Vetting an AI Notetaker: Security, SOC 2 and Retention Questions
Before approving an AI notetaker, get written answers on five things: what a SOC 2 report actually covers, where recordings and transcripts are stored and for how long, whether your data trains their models, who can access it, and how consent is handled. A badge on a website isn't an answer to any of these.
Notetakers listen to sales calls, customer conversations and sometimes board or HR discussions, so they hold some of your most sensitive information. The steps below help a sales leader or ops owner run a fair review with the security team, and they apply whether you're comparing Fathom, Fireflies, Otter or another tool.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
What should you ask for to check SOC 2?
SOC 2 is an audit framework, and what matters is the report itself. Ask the vendor for their current SOC 2 report under NDA, and read these parts:
- Type: a Type I report describes controls at a point in time, and Type II covers how they operated over a period.
- Period covered: check the dates and whether they're recent.
- Scope: which systems and services were audited, and whether the product you'll use is included.
- Trust criteria: security is the base, and availability or confidentiality may also matter to you.
- Exceptions: any findings the auditor noted, and the vendor's responses.
If a vendor says only that they're "compliant," ask for the report. Don't assume any tool has a specific certification. Confirm it in the vendor's own documentation and have your security team review it.
How do you evaluate data retention and deletion?
Find out what's stored, where and for how long, then compare it with your own policy. Ask:
- What's kept: audio, video, transcripts, summaries, and metadata such as participant names?
- Where is it stored, and can you choose a region if your customers require it?
- What are the default retention periods, and can admins change them?
- Can you delete a recording or a whole account on request, and how long does deletion take, including from backups?
- What happens to your data if you cancel?
Match the answers with your customer contracts. Some customers restrict recording or require deletion after a set time, and your notetaker settings have to allow that.
Does the vendor train models on your conversations?
This is the question that surprises people most. Ask directly, and get the answer in the terms or a data processing addendum:
- Are your transcripts used to train or improve any models, theirs or a third party's?
- Which third-party AI providers process your data, and under what terms?
- Can you opt out, and is that the default or a setting someone must change?
- How is data separated between customers?
A vague answer is a reason to ask again or move on. If your sales calls include customer confidential information, you need clear commitments in writing.
Who can access recordings, and how is access controlled?
By default, many notetakers make meeting content visible to attendees or teammates. Check the controls before rollout:
- Single sign-on and multi-factor authentication for the tool.
- Role-based permissions, so you can limit who sees which calls.
- Sharing settings, including public links, and whether admins can disable them.
- Audit logs showing who viewed or exported a recording.
- Integrations, such as the CRM sync, and what data flows to them. See how this ties to CRM data hygiene.
Then set a default that fits the sensitivity of your calls. Customer-facing calls might be shared with the sales team, while calls about renewals or pricing may need narrower access.
How do you handle recording consent and rollout?
Recording laws differ by location and by who is on the call, and some places require consent from everyone. Talk to your attorney about which rules apply to your calls, especially across states or countries, and don't rely on the tool's defaults.
Then plan the rollout:
- Add a clear notice at the start of calls, and give people a way to opt out.
- Publish a short internal policy on what may and may not be recorded.
- Run a pilot with a small group before company-wide use.
- Recheck the vendor's terms and security page every year.
For the wider review process, pre-clearing security reviews covers how to make answers reusable, and the comparison of notetakers can help you shortlist.
What Good Looks Like
No AI notetaker is used with customers until its SOC 2 report, data retention, model-training terms, access controls and consent handling have been reviewed and approved in writing.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Fits a small sales team shortlisting a notetaker, so ask for its security documentation and retention terms in writing.
Fits a team that wants searchable transcripts across meetings, so review its access controls and data handling before rollout.
Fits a team recording many kinds of meetings, so confirm how sharing defaults and retention are set for your workspace.
Frequently Asked Questions
What is the difference between SOC 2 Type I and Type II?
A Type I report describes whether controls are designed properly at one point in time. A Type II report tests whether they worked over a period. Ask for the report, check its dates and scope, and confirm your product is covered.
Do AI notetakers train on my meeting data?
It depends on the vendor and plan, so ask directly and get the answer in the terms or data processing addendum. Ask about third-party AI providers too, and confirm whether opting out is the default or a setting.
Do I need consent to record sales calls with an AI notetaker?
Often yes, and the rules vary by location and who is on the call. Check with your attorney, notify participants at the start of each call, and give people a way to decline before you record.
How long should a company keep recordings and transcripts?
Only as long as you need them for coaching, deal work or a contract requirement. Set a default retention period with your legal and security teams, apply it in the tool, and make sure deletion requests can be honored.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
CRM Data Hygiene: What to Check Daily, Weekly and Quarterly
A CRM data hygiene routine by cadence: what to fix weekly, monthly and quarterly, who owns each task, and how to catch duplicates and stale deals early.
Pre-Clearing Security Reviews Before Procurement Asks
How to prepare your security documentation before a buyer's review even starts, so the security step doesn't become the surprise that stalls your deal.
Fathom vs Fireflies vs Otter: AI Meeting Assistants Compared
Compare Fathom, Fireflies, and Otter for AI meeting recording, automated CRM note synchronization, sales call summaries, action items, and rep coaching.
Fathom vs Fireflies for B2B Sales: AI Call Notes Compared
Compare Fathom and Fireflies for B2B sales teams, automated HubSpot and Salesforce sync, custom deal fields, action item handoffs, and AE coaching.
A 120-Day Renewal Timeline for Customer Success Teams
A day-by-day renewal timeline from 120 days out to signature and after: what to review, who owns each step, when to escalate and how to handle at-risk renewals.
Deal Risk Signals to Check in Every Open Deal
Warning signs that an open B2B deal is in trouble, grouped by buyer engagement, stakeholders, timeline and commercials, plus what to do about each.