Company profile

Granola

Trust Center, Security, DPA, Subprocessors, and AI Data Usage Evidence

Granola has a maturing public trust surface for an AI meeting-notes product. The baseline profile records official public surfaces such as Trust Center, Security, Privacy, DPA, Subprocessor reference, SOC 2 / compliance claims, AI data usage, and enterprise feature references. This is a public evidence baseline, not a security assessment, compliance certification, buying-intent claim, or vendor recommendation.

Evidence surface Observed public source What it means What not to infer
Trust Center Observed public Trust Center or trust portal Buyer assurance surface Not proof of current buying intent or security quality
Security Observed security page or security documentation Security review surface Not implementation verification
DPA Observed DPA or legal terms reference Legal review surface Not a GDPR compliance determination
Subprocessors Observed subprocessor reference or list Vendor review surface Verify the live list before relying on it
AI data usage Observed AI policy, data usage language, or product documentation Model-training and data-handling review relevance Not implementation verification
Privacy Observed privacy policy or privacy documentation Privacy review surface Not legal compliance determination
Category AI SaaS / meeting notes and productivity
Evidence status Candidate signal
Last checked 2026-06-27

Public evidence lookup surfaces

These rows summarize reviewed public evidence fields for each company profile. They show observed and not-promoted surfaces without making security, compliance, or buying-intent conclusions.

Evidence surface Review status Observed public source What it means What not to infer
Trust Center Observed during review Source URL observed Customer-assurance surface Not proof of trust maturity, security quality, certification, or buying intent
Security Observed during review Source URL observed Security review surface Not implementation verification or control operating effectiveness
Privacy Observed during review Source URL observed Privacy review surface Not legal compliance determination
Terms / Legal Not observed during review No standalone public source promoted in this review Contract and legal review surface Not legal sufficiency or compliance determination
DPA Observed during review Source URL observed Data processing legal review surface Not GDPR compliance proof
Subprocessors Observed during review Source URL observed Vendor and data-flow review surface Verify the live list before relying on it
Certification / compliance claim review Observed during review Observed field without standalone URL in this profile Assurance packaging or public claim review surface Not independent audit validation or current certification proof
AI policy / data usage Observed during review Source URL observed Model-training and data-handling review relevance Not implementation verification or model-risk conclusion
Enterprise-readiness evidence Observed during review Observed field without standalone URL in this profile Enterprise-readiness surface Not a complete control assessment or enterprise suitability judgment

Public evidence sections

Granola Trust Center, security, and SOC 2 evidence

Granola's reviewed public evidence includes a Trust Center, Security page, SOC 2 Type II statement, vulnerability disclosure or security-report references, and customer-assurance surfaces. This page records observed public trust packaging for review context only; it does not independently verify security quality.

Granola DPA, GDPR-related, and subprocessor evidence

Granola publishes a Data Processing Addendum and points users to Trust Center subprocessor information. GDPR / UK GDPR-related language was observed in reviewed public documentation. This page does not determine Granola's GDPR compliance; buyers should review the live DPA, subprocessors, processing terms, and their own legal requirements.

Granola AI data usage and customer data training language

Granola's reviewed public evidence includes AI data usage and customer data handling language. This is relevant because meeting notes and transcript data create buyer review questions around model training, retention, deletion, and enterprise controls. This profile does not independently verify model-training behavior or workspace-specific controls.

Granola data residency, hosting, encryption, and enterprise controls

Granola's reviewed public evidence references enterprise-relevant controls such as Trust Center request flow, DPA, SOC 2, US data residency, vulnerability disclosure, security reports or post-mortems, SSO, and admin-control references. These are public enterprise-readiness evidence surfaces, not a complete control assessment.

What this public evidence does not prove

Do not infer that Granola is currently buying compliance, security, privacy, trust center, questionnaire automation, or AI governance tooling. Do not infer that unobserved evidence is absent. Do not treat this profile as a legal opinion, vendor-risk decision, compliance certification, security ranking, or proof that implementation matches public documentation.

Company name
Granola
Category
AI SaaS / meeting notes and productivity
Evidence status
Candidate signal
Current maturity stage
maturing AI meeting-notes trust surface
Last checked
2026-06-27

Compliance and security claim status

SOC 2 Type 2-related public claim observed; report type, entity scope, report period, and current status require verification; GDPR-related public language observed

Enterprise-readiness evidence

Trust Center request flow, DPA, SOC 2, local/no-bot meeting model, US data residency, vulnerability disclosure, security reports/post-mortems, SSO and enterprise admin-control references

False-positive note

Security reports, SOC 2 language, DPA availability, and AI data usage language can be trust-positive or review-triggering depending on buyer context. Do not frame these signals as negative without specific workflow, timing, or customer-pressure evidence.