Nine Questions to Ask an AI Transcription Vendor Before You Upload a Recording

ai-transcription-vendor-security-questions

The recorder gets a security review. The transcription tool usually does not. Both end up holding the same conversation — the salary discussion, the legal call, the customer complaint that later becomes a claim.

Transcription has become a default step rather than a decision. Someone drops a recording into a browser tab, a transcript appears, and the meeting moves on. No purchase order, no data protection impact assessment, no entry in the vendor register. By the time anyone asks, the audio has already left.

The questions below are the ones worth asking before that happens. They are deliberately answerable: a vendor who has thought about this can respond to all nine in writing, in a paragraph each. A vendor who cannot is telling you something useful.

Why Transcription Slips Past Vendor Review

Three things make it invisible. It is usually free at the point of use, so no procurement step is triggered. It is adopted by individuals rather than teams, so it never appears on an architecture diagram. And it looks like a utility — the same mental category as a PDF converter — rather than a processor holding hours of unredacted speech.

Recordings are also unusually rich. A document contains what someone decided to write down. A recording contains everything, including the five minutes before the agenda started and the aside that nobody would have put in an email.
codacy-alternatives-2

A recording rarely stops at the vendor. Each hop is a place the audio exists — and a place a deletion request has to reach.

1. Where Does the Recording Physically Sit?

Not “the cloud”. Which provider, which region, and whether that changes under load. If your policy commits you to keeping personal data inside a jurisdiction, this answer either holds that commitment or quietly breaks it.

Ask the same question about the transcript separately. Some products store audio in one region and text in another because the text sits in a managed database somewhere else entirely.

2. How Long Does the Audio Survive After the Transcript Exists?

These are two objects with two lifetimes. The transcript is what you asked for; the audio carries the voice, the tone, and everything said before the meeting formally started. Many vendors keep audio indefinitely because nobody asked them not to.

A good answer names a number. WhoScribe, for example, deletes stored audio after seven days on its free plan and thirty days on the paid one, and publishes those figures rather than describing them as “industry standard retention”. Whatever the number is, you want it in days and in writing.

3. Is My Audio Used to Train Models?

Ask for the answer in the contract, not on the marketing page. If the terms are silent, assume yes and negotiate. This question has two halves that are often answered as one: the vendor’s own models, and whatever model provider sits behind them.

A vendor can honestly say “we do not train on your audio” while sending it to a provider who does. The question you actually need answered is whether anyone in the chain trains on it.

4. Who at the Vendor Can Open My File?

Support engineers usually can, because debugging a failed job means looking at the job. That is not automatically a problem. It becomes one when there is no access log, no approval step, and no way for you to find out afterwards.

5. What Does a Share Link Actually Expose?

Share links are the quiet failure mode. A transcript link forwarded once into an email thread can outlive the project by years, and it keeps working long after the person who created it has left.

Two things matter. Whether the address is guessable — sequential identifiers are still surprisingly common — and whether search engines are told to stay away from it. A shared transcript that gets indexed is not a breach of your systems, but it is a disclosure, and it is one you will have to report.

6. Which Sub-Processors See the Audio?

Most transcription products are a thin layer over someone else’s speech model. That provider is a sub-processor, and your obligations follow the data to it. Ask for the list, and ask how you will be told when it changes — because it will change, usually without an announcement.

7. Does Deletion Delete?

Deletion in the interface often means the row disappears from your view. Ask specifically about backups, job queues, and any copy held by the sub-processor, and ask how long full erasure takes. “Immediately” is usually wrong; “within thirty days including backups” is usually honest.

8. What Happens to a File When the Job Fails?

Failed jobs are where orphaned data accumulates. The upload succeeded, the transcription did not, and the file now sits in a temporary directory that no retention policy describes. Ask whether failed uploads are cleaned on a schedule, and what that schedule is.

9. Can You Get Everything Out?

Export is a security question, not only a convenience one. If leaving is painful, you will stay through an incident you would otherwise have walked away from. Ask for open formats, check that export is self-service, and test it before you need it.

The Checklist

Take this into the call. The right-hand column is what a considered answer sounds like.

Question What a Good Answer Looks Like
Where does the audio sit? Named provider and region, with a note on what happens under load
Where does the transcript sit? Answered separately — often a different system from the audio
Audio retention after transcription A number in days, published, not “industry standard”
Training on customer audio Excluded in the contract, for the vendor and every sub-processor
Internal access Limited, logged, and reviewable by you on request
Share links Unguessable addresses, excluded from search engines, revocable
Sub-processors A published list plus a change notification process
Deletion Covers backups and queues, with a stated completion window
Failed jobs Temporary files removed on a schedule the vendor can describe
Export Open formats, self-service, no support ticket required

Running the Review in Half an Hour

You do not need a full assessment to make this decision. A short, ordered pass gets you most of the way:

  1. Read the retention section of the terms first. If it does not exist, stop — the rest will not be better.
  2. Find the sub-processor list. If it is not published, ask for it in writing before the trial.
  3. Create a transcript and open its share link in a private window. See what a stranger would see.
  4. Delete it, then reopen the link. Confirm what “delete” did.
  5. Export in an open format and check that the file is complete and usable elsewhere.

Steps three and four take five minutes and answer the two questions most likely to produce an incident.

The Ones That Look Boring Are the Ones That Bite

Questions 5, 7 and 8 are the most often skipped. None of them involves an attacker. They are all about data that stayed longer, travelled further, or sat more openly than anyone intended — which is what most reportable incidents actually look like from the inside.

Frequently Asked Questions

Do I Need a DPIA for a Transcription Tool?

If the recordings contain personal data and the processing is systematic, treat it like any other processor and apply your usual threshold. The practical trigger is scale: one interview is a judgement call, transcribing every client call is not.

Is On-Device Transcription Safer?

It removes the network hops, and with them several of these questions. It usually costs accuracy and language coverage. The right choice depends on how sensitive the recordings are, not on which architecture sounds safer in a meeting.

Is SOC 2 or ISO 27001 Enough to Skip These Questions?

No. Those certifications tell you a vendor has controls and follows them. They do not tell you the retention period, the sub-processor list, or what a share link exposes. Ask anyway — a certified vendor will answer quickly.

We Only Transcribe Internal Meetings. Does This Still Apply?

Internal meetings are where compensation, performance and legal exposure get discussed openly. In practice they are often more sensitive than customer calls, not less.

What If the Vendor Will Not Answer in Writing?

That is an answer. A vendor that cannot describe its own retention and sub-processor chain in a paragraph has not written it down internally either.

How Often Should the Review Be Repeated?

Annually, and whenever the sub-processor list changes. The model provider behind a transcription product is the part most likely to change without you noticing.


WhoScribe is a transcription tool for audio and video, operated by LingoScript Ltd in the United Kingdom (company no. 14794098). Its retention periods, export formats and plan limits are published at whoscribe.ai/pricing.

Partners