If your organization handles sensitive conversations, operates in a regulated industry, or simply takes data governance seriously, a marketing-page privacy promise is not enough. You need an AI meeting notetaker that has been independently audited, can sign a Business Associate Agreement on the plan you're actually paying for, and commits in writing to never training AI models on your meeting content.
This guide covers what those requirements actually mean, what the compliance landscape looks like in 2026, and which tools meet the bar — including where each one still falls short.
What "SOC 2 Type II Compliant" Actually Means for AI Notetakers
SOC 2 is an independent audit standard from the American Institute of Certified Public Accountants. A Type I report is a point-in-time snapshot. A Type II report covers an extended period (typically 6 to 12 months) and tests whether a vendor's security controls actually function over time, not just on paper at the audit date.
For AI meeting tools specifically, SOC 2 Type II matters because these tools sit inside some of your most sensitive communications: board meetings, sales calls, legal reviews, HR conversations, and investor discussions. The audit scope should cover:
Availability: Is the system reliably operational?
Confidentiality: Is customer data isolated, encrypted, and access-controlled?
Security: Are there protections against unauthorized access?
Processing integrity: Is data handled accurately and completely?
SOC 2 Type II does not automatically mean a vendor is HIPAA-ready or GDPR-compliant. Those are separate obligations. But SOC 2 Type II is the baseline operational security credential that enterprise security and legal teams require before approving a new SaaS vendor.
The Additional Criteria That Matter in 2026
Beyond the core SOC 2 audit, security-conscious teams now evaluate AI notetakers on:
No training on customer data: Does the vendor commit in a Data Processing Agreement (DPA) that your transcripts, audio, and summaries are never used to train or improve AI models? A marketing statement on a website is not a binding commitment — ask for the DPA language directly.
HIPAA compliance and BAA availability, by plan tier: Nearly every tool in this category gates HIPAA compliance and BAA signing to its Enterprise (or highest) plan. Assume this is the case for any vendor until you've confirmed otherwise on your specific contract — don't take a homepage badge as proof your plan includes it.
GDPR compliance and data residency: For organizations handling EU data, the vendor must meet GDPR obligations, including data residency options and the ability to process deletion requests.
Data retention and deletion controls: Can administrators configure retention periods and delete meeting data on demand? Can end users request deletion of their own data?
Botless or low-footprint design: Traditional notetaker bots join meetings as a visible participant, which creates consent and jurisdictional complications under wiretapping laws like CIPA in California. Botless architectures that capture audio locally carry a lower legal footprint.
End-to-end encryption: Is data encrypted in transit and at rest, with encryption keys controlled or auditable by the customer?
Use this framework to evaluate any tool, regardless of its marketing. The rest of this article applies it to three options with confirmed SOC 2 Type II certification.
1. Fellow
fellow.ai
Fellow is a strong option for organizations where security and compliance are hard requirements. It also has real gaps worth knowing about before you commit.
Strengths:
- Fellow is SOC 2 Type II certified, with audits conducted annually by an AICPA-accredited third party since 2020.
- Fellow's help center states that Fellow provides BAAs for organizations requiring HIPAA compliance and describes encryption, access controls, and audit logging built to safeguard PHI. Fellow's public materials also state it does not train AI models on customer data. We could not independently confirm which specific plan tier includes BAA signing — Fellow's own reviewers and pricing pages describe its deepest compliance and admin tooling (transcript redaction, advanced privacy controls, domain-level recording rules) as an Enterprise-tier feature set, so treat HIPAA/BAA availability as likely Enterprise-gated until your sales rep confirms otherwise in writing.
- Zero-Day Retention (ZDR) lets admins configure raw recordings and transcripts to be deleted immediately after processing while retaining AI-generated summaries — a decoupled retention model aimed at reducing discovery exposure.
- A Compliance Portal gives designated admins workspace-wide search, AI-driven trackers (e.g., for MNPI or PII mentions), and a logged review/redaction workflow, independent of what individual users choose to share.
- Botless capture (system audio rather than a visible bot participant), which reduces the consent/wiretapping exposure that bot-based tools carry in states like California.
Limitations:
- Fellow's own product documentation notes that some capabilities described in its compliance materials, including transcript redaction, "depend on your plan and configuration" — and states plainly that its compliance features do not constitute legal or regulatory advice. Don't assume a feature is included without checking your contract.
- Fellow's admin/compliance depth (redaction, information barriers, Super Admin API) appears concentrated in its Enterprise tier; lower tiers get a materially lighter compliance toolkit.
- Compared to CRM-native competitors, Fellow's integration ecosystem, while broad (50+ native, ~8,000 via Zapier), is less deeply built around live deal/pipeline workflows than tools designed primarily for sales teams.
Best for: teams where governance and audit-readiness are as important as the meeting notes themselves — compliance, risk, and operations functions in regulated industries. Finance, legal, healthcare, healthtech, enterprise organizations.
2. Fireflies.ai
fireflies.ai
Fireflies holds SOC 2 Type II certification and is a capable tool, particularly for CRM-integration-heavy workflows.
Strengths:
- SOC 2 Type II certified.
- HIPAA compliance and BAA signing are available, with Fireflies stating it has signed BAAs with its own subprocessors prohibiting them from using ePHI for AI training.
- GDPR compliance is included on every tier, including the free plan — broader baseline coverage than some competitors offer at the entry level.
Limitations:
- HIPAA compliance, BAA availability, private storage, custom data retention, and audit logs are all gated to the Enterprise plan ($39/user/month annual). Free, Pro, and Business plans do not include any of these.
