
Otter.ai
Security and trust center evidence
Summary
Otter.ai has 1 registry-verified row and 5 vendor-stated rows in the CertReports index, last verified 17 Sep 2026. The strongest row is HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured). This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.
Reviewer brief
As of 17 Sep 2026, Otter.ai states on its trust centre that it displays a HIPAA badge, though the evidence notes BAA availability has not yet been captured, so a BAA offering cannot be confirmed as of that date. As of 17 Sep 2026, Otter.ai states on its trust centre that it holds SOC 2, though no separate report details are provided in this evidence. As of 17 Sep 2026, Otter.ai states on its trust centre that it complies with GDPR and, separately, with CCPA / CPRA. As of 17 Sep 2026, Otter.ai is listed in the EU-US Data Privacy Framework registry with active EU-US, SW-US, and UK Extension certifications, issued 30 Aug 2018 and expiring 28 Mar 2027. As of 17 Sep 2026, Otter.ai states on its trust centre that it complies with TX-RAMP, and a public subprocessors list with 2 entries is available; no public evidence was found for any other frameworks not listed here.
- HIPAA: as of 17 Sep 2026, Otter.ai states on its trust centre it displays a HIPAA badge; BAA availability not confirmed in evidence.
- SOC 2: as of 17 Sep 2026, Otter.ai states on its trust centre that it holds SOC 2 (no report details provided).
- EU-US Data Privacy Framework: as of 17 Sep 2026, Otter.ai is listed in the DPF registry with active certifications (issued 30 Aug 2018, expires 28 Mar 2027).
Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.
Among communications and cpaas vendors
1verified rows
Category median 1, across 49 indexed communications and cpaas vendors. Otter.ai has more verified rows than 84 percent of them.
collaborationmeeting-notesmeeting-transcriptionreal-time-transcription
Compare with similar vendors
Pick your own comparisonCompliance grid
- HIPAAVendor-stated
Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured)
as of 17 Sep 20261 source
SOC 2Vendor-statedVendor states SOC 2 on its trust centre
as of 17 Sep 20261 source- GDPRVendor-stated
Vendor states GDPR on its trust centre
as of 17 Sep 20261 source
EU-US Data Privacy FrameworkVerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 20261 source- CCPA / CPRAVendor-stated
Vendor states CCPA on its trust centre
as of 17 Sep 20261 source
TX-RAMPVendor-statedVendor states TX-RAMP on its trust centre
as of 17 Sep 20261 source
Legal artefacts
Subprocessors (2)
- FMFirewall Monitoring Virtual Private Cloud
- NINotifications Infrastructure Amazon Web Services
Change history
- 17 Sep 2026CCPA / CPRA evidence addedA CCPA / CPRA row entered the index with state Vendor-stated.
- 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 17 Sep 2026HIPAA evidence addedA HIPAA row entered the index with state Vendor-stated.
- 17 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
- 17 Sep 2026TX-RAMP evidence addedA TX-RAMP row entered the index with state Vendor-stated.
- 17 Sep 2026Subprocessor added: Firewall Monitoring Virtual Private CloudFirewall Monitoring Virtual Private Cloud appeared on the subprocessor list.
- 17 Sep 2026Subprocessor added: Notifications Infrastructure Amazon Web ServicesNotifications Infrastructure Amazon Web Services appeared on the subprocessor list.
Similar vendors with evidence
Related by product tags and the Communications and CPaaS category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.