Trust Center

Security and privacy
at echory

echory processes live business conversations, including audio, transcripts and AI-generated output. This page sets out the security measures we implement, the sub-processors we engage and the documents that support both. Each statement corresponds to a clause in our contractual documentation.

Last updated 26 August 2026 · Echory GmbH, Düsseldorf, Germany

Data residency
European Union
AWS eu-central-1, Frankfurt. Personal data remains within the EEA except where disclosed in the sub-processor register.
Encryption
AES-256
TLS 1.3
AES-256 at rest on the AWS storage layer. TLS 1.3 for all HTTPS and WebSocket connections.
AI model training
Excluded by contract
Language model data is excluded from training by the provider’s API terms. Speech-to-text training is disabled at account level.
Tenancy
Key per tenant
Customer data is scoped by tenant identifier, and transcripts and sensitive meeting content carry a dedicated encryption key per tenant.
Security practices

Implemented controls

The following controls are in place and documented in our Technical and Organisational Measures.

Infrastructure

  • Hosted on AWS eu-central-1 (Frankfurt). Echory operates no infrastructure of its own
  • Private subnets, security groups on default-deny, subnet-level network ACLs
  • Physical security is delegated to AWS (ISO 27001, SOC 1/2/3, ISO 27017/27018)

Access control

  • Multi-factor authentication enforced on every administrative account
  • Unique credentials per person. No shared service accounts
  • Need-to-know access, revoked within one business day of departure

Data protection

  • AES-256 at rest, TLS 1.3 in transit including the audio stream
  • Audio is session-scoped and deleted once transcription completes
  • Transcripts and sensitive meeting content carry a dedicated encryption key per tenant
  • All personal data deleted within 30 days of contract termination

AI processing

  • No sub-processor trains, fine-tunes or improves models on customer data
  • Speech-to-text runs through an EU endpoint and remains inside the EEA
  • Only data strictly necessary for a given task leaves our infrastructure

Continuity

  • Daily automated database snapshots, seven-day retention, encrypted
  • Internal recovery targets of four hours (RTO) and 24 hours (RPO)
  • Contractual availability and response times are set in the Service Level Addendum

Incident response

  • Controllers notified within 24 hours of a confirmed or suspected breach
  • Notification covers nature, scope, likely consequences and mitigation
  • Post-incident review for every critical and high-severity incident
Certification

Independent certification

Echory GmbH does not currently hold an independent security certification of its own. Its infrastructure and AI sub-processors do: AWS is certified to ISO 27001, SOC 1/2/3 and ISO 27017/27018; Deepgram and OpenAI hold SOC 2 Type II, and OpenAI additionally holds ISO 27001. Where a control is delegated to a sub-processor, this page states that it is delegated.

Changes to our sub-processors

Before a new sub-processor begins processing customer personal data, controllers are notified in accordance with the Data Processing Addendum, which sets the notice period and the right to object. The current list, together with its change history, is published on the sub-processor register.

Contact

Security and privacy enquiries

Security, privacy and contractual enquiries
security@echoryflow.com

Security questionnaires and due diligence requests, questions on processing, sub-processors, deletion requests and data subject rights, requests for the Master Services Agreement, Data Processing Addendum, Standard Contractual Clauses and service levels, and reports of suspected vulnerabilities. We acknowledge every vulnerability report received and take no action against researchers acting in good faith.