Snapshot 54888
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Noota Trust Center We prioritize system security and customer privacy at every stage of the engineering process. Noota runs on enterprise-grade infrastructure with security, performance, and reliability at its core. We apply a security-by-design approach and encrypt all customer data — recordings, transcripts, emails, and metadata — at rest and in transit. Our systems are continuously monitored and updated to ensure full data protection. Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation. Skip to main content Noota Trust Center We prioritize system security and customer privacy at every stage of the engineering process. Noota runs on enterprise-grade infrastructure with security, performance, and reliability at its core. We apply a security-by-design approach and encrypt all customer data — recordings, transcripts, emails, and metadata — at rest and in transit. Our systems are continuously monitored and updated to ensure full data protection. ⌘K OverviewDocumentationControlsSubprocessors Loading content... Certifications Trusted by Shotgun Bouygues Group Accor Carrefour FONCIA AMI PARIS Adsearch Harry Hope Trust center by Wolfia: AI trust center & security questionnaire automation Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers Documentation Certifications ISO/IEC 27001 Certificate Security Noota Software Application System Description External Penetration Testing Report External Penetration Testing Report Security Assurance Plan Subprocessors Bastion Technologies · France Bastion Technologies is used to manage our cyber security and compliance. France Brevo · France Email Marketing France Gladia · Europe Transcription Services Europe Google Cloud Platform · Europe Infrastructure Hosting Europe Mistral AI · France LLM service France Controls Data security Protects customer information through strong encryption and logical separation measures. Encryption in transit Data isolation Customer data ownership Restricted internal access Encryption at rest Data lifecycle management Gives customers granular control over how long data is kept and how it is permanently removed. Customisable data retention periods Permanent deletion within 24 hours Default 30-day archive for free accounts Contract-termination purge Zero-retention post-deletion policy Access control Ensures only authorised users and organisations can reach sensitive resources. Role-based access control Single sign-on integration Private workspaces by default Meeting-level recording control Explicit internal access approval Frequently asked security questions Is Noota secure? Noota operates this public trust center. It publishes 6 independent compliance certifications, security documentation available on request, and a published list of its subprocessors. Is Noota SOC 2 compliant? Yes. Noota maintains SOC 2 Type II compliance. You can review this in the compliance section of this trust center. Does Noota have ISO 27001 certification? Yes. Noota is ISO 27001 certified. You can review this certification in the compliance section of this trust center. Is Noota GDPR compliant? Yes. Noota maintains GDPR compliance. See the compliance section of this trust center for details. Who are Noota's subprocessors? Noota discloses its subprocessors in this trust center, including Bastion Technologies, Brevo, and Gladia. See the subprocessors section for the complete list. How do I request Noota's security documentation? You can request access to Noota's security documentation directly through this trust center. Submit an access request and the Noota team reviews and grants access. Trust center by Wolfia: AI trust center & security questionnaire automation Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers Controls Data security Protects customer information through strong encryption and logical separation measures. Encryption in transit Every connection to the service is secured with tls 1.2/1.3, preventing eavesdropping or tampering as data moves between users and the platform. Data isolation Each customer’s transcripts, audio and metadata are fully segregated from other tenants, preventing cross-tenant access and strengthening confidentiality. Customer data ownership Customers retain full legal ownership of their content and can require its removal at any time, reinforcing control and compliance with contractual obligations. Restricted internal access Internal staff may view customer data only when explicitly authorised by the client, with all access logged for accountability. Encryption at rest All stored customer data is protected using aes-256 encryption, reducing the risk of unauthorized disclosure if physical media are compromised. Data lifecycle management Gives customers granular control over how long data is kept and how it is permanently removed. Customisable data retention periods Enterprise administrators can set retention from 1 day to 3 years, aligning storage practices with internal policies and regulations. Permanent deletion within 24 hours When a meeting is deleted, all copies in production and backups are irreversibly erased in under 24 hours, minimising residual risk. Default 30-day archive for free accounts Free plans automatically archive content after 30 days, ensuring data is not kept longer than necessary. Contract-termination purge Upon contract end, all customer data is purged unless otherwise agreed, preventing unnecessary retention. Zero-retention post-deletion policy No cold storage or delayed deletion is performed once data is removed, eliminating lingering copies. Access control Ensures only authorised users and organisations can reach sensitive resources. Role-based access control Owner, admin and member roles provide least-privilege permissions that match job responsibilities across the organisation. Single sign-on integration Enterprise customers can connect corporate identity providers for centralised user authentication and streamlined off-boarding. Private workspaces by default Each user’s recordings remain private unless they choose to share, protecting confidentiality out of the box. Meeting-level recording control Users or admins can disable the service for specific meetings, preventing accidental