90 Days Gen AI Risk Trial -Start Now
Book a demo
Audio·Free; Pro $10/mo; Business $19/mo; Enterprise $39/mo·fireflies.ai

Fireflies.ai

Fireflies.ai is a meeting notetaker that joins video calls, transcribes and summarizes, and layers conversation intelligence, analytics, and CRM sync for sales, recruiting, and customer teams.

Risk Score
Medium
4/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Fireflies.ai (fireflies.ai) joins Zoom, Meet, Teams, and Webex meetings via the Fred bot, transcribes conversations, produces AI summaries, and captures topic trackers, sentiment, and talk-time analytics. It syncs to Salesforce, HubSpot, Slack, and Notion, and offers a Rules Engine for admin governance. Fireflies is SOC 2 Type II certified, GDPR compliant, and offers HIPAA BAA on the Enterprise plan with private storage. Key enterprise differentiator: Fireflies states meeting data is never used for AI model training and enforces 0-day retention with vendors and subprocessors. Risk remains around consent, bot auto-join of calendar events, and the wide integration footprint that propagates sensitive conversation content across downstream systems. Enterprise tier unlocks SSO, SCIM, HIPAA, and private storage.

Risk factors

3
  • Transcribes and stores meeting data in the cloud.
  • Potentially sensitive information shared during calls.
  • Requires user consent for data processing.

Recommendations

8
  • Disable bot auto-join for sensitive meeting series (HR, legal, board, M&A)
  • Enforce Enterprise tier for org-wide rollout to gain SSO, SCIM, and private storage
  • Require HIPAA BAA execution before any healthcare team uses Fireflies
  • Block personal Fireflies accounts on corporate email domains
  • Configure Rules Engine to restrict CRM and Slack integrations to approved spaces
  • Announce recording at meeting start and honor participant opt-outs
  • Review talk-time and sentiment analytics use with employment counsel to avoid surveillance claims
  • Audit which meetings Fred has been invited to on a quarterly basis

Data handling

Storage
Meeting audio, video, and transcripts stored with AES-256 at rest and TLS in transit; private storage available on Enterprise tier.
Retention
Zero-day retention with vendors and subprocessors; customer-visible retention governed by plan tier and admin configuration.
Training on inputs
Meeting data is never used for AI model training per vendor commitment.