AssemblyAI’s account-wide model-improvement opt-out is enabled. OpenAI API data is not used for training by default; response storage and prompt caching are disabled in Autopen’s integration. Zero Data Retention approval from OpenAI remains open.
What Autopen can read, what it cannot, and what we are still proving.
This page separates what is encrypted from what is not, what our providers see, what we have configured, what is still being validated, and what we do not claim.
Identity boundaries, tenant checks, encrypted client caches, deletion paths, policy, and audit contracts exist in source.
Managed database, cache, and private encrypted object storage are deployed; backup, restore, deletion, monitoring, key rotation, and real-tenant drills remain required.
Autopen is not currently SOC 2 or ISO 27001 certified and does not claim HIPAA, FERPA, or regulated-data eligibility.
What Autopen can and cannot read
This is a protected account. On an account that has not been protected, Autopen can read everything in both columns. Every new account is protected before its first note. Accounts created before protection was required are protected once their owner turns it on, and their older notes stay readable by the service until that sealing completes.
Encrypted records Autopen cannot decrypt without a recovery copy of your key
- The transcript of a saved meeting
- The notes of a saved meeting
- The meeting title
- Folder names
- Speaker names you have corrected
Autopen can read:
- That a meeting happened, when it started and ended, and which app captured it
- Which folder a meeting is filed in (the folder id, not its name)
- The names of your note styles and the instructions you write into them
- One-off instructions and custom vocabulary you type for a single meeting
- Your account email and sign-in identity, held by WorkOS
- Your audio, while it is being transcribed, and your transcript, while the notes are being written
- When you use Ask, your question, the meeting passages sent with it, and recent turns of that conversation. On a protected account those passages come from your device. Autopen does not keep an Ask conversation as server-side history; the notes provider may hold content in abuse-monitoring logs for up to 30 days
- A working copy of the transcript, while your notes are being generated. When processing finishes, is cancelled, or permanently fails, we schedule that copy for deletion; it stays readable until cleanup succeeds, and retries, stalled processing or a failed cleanup pass can keep it longer
- A copy of your key, if you chose to keep a recovery copy
- Anything written before the account was protected, if it is still in an encrypted database backup that has not aged out
Cloud processing with explicit boundaries.
The service and its approved providers must process customer content to produce transcripts and notes. That means Autopen is not end-to-end encrypted. Zero-access encryption protects what is stored after that, not the processing itself. Audio and the working transcript are processed in our cloud to write your notes and are scheduled for deletion when that processing ends, as described above; the saved notes and transcripts are sealed with your key. Accounts created before protection was on are sealed once the owner turns it on; older notes stay readable by the service until that sealing completes.
Mobile or desktop app
Captures audio, stores sessions in the operating-system vault, and maintains an encrypted local text cache. Desktop audio is encrypted and authenticated before entering the crash-recovery journal.
Identity, orchestration, and workspace
Authorizes access, coordinates processing, enforces tenant and policy boundaries, and synchronizes permitted text artifacts.
Identity, speech, notes, and hosting
Each provider receives only the category needed for its role. Provider credentials remain server-side.
Who receives what.
Provider scope and retention are reviewed as the Service matures. The list below reflects the currently deployed architecture, not a promise that the stack will never change.
| Provider | Purpose | Information received | Current safeguard |
|---|---|---|---|
| WorkOS | Authentication and organization identity | Identity, sign-in, session, domain, membership, role, and directory information | Meeting audio and note content are outside the authentication path |
| Netlify | Public website and desktop installer delivery | Web request information; release files and metadata | No Autopen advertising or analytics cookies. Installer downloads need no account and set no Autopen session cookie. |
| Railway | API, worker, database, cache, and private object-storage infrastructure | Customer and operational information needed to run the Service | U.S. East deployment; staged audio reaches private storage as Autopen-encrypted AES-256-GCM ciphertext |
| AssemblyAI | Speech-to-text processing | Audio plus relevant language or vocabulary context | Account-wide no-training/no-benchmarking opt-out; one-day asynchronous TTL; immediate transcript deletion request after retrieval |
| OpenAI API | Structured note generation | Transcript text, selected note-style instructions, and necessary context | No training by default; store=false; prompt caching disabled; default abuse-log retention remains until ZDR or MAM is approved and verified |
| Azure Key Vault | Holds the wrapping key for optional recovery copies | Public wrapping material and wrapped key capsules. No meeting content. | The private wrapping key is never in the Autopen repository or app image. |
| Sentry (Functional Software, Inc.) | Crash and error diagnostics for the Autopen server and the iPhone and Windows apps | Error type, code location, app version, OS version, and device model. No meeting content, titles, audio, email, account identifiers, or per-install identifiers. | United States processing; IP storage disabled in the Sentry projects; 90-day retention |
A product invariant, not a hidden opt-in.
Autopen does not sell meeting content, use it for advertising, or use it to train an Autopen model. The enterprise policy model deliberately has no customer-content training switch.
- AssemblyAI support confirmed the account-wide opt-out applies prospectively to current and future keys, projects, prerecorded requests, and streaming requests.
- The confirmed control excludes Customer Data and de-identified Customer Data from model training and benchmarking.
