AssemblyAI’s account-wide model-improvement opt-out is enabled. OpenAI API data is not used for training by default; response storage and prompt caching are disabled in Autopen’s integration. OpenAI ZDR approval remains a launch gate.
Security claims should be verifiable.
This page separates Autopen’s application control design, configured provider safeguards, validation still in progress, and certifications we do not yet claim.
Identity boundaries, tenant checks, encrypted client caches, deletion paths, policy, and audit contracts exist in source.
Managed database, cache, and private encrypted object storage are deployed; backup, restore, deletion, monitoring, key rotation, and real-tenant drills remain required.
Autopen is not currently SOC 2 or ISO 27001 certified and does not claim HIPAA, FERPA, or regulated-data eligibility.
Cloud processing, described without euphemism.
The service and its approved providers must process customer content to produce transcripts and notes. That means Autopen is not end-to-end encrypted.
Mobile or desktop app
Captures audio, stores sessions in the operating-system vault, and maintains an encrypted local text cache.
Identity, orchestration, and workspace
Authorizes access, coordinates processing, enforces tenant and policy boundaries, and synchronizes permitted text artifacts.
Identity, speech, notes, and hosting
Each provider receives only the category needed for its role. Provider credentials remain server-side.
Who receives what.
Provider scope and retention are reviewed as the Service matures. The list below reflects the currently deployed architecture, not a promise that the stack will never change.
| Provider | Purpose | Information received | Current safeguard |
|---|---|---|---|
| WorkOS | Authentication and organization identity | Identity, sign-in, session, domain, membership, role, and directory information | Meeting audio and note content are outside the authentication path |
| Railway | API, worker, database, cache, and private object-storage infrastructure | Customer and operational information needed to run the Service | U.S. East deployment; staged audio reaches private storage as Autopen-encrypted AES-256-GCM ciphertext |
| AssemblyAI | Speech-to-text processing | Audio plus relevant language or vocabulary context | Account-wide no-training/no-benchmarking opt-out; one-day asynchronous TTL; immediate transcript deletion request after retrieval |
| OpenAI API | Structured note generation | Transcript text, selected note-style instructions, and necessary context | No training by default; store=false; prompt caching disabled; default abuse-log retention remains until ZDR or MAM is approved and verified |
A product invariant, not a hidden opt-in.
Autopen does not sell meeting content, use it for advertising, or use it to train an Autopen model. The enterprise policy model deliberately has no customer-content training switch.
- AssemblyAI support confirmed the account-wide opt-out applies prospectively to current and future keys, projects, prerecorded requests, and streaming requests.
- The confirmed control excludes Customer Data and de-identified Customer Data from model training and benchmarking.
- Autopen’s server requests provider-transcript deletion after retrieving a completed AssemblyAI result.
- OpenAI states that API data is not used for model training by default; Autopen additionally disables Responses storage and GPT-5.6 prompt caching.
- OpenAI project-level ZDR or MAM approval, DPA evidence, and account data-sharing verification remain required before a stronger retention claim.
- Operational, security, abuse-prevention, and billing metadata may still be retained under provider terms.
Provider policy
AssemblyAI account participation is disabled; OpenAI API data is excluded from training by default unless expressly opted in.
Application gate
AssemblyAI confirmation is fail-closed. OpenAI requests are stateless and use neither response storage nor prompt caching.
Retention boundary
AssemblyAI receives a one-day ceiling plus earlier deletion requests. OpenAI ZDR or MAM remains pending; the public policy discloses the default abuse-log boundary.
Minimize the sensitive part of the system.
Audio is treated as the highest-sensitivity transient artifact. Transcript, notes, account, organization, and audit data have different purposes and require different retention rules.
| Data | Purpose | Designed behavior | Production evidence required |
|---|---|---|---|
| Raw audio | Transcription | Private staged object; deletion after terminal processing; incomplete-upload expiry | Bucket policy, lifecycle, provider deletion, orphan alarm, and backup-exclusion proof |
| Transcript | Core meeting record | Tenant-scoped durable text plus encrypted endpoint cache | Managed database, restore, expiry, purge, tenant-isolation, and backup-expiry proof |
| Notes and styles | Professional synthesis and preferences | Tenant-scoped text with provider and model provenance | Same storage proof plus note-provider retention and deletion alignment |
| Identity and sessions | Access and synchronization | WorkOS identity; opaque rotating Autopen sessions in OS vaults | Real IdP, MFA, directory, revocation, and incident-recovery evidence |
| Admin audit | Investigation and assurance | Append-only, content-free events and signed SIEM projection | Collector, retry, time-integrity, access, retention, and immutability proof |
Defense in depth starts before infrastructure.
These controls exist in the application and deployed service contract. They reduce risk, but they do not establish that the deployment operates effectively under every customer load or satisfies an external assurance standard.
Brokered, verified access
PKCE, state, strict callback allowlisting, one-time native codes, opaque rotating sessions, SSO-required domain enforcement, roles, and active-membership checks.
Ownership is checked twice
Tenant-scoped service calls and cross-tenant denial tests are designed to be backed by relational constraints and row-level security.
OS vaults and encrypted caches
Sessions live in each platform's protected credential vault; text caches are encrypted and removed on account-bound sign-out or acknowledged wipe.
Server-only provider credentials
Native clients do not contain speech or note-provider keys. Uploads are type, size, digest, contiguity, and expiry checked.
Grounded and schema constrained
Transcript and style text are treated as untrusted source material; outputs are schema validated and fabricated commitments are quality failures.
Metadata without a content browser
Role-gated administration covers identity, policy, devices, usage, deletion, and audit without a route for reading another member’s private meeting.
What must happen before an enterprise claim.
A source checklist is not a substitute for contracts, operational history, independent testing, or a scoped audit report.
Documented now
- Architecture and processing boundaries
- Data inventory and retention design
- Identity, policy, endpoint, and audit control contract
- Provider training configuration and deletion behavior
- Truthful remote-wipe and administrator privacy boundaries
- Executable production-gate and verification checklists
Still required
- Reviewed infrastructure-as-code and least-privilege deployment
- Backup restore, deletion, key rotation, and incident exercises
- Real-tenant IdP, directory, MDM/MAM, and SIEM validation
- Dependency scanning, signed artifacts, SBOM, and vulnerability program
- OpenAI ZDR or accepted MAM decision; provider DPAs, regions, subprocessors, support-access, and breach process
- Independent penetration test and SOC 2 Type II report when earned
Ask the hard questions early.
Send security, privacy, architecture, procurement, or responsible-disclosure questions to our current private contact. Do not include customer content, credentials, tokens, exploit code that affects third parties, or other secrets in the first message.