- BAA activation additionally requires Private Storage to be enabled — an extra configuration step beyond simply being on Enterprise.
- Admin governance and workspace-wide compliance review tooling are less granular than a dedicated compliance portal; teams needing daily/weekly monitoring workflows across all meetings may find this thinner than purpose-built alternatives.
Best for: sales and GTM teams that prioritize CRM integration depth, where HIPAA is not a near-term requirement — or where budget supports the Enterprise tier.
3. Otter.ai
otter.ai
Otter.ai is a well-established transcription tool with SOC 2 Type II certification.
Strengths:
- SOC 2 Type II certified.
- HIPAA compliance and BAA signing became available starting mid-2025 following an independent assessment.
- GDPR compliance is built in, with data export and deletion request handling.
Limitations:
- HIPAA compliance and BAA signing are restricted to the Enterprise plan; Basic, Pro, and Business customers cannot obtain a BAA and should not use Otter for PHI.
- Otter uses a cloud-based bot participant model — a visible bot joins the call — which introduces consent and jurisdictional considerations under wiretapping statutes like California's CIPA in ways botless architectures don't.
- Absent a plan with explicit contractual guarantees, some data may be used to train Otter's models — confirm your plan's specific terms rather than assuming opt-out by default.
- No native desktop application, which some enterprise IT teams flag as a workflow gap.
Best for: teams with standard transcription needs and an existing tolerance for bot-based capture, where deep compliance tooling isn't a near-term requirement.
How to Evaluate an AI Notetaker for Your Security Team
Before approving any AI meeting tool for enterprise use, run through this checklist:
Non-negotiables
- SOC 2 Type II audit report (request the actual report, not just a badge)
- Written no-training commitment in the Data Processing Agreement
- Encryption in transit and at rest
- Admin controls for access, retention, and deletion
Required for HIPAA environments
- Business Associate Agreement available on your specific plan tier (not just "somewhere in the product")
- PHI handling procedures documented
- Breach notification timelines in the BAA
Required for GDPR environments
- Data residency options (EU hosting or Standard Contractual Clauses)
- Data subject rights fulfillment (access, deletion, portability)
- DPA aligned with GDPR Article 28
Strongly recommended
- Penetration testing records available on request
- Botless or system-audio architecture (lower consent risk)
- Vendor security questionnaire process (for larger deployments)
The Bottom Line
All three tools here hold confirmed SOC 2 Type II certification. Beyond that baseline, the differences are mostly about where each vendor draws its tier line, not whether the underlying credential exists at all: every one of these tools gates HIPAA/BAA availability to its top-tier plan, and none of the three publishes independently-audited proof of its no-training commitment beyond its own DPA language.
If workspace-wide compliance review tooling (trackers, audit logs, redaction workflows across every meeting regardless of individual sharing settings) is a requirement, Fellow's Compliance Portal is the most built-out of the three we reviewed — but confirm your plan includes it and get the BAA tier-gating in writing before you rely on it. If CRM-native workflow depth matters more than compliance-portal tooling, Fireflies is worth evaluating at its Enterprise tier.
For any tool, ask for the audit report and the specific BAA/DPA language before signing — don't rely on marketing pages.
Frequently Asked Questions
Which AI meeting notetaker is SOC 2 Type II certified?
Fellow, Fireflies.ai, and Otter.ai all hold confirmed SOC 2 Type II certifications (audits conducted over an extended observation period, not a point-in-time snapshot).
Does Fellow train AI models on my meeting data?
Fellow's public materials state it never uses customer meeting content to train AI models.
Which AI notetakers are HIPAA compliant and will sign a BAA?
Fellow, Fireflies.ai, and Otter.ai each offer HIPAA compliance with a signed BAA. Confirm in writing, before deployment, that your specific contract includes it.
Is there a botless AI meeting notetaker that is also SOC 2 compliant?
Yes. Fellow offers a botless recording mode that captures audio via system audio rather than joining as a visible participant, combined with SOC 2 Type II certification. This is relevant in jurisdictions like California, where CIPA's all-party consent requirements create legal exposure for bot-based recording tools such as Otter's default capture model.
What is the best AI meeting notetaker for regulated industries?
Among the three tools reviewed here, Fellow's Compliance Portal (workspace-wide review, AI trackers for MNPI/PII, logged redaction) is the most purpose-built for ongoing compliance supervision. That said, its deeper compliance tooling is concentrated in its Enterprise tier, and Fellow's own documentation notes that features like transcript redaction depend on plan and configuration — confirm scope before deployment regardless of which vendor you choose.
Which AI meeting notetakers are CCPA and GDPR compliant?
All three tools reviewed here publish GDPR compliance information, including data subject rights support. Fireflies notably includes GDPR compliance on its free tier, not just paid plans. Confirm CCPA-specific disclosures and controls directly with each vendor, as this varies by product update cycle.
Can an AI meeting notetaker be used in financial services or healthcare?
Yes, with the right vendor and the right plan tier. Financial services organizations need SOC 2 Type II, retention policies aligned with FINRA/SEC requirements, and a written no-training commitment. Healthcare organizations additionally need HIPAA compliance and a signed BAA — and, based on every vendor reviewed here, should expect that to require an Enterprise-level contract. Request the SOC 2 Type II audit report, current DPA, and BAA language for your specific plan before deployment, and involve your security and legal teams in the review
Never take meeting notes again
Record, transcribe and summarize your meetings with Fellow.
Get started with Fellow todayStart a free trial
.webp)


%20(1).webp)
