. Contracted Subprocessor Workato
Otter.ai, Inc. Contracted Subprocessor Crescendo (formerly PartnerHero)
Otter.ai, Inc. Contracted Subprocessor WorkOS
Otter.ai, Inc. Contracted Subprocessor PlanHat
Otter.ai, Inc. Contracted Subprocessor On24

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 3 — registry checks and verification ladders, click to view
EU-U.S. Data Privacy Framework (with UK Extension and Swiss-U.S. DPF)Vendor claimed only

Self-certification to the U.S. Department of Commerce covering personal data received from the EU, UK (and Gibraltar) and Switzerland; not an independent audit. The privacy policy points to dataprivacyframework.gov; the registry was not checked in this scan.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 42001Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

EU-U.S. Data Privacy FrameworkClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Oct 5, 2026: Verified on the registry

Sources 13 — click to view
Otter Voice Meeting Notes - Otter.ai
AI Documentation · Vendor · retrieved Oct 5, 2026
Otter Voice Meeting Notes - Otter.ai
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Otter Voice Meeting Notes - Otter.ai
DPA · Vendor · retrieved Oct 5, 2026
Subprocessors | Otter.ai
Subprocessor List · Vendor · retrieved Oct 5, 2026
Otter.ai Privacy Policy | Otter.ai
Privacy Notice · Vendor · retrieved Oct 5, 2026
Otter Voice Meeting Notes - Otter.ai
Certification Or Compliance Page · Vendor · retrieved Oct 5, 2026
Otter Voice Meeting Notes - Otter.ai
Terms · Vendor · retrieved Oct 5, 2026
Otter Voice Meeting Notes - Otter.ai
Changelog Or Release Notes · Vendor · retrieved Oct 5, 2026
Blog | Otter.ai
Technical Article · Vendor · retrieved Oct 5, 2026
Otter Voice Meeting Notes - Otter.ai
AI Documentation · Vendor · retrieved Oct 5, 2026
Otter Voice Meeting Notes - Otter.ai
Trust Or Security Page · Vendor · retrieved Oct 5, 2026
Otter Voice Meeting Notes - Otter.ai
DPA · Vendor · retrieved Oct 5, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Oct 5, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Otter.ai at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.

Monitor for changes

Get an email if its TRUSTYCYBER Score, grade or certifications change. One credit per refresh; reading the report always stays free.