You choose where your conversations live.

Noota captures what your organisation says out loud. That makes security the foundation of the product, not a feature of it. We are ISO 27001 certified and SOC 2 Type II, and you decide — at workspace level — whether Noota runs on our standard European infrastructure or on the fully sovereign one.

ISO 27001

SOC 2 Type II

GDPR

EU datacenter

Privately hosted AI

SSO & SAML

The only meeting AI where you pick the infrastructure.

Every other platform decides for you: one cloud, one set of models, one jurisdiction.

Noota ships two complete environments and lets your security team choose the one that clears their review, without giving up a single feature.

Public bodies

Banks & insurers under DORA

Health & legal

Groups that refuse EU transfers

0

Non-conformities at our ISO 27001 audit

100%

MFA coverage on internal access

99.9%

Uptime on core services

2

Independent penetration tests last cycle

Two environments. Your call, not ours.

The choice is made when the workspace is created and can be changed later. Same product, same features — what changes is where it runs and which models it is allowed to reach.

standard

This is some text inside of a div block.

The default for most teams. Everything stays in the EU, with the full model range available. Outbound calls display your own number, and nothing is held back from the feature set.

Google Cloud
MongoDB Atlas
Vertex AI
Claude
Gemini
Mistral

sovereign

This is some text inside of a div block.

For regulated and public-sector work. European sub-processors only, open-weight models hosted in the EU, and no transfer outside the European Union at any hop. Voice runs through Telnyx, so outbound calls mask your number — the honest trade-off.

Scaleway
Telnyx
Mistral
Kimi
GLM
Open weights

The compliance register

What we hold, what is under way, and what belongs to our providers rather than to us. Every line links to the evidence behind it.

ISO/IEC 27001

Certified — Jul 2026

Information security management. Scope: our SaaS meeting intelligence platform, across six departments.

SOC 2 Type II

Certified — 2026

Security, availability, confidentiality and privacy, evidenced over an observation period rather than at a point in time.

GDPR

Compliant — Ongoing

DPA, records of processing and a full sub-processor list. Consent management built into the product, not bolted on.

DORA

In progress — 2026

Digital Operational Resilience Act. Alignment work under way for financial-sector customers and their ICT third-party register.

EU hosting

Standard — Ongoing

Data and AI processing stay inside the European Union on both environments, with no transfer outside it in the sovereign one.

Sovereign deployment

Your choice — Ongoing

European sub-processors only, with its own security assurance plan and its own disaster recovery plan.

HDS / HIPAA

Provider-level — Ongoing

Our cloud providers hold these certifications. Noota itself does not — we host on infrastructure that meets those requirements.

Three things we never do

Most of this page describes controls. This part describes decisions — the ones that do not change with a plan, a price or a customer.

Never train

Your conversations are not used to train our models, or anyone else's, on any plan including Free. In the standard environment, frontier models are reached only through the Vertex AI gateway; in the sovereign one, open-weight models run on European infrastructure.

Never sell

No data brokerage, no advertising, no enrichment resold to a third party. Our revenue comes from subscriptions and nothing else.

Never share

Sub-processors are limited to what running the service requires, and every one of them is listed — per environment — in the trust center before you sign anything.

The controls behind it

Audited under ISO 27001, operated every day, reviewed on a schedule rather than when someone asks.

Encryption

Encrypted end to end of the pipeline

256-bit AES for data at rest, TLS 1.2 and 1.3 in transit, with keys managed in the cloud provider's KMS. Recordings, transcripts, emails and metadata are covered alike.

Isolation

Environments that never touch

Development, test and production are fully separated, and all three sit in European datacenters. No customer data ever reaches a non-production environment.

Identity

Your directory, your rules

SSO with Azure AD and SAML, automatic provisioning and de-provisioning, and role-based access on your side of the boundary.

Internal access

Least privilege, reviewed quarterly

100% MFA coverage through Google Workspace SSO, twelve-character passwords with special characters, and access rights reviewed every quarter.

Testing

Broken into on purpose

Two independent penetration tests were run over the last audit cycle, with remediation verified at re-test and no findings left open. Vulnerability scans run annually.

Continuity

Restores we have actually run

Disaster recovery plans exist in standard and sovereign versions. Point-in-time restore of the production database was last tested in July 2026. Above 99.9% uptime on core services.

Trust center

Everything documented, before you ask.

EU AI Act compliance badge

Conforme all'AI Act

GDPR compliance badge

Conforme al GDPR

ISO 27001 compliance badge

Pratiche allineate alla norma ISO 27001

CCPA compliance badge

Conforme al CCPA

Certificazione SOC 2 Type II

ISO 27001 compliance badge

Conforme alla norma ISO 27001

Certificazione SOC 2 Type II

EU data hosting compliance badge

Architettura abilitata SecNumCloud

EU AI Act compliance badge

Conforme all'AI Act

SSL compliance badge

Analisi dei bias

GDPR compliance badge

Conforme al GDPR

CCPA compliance badge

Conforme al CCPA

FAQ

Can I really choose my infrastructure?

Yes, and it is the point of this page. The choice is made when the workspace is created and can be changed afterwards. Both environments run the same product; what differs is the hosting, the sub-processors and the models each one is allowed to reach.

Where is my data stored?

In the European Union in both cases. The standard environment runs on Google Cloud EU regions with MongoDB Atlas; the sovereign one runs on Scaleway in Paris, with voice through Telnyx, and no transfer outside the EU at any hop.

Which AI models can reach my content?

In the standard environment: Mistral, plus Claude and Gemini reached exclusively through the Google Vertex AI gateway — never directly from a model vendor, so processing stays inside our contracted cloud perimeter. In the sovereign environment: Mistral and open-weight models such as Kimi and GLM, running on European infrastructure. Nothing is sent to a US-controlled endpoint.

Do you train on my conversations?

No. Not on any plan, not on Free, not for evaluation, not for fine-tuning. Your content is never used to train our models or anyone else's.

How do I get your DPA?

Our data processing agreement is available to customers and prospects on signature of an NDA. Request it and we will send the current version, along with the sub-processor table for the environment you are on. dpo@noota.io

How long do you keep my data?

Business and Enterprise customers set their own retention, from one day to three years. By default data is kept for the length of the contract and deleted when the account is. On the Free plan, data is archived after one month.

Can I keep the text without the recording?

Yes. Text-only mode drops the audio and video and keeps the transcript, and an administrator can enforce it across the whole organisation so no recording is ever stored.

Are you ready for DORA?

Our DORA alignment work is under way. We already supply the contractual and register information financial-sector customers need for their ICT third-party inventory — ask us and we will walk your team through where we stand.

How do I report a vulnerability?

Write to security@noota.io. We acknowledge every report and we do not pursue researchers acting in good faith.