Skip to main content

A session transcript is a record of your company's unresolved strategic weaknesses, spoken aloud

We know what the artefact is. Everything below is about where it goes, who can read it, how long it lives and how you destroy it. A security reviewer can work through this page and start the review without needing a call.

The five answers

Is the audio stored
No. It is processed while the room is live and no recording of it is kept. What persists is the transcript. What happens to what you say
Is it transcribed
Yes. The transcript is the artefact you leave with, and it is what the session leaves behind. You can delete any session yourself, and deletions are purged from backups within 30 days.
Who can read it
The account that ran the session. Staff access is limited to named people, for support, on request, and it is logged. The access model
Is it used for training
No. Neither by us nor by the model vendor under the terms we buy on. Every vendor that touches it, named
How do I purge it
Delete the session, or delete the account. Both are self serve, both destroy the audio and the transcript, and the account page states what survives and why. Deletion and export requests

What is measured, and what is not

Voice to voice

1471 ms

Voice to voice, published with its method and its stage breakdown.

MEASURED 2026-08-19, 122 readings

How we measured it

Decision layer

619 tests

The turn taking policy, the bid scoring and the configuration guards are built and verified.

MEASURED 2026-08-23, 1 reading

What the suite covers

Real human sessions

0 sessions

Every measured turn used pre-rendered audio. The enterprise scaffolding has not been started.

MEASURED 2026-08-23, 1 reading

What happens next

Sub-processors named

Sub-processor count pending

Every vendor that touches customer data is named, including the model vendor.

PENDING

Who touches your audio

This is a procurement problem before it is an IT problem

The risk here is not that an account gets breached. It is that the artefact itself is sensitive by construction. A session is your people saying out loud what is wrong with a plan they have not told the board about yet, and most vendors in this category have not noticed that is what they are storing.

Two things we found while reading the category on 23 August 2026 are worth a security reviewer's attention, because both are published and both are checkable. One product's store listing declares that it collects no data while its own privacy policy enumerates categories that include voice audio. Three others ingest free text strategic briefs and publish no legal surface at all.

We are not naming them here. The point is not who they are. It is that the question you are about to ask us is a question the category has mostly not been asked, and that the answers below are worth reading against whatever else you are evaluating.

What exists today, and what does not

Enterprise capabilities, with a straight answer against each. The enterprise scaffolding has not been started, so most of this table says no.
CapabilityExists todayThe honest answer
Single sign on No On the roadmap, in review
Directory provisioning No On the roadmap, in review
Audit log and export No On the roadmap, in review
Tenancy isolation No Not built. Sessions are isolated per account, not per tenant
Data residency choice No United States only. No European region and no way to request one
Retention override No Retention is the published default for every account
Session without a transcript No Not built. A session produces a transcript or it does not run
Delete one session Yes Self serve, from the session, and it destroys the audio and the transcript
Export everything Yes Self serve, from the account page, in a machine readable form
Role model No One role. Every account holder can do everything their own account can do
Service level agreement No Not planned. There is no operating history to write one from

Nothing in that table is coming next quarter unless the roadmap says so in the future tense, with the state it is genuinely in. We would rather you learned this here than three weeks into a procurement.

The roadmap, and the two rows that say not planned

Start the review without a call

Not yet produced

A signed document you can download and send to your own lawyer. The terms are published as text on this site already. The file waits on counsel and on the entity name that would sign it.

Blocked on counsel, and the legal entity in the pending register 2026-08-26

Not yet produced

A figure showing where your words go and where they stop. It has to match the sub processor list exactly, and that list is not final, so drawing it now would publish a boundary we might move.

Blocked on the sub processor list being final 2026-08-26

Where it sits, and for how long

The hard part first. Session audio and transcripts are processed in the United States, in Google Cloud's us-central1 region. There is no European processing region and no way to request one. For a customer in the United Kingdom or the European Economic Area that is a transfer out of the region, covered by Standard Contractual Clauses and by the safeguards in the data processing agreement.

If your procurement requires local residency, we cannot meet it today. That is on the roadmap in review, without a date, because we do not have a date we could keep.

Every retention period on this site is a number of days, months or years. The phrase that means nothing appears nowhere, and a build that introduced it would fail.

The retention schedule, with a number on every row. The same rows a reviewer reads on the data page, from the same register.
DataHow long it is keptHow it is destroyed
Session audio, yours and the personas' Not retained. Processed while the room is live Nothing to delete, because nothing is written
Transcripts and the brief Kept until you delete them, then gone within 30 days including backups Delete a session yourself, or delete the account
Session metadata, such as duration and floor share 24 months, then aggregated Aggregated records carry no identifier
The one question a session ends on Destroyed with the session, so within 30 days of you deleting it Deleted with the session
Server logs 90 days Purged automatically
Backups Purged within 30 days of the source being deleted Automatic, and this is the number questionnaires ask for
Billing records 7 years Tax law requires them, so they survive a deletion request
Consent records 6 years after the consent is withdrawn Kept to evidence that the choice was honoured

Billing records survive a deletion request because tax law requires them, and the row above says so rather than leaving a reviewer to find out during an audit. The same schedule, written for the person whose data it is.

What you are actually deploying

A browser client and a hosted room. There is nothing to install, nothing to run inside your network, and no agent on an endpoint. A person opens a page, is authenticated by the account they created, and joins a room that exists for the length of the session.

There is no administrator console, because there is no tenancy model yet and an administrator with nothing to administer is a screen that implies a capability we do not have. When the enterprise scaffolding is built, it will appear in the build log on the day it reaches users.

Certification, stated plainly

Where each standard actually stands, and what there is to show for it.
StandardWhere it standsWhat there is to show
SOC 2 Type I No report. We have not engaged an auditor None to show. The date it is achieved is published here and nowhere else
SOC 2 Type II Not started None to show
ISO 27001 Not held, and not currently in progress None to show
External penetration test Not yet commissioned. There is no client application to test The date and the testing firm are published here once there is one
UK GDPR and EU GDPR We act as controller for account data and as processor for session content The privacy notice and the pre-signed data processing agreement
WCAG 2.2 Level AA The target for this website. Conformance is not claimed The accessibility statement, with the known gaps listed by name

What we have instead is published and checkable in an afternoon: the controls, the pre-signed agreement, and every sub-processor named. We also answer a security questionnaire, and the turnaround is stated in the questions below rather than promised here. An audit follows customers rather than leading them, and we will say so on the day we start one.

The questions your security team will send us

Where is my data stored?

Your Tingvar session audio and transcripts are processed in the United States, in Google Cloud's us-central1 region, and we do not currently offer an EU-only processing region. For customers in the UK and the EEA, that means a transfer out of your region. We rely on Standard Contractual Clauses and the safeguards in our DPA. If your procurement requires EU data residency, the honest answer today is that we cannot meet it, and we would rather you knew that before you bought than after.

Do you have SOC 2 or ISO 27001?

No, Tingvar holds no SOC 2 report and no ISO 27001 certificate, and we will not claim a stage of either one that we have not reached. No product in the set we crawled on 23 August 2026 publishes one either. What we do have is published: the controls on the security page, a pre-signed DPA you can read in full without a form, and every sub-processor named including the model vendor. We answer a security questionnaire in five business days.

Do you have a DPA?

Yes, Tingvar publishes a pre-signed data processing agreement at tingvar.com/dpa that your legal team can read in full before speaking to anybody here. It carries the sub-processor list by reference, the 30 day change notice, and the transfer mechanism we rely on for customers outside the United States. There is no form in front of it and no call required. A signed file follows once the four outstanding entity details are supplied. If your own paper has to be used, the demo page is the route.

Can we get single sign-on?

No, Tingvar does not have single sign-on today, and the enterprise scaffolding it belongs to has not been built. Single sign-on, tenancy controls and audit export are on the roadmap in the future tense, each with the state it is in, the date it was last reviewed, and no delivery date. We would rather you learned that here than on a call three weeks into a procurement. If it is a hard requirement, tell us on the demo form and we will say honestly where it sits.

What is your uptime commitment?

Tingvar does not publish an uptime percentage, because we have no operating history to base one on. A number invented before the service has run is not a commitment, it is a guess with a percentage sign on it. There is no status page yet: operational notices and incident updates go out through support, and a status page is scheduled for general availability rather than for launch. When we have enough operating history to write a service level agreement we can keep, we will publish it and date it.

Not yet produced

Our answers to the questions a procurement team asks, written down once so you are not waiting on us to type them. It is producible today from the security page and it has not been produced.

Blocked on production 2026-08-26

Book a demo

Tell us what you want put under pressure and who has to approve buying it. A person replies within 2 business days, and the reply comes from somebody who can answer a technical question rather than from a scheduler.

PENDING No service answers this form yet. The application is being built separately, so sending it reaches an endpoint that returns an error. Nothing you type is stored and nobody reads it.

A sentence is enough here. The full brief comes later, before the room opens.

Optional, and off unless you tick it.

The last box is off and nothing ticks it for you. Sending this form does not subscribe you to anything and it does not create an account.