Last updated: August 11, 2026
At ConvertAudioToText, the security and privacy of your data is a top priority. We implement industry-standard security measures to ensure your files, transcripts, and personal information are protected at every stage.
All data is encrypted in transit using TLS 1.2+ (HTTPS). Files stored in our cloud storage are encrypted at rest using AES-256 encryption. API communications between our services are encrypted end-to-end.
We follow strict data minimization principles for file handling:
Our infrastructure is hosted on industry-leading cloud providers with SOC 2 compliance. File storage uses encrypted object storage with built-in redundancy. Our managed database has automated backups and point-in-time recovery.
ConvertAudioToText is not itself SOC 2 or ISO 27001 certified, and we do not claim to be. The infrastructure we build on carries those certifications for the hosting and storage layers: Cloudflare for the edge network and object storage, Hetzner for application and database hosting. Payments are handled by our Merchant of Record, who is PCI DSS compliant. For GDPR, ReachUp LTD is the data controller; every subprocessor we use, what data it receives, and where it processes that data is listed on our subprocessors page.
Access to production systems is restricted to authorized personnel only. We use role-based access control, multi-factor authentication, and audit logging for all administrative access. Your transcripts are accessible only to you through authenticated API calls.
We use a third-party AI engine for transcription processing. It processes audio data in real time and does not retain your audio after processing. Payment processing is handled by our Merchant of Record, who is PCI DSS compliant.
If you discover a security vulnerability, please report it responsibly by emailing security@convertaudiototext.com. We take all reports seriously and will respond within 48 hours.