How Astrid protects your firm's data
Reviewed August 19, 2026
Astrid handles call recordings, transcripts, and matter data for law firms, much of it privileged or otherwise sensitive. Here is what we actually do to protect it, and where we're honest that we haven't built or earned something yet.
Where your data lives
Astrid is hosted on Google Cloud Platform, with all application data stored and processed in the United States. We don't operate our own data centers. We rely on Google Cloud's infrastructure and its own security practices for the physical and network layer underneath our application.
Encryption
Data is encrypted in transit between your browser and Astrid, and at rest in our databases and file storage, using Google Cloud's standard encryption for both.
Data isolation between firms
Astrid is a multi-tenant platform: every firm's calls, notes, matters, and client data are logically isolated by firm. Every request for firm data is scoped to the requesting user's own firm at the database layer, not just filtered in the interface; a user at one firm cannot query another firm's data through the application.
Access control within a firm
Within a firm, access follows seat roles: attorney, staff, and firm administrator, plus a separate platform-administrator role for Astrid's own team. A call, note, or transcript marked privileged is restricted to attorney seats and firm administrators. Anyone else sees that it exists without seeing its content. Fields that control authorization, like a user's firm or seat type, are always set by Astrid's own servers and are never something a client request can set directly.
Redaction of personal information
A firm can turn on automatic redaction of categories of personal information from a call transcript. When enabled, redaction happens at transcription time, before the transcript is stored or used to draft a note. The unredacted version is never written to the database.
AI and model training
Astrid uses third-party transcription and AI providers to convert call audio into text and draft notes and recap emails. These providers process your firm's content only to return the output Astrid requested. We do not permit them to use your firm's content to train or improve models for their own or any other customer's benefit.
Approval audit trail
Every note approval records who approved it, their seat role at the time, and when, captured as a permanent snapshot, not a reference that could later be silently changed by, for example, a seat-role change or a deleted account. A locked note can only be edited again through an explicit, logged reopen step by an attorney.
Account security
Sign-in is by email and password today; we don't yet support enterprise single sign-on (SAML/SCIM) or multi-factor authentication as a first-class login method. If your firm needs either of those for a purchase decision, tell us: it helps us prioritize.
Data retention and deletion
We retain a firm's call recordings, transcripts, notes, and matter data for as long as the firm's account is active, and for a reasonable period afterward so the firm can export its records. A firm can request deletion of specific content or its full account at any time; see our Privacy Policy for the full policy.
Security incidents
If we confirm a security incident affecting a firm's data, we will notify that firm promptly and work with them on next steps. We don't have a formal, published notification-time commitment yet. If your firm needs one in writing as part of a vendor agreement, contact us.
Certifications and independent audits
Astrid is an early-stage product. We do not currently hold SOC 2 or any other formal third-party security certification, and we have not yet completed an independent penetration test. We're straightforward about this rather than implying otherwise. If formal certification is a requirement for your firm, let us know where you are in your evaluation and we'll tell you honestly where we stand against it.
Questions
If your firm's security or IT review needs more detail than this page covers, we're glad to get on a call and go through it directly.