Tiro
Security isn't a feature. It's how we operate.
Tiro is an AI meeting assistant, built for security from day one. Explore our certifications, controls, and policies — and request the documents your security team needs.
Start your security review
Welcome to Tiro's Trust Center. Use this portal to review our security posture, browse our certifications and controls, and request the documents your security team needs.
Compliance
Independently audited certifications, plus the frameworks our security program aligns to.
ISO/IEC 27001:2022
Certified June 4, 2026 · Sensiba LLP
The international standard for an information security management system (ISMS), confirmed by an independent, accredited audit.
SOC 2 Type 1
5 Trust Services Criteria
Attests that our security controls are suitably designed at a point in time across five Trust Services Criteria.
SOC 2 Type 2
Attested July 24, 2026 · Sensiba LLP
Evaluates how those controls actually operated over the audit period, across the same five Trust Services Criteria. Unqualified opinion.
Frameworks & self-attestations
Frameworks our information security program aligns to. Self-attested unless an audit is noted.
- NIST CSF
- NIST AI RMF
- CIS Controls 8.1
- GDPR
- CCPA / CPRA
Controls
View allData security & encryption
- Audio discarded after transcription
- Encryption at rest and in transit
- Per-user encryption keys
Access control & authentication
- Least-privilege access (RBAC / ABAC)
- Restricted plaintext access
- Single sign-on (SAML 2.0)
Infrastructure & availability
- Korean data residency (AWS Seoul)
- Multi-AZ resilience
- Encrypted automated backups
AI security & data privacy
- No model training on customer data
- Zero-Data-Retention vendor terms
- PII auto-masking
How your data flows
What happens to a meeting from capture to deletion, and which providers see what.
- 1Capture
Meeting audio is captured and streamed over TLS 1.2+ — never written to disk in plaintext.
- 2Transcribe
Audio is sent to a speech-to-text provider under a Zero-Data-Retention contract, converted to text, then discarded.
- 3Summarize
Transcript text is sent to an LLM provider (Zero Data Retention, no training) to generate summaries and answers.
- 4Store
Notes, transcripts, and summaries are encrypted at rest with AES-256 in the AWS Seoul region, isolated by per-user keys.
- 5Delete
On deletion, content is removed from the database, backups, vector indexes, and caches; KMS keys are scheduled for deletion on account closure.
Data ownership & privacy
Your data is yours. Here is how we handle ownership, processing terms, and where your data lives.
You own your data
Customer content belongs to you. We process it only to provide the service, never sell it, and never use it to train AI models.
DPA & SCCs
A Data Processing Agreement is available, incorporating EU Standard Contractual Clauses for international transfers.
Data residency
Data is stored in the AWS Seoul region (ap-northeast-2) by default. Enterprise customers can request a dedicated region or VPC.
Data subject rights
We support access, correction, export, and deletion requests in line with GDPR and CCPA.
VDI & closed-network environments
Tiro runs in locked-down VDI and closed-network environments with no client to install — finance, public-sector, and enterprise teams use it through their in-house virtual desktops.
No client to install
A standard HTTPS web app — it works in Chrome, Edge, and Safari inside a VDI, with no native client or agent to deploy.
Gateway & CASB friendly
All traffic stays on the *.tiro.ooo domain, so VDI gateways and CASBs (Prisma Access, Netskope, Zscaler, and others) can apply domain- and IP-based policy. Fixed egress IPs and domain allowlists are available for enterprise.
Admin-controlled export
Note export (PDF/Markdown/DOCX) is governed at the admin level, and every download and export is written to the audit log — so your VDI data-loss controls extend to Tiro.
Doesn't rely on the endpoint
Confidentiality comes from server-side per-user encryption, not the device — the database is never exposed in plaintext, even to operators.
Incident response & availability
How we detect, respond to, and communicate security incidents — and where to check live status.
Detect
24×7 monitoring (AWS GuardDuty, Inspector, WAF, CloudTrail) surfaces anomalies in real time.
Respond
Confirmed security incidents trigger a 4-hour first-response SLA for enterprise customers.
Notify
Affected customers are notified within a 24-hour breach-notification SLA, with scope, impact, and remediation.
Review
Every incident is followed by a post-incident review and corrective actions.
Vulnerability disclosure
We welcome reports from security researchers and handle them responsibly.
We acknowledge reports within 3 business days and keep you updated through remediation.
Good-faith research conducted under this policy is authorized — we will not pursue legal action against researchers who follow it.
Data we handle
What Tiro processes, and how each category is protected.
- Meeting audio — discarded immediately after transcription
- Transcripts & summaries — encrypted at rest with AES-256
- Account & organization information
- Usage & diagnostic logs