Security Questions to Ask Any Transcription Vendor
A customer call recording holds more than a customer's question. It holds their name, sometimes their account number, occasionally a health detail mentioned in passing while explaining why they missed a payment. The moment that recording gets uploaded to a transcription tool, a third party has access to whatever the conversation actually contained, unedited.
Most businesses record more than they realize. Sales calls, client interviews, podcast episodes, all-hands meetings, therapy intake sessions, deposition prep. Each one gets sent to some transcription vendor, and almost nobody reads that vendor's security policy before hitting upload. This post is a checklist for reading it, built from a published enterprise security guide and framed so you can apply it to any transcription tool you're evaluating.
Quick Navigation
- Why This Matters for Any Audio You Send Out
- An Early Disclosure
- The Vendor-Evaluation Checklist
- Questions to Add for Regulated Industries
- What BrassTranscripts Publishes About Its Own Practices
- A Parallel Worth Noting
- How to Actually Use This Checklist
- Frequently Asked Questions
Why This Matters for Any Audio You Send Out
Recordings capture whatever was said, and conversations wander. A sales call drifts into a prospect's divorce. A client interview touches a medical diagnosis. A recorded intake call for a financial services firm states an account number out loud. None of that was the point of the recording, and all of it is now sitting on a transcription vendor's server.
The risk isn't hypothetical. A 2024 lawsuit against Otter.ai alleged the company recorded meeting participants and used the resulting data to train its models without proper consent from everyone on the call. That case is a useful reminder of what's actually at stake when a vendor's data practices aren't clear: where your file lives, and what happens to it after the transcript is delivered.
An Early Disclosure
Brass-SEO and BrassTranscripts are both built by Copper Sun Content and Creative, LLC. Same company, two different products for two different jobs: Brass-SEO reads your Google Search Console and GA4 data, BrassTranscripts turns audio and video into text.
That relationship is worth naming up front because BrassTranscripts published the security and privacy guide this checklist is drawn from, and it would be easy to read a Brass-SEO post citing a sister company's guide as a sales pitch dressed up as research. It isn't meant that way. The checklist below applies to any transcription vendor, BrassTranscripts included. Run it against BrassTranscripts the same way you'd run it against Otter.ai, Fireflies, Rev, or whoever else is on your shortlist. A vendor that can't answer these questions clearly is a vendor to think twice about, regardless of which company built it.
The Vendor-Evaluation Checklist
Enterprise security reviews tend to sort vendor requirements into three tiers: things you can't proceed without, things a serious vendor should have, and things that matter only for specific compliance needs. That structure works just as well for a small business picking a transcription tool as it does for an enterprise buyer.
Tier 1: Must-Have Questions
These are non-negotiable regardless of company size.
- How long do you keep my audio file, and how long do you keep the transcript? Get specific numbers, not "we don't keep data longer than necessary."
- Is my data encrypted in transit and at rest? Ask specifically about TLS 1.2 or higher for data in transit, and whether stored files are encrypted at rest.
- Do you use my recordings or transcripts to train your AI models? This is the question most vendors answer vaguely. Push for a direct yes or no.
- Where is my data physically stored? Some businesses have contractual or regulatory requirements about geographic data residency.
Tier 2: Should-Have Questions
A vendor serious about security should be able to answer these without hesitation.
- Do you hold a SOC 2 Type II certification or ISO 27001? These aren't the same as a vendor's own claims about being secure. They're third-party audits.
- Can I export an audit log of who accessed a given file? Complete logs of who accessed what matter if you ever need to demonstrate compliance after the fact.
- What is your documented deletion process? "We delete it" and "here is exactly what happens to the file at deletion, including backups" are different answers.
- Do you have a published breach response policy? Ask what happens, and how fast you'd be notified, if something goes wrong.
Tier 3: Nice-to-Have Questions
These matter more as your volume or sensitivity increases, less for a single occasional file.
- Do you offer private hosting or a dedicated instance?
- Can I supply my own encryption keys?
- Is there an API for pulling compliance reports automatically?
- Can retention be set per file or per project, rather than as one blanket policy?
Questions to Add for Regulated Industries
The base checklist covers general risk. Specific industries carry legal requirements on top of it.
Healthcare. If a recording could contain protected health information, ask whether the vendor will sign a Business Associate Agreement under HIPAA. HIPAA also requires six years of retained access logs and a 60-day breach notification window, so ask whether the vendor's own retention and notification practices meet those thresholds.
Legal. Transcripts of client conversations can become discoverable in litigation, and recording without consent can violate wiretapping laws depending on the state. Ask whether the vendor's retention policy is short enough that old transcripts aren't sitting around waiting to become exhibits, and confirm the vendor understands attorney-client privilege implications before you send anything from a client matter.
