What security do you get?
Organization security settings cover four areas.- Authentication: Unify sign-in with your corporate identity system through SAML SSO.
- Access control: Restrict access to specific IPs and govern share link visibility with policies.
- Personal data: Mask personal information recorded in notes, like phone numbers and emails, with a masking policy.
- Evidence: Review permission change history, export audit and access logs as CSV, and stream audit events to your SIEM in near real time. See Audit logs and SIEM.
- Baseline security: Encryption at rest, storage in the Seoul region, and no AI training on your data apply to every plan. See Privacy and security.
Unify sign-in with SSO
Tiro supports SAML-based SSO. Connect an IdP such as Okta or Azure AD (Microsoft Entra ID), and your team signs in to Tiro with their corporate accounts.- You can run SSO-only. Block other methods like email and social sign-in, and account management lives entirely in your IdP.
- Closed-network environments without direct access to external authentication services are supported too.
Restrict access to your network
Limit workspace access to approved IPs only. This allows connections through your corporate network or VPN exclusively. If you need a static IP to register in your firewall, that’s supported as well. The exact configuration is worked out during onboarding.Turn on personal data masking
Turn on personal data masking as an organization policy, and personal information in newly created notes, like phone numbers, emails, and ID numbers, is masked automatically in the transcript and documents. This option fits environments like call centers, where customer personal data comes up often in conversations. Masking is decided when a note is created. Once the policy is on, it applies to notes you create afterward and doesn’t change notes already saved. If the option is enabled for your organization, an organization admin can turn it on and off directly with the [Personal info masking] toggle in the [Security] tab of the organization settings.Control share links
Manage the maximum visibility, longest expiry, and allowed company domains for share links through policy, and revoke active links from one place. For details on how this works, see Link sharing security.How do I change a locked setting?
Contact your account manager or partners@theplato.io. Organization security policies are gathered in the [Security] tab of your organization settings, split between items an organization admin can change directly and items Tiro configures to match your contract. Items an organization admin can’t change show a View only badge next to the title, with the switch shown in a non-pressable state. Below the description, a notice tells you where to direct your request.The organization settings screen, including the [Security] tab, opens only for organization admins. Regular members don’t see the screen at all.
Items your organization can turn on and off directly
Each item below is governed by its own policy option. When an item’s option is open for your organization, an organization admin can toggle that item right in the [Security] tab; if it isn’t open, a View only badge appears in the same spot instead. One item being open doesn’t mean every item is.- [Allow screen capture] Lets members capture the screen in client apps. Turn it off to block screen capture for every member.
- [Personal info masking] Automatically masks personal data in newly created notes.
- [Audio replay] Selects how long paragraph-by-paragraph audio replay stays available. Turn it off or set a period, and members can’t replay audio past that period.
- [Organization workspaces only] Allows creating and recording new notes only in organization workspaces.
- [Preserve departed member notes] Keeps notes in the organization archive workspace even after a member leaves.
- [Allowed hosts] A host list applied to every API key in the organization.
- [Allowed IPs] Add or edit the IP ranges allowed to connect. When this item’s option is open for your organization, an admin can manage the ranges directly.
Items you can view but must contact us to change
If an item’s option isn’t open for your organization, that item shows a View only badge. That includes [Allowed IPs]: without this item’s option open, you can only check the currently registered ranges, and to add or remove ranges you need to contact your account manager or partners@theplato.io. If the option isn’t open and no ranges are registered yet, there’s nothing to check, so the same spot shows an Enterprise option badge instead. Even with the option open, double-check before changing ranges, since a mistyped range can lock your entire organization out.When workspace settings overlap with organization policy
If your organization has a share link policy, the top of the [Sharing policy] section in workspace settings shows a notice that organization policy applies as well. A workspace admin can still change the settings below it, but the value that actually applies is the stricter of the workspace setting and the organization setting. Even if the workspace is left wide open, a narrower organization policy wins.Frequently asked questions
Can I get security review materials?
Yes. Tiro holds ISO/IEC 27001:2022 certification and has completed both SOC 2 Type 1 and Type 2 examinations. Security review materials such as audit reports, data locations, and the subprocessor list are provided after an NDA is signed. Reach out to our sales team.Can I store data in a specific region only?
Note data is stored in the AWS Seoul region by default. If you need a dedicated VPC or a different region, that can be arranged in your contract.What does the onboarding process look like?
Leave an inquiry, and our sales team reviews your organization’s security requirements and designs a tailored setup with you. A custom onboarding session and a hotline are included too.Related pages: Privacy and security · Link sharing security · Tiro plans