Your recordings are business records: customer conversations, research data, meetings you can’t repeat. Speak AI treats them that way. Data is encrypted in transit and at rest , access is controlled at the team level, and deletion is yours to control: files you delete enter a 7-day recovery window, then are permanently removed .
Speak AI has served research teams, healthcare organizations, and enterprises since 2018; 250,000+ people and teams use it, rated 4.9 on G2.
The questions security reviews ask
Where does my data live, and who can see it? Your workspace’s data is isolated to your account; inside it, groups and permissions control which teammates see which folders.
Is my data used to train AI models? See the third-party data privacy policy for the contractual position on sub-processors and data use.
Can I redact sensitive content? Exports can redact names, emails, locations, brands, and dates. (Language coverage documented after middleware verification.)
What happens when I delete data? Data deletion: 7-day soft delete, then permanent removal.
The policy library
All 41 security, privacy, and governance policies, published in full for security reviews and procurement. Each one is its own page, so you can send a reviewer a direct link rather than a PDF.
Security program
How the programme is run, and how issues are found and closed.
- Information security program policy
- Acceptable use policy
- Asset management policy
- Change management policy
- Log management policy
- Vulnerability management policy
- Incident reporting and response policy
Access and identity
Who gets in, with what, and from where.
Data and privacy
How data is classified, protected in transit and at rest, and retired.
- Data classification policy
- Information classification policy
- Encryption policy
- Encrypted communications policy
- Records retention policy
Network and infrastructure
The systems the service runs on and how they are hardened.
- Network security policy
- Network segmentation policy
- Network device hardening standards
- DMZ security policy
- Wireless security policy
- Cloud hosting compliance policy
- Internet of Things security policy
- Collaborative computing policy
Continuity and recovery
What happens when something fails.
- Business continuity plan
- Disaster recovery plan
- Service continuity policy
- Offsite backup storage policy
- Pandemic and infectious disease plan
People and premises
Staff, and the places the work happens.
Suppliers and third parties
Anyone Speak AI depends on, and what they are held to.
Governance and ethics
Conduct, compliance and the commitments the company makes.
- Internal compliance and ethics program
- Anti-bribery and anti-corruption policy
- Anti-competitive practices policy
- Sanctions compliance policy
- Fraud detection and prevention policy
- Modern slavery policy
- ESG policy
Running a security review?
Send us your questionnaire, or talk it through directly: book a security review call. We answer procurement and compliance questions for a living.
Related: Policies · Data deletion · Groups and permissions