AI notetaker security checklist: 7 checks to run before you trust one
Last updated August 17, 2026
Run seven checks on any AI notetaker before bringing it to work: consent visibility, who processes your audio, how long recordings are kept, what deletion removes, how voiceprints are handled, whether actions need approval, and whether subprocessors are disclosed. Each check below explains what good looks like, then answers it for Audria.
1. Is consent visible?
The person running the tool should agree to processing before it starts, and anyone nearby should be able to tell the tool’s state from the screen. For Audria: a one time consent sheet appears before anything you say or type is processed, and capture always shows its state, including a paused pill when a call or another app takes the microphone.
2. Who processes your audio?
Your recordings pass through the vendor and usually through the vendor’s providers as well, and you should be able to find out which companies those are. For Audria: the security page names who processes transcript content, what each party sees, and where.
3. How long are recordings kept?
Ask what happens to audio over time and whether the answer is written down anywhere you can cite. For Audria: you can delete any single memory from its detail screen at any time, and deleting your account removes stored audio permanently once the 30 day grace window completes.
4. What does deletion actually remove?
A vague promise to remove data on request tells you little; an enumerated list tells you what survives. For Audria: account deletion removes everything held under your account, including voiceprints and stored audio, after the 30 day grace window completes.
5. How are voiceprints handled?
Any tool that recognises speakers holds some representation of your voice, so check whether the vendor says what happens to it and whether removing it takes a separate request. For Audria: your voiceprint is deleted with your account, with nothing separate to file.
6. Do actions wait for approval?
A notetaker that can send email or file tickets is acting on your behalf, so ask what can run without you. For Audria: nothing runs until you tap Run, and risky steps ask for an extra per step confirmation.
7. Are subprocessors disclosed?
A subprocessor list tells you who else you are trusting when you trust the vendor, and a tool that will not publish one leaves this checklist incomplete. For Audria: the subprocessor table is published on the security page, with the purpose, data, and region for each entry.
Frequently asked questions
What should I check before using an AI notetaker at work?
Seven things: consent visibility, who processes your audio, how long recordings are kept, what deletion removes, how voiceprints are handled, whether actions need approval, and whether subprocessors are disclosed.
Does Audria publish a subprocessor list?
Yes. The Audria security page includes a subprocessor table listing each company, its purpose, the data it sees, and its region.