Skip to main content

What Does Speak Do For Security?

How does Speak protect data, ensure confidentiality, encrypt information, select server locations and more.

Written by Speak Ai
Updated this week

What are the locations of your data centres?

Your files and account data are stored in Canada Central (MongoDB Atlas) and US North (Amazon Web Services) regions. All storage uses encrypted, redundant infrastructure with automated backups.

When you use features like transcription and AI analysis, your content is processed by our infrastructure partners. Processing may occur in the United States. For organizations with specific regional data requirements, enterprise plans offer the ability to discuss custom data residency configurations.

Does my data get used for model training?

No. Speak AI does not use customer data to train AI models. We have Business Associate Agreements (BAAs) with OpenAI and Anthropic that contractually prohibit this. Your data is processed solely to serve your requests and return results.

We may review anonymized usage patterns and debug transcription or AI Chat interactions to improve our prompts, instructions, and in-app experience. This is operational improvement, not model training. We never sell your data to anyone.

When you use Custom Vocabulary or configure AI Agents with custom instructions, you are choosing to provide data that shapes how AI models respond within your account. This is user-directed.

What about HIPAA?

Speak AI completed a HIPAA compliance assessment in 2021 and maintains the security controls and practices established during that process. We execute BAAs with our AI infrastructure providers including OpenAI and Anthropic. We do not hold a current third-party HIPAA audit. Organizations with specific HIPAA requirements should contact us at [email protected] to discuss their compliance needs.

Are there Standard Contractual Clauses (SCCs) in place for data travelling outside of the EU?

We maintain data processing practices aligned with GDPR requirements. For EU data transfers, we use Standard Contractual Clauses. EU-based users can request data export or deletion through their account settings or by contacting us.

How is personal data securely deleted?

You have full control over your data. Delete individual files, folders, or your entire account from Settings > Data Management. When you delete content, it is removed from our active systems. It may persist in encrypted backups for a limited retention period before being permanently purged.

Do you have a support function?

Yes. Our support includes in-app chat, email support at [email protected], and phone assistance at +1 (647) 261-6919. We also maintain a comprehensive Help Center with 200+ articles.

Is 2FA or Single Sign-On available?

Two-Factor Authentication (2FA) is available through Google Workspace. We also support Google SSO for team accounts.

Is data encrypted at rest?

Yes. All data stored on Speak AI is encrypted at rest using industry-standard AES encryption. Data in transit is protected via TLS/HTTPS. Encryption keys are rotated regularly.

Do you conduct penetration testing?

We run automated dependency scanning and vulnerability assessments through our development pipeline, including GitHub security scanning. We monitor for security advisories across our technology stack and apply patches promptly. We do not currently engage a third-party firm for formal annual penetration testing.

How do you manage vulnerabilities?

We actively manage vulnerabilities through automated scanning tools integrated into our development workflow. These tools inspect dependencies and generate vulnerability reports. Critical and high-severity issues are prioritized for immediate remediation.

Is the platform as secure during the trial period?

Yes. The same security protocols apply to all accounts, whether on a free trial or a paid plan.

Do you work with researchers and educational institutions?

Yes. We work with researchers and institutions globally including Brown, Cambridge, NYU, Stanford, Princeton, Cornell, UC Davis, Columbia, Georgetown, Western University, and many more. We have special offers available for academic use. Just reach out at [email protected].

What technology stack do you use?

  • Angular (frontend)

  • Node.js / Express (backend)

  • MongoDB Atlas (database, Canada Central)

  • Amazon Web Services (infrastructure)

What other systems does Speak AI interact with?

  • AI Processing: OpenAI (BAA in place), Anthropic/Claude (BAA in place), Google Gemini

  • Transcription: AWS Transcribe, Microsoft Azure Speech, Deepgram, AssemblyAI

  • Payments: Stripe, Paddle, RevenueCat

  • Analytics: Google Analytics, Amplitude, LogRocket

  • Communication: Intercom, SendGrid

Privacy Policy & Terms of Service

You can find our Privacy Policy here and our Terms of Service here. For a plain-language overview, see our Privacy Overview.

Did this answer your question?