Wave is SOC 2 Type 1compliant. Recordings, transcripts, and summaries are encrypted in transit and at rest, never used to train AI models, and can be permanently deleted at any time. Below is exactly how Wave handles your data — and what we will and won’t do with it.
Wave’s independent Type 1 report addresses its system description and the suitability of the design of controls relevant to the AICPA Security criteria as of March 1, 2025. As a Type 1 report, it did not test operating effectiveness over a period of time. The full report is openly downloadable — download the SOC 2 Type 1 report (PDF). Read more about what the audit covered in our SOC 2 announcement.
Your audio, transcripts, and summaries are not used to train speech-recognition or summarization models — and we do not authorize the third-party processors Wave relies on to use your content for training either. This applies on every plan, including the free tier.
Recordings and transcripts are encrypted in transit with TLS 1.2+ and at rest with AES-256. Customer data lives in Google Cloud’s Firestore, inside Google’s data centers, under their physical, network, and operational controls. Authentication is industry-standard, with rate limits and audit logging on sensitive actions.
Every recording, transcript, and summary belongs to you. You can delete individual recordings at any time, or permanently delete your entire account and all data from Settings. Deleted data is removed from active systems and purged from backups on our standard retention cycle. Read the full privacy policy.
Wave is not HIPAA compliant. Individuals may use Wave to record their own appointments for personal reference, subject to recording-consent laws. Wave is not for provider, clinical, or other HIPAA-regulated workflows. Recording laws vary by jurisdiction — see our guide to meeting recording laws before recording in regulated contexts.
Email security@wave.co with details. We aim to acknowledge reports within one business day and follow coordinated disclosure on legitimate findings.
Yes. Wave is SOC 2 Type 1 compliant. The independent report addresses Wave's system description and the suitability of the design of controls relevant to the Security criteria as of March 1, 2025. As a Type 1 report, it did not test operating effectiveness over a period of time.
No. Wave does not use your recordings, transcripts, or summaries to train AI models — on any plan, including the free tier. Your audio and content are not shared with third parties for training.
Recordings, transcripts, and summaries are encrypted in transit with TLS 1.2+ and at rest with AES-256 inside Google Cloud's Firestore. Authentication is industry-standard with rate limits and audit logging on sensitive actions.
Customer data — recordings, transcripts, summaries — is stored in Google Cloud (Firebase / Firestore), inside Google's data centers, under their physical, network, and operational security controls.
Only you, and anyone you explicitly share a recording with. Wave employees do not access customer recordings except in narrow, audit-logged cases required for support — and only with your explicit consent.
Yes. You can delete individual recordings from inside any Wave app, and you can permanently delete your entire account and all associated data from Settings. Deleted data is removed from active systems and purged from backups on the standard backup retention cycle.
Wave for Teams includes centralized billing and an admin dashboard. For enterprise security needs (SSO, custom retention, custom DPAs), contact support@wave.co.
Wave is not HIPAA compliant. Individuals may use Wave to record their own appointments for personal reference, subject to recording-consent laws. Wave is not for provider, clinical, or other HIPAA-regulated workflows.
Yes. The SOC 2 Type 1 report is openly downloadable from the Wave security page — no NDA required. For a Data Processing Agreement (DPA), email support@wave.co with your company details.
Email security@wave.co with details. We aim to acknowledge reports within one business day and follow coordinated disclosure on legitimate findings.

Product
Social Media
Use Cases
Compare
All rights reserved
Made with love in New York City