Fathom captures, transcribes, and summarizes Zoom, Google Meet, and Microsoft Teams calls. Free for individuals, with AI-powered CRM updates for teams.
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
-
HIPAA
Public claim of compliance with US health-data privacy and security rules. HIPAA has no certification; compliance is self-attested.
-
GDPR
Public claim of alignment with the EU General Data Protection Regulation.
-
CCPA
Publicly advertised on the organization’s trust center.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Fathom discloses on its trust center. Linked entries have their own profile in the Trust Index.
53% chain trust: 16 of 30 disclosed subprocessors are themselves in the Trust Index.
- Google Cloud Platform Primary Cloud Provider
- Anthropic AI Provider
- OpenAI AI Provider
- ElevenLabs AI Provider
- Elastic Search Provider
- Fireworks AI Provider
- Modal AI Provider
- Voyage AI AI Provider
- Amplitude Data analytics
- Brandfetch Brand & Logo API
- Census Data Analytics & ETL
- ChartMogul Data analytics
- Courier Email Provider
- Cloudflare CDN
- FiveTran Data Analytics & ETL
- Front Helpdesk Provider
- Hex Data analytics
- HubSpot CRM
- New Relic Application Monitoring
- omni Data analytics
- Postmark Email Provider
- Pusher In-App Communication
- Retool Data Analytics & ETL
- Reveal Partnership Marketing Platform
- RevenueHero Sales
- Sentry Application Monitoring
- Sphere Finance and payments
- Stripe Payment Processor
- UserVoice Feedback Tracking Platform
- Warmly Sales
Named as a subprocessor by
Organizations in the Trust Index that disclose Fathom as a subprocessor.
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.