Security & Trust

What Autopen can read, what it cannot, and what we are still proving.

This page separates what is encrypted from what is not, what our providers see, what we have configured, what is still being validated, and what we do not claim.

!
Current status: the production backend is live. Its operating controls are not approved for regulated workloads. Record and upload content only when you have authority to do so and its sensitivity is appropriate for the safeguards described here.
ConfiguredProvider training controls

AssemblyAI’s account-wide model-improvement opt-out is enabled. OpenAI API data is not used for training by default; response storage and prompt caching are disabled in Autopen’s integration. Zero Data Retention approval from OpenAI remains open.

ImplementedApplication safeguards

Identity boundaries, tenant checks, encrypted client caches, deletion paths, policy, and audit contracts exist in source.

ValidationProduction operations

Managed database, cache, and private encrypted object storage are deployed; backup, restore, deletion, monitoring, key rotation, and real-tenant drills remain required.

Not claimedCertification and regulated use

Autopen is not currently SOC 2 or ISO 27001 certified and does not claim HIPAA, FERPA, or regulated-data eligibility.

What Autopen can and cannot read

This is a protected account. On an account that has not been protected, Autopen can read everything in both columns. Every new account is protected before its first note. Accounts created before protection was required are protected once their owner turns it on, and their older notes stay readable by the service until that sealing completes.

Encrypted records Autopen cannot decrypt without a recovery copy of your key

  • The transcript of a saved meeting
  • The notes of a saved meeting
  • The meeting title
  • Folder names
  • Speaker names you have corrected
Four things to know. Autopen reads your audio and transcript while the meeting is being processed, and it reads your question and the passages you send when you use Ask. Our systems can read a working copy of the transcript until cleanup removes it. If you chose a recovery copy of your key, Autopen can decrypt this account's saved records. Content saved before the account was protected may still sit in an encrypted database backup.

Autopen can read:

  • That a meeting happened, when it started and ended, and which app captured it
  • Which folder a meeting is filed in (the folder id, not its name)
  • The names of your note styles and the instructions you write into them
  • One-off instructions and custom vocabulary you type for a single meeting
  • Your account email and sign-in identity, held by WorkOS
  • Your audio, while it is being transcribed, and your transcript, while the notes are being written
  • When you use Ask, your question, the meeting passages sent with it, and recent turns of that conversation. On a protected account those passages come from your device. Autopen does not keep an Ask conversation as server-side history; the notes provider may hold content in abuse-monitoring logs for up to 30 days
  • A working copy of the transcript, while your notes are being generated. When processing finishes, is cancelled, or permanently fails, we schedule that copy for deletion; it stays readable until cleanup succeeds, and retries, stalled processing or a failed cleanup pass can keep it longer
  • A copy of your key, if you chose to keep a recovery copy
  • Anything written before the account was protected, if it is still in an encrypted database backup that has not aged out
Our transcription and notes providers always receive the meeting in the clear. That is how a transcript and notes get produced.
System boundary

Cloud processing with explicit boundaries.

The service and its approved providers must process customer content to produce transcripts and notes. That means Autopen is not end-to-end encrypted. Zero-access encryption protects what is stored after that, not the processing itself. Audio and the working transcript are processed in our cloud to write your notes and are scheduled for deletion when that processing ends, as described above; the saved notes and transcripts are sealed with your key. Accounts created before protection was on are sealed once the owner turns it on; older notes stay readable by the service until that sealing completes.

Authorized endpoint

Mobile or desktop app

Captures audio, stores sessions in the operating-system vault, and maintains an encrypted local text cache. Desktop audio is encrypted and authenticated before entering the crash-recovery journal.

Autopen service

Identity, orchestration, and workspace

Authorizes access, coordinates processing, enforces tenant and policy boundaries, and synchronizes permitted text artifacts.

Approved subprocessors

Identity, speech, notes, and hosting

Each provider receives only the category needed for its role. Provider credentials remain server-side.

Content boundary: the speech provider sees audio and relevant language or vocabulary context. The notes provider sees transcript text and note-style instructions. WorkOS receives identity and organization information, not meeting audio or note content merely because a user signs in.
Current subprocessors

Who receives what.

Provider scope and retention are reviewed as the Service matures. The list below reflects the currently deployed architecture, not a promise that the stack will never change.

ProviderPurposeInformation receivedCurrent safeguard
WorkOSAuthentication and organization identityIdentity, sign-in, session, domain, membership, role, and directory informationMeeting audio and note content are outside the authentication path
NetlifyPublic website and desktop installer deliveryWeb request information; release files and metadataNo Autopen advertising or analytics cookies. Installer downloads need no account and set no Autopen session cookie.
RailwayAPI, worker, database, cache, and private object-storage infrastructureCustomer and operational information needed to run the ServiceU.S. East deployment; staged audio reaches private storage as Autopen-encrypted AES-256-GCM ciphertext
AssemblyAISpeech-to-text processingAudio plus relevant language or vocabulary contextAccount-wide no-training/no-benchmarking opt-out; one-day asynchronous TTL; immediate transcript deletion request after retrieval
OpenAI APIStructured note generationTranscript text, selected note-style instructions, and necessary contextNo training by default; store=false; prompt caching disabled; default abuse-log retention remains until ZDR or MAM is approved and verified
Azure Key VaultHolds the wrapping key for optional recovery copiesPublic wrapping material and wrapped key capsules. No meeting content.The private wrapping key is never in the Autopen repository or app image.
Sentry (Functional Software, Inc.)Crash and error diagnostics for the Autopen server and the iPhone and Windows appsError type, code location, app version, OS version, and device model. No meeting content, titles, audio, email, account identifiers, or per-install identifiers.United States processing; IP storage disabled in the Sentry projects; 90-day retention
No customer-content training

A product invariant, not a hidden opt-in.