capture of sensitive conversations. Explicit internal access approval Support or devops staff may only access content when clients share a secret identifier, ensuring oversight of privileged actions. Privacy and compliance Demonstrates alignment with european privacy law and transparent personal-data handling. GDPR compliance The platform meets eu data protection obligations, including eu-only hosting, lawful processing and support for all data-subject rights. Appointed data protection officer A designated dpo oversees privacy governance and serves as a point of contact for regulators and customers. Data protection impact assessments DPIAs are conducted for sensitive use cases, ensuring risks are identified and mitigated before processing begins. Data-subject rights fulfilment within 30 days Requests for access, deletion, portability or objection are honoured in no more than 30 days, helping customers meet legal timelines. No customer data used for AI training Transcripts, audio and metadata are never fed into internal models, preventing unintended reuse of personal information. Infrastructure security Leverages certified cloud environments and strict geographic controls to safeguard operations. EU-only hosting for EU customers European user data is stored exclusively in belgian and dutch data centres, supporting regional sovereignty requirements. Certified cloud provider Production runs on a cloud platform that maintains iso 27001 and soc 2 attestations, adding independent validation of foundational controls. Separated backup storage Backups are held in physically and logically distinct locations from production systems, reducing correlated failure risk. Incident response Provides a structured approach to detect, contain and communicate security events. Documented incident response plan Clear procedures guide investigation, containment and remediation activities to minimise business impact. Regulatory breach notification Affected customers are informed in accordance with laws such as GDPR, supporting transparency and legal compliance. Post-incident review process Every incident is audited and lessons learned are fed back into controls, driving continuous improvement. Backup and recovery Maintains resilient copies of critical metadata while limiting unnecessary replication of sensitive content. Four-hour backup frequency Metadata is backed up every four hours, limiting potential data loss in the event of system failure. Encrypted backup storage All backup files are encrypted and isolated, preventing compromise if backup repositories are accessed. One-year metadata retention limit Backed-up metadata is retained for up to a year, balancing recovery needs with privacy obligations. No content data in backups by default Audio and transcript files are excluded from routine snapshots unless contractually agreed, reducing exposure of sensitive material. Third-party management Controls how service providers handle customer information and limits downstream risk. Data processing agreements All subprocessors operate under strict dpas that define security and privacy obligations, extending protections beyond the core platform. Zero-retention requirement for processors Third-party services are contractually barred from storing customer data longer than necessary, lowering residual exposure. Quarterly review of third-party access logs Access by processors is logged and reviewed every quarter, ensuring continued compliance with contractual terms. Audit and assurance Provides independent verification and continuous oversight of the security programme. Semi-annual internal security audits Comprehensive internal reviews are performed every six months to evaluate control effectiveness. Annual third-party penetration testing External specialists test the platform each year, identifying vulnerabilities before they can be exploited. Centralised audit logging All user and administrator actions are captured for forensic analysis and compliance reporting. User privacy controls Empowers customers to tailor privacy-sensitive features to their organisational policies. Automated recording notifications Participants are automatically informed that a session is being recorded, supporting transparency and consent requirements. Organisation-wide sentiment analysis toggle Administrators can disable sentiment analysis across all workspaces, limiting processing of potentially sensitive insights. On-demand anonymised reporting Users may request anonymised versions of transcripts, enabling safer information sharing with broader audiences. Documentation Certifications ISO/IEC 27001 Certificate Security Noota Software Application System Description External Penetration Testing Report External Penetration Testing Report Security Assurance Plan Information Security Policy Acceptable Use Policy Access Control Policy Authentication and Password Policy Backup and Restore Policy Data Classification Policy Encryption Policy Information Security Communication Plan Information Security Management System Policy Information Security Management System Scope Information Security Policy Policies CHS User Front-End Architecture Diagram Anti-Corruption and Influence Peddling Policy Business Continuity and Disaster Recovery Plan Change Management Plan Change Management Policy Code of Conduct Policy Data Disposal Policy Data Retention Policy Documented Information Control Procedure Human Resources Policy Information Security Management System Roles and Responsibilities Information Security Objectives ISMS Continuous Improvement Procedure AI Ethics Implementation Guide Corporate Social Responsibility Policy Corporate Social Responsibility Officer Designation Code of Conduct Privacy & Legal Privacy Policy Terms & Conditions EU Artificial Intelligence Act Qualification Analysis Data Processing Agreement Bastion Technologies · France Bastion Technologies is used to manage our cyber security and compliance. France Brevo · France Email Marketing France Gladia · Europe Transcription Services Europe Google Cloud Platform · Europe Infrastructure Hosting Europe Mistral AI · France LLM service France Recall · Europe Meeting Services Europe Scaleway · France Infrastructure Hosting France Loading content... Updates Subprocessors