Nobody researching this at a therapy practice, a law firm or a clinic is comparing transcription accuracy. The actual trigger is usually a single moment: a client asks where the recording of their session lives, a firm's IT policy flags a new SaaS vendor for review, or a colleague notices a notetaker's terms allow the vendor to use call audio for anything at all. From that point on, the feature list stops mattering and one paragraph on a security page becomes the whole decision. Eight tools, read for exactly that paragraph, checked today rather than assumed from memory — because a compliance claim is the kind of fact that moves between one search and the next far more than a price does.
Two things worth saying before the list. First, nothing below is legal or compliance advice, and no certification named here is a substitute for your own counsel or your own compliance officer reading the vendor's actual agreement. Second, a certification is a claim a vendor makes about itself — this page reports what each one states on its own site today, links to where it says it, and leaves the judgment of whether that is sufficient to the reader and the people they actually answer to. A related question — whether "private" and "compliant" mean the same thing — gets its own treatment here; this page stays on the paperwork specifically.
Wispr Flow — the most paperwork, mid-transition right now
Wispr Flow's notetaker rides the same $15-a-month Pro subscription as its dictation product, per its pricing page checked today. Its compliance story is the most detailed of any name on this page, and also the most worth reading precisely rather than summarising from a badge: its own compliance FAQ states that an earlier SOC 2 Type II and ISO 27001 certification were "proactively invalidated in March 2026 due to platform integrity concerns at the original auditor," and that Wispr re-engaged a new auditor, A-LIGN, afterward. As of today, a SOC 2 Type I report completed in April 2026 with a clean opinion, SOC 2 Type II is in a re-audit that has not yet concluded, and ISO 27001:2022 cleared its first stage in April 2026 with the second stage scheduled for June. A Business Associate Agreement is available for healthcare customers, per the same page. None of that makes the paperwork worthless — a completed Type I and a named auditor is more than most of this list offers — but "SOC 2 and ISO 27001 certified," stated flatly, is not currently the accurate summary of where Wispr Flow's audits actually stand, and a compliance reviewer checking the primary source will notice the difference. Full comparison here.
Fireflies — a HIPAA claim stated plainly, on its own terms
Fireflies' plans span a free tier through Business, detailed on its pricing page checked today. Its own security page states outright: "HIPAA Compliant — Complete protection for healthcare and educational organizations," alongside SOC 2 Type II, a stated GDPR alignment, and a zero-data-retention line promising audio is never used for AI training or for anything outside direct business needs. That is a more direct claim than most competitors make about themselves, stated on a page the vendor controls rather than qualified the way Wispr's currently is. What the page does not do is name a Business Associate Agreement process by that term — worth confirming directly with Fireflies before treating "HIPAA Compliant" as equivalent to "will sign our BAA." A bot still joins the call on every tier. Full comparison here.
Otter — SOC 2 achieved, HIPAA explained rather than claimed
Otter's privacy and security page, checked today, states it has "achieved SOC 2 Type 2" certification and describes a 30-day trash-retention window before a deleted conversation is actually removed. The same page also discusses HIPAA — but as an explanation of what the law is, not as a claim that Otter itself is HIPAA compliant or that it will sign a BAA; the two read very differently side by side, and it is worth reading the actual sentence rather than assuming a mention equals a certification. Pricing runs free through Business at $19.99–$30 a month, per its pricing page today, and a bot joins by default on every paid tier. Full comparison here.
Granola — SOC 2 stated, a DPA on request, no HIPAA claim
Granola's Business tier is $14 a user a month per its pricing page checked today. Its security page, also checked today, states SOC 2 Type 2 has been shown to independent auditors and that a Data Processing Agreement is "available upon request" for GDPR purposes — but neither HIPAA nor a Business Associate Agreement appears on that page at all, which is a real gap for a therapy or medical practice specifically, even though Granola is arguably the most feature-complete tool on this whole page for a non-regulated team. Its own pricing page states every tier can opt out of model training, meaning training is on by default until that setting is found. Full comparison here.
tl;dv — the one offering a choice of where data lives
tl;dv's security commitment page, checked today, states tl;dv is SOC 2 Type II compliant and GDPR-compliant, being based in Europe, and — the detail that actually matters for this list — lets an account choose whether its AI processing happens in Europe or the US. For a practice bound by a specific data-residency requirement, that is a control none of the other seven names here offer at all. The same page notes its underlying infrastructure providers carry ISO 27001 certification, which describes where the data centers sit rather than a certification tl;dv itself holds directly — a distinction worth keeping straight when reading the page rather than collapsing into "tl;dv is ISO certified." HIPAA and a BAA are not mentioned. Full comparison here.