Autopen does not sell meeting content, use it for advertising, or use it to train an Autopen model. The enterprise policy model deliberately has no customer-content training switch.

  • AssemblyAI support confirmed the account-wide opt-out applies prospectively to current and future keys, projects, prerecorded requests, and streaming requests.
  • The confirmed control excludes Customer Data and de-identified Customer Data from model training and benchmarking.
  • Autopen’s server requests provider-transcript deletion after retrieving a completed AssemblyAI result.
  • OpenAI states that API data is not used for model training by default; Autopen additionally disables provider response storage and prompt caching.
  • OpenAI project-level ZDR or MAM approval, DPA evidence, and account data-sharing verification remain required before a stronger retention claim.
  • Operational, security, abuse-prevention, and billing metadata may still be retained under provider terms.
01

Provider policy

AssemblyAI account participation is disabled; OpenAI API data is excluded from training by default unless expressly opted in.

02

Application gate

AssemblyAI confirmation is fail-closed. OpenAI requests are stateless and use neither response storage nor prompt caching.

03

Retention boundary

AssemblyAI receives a one-day ceiling plus earlier deletion requests. Zero Data Retention with our notes provider is not in place; their default abuse-monitoring logs may hold content for up to 30 days.

Data lifecycle

Keep the sensitive part of the system small.

Audio is treated as the highest-sensitivity transient artifact. Transcript, notes, account, organization, and audit data have different purposes and require different retention rules.

DataPurposeDesigned behaviorProduction evidence required
Desktop recovery audioCrash and interruption recoveryAuthenticated encrypted local journal; recovery eligibility capped at seven days and tightened by organization policy; cryptographic erasure after success or discardClean-device crash, recovery, expiry, and erasure drills
Raw audioTranscriptionPrivate object storage, encrypted by Autopen before it is written; deleted after a terminal transcription attempt; incomplete uploads expire. A failed or stalled retry can hold staged audio longer.Bucket policy, lifecycle, provider deletion, orphan alarm, and backup-exclusion proof
TranscriptCore meeting recordOn a protected account, encrypted by Autopen to your account key before storage. Otherwise tenant-scoped durable text. Both plus an encrypted cache on the device.Managed database, restore, expiry, purge, tenant-isolation, and backup-expiry proof
Notes and stylesProfessional synthesis and preferencesNotes are encrypted to your key on a protected account. Style names and style instructions are stored in the clear, by design, so they can be applied server-side.Same storage proof plus note-provider retention and deletion alignment
Your account keyOpening your protected meetingsCreated on your device and kept in the platform credential store. Never sent to Autopen unless you choose a recovery copy.Today a protected account can only be opened on a device that already holds its key. Recovery on a second computer is not available yet, and pairing between devices is not built.
Identity and sessionsAccess and synchronizationWorkOS identity; opaque rotating Autopen sessions in OS vaultsReal IdP, MFA, directory, revocation, and incident-recovery evidence
Admin auditInvestigation and assuranceAppend-only, content-free events and signed SIEM projectionCollector, retry, time-integrity, access, retention, and immutability proof
Application safeguards

Application and infrastructure controls work together.

These controls exist in the application and deployed service contract. They reduce risk, but they do not establish that the deployment operates effectively under every customer load or satisfies an external assurance standard.

Identity

Brokered, verified access

PKCE, state, strict callback allowlisting, one-time native codes, opaque rotating sessions, SSO-required domain enforcement, roles, and active-membership checks.

Tenant isolation

Ownership is checked twice

Tenant-scoped service calls and cross-tenant denial tests are designed to be backed by relational constraints and row-level security.

Endpoint

OS vaults and encrypted recovery

Sessions live in each platform's protected credential vault; text caches and recoverable desktop recording journals are encrypted and removed on the applicable sign-out, wipe, success, discard, or expiry boundary.

Processing

Server-only provider credentials

Native clients do not contain speech or note-provider keys. Uploads are type, size, digest, contiguity, and expiry checked.

Generated output

Grounded and schema constrained

Transcript and style text are treated as untrusted source material; outputs are schema validated and fabricated commitments are quality failures.

Administration

Metadata without a content browser

Role-gated administration covers identity, policy, devices, usage, deletion, and audit without a route for reading another member’s private meeting. On a protected account there is no server-side index over your meeting text, because building one would mean reading it; search runs on your device instead. On an account that is not protected, an account-scoped server search index over your own meeting text is what makes search work, and no administrator route reads it.

Assurance roadmap

What must happen before an enterprise claim.

A source checklist is not a substitute for contracts, operational history, independent testing, or a scoped audit report.

Documented now

  • Architecture and processing boundaries
  • Data inventory and retention design
  • Identity, policy, endpoint, and audit control contract
  • Provider training configuration and deletion behavior
  • Truthful remote-wipe and administrator privacy boundaries
  • Executable production-gate and verification checklists

Still required

  • Reviewed infrastructure-as-code and least-privilege deployment
  • Backup restore, deletion, key rotation, and incident exercises
  • Real-tenant IdP, directory, MDM/MAM, and SIEM validation
  • Per-release binary SBOM and provenance, and ongoing vulnerability operations
  • OpenAI ZDR or accepted MAM decision; provider DPAs, regions, subprocessors, support-access, and breach process
  • Independent penetration test and SOC 2 Type II report when earned
  • Backup purge-on-expiry path for deleted and pre-protection content, and a verified maximum retention period covering every backup
  • Representative current-configuration quality evidence for transcription and notes
Security contact

Start the security review early.

Send security, privacy, architecture, procurement, or responsible-disclosure questions to our current private contact. Do not include customer content, credentials, tokens, exploit code that affects third parties, or other secrets in the first message.