Security & Compliance

Without security, Whisperit wouldn't exist.

We build for lawyers, so confidentiality is not a feature we added. It is the foundation everything else stands on. Every detail of how we protect your data is published below, and we will gladly answer any question that remains.

Infrastructure

Swiss Hosting

Your data never leaves Switzerland. All Whisperit infrastructure runs on ISO 27001-certified Swiss data centres, subject to Swiss law and independent from US CLOUD Act jurisdiction. No data transfers to third-country servers without explicit consent.

Encryption

AES-256 Encryption

All documents, transcriptions, and case data are encrypted using AES-256 at rest and TLS 1.3 in transit. Encryption keys are managed per-tenant and never shared. Even Whisperit employees cannot read your documents. Your clients' confidential information stays confidential.

AI Safety

Human-in-the-Loop AI Review

Every AI-generated document, draft, or suggestion is explicitly presented for your review before it can be used or sent. Whisperit never auto-sends or auto-files anything on your behalf. You approve each action. This ensures professional accountability and eliminates the risk of unreviewed AI output reaching clients or courts.

Data Ethics

Your Data Never Trains AI Models

Whisperit does not use your documents, cases, voice recordings, or any client data to train, fine-tune, or improve AI models. Your data is exclusively used to serve your firm. We work with AI providers under strict data processing agreements that explicitly prohibit training on customer data.

Compliance

GDPR & nFADP Compliant

Whisperit is fully compliant with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nFADP, in force since September 2023). We act as Data Processor for your client data, and as Data Controller only for account data. Data Processing Agreements (DPAs) are available on request and included in Enterprise contracts.

Certification

SOC 2 Type II (In Progress)

Whisperit is currently undergoing SOC 2 Type II audit by an accredited third-party assessor. We publish a public-facing security page and share audit reports under NDA with Enterprise customers. ISO 27001 certification is also on our roadmap.

Our security commitments

Access control

Role-based access ensures that each team member only sees the cases and documents they need. Audit logs record every access, edit, and export.

Two-factor authentication

All accounts support TOTP-based 2FA. Enterprise plans include SSO via SAML 2.0 and OIDC for integration with your identity provider.

Data residency

By default, all data is stored and processed exclusively in Switzerland. No data is replicated outside Swiss territory without explicit configuration.

Vulnerability management

We conduct regular penetration tests and maintain a responsible disclosure programme. Critical vulnerabilities are patched within 24 hours.

Business continuity

Whisperit maintains automated backups with 30-day retention and a recovery time objective (RTO) of under 4 hours. Enterprise SLAs include uptime guarantees.

On request

The technical data flow documentation

For security teams who need more than a summary. This is the document we hand to IT and compliance reviewers, covering exactly where your data goes and who can reach it.

  • System architecture and hosting environments, region by region
  • Data residency tiers, including Swiss-only processing
  • Every AI provider, what is sent to each, and the fallback chain
  • Sub-processors, their role, and the agreements covering them
  • Retention, deletion, backups, and recovery objectives

Already a Whisperit customer? Open it without the email step

Request the document

Enter your email and we'll send you a link. No sales call required.

Frequently asked questions

The questions security and IT teams ask us most often, answered against our current terms and technical documentation.

Where is my data stored and processed?

Your documents, transcriptions, and case data are stored on Swiss infrastructure in ISO 27001-certified data centres, under Swiss law and outside US CLOUD Act jurisdiction. Where AI processing happens depends on the residency tier your firm is on, which is set out in the next answer and in full in the technical data flow document.

Can I choose where my data is processed?

Yes. We operate three residency tiers. Swiss Only routes every AI feature through a Swiss-hosted provider and never falls back to another jurisdiction: if that provider is unavailable, the request fails rather than rerouting. EU routes through an EU-based provider. Global adds a further international fallback. Your tier is configured per tenant and does not change without your request.

How do you handle AI data privacy?

No AI provider we use trains on your data; our data processing agreements prohibit it. Retention is provider-specific and documented: the Swiss provider deletes data once processing completes, and the EU provider keeps nothing beyond the duration of the API call. The Swiss Only and EU tiers never reroute assistant traffic to another jurisdiction, while the Global tier adds an international fallback for availability. Deep research, which reaches OpenAI in the US, is opt-in and transmits only your search query, never document contents. The full provider-by-provider picture is in the technical data flow document.

What security certifications and compliance do you maintain?

We comply with the EU GDPR and the Swiss nFADP, and we act as data processor for your client data. SOC 2 Type II is currently in audit with an accredited third-party assessor, and ISO 27001 is on our roadmap.

What encryption standards do you use?

AES-256 for data at rest and TLS 1.3 in transit. Encryption keys are managed per tenant and never shared between customers, and data is isolated between firms. Whisperit staff cannot read your documents.

How do you protect attorney-client privilege?

Processing is governed by Swiss law and the nFADP, with role-based access so each team member sees only the matters they need. Audit logs record every access, edit, and export. Our staff are bound by confidentiality obligations under our terms, and access to client data is limited to authorised personnel.

Can I export and delete my data?

You alone hold the rights to your data. During your contract you can request a free export at any time in JSON, CSV, PDF, or the original native format, with documentation of the export schema. After termination you have three months to request your data before we are authorised to destroy it. Write to legal@whisperit.ai for any data request.

How do you ensure confidentiality for legal professionals?

Our terms oblige us to keep confidential everything we learn in the course of working with you, and not to disclose it to third parties without your express authorisation. Sub-processors are published, contractually bound, and listed with the role each one performs, so you can see exactly who can touch your data.

Can I choose or bring my own AI model?

Model routing is configured per tenant by us rather than exposed in the interface, so it cannot be changed accidentally. You can request a different configuration, and we will honour it provided the provider meets the same data protection guarantees. Letting firms select a compliant model directly is on our roadmap; we would rather say that plainly than imply it already ships.

What legal jurisdiction applies to data protection?

Swiss law governs the contract, with jurisdiction at our registered office in Prilly, Switzerland. That places your data under one of the strictest privacy regimes in the world and gives you a predictable forum, independent of US disclosure regimes.

Have security questions?

Our team is happy to walk you through our architecture, share compliance documentation, or arrange a security review.