- Autopen’s server requests provider-transcript deletion after retrieving a completed AssemblyAI result.
- OpenAI states that API data is not used for model training by default; Autopen additionally disables provider response storage and prompt caching.
- OpenAI project-level ZDR or MAM approval, DPA evidence, and account data-sharing verification remain required before a stronger retention claim.
- Operational, security, abuse-prevention, and billing metadata may still be retained under provider terms.
Provider policy
AssemblyAI account participation is disabled; OpenAI API data is excluded from training by default unless expressly opted in.
Application gate
AssemblyAI confirmation is fail-closed. OpenAI requests are stateless and use neither response storage nor prompt caching.
Retention boundary
AssemblyAI receives a one-day ceiling plus earlier deletion requests. Zero Data Retention with our notes provider is not in place; their default abuse-monitoring logs may hold content for up to 30 days.
Keep the sensitive part of the system small.
Audio is treated as the highest-sensitivity transient artifact. Transcript, notes, account, organization, and audit data have different purposes and require different retention rules.
| Data | Purpose | Designed behavior | Production evidence required |
|---|---|---|---|
| Desktop recovery audio | Crash and interruption recovery | Authenticated encrypted local journal; recovery eligibility capped at seven days and tightened by organization policy; cryptographic erasure after success or discard | Clean-device crash, recovery, expiry, and erasure drills |
| Raw audio | Transcription | Private object storage, encrypted by Autopen before it is written; deleted after a terminal transcription attempt; incomplete uploads expire. A failed or stalled retry can hold staged audio longer. | Bucket policy, lifecycle, provider deletion, orphan alarm, and backup-exclusion proof |
| Transcript | Core meeting record | On a protected account, encrypted by Autopen to your account key before storage. Otherwise tenant-scoped durable text. Both plus an encrypted cache on the device. | Managed database, restore, expiry, purge, tenant-isolation, and backup-expiry proof |
| Notes and styles | Professional synthesis and preferences | Notes are encrypted to your key on a protected account. Style names and style instructions are stored in the clear, by design, so they can be applied server-side. | Same storage proof plus note-provider retention and deletion alignment |
| Your account key | Opening your protected meetings | Created on your device and kept in the platform credential store. Never sent to Autopen unless you choose a recovery copy. | Today a protected account can only be opened on a device that already holds its key. Recovery on a second computer is not available yet, and pairing between devices is not built. |
| Identity and sessions | Access and synchronization | WorkOS identity; opaque rotating Autopen sessions in OS vaults | Real IdP, MFA, directory, revocation, and incident-recovery evidence |
| Admin audit | Investigation and assurance | Append-only, content-free events and signed SIEM projection | Collector, retry, time-integrity, access, retention, and immutability proof |
Application and infrastructure controls work together.
These controls exist in the application and deployed service contract. They reduce risk, but they do not establish that the deployment operates effectively under every customer load or satisfies an external assurance standard.
Brokered, verified access
PKCE, state, strict callback allowlisting, one-time native codes, opaque rotating sessions, SSO-required domain enforcement, roles, and active-membership checks.
Ownership is checked twice
Tenant-scoped service calls and cross-tenant denial tests are designed to be backed by relational constraints and row-level security.
OS vaults and encrypted recovery
Sessions live in each platform's protected credential vault; text caches and recoverable desktop recording journals are encrypted and removed on the applicable sign-out, wipe, success, discard, or expiry boundary.
Server-only provider credentials
Native clients do not contain speech or note-provider keys. Uploads are type, size, digest, contiguity, and expiry checked.
Grounded and schema constrained
Transcript and style text are treated as untrusted source material; outputs are schema validated and fabricated commitments are quality failures.
Metadata without a content browser
Role-gated administration covers identity, policy, devices, usage, deletion, and audit without a route for reading another member’s private meeting. On a protected account there is no server-side index over your meeting text, because building one would mean reading it; search runs on your device instead. On an account that is not protected, an account-scoped server search index over your own meeting text is what makes search work, and no administrator route reads it.
What must happen before an enterprise claim.
A source checklist is not a substitute for contracts, operational history, independent testing, or a scoped audit report.
Documented now
- Architecture and processing boundaries
- Data inventory and retention design
- Identity, policy, endpoint, and audit control contract
- Provider training configuration and deletion behavior
- Truthful remote-wipe and administrator privacy boundaries
- Executable production-gate and verification checklists
Still required
- Reviewed infrastructure-as-code and least-privilege deployment
- Backup restore, deletion, key rotation, and incident exercises
- Real-tenant IdP, directory, MDM/MAM, and SIEM validation
- Per-release binary SBOM and provenance, and ongoing vulnerability operations
- OpenAI ZDR or accepted MAM decision; provider DPAs, regions, subprocessors, support-access, and breach process
- Independent penetration test and SOC 2 Type II report when earned
- Backup purge-on-expiry path for deleted and pre-protection content, and a verified maximum retention period covering every backup
- Representative current-configuration quality evidence for transcription and notes
Start the security review early.
Send security, privacy, architecture, procurement, or responsible-disclosure questions to our current private contact. Do not include customer content, credentials, tokens, exploit code that affects third parties, or other secrets in the first message.