Every field is source-linked and dated.See the rubric behind the grades.

How we grade
Sovereign AI Registry
ExploreBlogGov accessCertsCountries

Footer

Sovereign AI Registry

The compliance registry for AI vendors. Data residency, training defaults, retention, subprocessors and EU AI Act posture — one row per vendor, product and deployment, every claim linked to its source.

Registry

  • Explore vendors
  • Deployment models
  • Categories
  • Countries

Compliance

  • Gov access exposure
  • EU AI Act roles
  • Certifications

Resources

  • FAQ
  • Methodology
Built with ShipMore·Build yours →

© 2026 Sovereign AI Registry. All rights reserved.

  1. Explore
  2. Fireflies.ai notetaker
FN

Fireflies.ai notetaker

Sovereignty grade D (40/100). No EU residency; no training on your data. Fireflies.ai, United States.

Category
meeting-ai
Deployments
Hosted API
Certifications
SOC 2 Type II
Government access exposure
US CLOUD Act
Countries
United States
Categories
meeting-ai
EU AI Act role
provider

Details

Deployment
hosted
Hq Country
United States
Hq City
San Francisco
Ownership
private
Founded
2016
Trust Center Url
trust.fireflies.ai
Training Default
never
Residency Options
United States, private storage options for enterprise
Gov Access Exposure
us-cloud-act
Eu Ai Act Role
provider
Certs
SOC 2 Type II
DPA available
yes
Zero Retention Available
Yes
Retention Default
A zero-data-retention policy for meeting content: audio, video, transcripts and summaries are "not stored by any third-party vendor after processing", not accessible to a vendor once the service completes, and not used to train internal or external models. Account-level personal information is kept while the account is active.
Retention Exceptions
Fireflies is the only row in the registry that addresses voice as a biometric identifier: where voice data counts as a "biometric identifier" or "biometric information" it maintains a written retention schedule and destroys it once the collection purpose is satisfied or within three years of the individual's last interaction, whichever comes first. That is a BIPA-shaped commitment rather than a GDPR one, but it is a real published schedule and nothing else in this category has one.
Subprocessors
AssemblyAI (US, transcription), Soniox (US, transcription), OpenAI (US), Anthropic (US), Groq (US), Perplexity (US), Exa (US), ElevenLabs (US), Google Cloud Platform (US), Amazon Web Services (US), MongoDB Atlas, turbopuffer, GitHub, Google Workspace, New Relic, Heap, Apollo.io (US)
Subprocessor Count
17
Transfer Mechanism
none-stated
Eu Procurement Ready
fail
Eu Procurement Reason
The clearest illustration in the registry of why a good sub-processor list is a service to the buyer even when the answer is bad. Fireflies publishes seventeen named sub-processors with a live trust centre, and reading it shows a recorded meeting passing through two independent transcription vendors and five separate LLM vendors, every one of them American. The zero-retention policy is real and unusually specific, the biometric retention schedule is the only one of its kind here, and neither changes the jurisdiction: no EU residency is offered, no Chapter V transfer mechanism is named, and the number of US entities with a technical path to the audio is the highest in this batch. A European buyer should read the list before the marketing page, in that order.
Training Evidence Url
fireflies.ai/privacy
Training Claim Basis
stated
Training Confidence
high
Residency Evidence Url
fireflies.ai/security
Residency Claim Basis
inferred
Residency Confidence
medium
Retention Evidence Url
fireflies.ai/privacy
Retention Claim Basis
stated
Retention Confidence
high
Subprocessors Evidence Url
trust.fireflies.ai/subprocessors
Subprocessors Claim Basis
stated
Subprocessors Confidence
high
Residency Class
non-eu-only
Portability / Exit Path
proprietary-only
Subprocessor Jurisdiction
non-eu
Underlying model providers
AssemblyAI and Soniox (transcription), OpenAI, Anthropic, Groq (LLM), Perplexity and Exa (LLM search), ElevenLabs (audio)
At a glance
Governance Grade
D
Governance Score
40
EC SOV-2 Legal & Jurisdictional (0-4)
0
EC SOV-3 Data & AI (0-4)
1
Website

Similar

Read AI · Sep 2026

RARead AI meeting assistant

Sovereignty grade F (24/100). No EU residency. Read AI, United States.

meeting-ai
Governance Grade
F
Fathom · Aug 2026

FAFathom AI notetaker

Sovereignty grade D (35/100). No EU residency. Fathom, United States.

meeting-ai
Governance Grade
D
Granola · Sep 2026

GAGranola AI notepad

Sovereignty grade D (30/100). No EU residency. Granola, United States.

meeting-ai
Governance Grade
D

More Deployments

  • Hosted API68
  • Self-hosted weights6
  • On-premise6
  • Private VPC2

More Certifications

  • SOC 2 Type II46
  • ISO 2700136
  • ISO 4200113
  • ISO 270177
  • ISO 277017
  • ISO 270186
  • HDS5
  • HIPAA4
  • CSA STAR4
  • C54
  • ISO 90013
  • PCI DSS3
  • FedRAMP High3
  • ISO 27001:20223
  • SOC 2 (type unverified)2
  • ISO 500012
  • BSI C52
  • SOC 32
  • FedRAMP2
  • GDPR2
  • CSA STAR Level 12

More Government access exposure

  • US CLOUD Act44
  • No non-EU government access27
  • Mixed jurisdiction9
  • PRC National Intelligence Law2

More Countries

  • United States45
  • Germany9
  • France7
  • Switzerland5
  • Singapore3
  • Israel2
  • United Kingdom2
  • China2
  • Netherlands2

More Categories

  • Coding assistant15
  • meeting-ai13
  • Sovereign host13
  • Inference host13
  • SaaS-embedded11
  • Foundation model11
  • Cloud platform7

More EU AI Act role

  • Deployer59
  • General-purpose AI (GPAI)10
  • provider9
  • GPAI with systemic risk5