Security and compliance
Your calls are sensitive. Our security is auditable.
Most AI sales tools ask you to trust a marketing page. Airspeed publishes the audit, the control status, and what each framework actually covers, so your security reviewer can finish the review without waiting on us.
- SOC 2 Type II, independently audited
- GDPR and HIPAA compliant
- Encrypted in transit and at rest
We'll use your details to follow up on your demo request. Privacy policy.
A 30-minute demo and expert Q&A.
Last reviewed 9 September 2026
out of 5 · across verified G2 reviews
Enterprise-grade security
What Airspeed is certified for
SOC 2 Type II
Independently audited
GDPR
UK and EU data protection
HIPAA
Health information safeguards
Encryption
In transit and at rest
SSO and SAML
Through your own IdP
Live control status and the current reports, published by a third party.
Trusted by 100s of elite revenue teams
Is Airspeed SOC 2 compliant?
Yes. Airspeed holds SOC 2 Type II, and is both GDPR compliant and HIPAA compliant. Call data is encrypted in transit and at rest, authentication runs through SSO and SAML, and the controls behind all of it are monitored continuously rather than assembled once a year for an audit. The current report and live control status are published on the Airspeed Trust Center.
What each framework covers, and what it means for you
A certification badge tells you almost nothing on its own. This is what sits behind each one.
Access control
Who can see which calls?
Most call recorders show every call to everyone. Airspeed can follow the access rules you already run.
Mirrored from Salesforce or your org chart
Airspeed can mirror your Salesforce sharing model: org-wide defaults, role hierarchy, territories and manual shares. Or it follows the manager hierarchy in Airspeed. The same rules govern search, Ask Airspeed and analytics, so a chart never leaks a name.
Roles and granular permissions
Owner, admin, user, viewer and restricted roles ship with granular permissions admins can override per role: who can delete calls, see other people's calls or scorecards, edit CRM deals, or view every forecast.
Sessions you can see and revoke
See your active sessions, with browser, OS and location, and end any of them. Admins set a session lifetime for the org, and a login from a new device triggers an email alert.
Personal data redacted at transcription
Pick the categories of personal data Airspeed redacts during transcription, before anything is stored.
How it holds up
Four things a reviewer should check, not take on trust
Audited, not asserted
SOC 2 Type II means an auditor watched the controls operate over a window. The current report and the underlying control status are published on the Airspeed Trust Center, so you can check them yourself instead of taking a sales page at face value.
Monitored continuously
Controls are monitored on an ongoing basis rather than assembled once a year for an audit window. When something drifts, it surfaces as a failing control while it can still be fixed, not at the next renewal.
Access through your IdP
SSO and SAML mean Airspeed does not become a separate list of who works here. Access follows the identity provider your IT team already runs, which is what makes offboarding reliable rather than a checklist item someone has to remember.
Built under UK and EU rules
Airspeed is based in London, so GDPR is the regime the product was designed under rather than a compliance layer added for one market. That is a different starting point from retrofitting EU data protection onto a US-first architecture.
Recording disclosure
How do participants know they are being recorded?
Most notetakers leave the disclosure to the rep. Airspeed does the disclosing, and your admins decide who never gets recorded.
A consent page in seven languages
Every recorded meeting can carry a public consent page with the host, your company name, and dial-in details, in English, French, German, Spanish, Italian, Portuguese, or Dutch. Each consent is logged.
Attached from Outlook in one step
The Airspeed Outlook add-in creates the Teams meeting and adds the consent page to the invite at the same time, so nobody has to remember it.
Announced by voice and in chat
When the Airspeed Notetaker joins, it can announce the recording aloud and in the meeting chat. Your admins set the chat wording for the whole org.
Rules for what never gets recorded
Admins allowlist platforms, block domains and email addresses from ever being recorded, and can exclude internal meetings or default them to private. Reps can limit recording to external, confirmed, or hosted meetings, and default their own calls to private.
Bring your security
reviewer to the demo.
We will walk your team through the controls, the data flow, and anything the Trust Center does not already answer.
Can we stop Airspeed recording certain people or meetings?
Yes. Admins block specific domains and email addresses from ever being recorded, restrict recording to approved meeting platforms, and can switch off internal recording or default internal calls to private. Reps can also limit recording to external, confirmed, or hosted meetings, and set their own calls to private by default.
Is Airspeed SOC 2 compliant?
Yes. Airspeed holds SOC 2 Type II, which means an independent auditor tested the controls over a period of time rather than on a single date. The current report is available on the Airspeed Trust Center.
Is Airspeed GDPR compliant?
Yes. Airspeed is GDPR compliant and is based in London, so UK and EU data protection is the regime the product was built under rather than a later addition.
Is Airspeed HIPAA compliant?
Yes. Airspeed is HIPAA compliant, so teams whose calls touch protected health information can record and analyse them.
Is call data encrypted?
Yes, in transit and at rest. Recordings, transcripts, and the structured fields written back to your CRM are all covered.
Does Airspeed support SSO and SAML?
Yes. Authentication runs through your own identity provider, so access and offboarding follow the system your IT team already operates.
Where can I see the current reports and control status?
On the Airspeed Trust Center, which publishes the compliance reports and the live status of the underlying controls.
Does Airspeed hold ISO 27001?
No. Airspeed holds SOC 2 Type II and is GDPR and HIPAA compliant. ISO 27001 is a separate certification that Airspeed does not currently claim, and this page will say so until that changes.
Can Airspeed follow our Salesforce sharing rules?
Yes. Ask us to switch on record-level access control and Airspeed mirrors your Salesforce sharing model: org-wide defaults, role hierarchy, territories, manual shares and user record access. Settings show the sync state and the last sync time. The same rules apply to search, Ask Airspeed answers and analytics, so nothing a viewer cannot open appears by name.
Explore Airspeed
Most AI sales tools tell you what happened on the call. Airspeed does the work after it: your pipeline worked, your CRM updated, your reps coached, your forecast called.
The platform
For your team
Learn and compare