Transkripsie is built for teams that handle sensitive conversations. This page summarises the controls and capabilities we currently describe publicly. It is not a certification, audit report, or promise that every legal or contractual requirement has been completed.
For security questions, vulnerability reports, or enterprise onboarding, contact security@transkripsie.com. To report a vulnerability, please read our vulnerability disclosure policy first.
Security highlights
- TLS 1.2+ for public traffic and application-level encryption for configured audio and transcript data. Newer media files and newer transcript fields use AES-256-GCM; older files and fields use Fernet (AES-128-CBC with HMAC-SHA256). Not every older file is encrypted yet.
- WebAuthn passkeys, and a one-time code sent by email when an account signs in with a password from a device we have not seen before.
- Administrative and security audit events with configurable retention; the current default for those audit tables is 365 days. Audit records are currently stored in the application database.
- Encrypted backup workflows exist, but immutability, lifecycle retention, alerting, and complete media recovery are still under operational review.
- No independent penetration test has been completed yet.
Compliance
SOC 2 Type II
Not certifiedTranskripsie is not currently SOC 2 Type II certified, and no independent SOC 2 auditor report is being represented here. We are documenting and improving the controls needed for a future assessment.
GDPR
Privacy informationThe Service provides data export, account deletion, and privacy request channels. The Service is provided by myrandomcompany Incorporated, a Delaware corporation. Controller roles, vendor agreements, and international-transfer safeguards must be confirmed for the relevant launch and customer arrangement.
HIPAA
Not currently offeredWe are not currently representing Transkripsie as HIPAA-compliant or offering a Business Associate Agreement. Do not use the Service for PHI on that basis.
EU AI Act (Art. 50)
Information publishedThe AI page describes current AI features and limitations. This information is not a certification or legal conclusion that every use of the Service complies with the EU AI Act.
GDPR tools
Registered users can export all personal data and delete their account from Settings → Security in the dashboard:
- Download my data — ZIP export of profile, transcriptions, segments, and original audio (GDPR Art. 20 portability).
- Delete account — removes active account data according to the Service’s deletion workflow. Backup deletion timing is operationally dependent and no fixed backup-erasure period is promised while that control is under review.
Privacy requests: privacy@transkripsie.com.
Enterprise identity
SSO (SAML / OIDC)
Not yet enabledSingle sign-on through your identity provider (Okta, Microsoft Entra ID, Google Workspace, and others) is built but not enabled in production while we complete a security review. Contact security@transkripsie.com if you need it.
SCIM 2.0 provisioning
On requestAutomated user provisioning and deprovisioning from your IdP, set up with us for enterprise organisations. Contact security@transkripsie.com to discuss.
Email and password sign-in, with optional passkeys, is available to every account today.
Contact
Transkripsie is provided by:
- Seller: myrandomcompany Incorporated, a Delaware corporation, which provides the Transkripsie service.
- Place of registration: Delaware, United States. Delaware file number: Not yet published; it will be added here before paid service is offered.
- Directors and officers: Cornell Basson, sole director
- Business and notice address: 447 Broadway, 2nd FL 2913, New York, NY 10013, United States.
- Address for service of legal documents (registered agent): 1007 N Orange St, 4th Floor Ste 1382, Wilmington, DE 19801, United States.
- Telephone: Not yet published; it will be added here before paid service is offered.
- Email: support@transkripsie.com · Website: transkripsie.com