MacWhisper — no vendor in the loop, and no paperwork because of it
MacWhisper Pro is €64, paid once, confirmed on its own site today. It carries no compliance certification of any kind, and there is a real reason that gap is different from the others on this page: recording and transcription both happen locally, so there is no vendor receiving the audio for a certification to describe in the first place. Its summary step is the one exception — it connects to an AI provider the user selects, and if that provider is a cloud one, the audio for that specific step leaves the Mac after all, which is worth checking case by case rather than assuming "local app" covers every part of the workflow. Full comparison here.
superwhisper — local on Apple Silicon, cloud on Intel
superwhisper's Pro tier is $8.49 a month on its own pricing card checked today, with meeting recording already included in the free tier. Its own site states it works offline "so you can transcribe anytime," with a documented caveat that offline models run on Apple Silicon Macs while Intel Macs are steered toward cloud models instead — a detail that matters a great deal for a regulated practice still running an older Intel Mac, since the local-processing promise does not hold the same way on that hardware. No compliance certification is stated on its site. Full comparison here.
Coii AudioNotes — the plainer answer, without the paperwork to prove it
Coii AudioNotes is $19, paid once, for three of a practice's own Macs, with a 30-day trial that needs no card and no account. The microphone and the system audio are recorded as two separate tracks, transcribed on the machine while the session is still running, and turned into notes by a language model bundled inside the app — so no step of the process, not even the summary, involves sending audio to a server.
Decisions
- Diagnosis code confirmed, billed under the existing treatment plan
Actions
- Send the intake form ahead of next week's session
Open questions
- Referring physician has asked for notes; check whether a signed release is on file first
It holds none of the certifications named above — no SOC 2 report at any stage, no ISO 27001, no HIPAA attestation, no BAA to sign. That is a real gap against Wispr Flow and Fireflies for a practice whose compliance process specifically requires a named certification on file, and no amount of local processing substitutes for a document a reviewer was told to ask for. What it offers instead is the plainer version underneath all of that paperwork: the recording was never sent anywhere, so there is nothing for a certification to have to promise about it. Full comparison here and here for the two closest comparisons on this specific question.
Read the primary source, not the badge
A logo on a marketing page is not the same claim as the report it represents, and this whole list is evidence of why the difference matters: Wispr Flow displayed a SOC 2 badge for years before this year's invalidation and re-audit, and nothing about the badge itself would have told a reviewer which stage the underlying report was actually at on a given day. The primary source — the compliance page a vendor keeps current, not the icon on their homepage — is the only version of any of these claims worth actually citing in a vendor review.
What actually decides it
If a compliance process requires a named certification on file before a vendor can be approved at all, Wispr Flow's Type I report and Fireflies' stated HIPAA compliance are the two names here with something concrete to hand over today — read each one's own page rather than a summary of it, since Wispr's status specifically changed twice this year. If the requirement is choosing which country processes the data, tl;dv is the only name on this page offering that as a setting rather than a fixed answer. And if the actual requirement, once it is asked out loud, turns out to be "the recording should never leave this room in the first place, full stop" — the kind of standard a therapist or a lawyer often reaches for instinctively before any policy document gets involved — MacWhisper and Coii AudioNotes are the two names here where that is true by construction, not by a report a company had to be re-audited for.
Six licences on Wispr Flow's notetaker at $15 a month comes to $1,080 a year; the same six people on Coii AudioNotes, at $19 each, once, is $114 total. That arithmetic is only the deciding factor once the certification question has actually been answered, since for a regulated practice the paperwork frequently matters more than the price. A practice weighing a fully local setup against these eight is also worth pointing at this list of local-only transcription tools specifically, MacWhisper and Coii AudioNotes among them.
The table
| Alternative | Price | HIPAA / BAA | SOC 2 | Data residency choice |
|---|---|---|---|---|
| Wispr Flow | $0–$15/user/mo | BAA available; HIPAA-aligned controls | Type I complete Apr 2026; Type II re-auditing | Not stated |
| Fireflies | $0–$29/seat/mo | States "HIPAA Compliant"; BAA not named | Type II, stated | Not stated |
| Otter | $0–$30/user/mo | HIPAA explained, not claimed; no BAA named | Type 2, stated | Not stated |
| Granola | $0–$35/user/mo | Not mentioned | Type 2, stated | Not stated |
| tl;dv | €0–€39/seat/mo | Not mentioned | Type II, stated | Yes — EU or US |
| MacWhisper | €0–€64 once | Not applicable — local | None | Local by default |
| superwhisper | $0–$8.49/mo | Not mentioned | None | Apple Silicon local; Intel cloud |
| Coii AudioNotes | $19 once | None held | None held | Local, always |
Which to actually try
Read the primary source for whichever tool is under review rather than a badge on a marketing page — Wispr Flow's own compliance FAQ is more specific, and more current, than any secondhand summary of it including this one, and that is true of every vendor on this list. If the honest requirement turns out to be avoiding the question altogether — a recording that has nowhere to travel to, so there is no server for a policy to have to govern — Coii AudioNotes or MacWhisper are the two names here built that way from the start. Thirty days, no card, is enough time to sit a real session's worth of notes next to whatever a compliance officer actually asks for before the $19 comes up at all.