Steno · Trust Center

Steno Trust Center

Trust center

Steno maintains a public trust center documenting SOC 2 Type II and HIPAA compliance.

CompanyLegalLegal TechnologyCourt ReportingDepositionsLitigation SupportTranscriptionVideoArtificial IntelligenceSalesforce
Trust center: https://trust.steno.com/

Certifications & Compliance

SOC 2 Type IIHIPAA

Source

Trust Center

steno-trust-center.yml Raw ↑
generated: '2026-08-05'
method: searched
probe: true
url: https://trust.steno.com/
platform: Vanta Trust Center
platform_evidence: served HTML carries assets.vanta.com stylesheets and data-signature-manifest-url
  on https://assets.vanta.com/static/signature-manifest.*.json
scope: Steno Connect, Firm Dashboard, and Ops
certifications:
- name: SOC 2 Type II
  trust_service_criteria:
  - Security
  - Availability
  - Confidentiality
  auditor: Linford & Company LLP
  source: https://brief.steno.com/soc2-hipaa-compliance
- name: HIPAA
  note: audited for compliance with the Health Insurance Portability and Accountability
    Act of 1996 as a business associate handling protected health information in transcripts
    and proceedings
  auditor: Linford & Company LLP
  source: https://brief.steno.com/soc2-hipaa-compliance
continuous_monitoring:
  vendor: Vanta
  note: continuous control monitoring with real-time alerting and automated evidence
    collection, per Steno's published compliance post
related_pages:
- url: https://trust.steno.com/resources
  status: 200
  note: trust center resource list (Vanta-hosted, client-side rendered)
- url: https://help.steno.com/safety-and-security
  status: 200
  note: '"Is Steno Connect Safe And Secure?" knowledge-base article'
- url: https://steno.com/dpa
  status: 200
  note: Data Processing Addendum
vulnerability_disclosure: null
vulnerability_disclosure_note: 'no vulnerability disclosure program found: /.well-known/security.txt
  returns 404 on steno.com and 403 on api.steno.com, and steno.com/security returns
  404. The Vanta trust center is client-side rendered so any report-a-vulnerability
  link it carries was not readable anonymously.'
x-evidence:
- url: https://trust.steno.com/
  http_status: 200
  content_type: text/html
  observed: '<title>Steno Trust Center</title> + <link rel="canonical" href="https://trust.steno.com">'
- url: https://brief.steno.com/soc2-hipaa-compliance
  http_status: 200
  observed: names SOC 2 Type II (Security, Availability, Confidentiality), HIPAA, auditor
    Linford & Company LLP, and Vanta continuous monitoring
- url: https://steno.com/.well-known/security.txt
  http_status: 404
- url: https://steno.com/security
  http_status: 404