New Universal-3.5 Pro is here. Learn more: Async Realtime
Security

Protecting your data is our priority

AssemblyAI uses enterprise-grade security practices to keep your data safe. We approach security by design and default.

Security

Your data stays yours

Every request follows the same path: audio in, transcript out, nothing left behind. You control how long anything is kept, and the default is not for long.

Audio received

Processed in memory over an encrypted connection

Transcript delivered

Returned to you via API response or webhook

Data deleted

Audio and transcripts are not stored after processing

Zero data retention

Enable zero data retention and your audio files and transcripts are never stored after processing.

Opt out of model training

Your data is never used to train or improve our models when you opt out. One setting, enforced across every API.

Encrypted end to end

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256, across all environments.

Compliance

Independently verified

Our controls are audited by independent third parties. The latest evidence, reports, and updates always live in our trust center.

SOC 2 Type 2 report

We maintain a SOC 2 Type 2 report covering security, availability, and confidentiality, audited annually by an independent firm. Download the latest report anytime in our trust center.

Penetration tests and vulnerability scans

We conduct annual third-party penetration tests and run vulnerability scans on a regular cadence across our infrastructure and applications.

Practices

Defense in depth

Security is not one control, it is layers of them. From how engineers reach production to how we ship code and select vendors, each layer is built to hold on its own.

Access control

Role-based access, SSO, and least-privilege permissions govern access to production systems.

Infrastructure security

Hardened cloud infrastructure with network isolation and continuous configuration monitoring.

Monitoring and logging

Centralized logging and continuous monitoring detect and alert on anomalous activity.

Incident response

A documented incident response process with defined roles, escalation paths, and post-incident reviews.

Secure development

Code review, dependency scanning, and security checks are built into our development lifecycle.

Vendor management

Third-party vendors are reviewed for security posture before and throughout engagement.

Deployment options

The same security, wherever you run

Run on our fully managed cloud or inside your own environment. The controls, defaults, and guarantees stay the same either way.

Common questions