Security and privacy
at echory
echory processes live business conversations, including audio, transcripts and AI-generated output. This page sets out the security measures we implement, the sub-processors we engage and the documents that support both. Each statement corresponds to a clause in our contractual documentation.
Last updated 26 August 2026 · Echory GmbH, Düsseldorf, Germany
TLS 1.3
Published documentation
Each document below is the version currently in force. Where an agreement references a specific version, that version applies to that agreement.
Technical and Organisational Measures
The security controls implemented by Echory as data processor, covering access control, encryption, separation, resilience, AI processing, deletion and incident response. Incorporated by reference into every Data Processing Addendum.
Open TOMs v4.0Sub-processor Register
Each sub-processor engaged by Echory, its role, its processing location and the applicable transfer mechanism. Maintained continuously, with a change history and a contractual right to object.
Open the registerLegal Documents
Service Level Addendum, Data Processing Addendum, Data Act Addendum and the Master Services Agreement. Documents cleared for publication are available for download; the remainder are provided on request.
Open legal documentsData Register
The customer data the platform stores, its structure and format, what is exportable on switching and what is exempt as internal functioning. Required under Art. 25 and 26 of the Data Act.
Open the data registerImplemented controls
The following controls are in place and documented in our Technical and Organisational Measures.
Infrastructure
- Hosted on AWS eu-central-1 (Frankfurt). Echory operates no infrastructure of its own
- Private subnets, security groups on default-deny, subnet-level network ACLs
- Physical security is delegated to AWS (ISO 27001, SOC 1/2/3, ISO 27017/27018)
Access control
- Multi-factor authentication enforced on every administrative account
- Unique credentials per person. No shared service accounts
- Need-to-know access, revoked within one business day of departure
Data protection
- AES-256 at rest, TLS 1.3 in transit including the audio stream
- Audio is session-scoped and deleted once transcription completes
- Transcripts and sensitive meeting content carry a dedicated encryption key per tenant
- All personal data deleted within 30 days of contract termination
AI processing
- No sub-processor trains, fine-tunes or improves models on customer data
- Speech-to-text runs through an EU endpoint and remains inside the EEA
- Only data strictly necessary for a given task leaves our infrastructure
Continuity
- Daily automated database snapshots, seven-day retention, encrypted
- Internal recovery targets of four hours (RTO) and 24 hours (RPO)
- Contractual availability and response times are set in the Service Level Addendum
Incident response
- Controllers notified within 24 hours of a confirmed or suspected breach
- Notification covers nature, scope, likely consequences and mitigation
- Post-incident review for every critical and high-severity incident
Independent certification
Echory GmbH does not currently hold an independent security certification of its own. Its infrastructure and AI sub-processors do: AWS is certified to ISO 27001, SOC 1/2/3 and ISO 27017/27018; Deepgram and OpenAI hold SOC 2 Type II, and OpenAI additionally holds ISO 27001. Where a control is delegated to a sub-processor, this page states that it is delegated.
Changes to our sub-processors
Before a new sub-processor begins processing customer personal data, controllers are notified in accordance with the Data Processing Addendum, which sets the notice period and the right to object. The current list, together with its change history, is published on the sub-processor register.
Security and privacy enquiries
Security questionnaires and due diligence requests, questions on processing, sub-processors, deletion requests and data subject rights, requests for the Master Services Agreement, Data Processing Addendum, Standard Contractual Clauses and service levels, and reports of suspected vulnerabilities. We acknowledge every vulnerability report received and take no action against researchers acting in good faith.