Trust centre
Send this page to your security team
A Tingvar session produces a transcript, and that transcript is a record of your company's unresolved strategic weaknesses, spoken aloud and attributed. This page states where it goes, what we hold, and what we do not hold.
What Tingvar does with your session
| Item | What happens | Evidence |
|---|---|---|
| Session audio | Processed while the room is live. No recording is kept. | Your data |
| Transcripts | Kept until you delete them, then gone within 30 days including backups. | Privacy notice |
| Where it runs | The United States. There is no EU processing region today. | Sub-processors |
| Model training | Your sessions are not used to train models. | Sub-processors |
Certification status
We hold no third party assurance report. Nobody in the set we crawled on 23 August 2026 holds one either, and at least one publishes a badge anyway. The table below is what we can evidence today. When a row changes, the date it changed is published here.
| Standard | Status | Evidence |
|---|---|---|
| SOC 2 Type I | No report. We have not engaged an auditor | None to show. The date it is achieved is published here and nowhere else |
| SOC 2 Type II | Not started | None to show |
| ISO 27001 | Not held, and not currently in progress | None to show |
| External penetration test | Not yet commissioned. There is no client application to test | The date and the testing firm are published here once there is one |
| UK GDPR and EU GDPR | We act as controller for account data and as processor for session content | The privacy notice and the pre-signed data processing agreement |
| WCAG 2.2 Level AA | The target for this website. Conformance is not claimed | The accessibility statement, with the known gaps listed by name |
The questions a security review starts with
Who are your sub-processors?
Tingvar publishes every vendor that touches customer data at tingvar.com/subprocessors, including the model vendor, with the jurisdiction each one operates in. The list names the underlying cloud for any vendor that is itself reselling infrastructure, because a list that stops at the reseller tells a reviewer nothing. We give 30 days' notice before a new sub-processor begins processing customer data, and you can subscribe to changes. The page carries an effective date, so you can tell how current it is.
Do you have SOC 2 or ISO 27001?
No, Tingvar holds no SOC 2 report and no ISO 27001 certificate, and we will not claim a stage of either one that we have not reached. No product in the set we crawled on 23 August 2026 publishes one either. What we do have is published: the controls on the security page, a pre-signed DPA you can read in full without a form, and every sub-processor named including the model vendor. We answer a security questionnaire in five business days.
What is your uptime commitment?
Tingvar does not publish an uptime percentage, because we have no operating history to base one on. A number invented before the service has run is not a commitment, it is a guess with a percentage sign on it. There is no status page yet: operational notices and incident updates go out through support, and a status page is scheduled for general availability rather than for launch. When we have enough operating history to write a service level agreement we can keep, we will publish it and date it.
Documents
Every one of these is published, versioned and dated. None of them is behind a form.
| Document | Version | Updated |
|---|---|---|
| Privacy notice | 1.0.0 | 2026-08-24 |
| Terms of service | 1.0.0 | 2026-08-24 |
| Cookie and storage notice | 1.0.0 | 2026-08-24 |
| Data processing agreement | 1.0.0 | 2026-08-24 |
| Sub-processors | 1.0.0 | 2026-08-24 |
| Security | 1.0.0 | 2026-08-24 |
| AI use and limitations | 1.0.0 | 2026-08-24 |
| Billing, cancellation and refunds | 1.0.0 | 2026-08-24 |
| Vulnerability disclosure policy | 1.0.0 | 2026-08-24 |
| Accessibility statement | 1.0.0 | 2026-08-24 |
| Our commitments | 1.0.0 | 2026-08-24 |
| Your data | 1.0.0 | 2026-08-24 |
| Acceptable use policy | 1.0.0 | 2026-08-25 |
| Privacy requests | 1.0.0 | 2026-08-24 |
Security questionnaires
Talk to us before you buy
If your procurement needs EU data residency, single sign-on or an audit log, the honest answer today is that we do not have them. A demo settles quickly whether that is a blocker for you.
Changes
Last reviewed 2026-08-24, and reviewed again quarterly or on any change to the table above.