close
Security & Privacy

Your recordings belong to you. Period.

Wave is SOC 2 Type 1compliant. Recordings, transcripts, and summaries are encrypted in transit and at rest, never used to train AI models, and can be permanently deleted at any time. Below is exactly how Wave handles your data — and what we will and won’t do with it.

ComplianceSOC 2 Type 1
Encryption in transitTLS 1.2+
Encryption at restAES-256
InfrastructureGoogle Cloud (Firebase / Firestore)
AI training on your dataNever
Data ownership100% yours

SOC 2 Type 1 compliant

Wave’s independent Type 1 report addresses its system description and the suitability of the design of controls relevant to the AICPA Security criteria as of March 1, 2025. As a Type 1 report, it did not test operating effectiveness over a period of time. The full report is openly downloadable — download the SOC 2 Type 1 report (PDF). Read more about what the audit covered in our SOC 2 announcement.

We do not train AI on your data

Your audio, transcripts, and summaries are not used to train speech-recognition or summarization models — and we do not authorize the third-party processors Wave relies on to use your content for training either. This applies on every plan, including the free tier.

Encryption and infrastructure

Recordings and transcripts are encrypted in transit with TLS 1.2+ and at rest with AES-256. Customer data lives in Google Cloud’s Firestore, inside Google’s data centers, under their physical, network, and operational controls. Authentication is industry-standard, with rate limits and audit logging on sensitive actions.

You own and control your data

Every recording, transcript, and summary belongs to you. You can delete individual recordings at any time, or permanently delete your entire account and all data from Settings. Deleted data is removed from active systems and purged from backups on our standard retention cycle. Read the full privacy policy.

What Wave is not for

Wave is not HIPAA compliant. Individuals may use Wave to record their own appointments for personal reference, subject to recording-consent laws. Wave is not for provider, clinical, or other HIPAA-regulated workflows. Recording laws vary by jurisdiction — see our guide to meeting recording laws before recording in regulated contexts.

Reporting a security issue

Email security@wave.co with details. We aim to acknowledge reports within one business day and follow coordinated disclosure on legitimate findings.

Frequently asked

Is Wave SOC 2 compliant?+

Yes. Wave is SOC 2 Type 1 compliant. The independent report addresses Wave's system description and the suitability of the design of controls relevant to the Security criteria as of March 1, 2025. As a Type 1 report, it did not test operating effectiveness over a period of time.

Does Wave train AI models on my recordings or transcripts?+

No. Wave does not use your recordings, transcripts, or summaries to train AI models — on any plan, including the free tier. Your audio and content are not shared with third parties for training.

How is my data encrypted?+

Recordings, transcripts, and summaries are encrypted in transit with TLS 1.2+ and at rest with AES-256 inside Google Cloud's Firestore. Authentication is industry-standard with rate limits and audit logging on sensitive actions.

Where is my data stored?+

Customer data — recordings, transcripts, summaries — is stored in Google Cloud (Firebase / Firestore), inside Google's data centers, under their physical, network, and operational security controls.

Who can see my recordings?+

Only you, and anyone you explicitly share a recording with. Wave employees do not access customer recordings except in narrow, audit-logged cases required for support — and only with your explicit consent.

Can I permanently delete my recordings and account?+

Yes. You can delete individual recordings from inside any Wave app, and you can permanently delete your entire account and all associated data from Settings. Deleted data is removed from active systems and purged from backups on the standard backup retention cycle.

Does Wave support team or enterprise security controls?+

Wave for Teams includes centralized billing and an admin dashboard. For enterprise security needs (SSO, custom retention, custom DPAs), contact support@wave.co.

Is Wave HIPAA compliant?+

Wave is not HIPAA compliant. Individuals may use Wave to record their own appointments for personal reference, subject to recording-consent laws. Wave is not for provider, clinical, or other HIPAA-regulated workflows.

Can I get a copy of Wave's SOC 2 report or sign a DPA?+

Yes. The SOC 2 Type 1 report is openly downloadable from the Wave security page — no NDA required. For a Data Processing Agreement (DPA), email support@wave.co with your company details.

How do I report a security issue?+

Email security@wave.co with details. We aim to acknowledge reports within one business day and follow coordinated disclosure on legitimate findings.

Wave app screenshot showing meeting transcription
Wave AI note taker background pattern
Start today

Wave. Catch every word