Granola Trust Center, security, and SOC 2 evidence
Granola's reviewed public evidence includes a Trust Center, Security page, SOC 2 Type II statement, vulnerability disclosure or security-report references, and customer-assurance surfaces. This page records observed public trust packaging for review context only; it does not independently verify security quality.
Granola DPA, GDPR-related, and subprocessor evidence
Granola publishes a Data Processing Addendum and points users to Trust Center subprocessor information. GDPR / UK GDPR-related language was observed in reviewed public documentation. This page does not determine Granola's GDPR compliance; buyers should review the live DPA, subprocessors, processing terms, and their own legal requirements.
Granola AI data usage and customer data training language
Granola's reviewed public evidence includes AI data usage and customer data handling language. This is relevant because meeting notes and transcript data create buyer review questions around model training, retention, deletion, and enterprise controls. This profile does not independently verify model-training behavior or workspace-specific controls.
Granola data residency, hosting, encryption, and enterprise controls
Granola's reviewed public evidence references enterprise-relevant controls such as Trust Center request flow, DPA, SOC 2, US data residency, vulnerability disclosure, security reports or post-mortems, SSO, and admin-control references. These are public enterprise-readiness evidence surfaces, not a complete control assessment.
What this public evidence does not prove
Do not infer that Granola is currently buying compliance, security, privacy, trust center, questionnaire automation, or AI governance tooling. Do not infer that unobserved evidence is absent. Do not treat this profile as a legal opinion, vendor-risk decision, compliance certification, security ranking, or proof that implementation matches public documentation.