Security and compliance

Your calls are sensitive. Our security is auditable.

Most AI sales tools ask you to trust a marketing page. Airspeed publishes the audit, the control status, and what each framework actually covers, so your security reviewer can finish the review without waiting on us.

  • SOC 2 Type II, independently audited
  • GDPR and HIPAA compliant
  • Encrypted in transit and at rest

We'll use your details to follow up on your demo request. Privacy policy.

A 30-minute demo and expert Q&A.

Last reviewed 9 September 2026

Airspeed on G2
4.7

out of 5 · across verified G2 reviews

Enterprise-grade security

What Airspeed is certified for

SOC 2 Type II

Independently audited

GDPR

UK and EU data protection

HIPAA

Health information safeguards

Encryption

In transit and at rest

SSO and SAML

Through your own IdP

Open the Trust Center

Live control status and the current reports, published by a third party.

Trusted by 100s of elite revenue teams

FERMÀT
Foleon
PriceFX
Persona
TripleTen
Qdrant
Comply
Netradyne
Autogen
Menlo Security
Speechmatics
Reachdesk
Advantive
GetAccept

Is Airspeed SOC 2 compliant?

Yes. Airspeed holds SOC 2 Type II, and is both GDPR compliant and HIPAA compliant. Call data is encrypted in transit and at rest, authentication runs through SSO and SAML, and the controls behind all of it are monitored continuously rather than assembled once a year for an audit. The current report and live control status are published on the Airspeed Trust Center.

What each framework covers, and what it means for you

A certification badge tells you almost nothing on its own. This is what sits behind each one.

Framework
What it covers
What it means for your team
SOC 2 Type II
An independent auditor tests the controls over a period of time, not on a single day.
Your security team reviews evidence of how the controls behaved, rather than a claim that they exist.
GDPR
UK and EU data protection: lawful basis for processing, data subject rights, and processor obligations.
You can put Airspeed on conversations with EU and UK customers without a separate legal workstream.
HIPAA
Safeguards for protected health information.
Teams selling into healthcare can record and analyse calls that touch patient context.
Encryption
Data is encrypted in transit and at rest.
An intercepted request or a recovered disk does not hand anyone the contents of your calls.
SSO and SAML
Authentication runs through your own identity provider.
Joiners and leavers are handled where you already handle them, not in a second admin console.

Access control

Who can see which calls?

Most call recorders show every call to everyone. Airspeed can follow the access rules you already run.

Mirrored from Salesforce or your org chart

Airspeed can mirror your Salesforce sharing model: org-wide defaults, role hierarchy, territories and manual shares. Or it follows the manager hierarchy in Airspeed. The same rules govern search, Ask Airspeed and analytics, so a chart never leaks a name.

Roles and granular permissions

Owner, admin, user, viewer and restricted roles ship with granular permissions admins can override per role: who can delete calls, see other people's calls or scorecards, edit CRM deals, or view every forecast.

Sessions you can see and revoke

See your active sessions, with browser, OS and location, and end any of them. Admins set a session lifetime for the org, and a login from a new device triggers an email alert.

Personal data redacted at transcription

Pick the categories of personal data Airspeed redacts during transcription, before anything is stored.

How it holds up

Four things a reviewer should check, not take on trust

Audited, not asserted

SOC 2 Type II means an auditor watched the controls operate over a window. The current report and the underlying control status are published on the Airspeed Trust Center, so you can check them yourself instead of taking a sales page at face value.

Monitored continuously

Controls are monitored on an ongoing basis rather than assembled once a year for an audit window. When something drifts, it surfaces as a failing control while it can still be fixed, not at the next renewal.

Access through your IdP

SSO and SAML mean Airspeed does not become a separate list of who works here. Access follows the identity provider your IT team already runs, which is what makes offboarding reliable rather than a checklist item someone has to remember.

Built under UK and EU rules

Airspeed is based in London, so GDPR is the regime the product was designed under rather than a compliance layer added for one market. That is a different starting point from retrofitting EU data protection onto a US-first architecture.

Check the controls yourself

Recording disclosure

How do participants know they are being recorded?

Most notetakers leave the disclosure to the rep. Airspeed does the disclosing, and your admins decide who never gets recorded.

A consent page in seven languages

Every recorded meeting can carry a public consent page with the host, your company name, and dial-in details, in English, French, German, Spanish, Italian, Portuguese, or Dutch. Each consent is logged.

Attached from Outlook in one step

The Airspeed Outlook add-in creates the Teams meeting and adds the consent page to the invite at the same time, so nobody has to remember it.

Announced by voice and in chat

When the Airspeed Notetaker joins, it can announce the recording aloud and in the meeting chat. Your admins set the chat wording for the whole org.

Rules for what never gets recorded

Admins allowlist platforms, block domains and email addresses from ever being recorded, and can exclude internal meetings or default them to private. Reps can limit recording to external, confirmed, or hosted meetings, and default their own calls to private.

Bring your security
reviewer to the demo.

We will walk your team through the controls, the data flow, and anything the Trust Center does not already answer.

Can we stop Airspeed recording certain people or meetings?

Yes. Admins block specific domains and email addresses from ever being recorded, restrict recording to approved meeting platforms, and can switch off internal recording or default internal calls to private. Reps can also limit recording to external, confirmed, or hosted meetings, and set their own calls to private by default.

Is Airspeed SOC 2 compliant?

Yes. Airspeed holds SOC 2 Type II, which means an independent auditor tested the controls over a period of time rather than on a single date. The current report is available on the Airspeed Trust Center.

Is Airspeed GDPR compliant?

Yes. Airspeed is GDPR compliant and is based in London, so UK and EU data protection is the regime the product was built under rather than a later addition.

Is Airspeed HIPAA compliant?

Yes. Airspeed is HIPAA compliant, so teams whose calls touch protected health information can record and analyse them.

Is call data encrypted?

Yes, in transit and at rest. Recordings, transcripts, and the structured fields written back to your CRM are all covered.

Does Airspeed support SSO and SAML?

Yes. Authentication runs through your own identity provider, so access and offboarding follow the system your IT team already operates.

Where can I see the current reports and control status?

On the Airspeed Trust Center, which publishes the compliance reports and the live status of the underlying controls.

Does Airspeed hold ISO 27001?

No. Airspeed holds SOC 2 Type II and is GDPR and HIPAA compliant. ISO 27001 is a separate certification that Airspeed does not currently claim, and this page will say so until that changes.

Can Airspeed follow our Salesforce sharing rules?

Yes. Ask us to switch on record-level access control and Airspeed mirrors your Salesforce sharing model: org-wide defaults, role hierarchy, territories, manual shares and user record access. Settings show the sync state and the last sync time. The same rules apply to search, Ask Airspeed answers and analytics, so nothing a viewer cannot open appears by name.

See Airspeed in action

A 30-minute demo and expert Q&A.

We'll use your details to follow up on your demo request. Privacy policy.

Explore Airspeed

Most AI sales tools tell you what happened on the call. Airspeed does the work after it: your pipeline worked, your CRM updated, your reps coached, your forecast called.