A session transcript is a record of your company's unresolved strategic weaknesses, spoken aloud
We know what the artefact is. Everything below is about where it goes, who can read it, how long it lives and how you destroy it. A security reviewer can work through this page and start the review without needing a call.
The five answers
- Is the audio stored
- No. It is processed while the room is live and no recording of it is kept. What persists is the transcript. What happens to what you say
- Is it transcribed
- Yes. The transcript is the artefact you leave with, and it is what the session leaves behind. You can delete any session yourself, and deletions are purged from backups within 30 days.
- Who can read it
- The account that ran the session. Staff access is limited to named people, for support, on request, and it is logged. The access model
- Is it used for training
- No. Neither by us nor by the model vendor under the terms we buy on. Every vendor that touches it, named
- How do I purge it
- Delete the session, or delete the account. Both are self serve, both destroy the audio and the transcript, and the account page states what survives and why. Deletion and export requests
What is measured, and what is not
Voice to voice
1471 ms
Voice to voice, published with its method and its stage breakdown.
MEASURED 2026-08-19, 122 readings
Decision layer
619 tests
The turn taking policy, the bid scoring and the configuration guards are built and verified.
MEASURED 2026-08-23, 1 reading
Real human sessions
0 sessions
Every measured turn used pre-rendered audio. The enterprise scaffolding has not been started.
MEASURED 2026-08-23, 1 reading
Sub-processors named
Sub-processor count pending
Every vendor that touches customer data is named, including the model vendor.
PENDING
This is a procurement problem before it is an IT problem
The risk here is not that an account gets breached. It is that the artefact itself is sensitive by construction. A session is your people saying out loud what is wrong with a plan they have not told the board about yet, and most vendors in this category have not noticed that is what they are storing.
Two things we found while reading the category on 23 August 2026 are worth a security reviewer's attention, because both are published and both are checkable. One product's store listing declares that it collects no data while its own privacy policy enumerates categories that include voice audio. Three others ingest free text strategic briefs and publish no legal surface at all.
We are not naming them here. The point is not who they are. It is that the question you are about to ask us is a question the category has mostly not been asked, and that the answers below are worth reading against whatever else you are evaluating.
What exists today, and what does not
| Capability | Exists today | The honest answer |
|---|---|---|
| Single sign on | No | On the roadmap, in review |
| Directory provisioning | No | On the roadmap, in review |
| Audit log and export | No | On the roadmap, in review |
| Tenancy isolation | No | Not built. Sessions are isolated per account, not per tenant |
| Data residency choice | No | United States only. No European region and no way to request one |
| Retention override | No | Retention is the published default for every account |
| Session without a transcript | No | Not built. A session produces a transcript or it does not run |
| Delete one session | Yes | Self serve, from the session, and it destroys the audio and the transcript |
| Export everything | Yes | Self serve, from the account page, in a machine readable form |
| Role model | No | One role. Every account holder can do everything their own account can do |
| Service level agreement | No | Not planned. There is no operating history to write one from |
Nothing in that table is coming next quarter unless the roadmap says so in the future tense, with the state it is genuinely in. We would rather you learned this here than three weeks into a procurement.
Start the review without a call
Every document a review needs is published now, with no form in front of it and no call required.
- The data processing agreement, pre-signed, downloadable today
- Every sub-processor with its region, including the model vendor
- Security practices: encryption, key management, access, logging, incident response
- What the personas can and cannot know, and what happens when one invents a number
- Acceptable use
- Vulnerability disclosure, with scope, response times and safe harbour
- The accessibility statement, with the gaps we know about
The sub-processor table names the model vendor. The category leader publishes a sub-processor list with no model vendor on it at all, despite sending debate content to one.
Not yet produced
A signed document you can download and send to your own lawyer. The terms are published as text on this site already. The file waits on counsel and on the entity name that would sign it.
Not yet produced
A figure showing where your words go and where they stop. It has to match the sub processor list exactly, and that list is not final, so drawing it now would publish a boundary we might move.
Where it sits, and for how long
The hard part first. Session audio and transcripts are processed in the United States, in Google Cloud's us-central1 region. There is no European processing region and no way to request one. For a customer in the United Kingdom or the European Economic Area that is a transfer out of the region, covered by Standard Contractual Clauses and by the safeguards in the data processing agreement.
If your procurement requires local residency, we cannot meet it today. That is on the roadmap in review, without a date, because we do not have a date we could keep.
