Sales Methodology & Revenue OperationsChecklist3 min readUpdated September 2026

Vetting an AI Notetaker: Security, SOC 2 and Retention Questions

Before approving an AI notetaker, get written answers on five things: what a SOC 2 report actually covers, where recordings and transcripts are stored and for how long, whether your data trains their models, who can access it, and how consent is handled. A badge on a website isn't an answer to any of these.

Notetakers listen to sales calls, customer conversations and sometimes board or HR discussions, so they hold some of your most sensitive information. The steps below help a sales leader or ops owner run a fair review with the security team, and they apply whether you're comparing Fathom, Fireflies, Otter or another tool.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

What should you ask for to check SOC 2?

SOC 2 is an audit framework, and what matters is the report itself. Ask the vendor for their current SOC 2 report under NDA, and read these parts:

  • Type: a Type I report describes controls at a point in time, and Type II covers how they operated over a period.
  • Period covered: check the dates and whether they're recent.
  • Scope: which systems and services were audited, and whether the product you'll use is included.
  • Trust criteria: security is the base, and availability or confidentiality may also matter to you.
  • Exceptions: any findings the auditor noted, and the vendor's responses.

If a vendor says only that they're "compliant," ask for the report. Don't assume any tool has a specific certification. Confirm it in the vendor's own documentation and have your security team review it.

How do you evaluate data retention and deletion?

Find out what's stored, where and for how long, then compare it with your own policy. Ask:

  1. What's kept: audio, video, transcripts, summaries, and metadata such as participant names?
  2. Where is it stored, and can you choose a region if your customers require it?
  3. What are the default retention periods, and can admins change them?
  4. Can you delete a recording or a whole account on request, and how long does deletion take, including from backups?
  5. What happens to your data if you cancel?

Match the answers with your customer contracts. Some customers restrict recording or require deletion after a set time, and your notetaker settings have to allow that.

Does the vendor train models on your conversations?

This is the question that surprises people most. Ask directly, and get the answer in the terms or a data processing addendum:

  • Are your transcripts used to train or improve any models, theirs or a third party's?
  • Which third-party AI providers process your data, and under what terms?
  • Can you opt out, and is that the default or a setting someone must change?
  • How is data separated between customers?

A vague answer is a reason to ask again or move on. If your sales calls include customer confidential information, you need clear commitments in writing.

Who can access recordings, and how is access controlled?

By default, many notetakers make meeting content visible to attendees or teammates. Check the controls before rollout:

  • Single sign-on and multi-factor authentication for the tool.
  • Role-based permissions, so you can limit who sees which calls.
  • Sharing settings, including public links, and whether admins can disable them.
  • Audit logs showing who viewed or exported a recording.
  • Integrations, such as the CRM sync, and what data flows to them. See how this ties to CRM data hygiene.

Then set a default that fits the sensitivity of your calls. Customer-facing calls might be shared with the sales team, while calls about renewals or pricing may need narrower access.

How do you handle recording consent and rollout?

Recording laws differ by location and by who is on the call, and some places require consent from everyone. Talk to your attorney about which rules apply to your calls, especially across states or countries, and don't rely on the tool's defaults.

Then plan the rollout:

  • Add a clear notice at the start of calls, and give people a way to opt out.
  • Publish a short internal policy on what may and may not be recorded.
  • Run a pilot with a small group before company-wide use.
  • Recheck the vendor's terms and security page every year.

For the wider review process, pre-clearing security reviews covers how to make answers reusable, and the comparison of notetakers can help you shortlist.

Executive Capability Standard

What Good Looks Like

No AI notetaker is used with customers until its SOC 2 report, data retention, model-training terms, access controls and consent handling have been reviewed and approved in writing.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Read what a SOC 2 report covers and collect your customers' contract terms on recording and data handling.
2. Do Manually:Send each shortlisted vendor the same questions and compare written answers side by side.
3. Delegate:Ask your security or legal lead to sign off on the report, the terms and the retention settings.
4. Automate:Set default sharing, retention and consent notices centrally so individual reps can't weaken them.
5. Buy:Choose the tool whose documented controls match your requirements and re-review it each year.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

What is the difference between SOC 2 Type I and Type II?

A Type I report describes whether controls are designed properly at one point in time. A Type II report tests whether they worked over a period. Ask for the report, check its dates and scope, and confirm your product is covered.

Do AI notetakers train on my meeting data?

It depends on the vendor and plan, so ask directly and get the answer in the terms or data processing addendum. Ask about third-party AI providers too, and confirm whether opting out is the default or a setting.

Do I need consent to record sales calls with an AI notetaker?

Often yes, and the rules vary by location and who is on the call. Check with your attorney, notify participants at the start of each call, and give people a way to decline before you record.

How long should a company keep recordings and transcripts?

Only as long as you need them for coaching, deal work or a contract requirement. Set a default retention period with your legal and security teams, apply it in the tool, and make sure deletion requests can be honored.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides