Skip to main content

Security

What we operate, what we do not hold, and what we have not measured. A reviewer should be able to fill in a questionnaire from this page without a call.

Version 1.0.0 Effective 2026-08-24 Last updated 2026-08-24

In short

Applies to: A security reviewer working through a questionnaire

  • We hold no SOC 2 report and no ISO 27001 certificate, and we say so here.
  • Session audio is processed in transit and not retained.
  • Known gaps are listed by name rather than summarised.

The certification position

We do not hold a SOC 2 report. We are not currently in an observation window and we have not engaged an auditor. When that changes, the date it changed is published here and nowhere else. Until then the controls we do operate are below, and we will complete your security questionnaire.

Third party assurance, stated as it is on 24 August 2026
StandardStatusEvidence
SOC 2 Type INo report. We have not engaged an auditorNone to show. The date it is achieved is published here and nowhere else
SOC 2 Type IINot startedNone to show
ISO 27001Not held, and not currently in progressNone to show
External penetration testNot yet commissioned. There is no client application to testThe date and the testing firm are published here once there is one
UK GDPR and EU GDPRWe act as controller for account data and as processor for session contentThe privacy notice and the pre-signed data processing agreement
WCAG 2.2 Level AAThe target for this website. Conformance is not claimedThe accessibility statement, with the known gaps listed by name

Controls

Each row states what is true of our own systems. Where a leg of the service belongs to a vendor, the vendor is named on the sub-processors page and its commitment is never restated here as if it were ours.

The controls Tingvar operates today
ItemStatus
Media in transitEncrypted. Browser media uses SRTP with DTLS key exchange
Site and application trafficEncrypted. TLS, with the transport policy published in our deployment configuration
At restNot yet verified on our own systems. We will state the algorithm here once it is configured and checked
Session audio storageNone. Audio is processed while the room is live and no recording is written
Who can read a transcriptAccess is limited to the founder and is logged. A role based access model is published here when the team is larger than one
Single sign-on, SCIM, audit exportNot available. The enterprise scaffolding they belong to is not built
DeletionSelf-service for a session and for a whole account. Backups purged within 30 days of the source deletion
Breach notificationAffected customers without undue delay, and the supervisory authority within 72 hours where the GDPR applies
Model training on your dataWe do not train on your sessions. The model vendor states the same for its own service, and the citation is on the sub-processors page

Retention

The full schedule lives on the privacy notice. The three rows a security review usually wants are here.

Retention, summarised. The full schedule is on the privacy notice
ItemHow longHow to delete it
Session audio, yours and the personas'Not retained. Processed while the room is liveNothing to delete, because nothing is written
Transcripts and the briefKept until you delete them, then gone within 30 days including backupsDelete a session yourself, or delete the account
Session metadata, such as duration and floor share24 months, then aggregatedAggregated records carry no identifier

Known gaps

This section exists because a security page with no gaps forces the reviewer to find them, and finding them is slower than reading them.

What we do not have on 24 August 2026
ItemStatus
No third party assurance reportNo SOC 2 report and no ISO 27001 certificate. No auditor is engaged
No external penetration testThere is no client application to test. The date and the firm are published here once there is one
No EU processing regionThe model is pinned to us-central1 in the United States
No role based access modelAccess is limited to one person and logged. That is a small answer, and it is the true one
No incident historyThe service has not run for customers, so there is nothing to report and no availability figure to publish

The questions that arrive next

What happens to my recording?

Tingvar does not store your session audio: it is processed while the room is live and no recording of it is kept. What persists is the transcript, the text of what you said and what each persona said, attributed line by line. Only the account that ran the session can read that transcript, and nobody at Tingvar reads one without your written request on a support case. You can delete any session yourself, and deletions are purged from backups within 30 days. The retention schedule is published at tingvar.com/trust/your-data.

Where is my data stored?

Your Tingvar session audio and transcripts are processed in the United States, in Google Cloud's us-central1 region, and we do not currently offer an EU-only processing region. For customers in the UK and the EEA, that means a transfer out of your region. We rely on Standard Contractual Clauses and the safeguards in our DPA. If your procurement requires EU data residency, the honest answer today is that we cannot meet it, and we would rather you knew that before you bought than after.

Do you have SOC 2 or ISO 27001?

No, Tingvar holds no SOC 2 report and no ISO 27001 certificate, and we will not claim a stage of either one that we have not reached. No product in the set we crawled on 23 August 2026 publishes one either. What we do have is published: the controls on the security page, a pre-signed DPA you can read in full without a form, and every sub-processor named including the model vendor. We answer a security questionnaire in five business days.

Reporting something

Reporting a vulnerability

If a control above is a hard requirement and we do not have it, a conversation settles it faster than a questionnaire round trip.

Book a demo