Every retention period on this site is a number of days, months or years. The phrase that means nothing appears nowhere, and a build that introduced it would fail.
| Data | How long it is kept | How it is destroyed |
|---|---|---|
| Session audio, yours and the personas' | Not retained. Processed while the room is live | Nothing to delete, because nothing is written |
| Transcripts and the brief | Kept until you delete them, then gone within 30 days including backups | Delete a session yourself, or delete the account |
| Session metadata, such as duration and floor share | 24 months, then aggregated | Aggregated records carry no identifier |
| The one question a session ends on | Destroyed with the session, so within 30 days of you deleting it | Deleted with the session |
| Server logs | 90 days | Purged automatically |
| Backups | Purged within 30 days of the source being deleted | Automatic, and this is the number questionnaires ask for |
| Billing records | 7 years | Tax law requires them, so they survive a deletion request |
| Consent records | 6 years after the consent is withdrawn | Kept to evidence that the choice was honoured |
Billing records survive a deletion request because tax law requires them, and the row above says so rather than leaving a reviewer to find out during an audit. The same schedule, written for the person whose data it is.
What you are actually deploying
A browser client and a hosted room. There is nothing to install, nothing to run inside your network, and no agent on an endpoint. A person opens a page, is authenticated by the account they created, and joins a room that exists for the length of the session.
There is no administrator console, because there is no tenancy model yet and an administrator with nothing to administer is a screen that implies a capability we do not have. When the enterprise scaffolding is built, it will appear in the build log on the day it reaches users.
Certification, stated plainly
| Standard | Where it stands | What there is to show |
|---|---|---|
| SOC 2 Type I | No report. We have not engaged an auditor | None to show. The date it is achieved is published here and nowhere else |
| SOC 2 Type II | Not started | None to show |
| ISO 27001 | Not held, and not currently in progress | None to show |
| External penetration test | Not yet commissioned. There is no client application to test | The date and the testing firm are published here once there is one |
| UK GDPR and EU GDPR | We act as controller for account data and as processor for session content | The privacy notice and the pre-signed data processing agreement |
| WCAG 2.2 Level AA | The target for this website. Conformance is not claimed | The accessibility statement, with the known gaps listed by name |
What we have instead is published and checkable in an afternoon: the controls, the pre-signed agreement, and every sub-processor named. We also answer a security questionnaire, and the turnaround is stated in the questions below rather than promised here. An audit follows customers rather than leading them, and we will say so on the day we start one.
The questions your security team will send us
Where is my data stored?
Your Tingvar session audio and transcripts are processed in the United States, in Google Cloud's us-central1 region, and we do not currently offer an EU-only processing region. For customers in the UK and the EEA, that means a transfer out of your region. We rely on Standard Contractual Clauses and the safeguards in our DPA. If your procurement requires EU data residency, the honest answer today is that we cannot meet it, and we would rather you knew that before you bought than after.
Do you have SOC 2 or ISO 27001?
No, Tingvar holds no SOC 2 report and no ISO 27001 certificate, and we will not claim a stage of either one that we have not reached. No product in the set we crawled on 23 August 2026 publishes one either. What we do have is published: the controls on the security page, a pre-signed DPA you can read in full without a form, and every sub-processor named including the model vendor. We answer a security questionnaire in five business days.
Do you have a DPA?
Yes, Tingvar publishes a pre-signed data processing agreement at tingvar.com/dpa that your legal team can read in full before speaking to anybody here. It carries the sub-processor list by reference, the 30 day change notice, and the transfer mechanism we rely on for customers outside the United States. There is no form in front of it and no call required. A signed file follows once the four outstanding entity details are supplied. If your own paper has to be used, the demo page is the route.
Can we get single sign-on?
No, Tingvar does not have single sign-on today, and the enterprise scaffolding it belongs to has not been built. Single sign-on, tenancy controls and audit export are on the roadmap in the future tense, each with the state it is in, the date it was last reviewed, and no delivery date. We would rather you learned that here than on a call three weeks into a procurement. If it is a hard requirement, tell us on the demo form and we will say honestly where it sits.
What is your uptime commitment?
Tingvar does not publish an uptime percentage, because we have no operating history to base one on. A number invented before the service has run is not a commitment, it is a guess with a percentage sign on it. There is no status page yet: operational notices and incident updates go out through support, and a status page is scheduled for general availability rather than for launch. When we have enough operating history to write a service level agreement we can keep, we will publish it and date it.
Not yet produced
Our answers to the questions a procurement team asks, written down once so you are not waiting on us to type them. It is producible today from the security page and it has not been produced.
Book a demo
Tell us what you want put under pressure and who has to approve buying it. A person replies within 2 business days, and the reply comes from somebody who can answer a technical question rather than from a scheduler.
The last box is off and nothing ticks it for you. Sending this form does not subscribe you to anything and it does not create an account.