Security without compromise

Esther Sève, co-founder, presenting data sovereignty and Swiss Transcript's commitments

Transcripts often contain sensitive or confidential information: personal data, medical details, business strategy or private testimony.

Swiss Transcript processes all your data exclusively on secure servers in Switzerland, guaranteeing its confidentiality and protection to the strictest standards.

Swiss Transcript is built on security by design : data confidentiality, integrity and sovereignty are not options bolted on afterwards; they are built into the architecture from the start, at every layer of the service.

Data processing in Switzerland

Hosted at Infomaniak in Geneva (ISO 27001), our only subprocessor. Open-source language models run on our own servers in Switzerland: no OpenAI, no Google, no AWS.

End-to-end encryption

TLS 1.3 in transit, AES-256 at rest, unique per-customer keys sealed in TPM modules. No black box: every step is documented.

FADP and GDPR compliance

Compliant with the Swiss FADP and the European GDPR; DPA and technical measures (TOM) accepted at sign-up. Notification of any incident within 72 hours, right to audit.

Two-factor authentication option

OTP app, FIDO2 key or biometrics: 2FA is available to all users and mandatory for Enterprise account administrators.

Immediate file deletion

An uploaded audio or video file is deleted automatically and permanently from our servers once transcription is complete. Transcripts and minutes remain under your control until you delete them; on Enterprise, a specific retention period can be set on request.

No content access by our staff

Encryption keys are derived from your password: nobody at Swiss Transcript can read your recordings, transcripts or minutes. Technically impossible.

The life cycle of your files

We only delete automatically the audio you already hold a copy of.

Your device

Phone or browser

Live recording

The only copy of the audio is in the device's browser: listen to it or export it from that device. The copy sent for transcription is deleted automatically.

Computer

Uploaded audio or video file

Your original stays with you. The copy sent is deleted automatically once the transcript is generated.

Encrypted transfer

Our servers, in Switzerland

temporary

Audio

in your account

Transcript and minutes

Deleted automatically once the transcript is generated (uploaded file, live recording)

Accessible from any device until you delete them.

Teams

Meeting recorded by our bot

The bot lives on our servers: the recording is created there, not on your device. As you have no copy, we do not delete it automatically: you delete it, or an automatic purge set on request does.

The logic: audio you already have (uploaded file, recording on your phone) has no reason to be kept with us. Teams audio exists only with us, so we keep it available to you. Can't find a file? See the FAQ →

Two-factor authentication (2FA)

Mobile authenticator app

Use the authenticator app of your choice to generate OTP (one-time password) access codes.

FIDO U2F security key

We support FIDO U2F physical security keys. Compatibility with YubiKey, Nitrokey and Token2 keys is ensured.

Biometric recognition

Biometric authentication, such as fingerprint or facial recognition, can also be used to access your account if your hardware supports it.

Regulatory compliance

Swiss Transcript complies with the strictest data protection regulations

GDPR compliance

GDPR

Compliant with the European Union's General Data Protection Regulation: regulated collection, storage and processing.

Swiss FADP

Swiss FADP

Compliant with the Federal Act on Data Protection (revised FADP), which governs processing by private parties and federal bodies.

Technological independence

Technological independence

Servers in Switzerland, no external cloud (Amazon, Google, Azure) or OpenAI. No data trains an AI model.

What we commit to, and what we don't do

Concrete, auditable commitments, written for IT, legal and data protection officers.

Never any training on your data

Your recordings and transcripts are never used to train models, neither by us nor by any third party. It is written in the DPA.

Audio deleted, retention under control

The uploaded file is deleted once transcription is complete. On Enterprise (from 50 h per month), a specific retention period can be set on request, for example an automatic purge after 7 days.

Your data stays yours

Full self-service export, per user. Logical separation of customers, 2FA available. 60 days' notice for any change of subprocessor.

Vendor file ready

DPA, technical and organisational measures (TOM), NDA and risk questionnaire, provided to your IT or legal department on request.

ISO 27001: where we stand

Not yet certified; our measures are aligned with the standard and formalised in the TOM. Our host is certified and audited every year.

No on-site installation

No on-premise, and we don't plan to offer it. We provide a sovereign Swiss cloud; if your own premises are a requirement, we are not the right solution.