cd /news/ai-products/granola-enterprise-security-what-is-… · home topics ai-products article
[ARTICLE · art-83867] src=zackproser.com ↗ pub= topic=ai-products verified=true sentiment=· neutral

Granola Enterprise Security: What Is Documented

Granola, an AI note-taking app, documents a SOC 2 Type II certification, encryption in transit and at rest, US AWS hosting, and an organization-wide model-training opt-out, but states it is not HIPAA compliant, cannot sign Business Associate Agreements, and offers no regional data residency outside the US. The app captures audio locally but sends it to transcription providers like Deepgram and AssemblyAI and AI providers like OpenAI and Anthropic, with notes stored in Granola's US-hosted AWS environment. Security teams should evaluate these documented capabilities and ask specific questions about subprocessors, retention, and admin controls during procurement.

read4 min views2 publishedAug 2, 2026
Granola Enterprise Security: What Is Documented
Image: Zackproser (auto-discovered)

Granola has a credible enterprise-security baseline: SOC 2 Type II, encryption in transit and at rest, United States AWS hosting, SSO for qualifying Enterprise workspaces, sharing controls, retention settings, and an organization-wide model-training opt-out.

It also has material constraints. Granola says it is not currently HIPAA compliant, cannot sign Business Associate Agreements, and does not offer regional data residency outside the United States. Security teams should evaluate the documented product rather than an imagined on-premises version.

The real data flow

"Runs locally" describes capture, not the entire processing path.

  • The Granola desktop app captures microphone and system audio on the user's device.
  • Audio is sent over encrypted connections to transcription providers such as Deepgram and AssemblyAI.
  • Granola sends transcript and note context to AI providers such as OpenAI and Anthropic to create enhanced notes.
  • The resulting transcript and notes are stored in Granola's US-hosted AWS environment.
  • Granola says meeting audio is not retained after transcription.

The desktop client caches notes locally for responsiveness and offline editing, but the service depends on cloud processing. Network allowlists, subprocessor review, and cross-border transfer analysis belong in the procurement process.

Security claims Granola currently documents

Area Current documented position
Independent assurance SOC 2 Type II; report available through the Trust Center
Encryption Data encrypted in transit and at rest
Hosting AWS servers in the United States
Meeting audio Processed for transcription and not retained after transcription
Notes and transcripts Stored until deleted or covered by an auto-deletion policy
Authentication Google or Microsoft authentication; Enterprise SSO for organizations with 50+ seats
MFA Enforced through the identity provider, not a Granola-native password system
Sharing Notes private by default; organization controls available on Enterprise
Model training User opt-out on Free and Business; organization-wide opt-out on Enterprise
Regional residency No EU, UK, Canada, or Australia residency option currently documented
HIPAA Not currently HIPAA compliant; no BAA

These points can change. Request the current SOC 2 report, subprocessor list, Data Processing Addendum, and product answers during every material vendor review.

Questions the security page cannot answer for you

A certification does not replace architecture and policy review. Ask Granola and your internal owners:

  • Which meeting categories and data classifications are allowed?
  • Which subprocessors receive audio, transcripts, notes, or metadata?
  • What happens when a user opts out of model improvement?
  • How are transcripts removed from primary storage and backups?
  • Can admins enforce sharing restrictions and transcript retention centrally?
  • How are Enterprise API keys scoped, logged, and rotated?
  • Which events appear in administrative audit data?
  • What support and incident-notification commitments are contractual?
  • Do your identity-provider controls enforce MFA, session lifetime, and offboarding?
  • Do Zapier, CRM, Slack, Notion, MCP, or API exports create a second retention path?

Answers should come from current documentation or contract language, not a marketing comparison.

HIPAA and medical data

Granola's own 2026 security guidance says the product is not HIPAA compliant and cannot sign a BAA. Healthcare organizations should not use it to store or process protected health information. SOC 2 Type II does not change that conclusion.

If a healthcare company wants Granola for non-clinical meetings, the compliance team should define a narrow scope that excludes PHI and confirm that participants can follow it in practice. A policy that depends on everyone remembering never to mention a patient may be too fragile for routine use. Retention and sharing deserve special attention

Granola retains notes and transcripts unless the user or administrator configures deletion. Transcript auto-deletion can remove transcripts after a selected period while leaving enhanced notes in place. That may reduce raw-transcript exposure, but the remaining notes can still contain sensitive meeting content.

Notes begin private. Users can share them directly, add them to team folders, generate links, or send them through integrations. Enterprise restrictions help, but a security review should follow the data into every connected destination.

A sensible pilot

Start with a small group and low-sensitivity internal meetings. Configure identity-provider MFA, model-training preferences, sharing restrictions, and transcript retention before the first call. Test deletion and offboarding instead of assuming they work as expected.

During the pilot, review:

  • whether consent is consistently obtained;
  • whether prohibited data appears in notes;
  • whether generated summaries overstate decisions;
  • where users export or share notes;
  • whether the retention period matches policy;
  • whether support and audit evidence meet procurement needs.

My recommendation

Granola is a reasonable candidate when an organization accepts US cloud processing, does not require HIPAA coverage, and wants a bot-free note-taking workflow. Regulated or data-residency-sensitive teams should resolve those gaps before a pilot.

── more in #ai-products 4 stories · sorted by recency
── more on @granola 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/granola-enterprise-s…] indexed:0 read:4min 2026-08-02 ·