Trust Center
Tiro
Security isn't a feature. It's how we operate.
Tiro is an AI meeting assistant, built for security from day one. Explore our certifications, controls, and policies — and request the documents your security team needs.
Controls
Security controls operating across our infrastructure and organization, grouped by area.
42 controls · last reviewed July 25, 2026
- Data security & encryption
- Access control & authentication
- Infrastructure & availability
- Monitoring & threat detection
- AI security & data privacy
- Data governance & sharing
- Corporate & organizational
- Incident response & continuity
Data security & encryption
6 controls- ActiveAudio discarded after transcriptionAudio is irreversibly discarded right after transcription and is never stored on disk in plaintext.
- ActiveEncryption at rest and in transitData is encrypted at rest with AES-256 and in transit with TLS 1.2+.
- ActivePer-user encryption keysSensitive content is encrypted with a separate per-user key, so even an operator with direct database access cannot read it in plaintext.
- ActiveManaged key custody (KMS / HSM)Keys are protected by AWS KMS using FIPS 140-2 Level 3 validated HSMs and rotated automatically every 12 months.
- ActiveNo customer data used for AI trainingNo customer data, including conversations, is used to train or fine-tune AI models — across all tiers.
- ActiveIrreversible deletionDeletion covers the operational database, backups, vector indexes, and caches; on account closure, KMS keys are scheduled for deletion.
Access control & authentication
7 controls- ActiveLeast-privilege access (RBAC / ABAC)Role- and attribute-based access controls enforce least-privilege access to systems and data.
- ActiveRestricted plaintext accessPlaintext content access is restricted to a small set of explicitly authorized personnel under least-privilege controls, and every access is logged at the query and column level.
- ActiveSingle sign-on (SAML 2.0)Enterprise SSO via Okta, Azure AD, Google Workspace and other IdPs keeps access in sync with your policies.
- ActiveMulti-factor authenticationOTP, authenticator apps, or hardware keys add a second factor and block logins even if a password leaks.
- ActiveIP allowlistingAccess can be restricted to approved IP ranges so only office or VPN traffic is permitted.
- ActiveSCIM provisioningUser onboarding and offboarding in your IdP sync to Tiro automatically via SCIM.
- ActiveSession & device controlsA default 30-minute idle timeout (configurable for enterprise) plus policy controls over concurrent sessions and device registration.
Infrastructure & availability
5 controls- ActiveKorean data residency (AWS Seoul)Data is hosted in the AWS Seoul region (ap-northeast-2); enterprise customers can choose a dedicated VPC or another region.
- ActiveMulti-AZ resilienceA Multi-AZ deployment keeps the service available through single-AZ failures.
- ActiveEncrypted automated backupsDatabases are backed up automatically under KMS encryption, with annual restore testing.
- ActiveTested recovery objectivesRecovery objectives are RTO 24h and RPO 24h, validated by annual restore tests.
- Active99.9% uptime SLAA 99.9% monthly availability SLA applies, with service credits if we miss it.
Monitoring & threat detection
6 controls- Active24×7 threat detectionAWS GuardDuty continuously monitors the environment for threats.
- ActiveVulnerability scanningAWS Inspector continuously scans workloads for vulnerabilities.
- ActiveWeb attack protectionA WAF together with Cloudflare protects against common web attacks.
- ActiveTamper-resistant loggingAudit and infrastructure logs are delivered to isolated, tamper-resistant storage, protected from modification by operational systems.
- ActiveAudit logsUser and admin activity is logged with configurable retention and can be exported or streamed to your SIEM.
- ActivePenetration testingWe run penetration testing and vulnerability assessments to identify and remediate risks proactively.
AI security & data privacy
5 controls- ActiveNo model training on customer dataCustomer conversations, transcripts, and summaries are never used to train or fine-tune models.
- ActiveZero-Data-Retention vendor termsEvery LLM and STT vendor is bound by a DPA that prohibits training and requires Zero Data Retention.
- ActivePII auto-maskingPersonally identifiable information in meeting notes can be detected and masked automatically.
- ActiveConfigurable data retentionRetention windows can be set by domain, with automatic deletion when the window closes.
- ActiveVendor routing controlsChoose which LLM and STT vendors are available to your tenant, including Korea-only routing.
Data governance & sharing
5 controls- ActiveExternal sharing controlsNote sharing can be limited to an allowlist of trusted domains.
- ActiveMobile screen-capture protectionScreenshots inside the mobile app can be blocked, with every attempt logged.
- ActiveOrganization retention policyEnterprise admins can enforce organization-wide retention windows centrally.
- ActiveComplete deletion on closureWhen an account is closed, related personal data is deleted within 14 days and the encryption keys protecting it are scheduled for deletion, rendering any residual copies cryptographically inaccessible.
- ActiveDeletion loggingEach deletion request, execution, and completion is logged, and an erasure record can be provided to enterprise customers on request.
Corporate & organizational
4 controls- ActiveSecurity trainingEmployees complete mandatory security training at onboarding.
- ActiveQuarterly access reviewsAccess rights are reviewed every quarter to keep least-privilege current.
- ActiveInformation security policiesA full information security policy set is maintained and operated on the dedicated GRC platform.
- ActiveVendor due diligenceSubprocessors are bound by DPAs that prohibit training and require Zero Data Retention.
Incident response & continuity
4 controls- ActiveIncident responseEnterprise customers are covered by a 4-hour first-response SLA for security incidents.
- ActiveBreach notification SLAAffected customers are notified of security incidents within a 24-hour notification SLA.
- ActiveBusiness continuity & DRBackups, Multi-AZ deployment, and tested recovery objectives underpin business continuity and disaster recovery.
- ActiveChange managementProduction changes follow controlled review and deployment processes.