90 Days Gen AI Risk Trial -Start Now
Book a demo
Audio·Free; Pro $8.33/mo; Business $19.99/mo; Enterprise custom·otter.ai

Otter.ai

Otter.ai is a meeting transcription assistant that joins Zoom, Meet, and Teams calls, produces live transcripts and summaries, and integrates with Salesforce, HubSpot, and Slack.

Risk Score
Medium
5/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Otter.ai (otter.ai) auto-joins calendar meetings via its OtterPilot agent, captures audio, and produces searchable transcripts, summaries, action items, and workflow outputs. It is SOC 2 Type II attested, certified under EU-US/UK-US/Swiss-US Data Privacy Frameworks for GDPR-grade transfers, and offers HIPAA compliance with BAA on the Enterprise plan. Enterprise risk centers on consent and scope: OtterPilot can auto-join any meeting on a user's calendar, recording confidential HR, legal, M&A, or customer conversations without all-party consent. Otter trains models on de-identified audio and transcriptions unless the user opts out via the transcript-rating flow. Business-tier and above support unlimited meetings; HIPAA requires Enterprise and an executed BAA.

Risk factors

3
  • Cloud-based service with third-party data handling
  • Default training on meeting transcripts without clear opt-out
  • Integration with other platforms may expose sensitive data

Recommendations

8
  • Disable OtterPilot auto-join and require explicit host consent per meeting
  • Block personal Otter accounts on corporate domains; enforce SSO on Enterprise tier
  • Require HIPAA BAA on Enterprise before any healthcare or PHI-bearing use
  • Train staff on two-party/all-party consent laws and announce recording at meeting start
  • Disable training opt-in by default via admin policy and user education
  • Restrict Salesforce, HubSpot, and Slack integrations to approved channels
  • Exclude HR, legal, board, and M&A meeting series from Otter calendar access
  • Configure custom retention policy and review auto-join scope quarterly

Data handling

Storage
Audio, transcripts, and derived outputs stored on AWS US infrastructure; EU/UK/Swiss data transferred under Standard Contractual Clauses and Data Privacy Framework.
Retention
Retained as long as necessary for service purposes or legal obligations; custom retention policies available on paid plans.
Training on inputs
Models trained on de-identified audio and transcriptions; users may opt out by declining permission in the transcript-quality rating flow.