Wave Is SOC 2 Type 1 Compliant
Wave completed a SOC 2 Type 1 examination covering the design of controls relevant to Security as of March 1, 2025. Here's what that means for you.

We're proud to announce that Wave has achieved SOC 2 Type 1 compliance. The independent auditor’s report addresses Wave’s system description and the suitability of the design of controls relevant to the American Institute of Certified Public Accountants (AICPA) Security criteria as of March 1, 2025.
What Is SOC 2?
SOC 2 (System and Organization Controls 2) is a security framework developed by the AICPA that defines how companies should manage customer data. A Type 1 report evaluates whether a company's security controls are properly designed at a specific point in time. It's not a self-assessment — an independent auditor examines your infrastructure, policies, and procedures and determines whether they meet the bar.
For a company that handles audio recordings, transcripts, and AI summaries of private conversations, this matters. You're trusting us with some of the most sensitive content in your professional life — meetings, phone calls, interviews, and board discussions. The SOC 2 report gives customers an independent opinion on our system description and the design of controls relevant to Security at that point in time.
What We Were Audited On
The SOC 2 framework supports five trust services categories. Wave’s Type 1 examination applied the criteria relevant to Security. Availability, Processing Integrity, Confidentiality, and Privacy were not separate in-scope categories in this report. A Type 1 examination assesses control design at a point in time; it does not test operating effectiveness over a period.
- Security. Protection against unauthorized access to systems and data. This includes network security, access controls, encryption, and monitoring.
Our Security Practices
SOC 2 compliance reflects how we've built Wave from the ground up. Here's what that looks like in practice:
- Encryption everywhere.All data is encrypted both at rest and in transit. Your recordings and transcripts are protected whether they're being stored, transferred, or processed.
- No AI training on your data.Wave never uses your recordings, transcripts, or summaries to train AI models. Your data is yours — we process it to deliver transcription and summaries, and that's it.
- Deletion controls. When you delete a recording, transcript, or summary, it is deleted from our systems at the time of deletion — we do not keep deleted content in backup archives.
- Strict access controls. Access to production systems and customer data is limited to authorized personnel with a legitimate business need. Access is logged and audited.
- Secure infrastructure. Wave runs on Google Cloud infrastructure with native encryption, and we use industry-standard security practices for network isolation, monitoring, and alerting.
Verify It Yourself
We believe in transparency. You can review our security posture and compliance documentation directly:
- Vanta Trust Center — Browse our security practices, policies, and compliance status in real time.
- SOC 2 Type 1 Audit Report — Download the full audit report from our independent auditor.
- Privacy Policy — Read our complete privacy commitments, including how we handle data from technology partners like Google Cloud, OpenAI, and AssemblyAI.
Why This Matters
Most meeting recording tools don't have SOC 2 compliance. Many don't even have a published security policy. If you're recording sensitive conversations — client calls, legal discussions, financial reviews, HR meetings, board sessions — the security of your recording tool should be a hard requirement, not an afterthought.
SOC 2 Type 1 is the starting point, not the finish line. We're continuing to invest in security and are working toward Type 2 compliance, which evaluates the effectiveness of controls over an extended period. We'll share updates as we progress.
If you have questions about our security practices, reach out at privacy@wave.co.
Try Wave free — record, transcribe, and summarize on your phone.
