← Back to blog
Wave Team

Wave Is SOC 2 Type 1 Compliant

Wave has achieved SOC 2 Type 1 compliance, verifying that our systems meet rigorous standards for security, availability, and confidentiality. Here's what that means for you.

Wave Is SOC 2 Type 1 Compliant

We're proud to announce that Wave has achieved SOC 2 Type 1 compliance. This certification, issued by an independent auditor, verifies that our systems and processes meet the standards established by the American Institute of Certified Public Accountants (AICPA) for security, availability, processing integrity, confidentiality, and privacy.

What Is SOC 2?

SOC 2 (System and Organization Controls 2) is a security framework developed by the AICPA that defines how companies should manage customer data. A Type 1 report evaluates whether a company's security controls are properly designed at a specific point in time. It's not a self-assessment — an independent auditor examines your infrastructure, policies, and procedures and determines whether they meet the bar.

For a company that handles audio recordings, transcripts, and AI summaries of private conversations, this matters. You're trusting us with some of the most sensitive content in your professional life — meetings, phone calls, interviews, medical appointments. SOC 2 compliance means our handling of that data has been independently verified.

What We Were Audited On

The SOC 2 framework covers five trust service criteria. Our audit evaluated Wave against all of them:

  • Security. Protection against unauthorized access to systems and data. This includes network security, access controls, encryption, and monitoring.
  • Availability. Systems are operational and accessible as committed. This covers uptime, disaster recovery, and incident response.
  • Processing Integrity. System processing is complete, valid, accurate, and timely. Your recordings are transcribed correctly and delivered reliably.
  • Confidentiality. Data designated as confidential is protected as committed. Your recordings, transcripts, and summaries are not accessible to unauthorized parties.
  • Privacy. Personal information is collected, used, retained, disclosed, and disposed of in conformity with our privacy commitments. See our full Privacy Policy for details.

Our Security Practices

SOC 2 compliance reflects how we've built Wave from the ground up. Here's what that looks like in practice:

  • Encryption everywhere. All data is encrypted both at rest and in transit. Your recordings and transcripts are protected whether they're being stored, transferred, or processed.
  • No AI training on your data. Wave never uses your recordings, transcripts, or summaries to train AI models. Your data is yours — we process it to deliver transcription and summaries, and that's it.
  • Permanent deletion. When you delete a recording, transcript, or summary, it's permanently removed from our servers. No soft deletes, no hidden backups. Gone is gone.
  • Strict access controls. Access to production systems and customer data is limited to authorized personnel with a legitimate business need. Access is logged and audited.
  • Secure infrastructure. Wave runs on Google Cloud infrastructure with native encryption, and we use industry-standard security practices for network isolation, monitoring, and alerting.

Verify It Yourself

We believe in transparency. You can review our security posture and compliance documentation directly:

  • Vanta Trust Center — Browse our security practices, policies, and compliance status in real time.
  • SOC 2 Type 1 Audit Report — Download the full audit report from our independent auditor.
  • Privacy Policy — Read our complete privacy commitments, including how we handle data from technology partners like Google Cloud, OpenAI, and AssemblyAI.

Why This Matters

Most meeting recording tools don't have SOC 2 compliance. Many don't even have a published security policy. If you're recording sensitive conversations — client calls, legal discussions, medical appointments, HR meetings, board sessions — the security of your recording tool should be a hard requirement, not an afterthought.

SOC 2 Type 1 is the starting point, not the finish line. We're continuing to invest in security and are working toward Type 2 compliance, which evaluates the effectiveness of controls over an extended period. We'll share updates as we progress.

If you have questions about our security practices, reach out at privacy@wave.co.

Try Wave free — record, transcribe, and summarize on your phone.

Wave app screenshot showing meeting transcription
Wave AI note taker background pattern
Start today

Wave. Catch every word

Wave Logo