Security
What we operate, what we do not hold, and what we have not measured. A reviewer should be able to fill in a questionnaire from this page without a call.
Version 1.0.0 Effective 2026-08-24 Last updated 2026-08-24
In short
Applies to: A security reviewer working through a questionnaire
- We hold no SOC 2 report and no ISO 27001 certificate, and we say so here.
- Session audio is processed in transit and not retained.
- Known gaps are listed by name rather than summarised.
The certification position
We do not hold a SOC 2 report. We are not currently in an observation window and we have not engaged an auditor. When that changes, the date it changed is published here and nowhere else. Until then the controls we do operate are below, and we will complete your security questionnaire.
| Standard | Status | Evidence |
|---|---|---|
| SOC 2 Type I | No report. We have not engaged an auditor | None to show. The date it is achieved is published here and nowhere else |
| SOC 2 Type II | Not started | None to show |
| ISO 27001 | Not held, and not currently in progress | None to show |
| External penetration test | Not yet commissioned. There is no client application to test | The date and the testing firm are published here once there is one |
| UK GDPR and EU GDPR | We act as controller for account data and as processor for session content | The privacy notice and the pre-signed data processing agreement |
| WCAG 2.2 Level AA | The target for this website. Conformance is not claimed | The accessibility statement, with the known gaps listed by name |
Controls
Each row states what is true of our own systems. Where a leg of the service belongs to a vendor, the vendor is named on the sub-processors page and its commitment is never restated here as if it were ours.
| Item | Status |
|---|---|
| Media in transit | Encrypted. Browser media uses SRTP with DTLS key exchange |
| Site and application traffic | Encrypted. TLS, with the transport policy published in our deployment configuration |
| At rest | Not yet verified on our own systems. We will state the algorithm here once it is configured and checked |
| Session audio storage | None. Audio is processed while the room is live and no recording is written |
| Who can read a transcript | Access is limited to the founder and is logged. A role based access model is published here when the team is larger than one |
| Single sign-on, SCIM, audit export | Not available. The enterprise scaffolding they belong to is not built |
| Deletion | Self-service for a session and for a whole account. Backups purged within 30 days of the source deletion |
| Breach notification | Affected customers without undue delay, and the supervisory authority within 72 hours where the GDPR applies |
| Model training on your data | We do not train on your sessions. The model vendor states the same for its own service, and the citation is on the sub-processors page |
Retention
The full schedule lives on the privacy notice. The three rows a security review usually wants are here.
| Item | How long | How to delete it |
|---|---|---|
| Session audio, yours and the personas' | Not retained. Processed while the room is live | Nothing to delete, because nothing is written |
| Transcripts and the brief | Kept until you delete them, then gone within 30 days including backups | Delete a session yourself, or delete the account |
| Session metadata, such as duration and floor share | 24 months, then aggregated | Aggregated records carry no identifier |
Known gaps
This section exists because a security page with no gaps forces the reviewer to find them, and finding them is slower than reading them.
| Item | Status |
|---|---|
| No third party assurance report | No SOC 2 report and no ISO 27001 certificate. No auditor is engaged |
| No external penetration test | There is no client application to test. The date and the firm are published here once there is one |
| No EU processing region | The model is pinned to us-central1 in the United States |
| No role based access model | Access is limited to one person and logged. That is a small answer, and it is the true one |
| No incident history | The service has not run for customers, so there is nothing to report and no availability figure to publish |
The questions that arrive next
What happens to my recording?
Tingvar does not store your session audio: it is processed while the room is live and no recording of it is kept. What persists is the transcript, the text of what you said and what each persona said, attributed line by line. Only the account that ran the session can read that transcript, and nobody at Tingvar reads one without your written request on a support case. You can delete any session yourself, and deletions are purged from backups within 30 days. The retention schedule is published at tingvar.com/trust/your-data.
Where is my data stored?
Your Tingvar session audio and transcripts are processed in the United States, in Google Cloud's us-central1 region, and we do not currently offer an EU-only processing region. For customers in the UK and the EEA, that means a transfer out of your region. We rely on Standard Contractual Clauses and the safeguards in our DPA. If your procurement requires EU data residency, the honest answer today is that we cannot meet it, and we would rather you knew that before you bought than after.
Do you have SOC 2 or ISO 27001?
No, Tingvar holds no SOC 2 report and no ISO 27001 certificate, and we will not claim a stage of either one that we have not reached. No product in the set we crawled on 23 August 2026 publishes one either. What we do have is published: the controls on the security page, a pre-signed DPA you can read in full without a form, and every sub-processor named including the model vendor. We answer a security questionnaire in five business days.
Reporting something
Reporting a vulnerability
If a control above is a hard requirement and we do not have it, a conversation settles it faster than a questionnaire round trip.