Security & Privacy

Your recordings belong to you. Period.

Wave is SOC 2 Type 1 compliant. Recordings, transcripts, and summaries are encrypted in transit and at rest, never used to train AI models, and can be permanently deleted at any time. Below is exactly how Wave handles your data — and what we will and won’t do with it.

ComplianceSOC 2 Type 1
Encryption in transitTLS 1.2+
Encryption at restAES-256
InfrastructureGoogle Cloud (Firebase / Firestore)
AI training on your dataNever
Data ownership100% yours

SOC 2 Type 1 compliant

Wave’s independent Type 1 report addresses its system description and the suitability of the design of controls relevant to the AICPA Security criteria as of March 1, 2025. As a Type 1 report, it did not test operating effectiveness over a period of time. The full report is openly downloadable — download the SOC 2 Type 1 report (PDF). Read more about what the audit covered in our SOC 2 announcement.

We do not train AI on your data

Your audio, transcripts, and summaries are not used to train speech-recognition or summarization models — and we do not authorize the third-party processors Wave relies on to use your content for training either. This applies on every plan, including the free tier.

Encryption and infrastructure

Recordings and transcripts are encrypted in transit with TLS 1.2+ and at rest with AES-256. Customer data lives in Google Cloud’s Firestore, inside Google’s data centers, under their physical, network, and operational controls. Authentication is industry-standard, with rate limits and audit logging on sensitive actions.

You own and control your data

Every recording, transcript, and summary belongs to you. You can delete individual recordings at any time, or permanently delete your entire account and all data from Settings. Deleted data is removed from our systems at the time of deletion — we do not keep deleted content in backup archives. Read the full privacy policy.

What Wave is not for

Wave is not HIPAA compliant. Individuals may use Wave to record their own appointments for personal reference, subject to recording-consent laws. Wave is not for provider, clinical, or other HIPAA-regulated workflows. Recording laws vary by jurisdiction — see our guide to meeting recording laws before recording in regulated contexts.

Reporting a security issue

Email security@wave.co with details. We aim to acknowledge reports within one business day and follow coordinated disclosure on legitimate findings.

Frequently asked

Is Wave SOC 2 compliant?+

Yes. Wave is SOC 2 Type 1 compliant. The independent report addresses Wave's system description and the suitability of the design of controls relevant to the Security criteria as of March 1, 2025. As a Type 1 report, it did not test operating effectiveness over a period of time.

Does Wave train AI models on my recordings or transcripts?+

No. Wave does not use your recordings, transcripts, or summaries to train AI models — on any plan, including the free tier. Your audio and content are not shared with third parties for training.

How is my data encrypted?+

Recordings, transcripts, and summaries are encrypted in transit with TLS 1.2+ and at rest with AES-256 inside Google Cloud's Firestore. Authentication is industry-standard with rate limits and audit logging on sensitive actions.

Where is my data stored?+

Customer data — recordings, transcripts, summaries — is stored primarily in Google Cloud (Firebase / Firestore), inside Google's data centers, under their physical, network, and operational security controls. Limited data is also processed by the subprocessors listed in our DPA at wave.co/dpa — for example, session text is indexed for search.

Who can see my recordings?+

Only you, and anyone you explicitly share a recording with. Wave employees do not access customer recordings except in narrow, audit-logged cases: support (with your explicit consent), investigating abuse or a security incident, or where the law requires it.

Can I permanently delete my recordings and account?+

Yes. You can delete individual recordings from inside any Wave app, and you can permanently delete your entire account and all associated data from Settings. Deleted data is removed from our systems at the time of deletion — Wave does not retain deleted content in backup archives, so once deleted it cannot be recovered.

Does Wave support team or enterprise security controls?+

Wave for Teams includes centralized billing and an admin dashboard. For enterprise security needs (SSO, custom retention, custom DPAs), contact support@wave.co.

Is Wave HIPAA compliant?+

Wave is not HIPAA compliant. Individuals may use Wave to record their own appointments for personal reference, subject to recording-consent laws. Wave is not for provider, clinical, or other HIPAA-regulated workflows.

Can I get a copy of Wave's SOC 2 report or sign a DPA?+

Yes. The SOC 2 Type 1 report is openly downloadable from the Wave security page — no NDA required. Wave's standard Data Processing Addendum is published at wave.co/dpa and applies automatically to business use; for a countersigned copy, email privacy@wave.co with your company details.

How do I report a security issue?+

Email security@wave.co with details. We aim to acknowledge reports within one business day and follow coordinated disclosure on legitimate findings.

Wave app screenshot showing meeting transcription
Wave AI note taker background pattern