Education. For any recording involving students, FERPA requires strict access controls and preserves parental rights for the records of minors. Ask who at the vendor's company can access files involving students, and confirm the answer is a short, named list rather than "the engineering team."
Financial services. SEC recordkeeping rules impose specific retention requirements on communications tied to regulated business. If a transcription vendor auto-deletes files faster than your compliance obligation requires you to keep them, that mismatch is your problem to solve before you adopt the tool, not after.
Every one of these should also prompt you to ask about a Data Processing Agreement, which GDPR and CCPA effectively require whenever a vendor processes personal data on your behalf. If a vendor can't produce a DPA on request, that's a Tier 1 problem no matter what industry you're in.
What BrassTranscripts Publishes About Its Own Practices
Applying the checklist to the vendor that supplied it: BrassTranscripts deletes audio and video files within 24 hours and deletes transcript text within 48 hours. No account is required to use the service, which means no email address or profile data gets collected for a one-off transcription job. A 30-word preview is shown before payment, so you can confirm the transcript quality before you're charged anything. Details on the full range of formats and pricing are on BrassTranscripts' own site.
That's one real example of what a specific, checkable answer to the retention question looks like. It's not a verdict on every other vendor. Some transcription tools keep files indefinitely on their free tiers and only offer configurable retention on paid enterprise plans, which is a legitimate business model choice; it just means you need to ask the retention question rather than assume the answer.
A Parallel Worth Noting
The same evaluation logic applies outside transcription. Brass-SEO connects to a business's Google Search Console and GA4 accounts using OAuth scopes limited to webmasters.readonly and analytics.readonly, so it can read search and traffic data but cannot modify anything in either account. Stored OAuth tokens are encrypted with AES-256-GCM rather than kept as plain text, and Brass-SEO's own data privacy page states directly that conversations are not used to train AI models. Neither fact makes Brass-SEO a transcription vendor, obviously. It's a second example of the same principle: a specific, checkable technical answer beats a general assurance, whether the product in question reads your Google Analytics or transcribes your sales calls. A related post, 5 questions to ask before giving any SEO tool your Google access, walks through that OAuth evaluation in more depth.
How to Actually Use This Checklist
Send the Tier 1 questions to a vendor's sales or support team before you upload anything sensitive, and get the answers in writing. A vendor that answers in specifics — exact retention windows, named certifications, a direct yes or no on AI training — has done the work. A vendor that answers in reassurance instead ("we take security seriously," "your data is safe with us") probably hasn't documented the specifics yet. That gap is worth knowing before you send the first file, not after.
Keep the written answers somewhere you can find them again. If a vendor changes its retention policy or gets acquired six months from now, you want a record of what you were told when you signed up, not a memory of a sales call.
For a one-off transcript of a public webinar, Tier 1 alone is probably enough due diligence. For a healthcare intake call, a client deposition, or a recorded financial advisory session, work through all three tiers and the industry-specific questions before you record a single file. The five minutes it takes to send those questions is small next to the cost of finding out later that a vendor kept files indefinitely, or trained a model on a conversation that was never meant to leave the room.
Frequently Asked Questions
Do I need to ask these questions for every recording, or just sensitive ones?
Ask the Tier 1 questions before adopting any transcription vendor, once, as part of picking the tool. You don't need to re-ask them per file. What changes per file is how much the answers matter: a public webinar transcript tolerates a vendor with looser retention than a recorded client intake call does.
What's the single biggest red flag when evaluating a transcription vendor?
A vague answer to whether your data trains their AI models. Retention windows and encryption are usually stated clearly because they're easy to verify. Training use is the question vendors most often dodge, because the real answer sometimes hurts adoption. If a vendor won't give a direct yes or no, treat that as a Tier 1 failure.
Does a vendor need a SOC 2 certification to be trustworthy?
Not necessarily, especially for a small business sending an occasional file. SOC 2 Type II matters more once volume or sensitivity increases, or once you're answering to a compliance requirement of your own. For a single interview transcript, verified encryption and a clear retention policy usually cover the real risk.
Is BrassTranscripts HIPAA compliant?
This post describes BrassTranscripts' published retention and account practices as one example within the checklist, not a compliance claim. If you're evaluating any vendor, including BrassTranscripts, for use with protected health information, ask directly whether they'll sign a Business Associate Agreement and confirm current certifications with the vendor before sending any file.
How is this different from just reading a vendor's privacy policy?
Privacy policies are written to be broadly true, which often means broadly vague. A specific question like "how many hours until my audio file is deleted" forces a specific answer that a general policy document usually won't give you. Use the policy as a starting point, then ask the Tier 1 questions directly if the policy doesn't already answer them in numbers.