Trust, built into
every workspace
Security, privacy and responsible AI controls for high-stakes engagement.
Murmurly is designed to help teams manage sensitive, high-impact engagements with clear control over data, access and AI. We combine technical safeguards, configurable workspace controls and transparent data practices to help customers use Murmurly with confidence.
-
Encrypted by default
Customer data is protected in transit using modern encryption and encrypted at rest within the cloud infrastructure used by Murmurly.
-
Controlled access
Workspace-level roles, configurable permissions and supported authentication controls help ensure people only access what they are authorised to use.
-
Privacy and data residency
Customers can select an EU or US deployment region, with clear contractual data-protection terms and transparent information about subprocessors.
-
Responsible AI
AI functionality operates within workspace controls and defined data-use safeguards, with customers remaining in control of how AI is enabled and used.
Security designed around your data
Protecting the information behind every engagement
Security is part of how Murmurly is designed and operated. We use layered access controls, encryption, monitoring and operational safeguards to protect Customer Personal Data and the systems used to process it.
-
Access and identity
Murmurly uses workspace-level role-based access controls and configurable permissions. Access to Customer Personal Data depends on workspace membership, assigned roles and permissions.
Supported authentication mechanisms include email-based authentication, passkeys, supported single sign-on and multi-factor authentication where available.
-
Workspace isolation
Customer workspaces are logically separated from one another. Access controls are designed to prevent users from accessing Customer Personal Data in a workspace unless they have been granted access to that workspace.
-
Encryption
Data transmitted between customer clients and Murmurly backend services is protected using TLS 1.2 or higher and secure WebSockets where applicable.
Customer Personal Data stored within the cloud infrastructure used by Murmurly is encrypted at rest using the encryption mechanisms of the applicable infrastructure provider. Backups containing Customer Personal Data are also subject to applicable encryption controls.
Secure operations
Security goes beyond authentication
Protecting a production SaaS platform requires controls across infrastructure, software development, monitoring and operational access.
-
Monitoring and vulnerability management
Murmurly maintains technical, operational and security logging appropriate to operating and protecting the Services. Relevant infrastructure and application components are monitored for availability, errors and security-relevant events.
We use vulnerability and dependency scanning and review identified security issues as part of our security processes. Additional security assessments may be performed where appropriate to the nature, risk and maturity of the Services.
-
Restricted production access
Access to production systems and Customer Personal Data is restricted to authorised personnel and only permitted where reasonably necessary for legitimate purposes such as maintenance, troubleshooting, security investigations, incident response or customer-requested support.
-
Development and testing
Murmurly does not intentionally use Customer Personal Data for software development or testing except where reasonably necessary for troubleshooting or another authorised purpose and subject to appropriate safeguards.
Production systems are logically separated from development and testing environments as appropriate to the architecture of the Services.
-
Backup and recovery
Murmurly uses backup and recovery mechanisms designed to support the availability and recovery of relevant production data and Services following technical failures or other incidents.
-
Incident response
We maintain processes for identifying, investigating, assessing, containing and remediating security incidents and Personal Data Breaches.
Privacy with clear responsibilities
Your data remains under your control
When a customer uses Murmurly to process personal data for its own business purposes, the customer generally acts as controller and Murmurly acts as processor under our Data Processing Addendum.
Murmurly may separately act as controller for limited purposes such as account administration, authentication, security and support, as described in our Privacy Policy.
-
Data minimisation
We limit Customer Personal Data disclosed or transmitted to third-party providers to the information reasonably necessary for the relevant functionality or processing purpose.
Where information is retrieved from optional integrations or other third-party services, we do not intentionally retain raw source data beyond what is reasonably necessary for the relevant functionality, except where otherwise instructed or required by law.
-
Trusted service providers
Providers that process Customer Personal Data on Murmurly’s behalf are assessed and subject to contractual and security safeguards in accordance with our Data Processing Addendum.
Responsible AI
AI that helps your team — with safeguards around your data
AI is deeply integrated into Murmurly, but control stays with the customer.
Murmurly includes AI-assisted functionality such as Murble, summarisation, content generation, information extraction, semantic search and real-time voice.
Customers control whether and how AI functionality is used within their workspaces.
Where AI Features process Customer Personal Data, that processing remains subject to the same workspace permissions, security measures and data-protection requirements that apply elsewhere in Murmurly.
-
No general-model training where supported
Murmurly configures third-party AI services, where supported by the provider, so that Customer Data submitted through the Services is not used to train or improve general-purpose AI models.
-
No emotion or psychological profiling
Murmurly does not use AI to infer, score or classify a person’s emotional or psychological state and does not create voiceprints or biometric templates.
-
Human oversight stays in the loop
AI-assisted functionality is designed to support users, not replace their judgment. Users remain responsible for reviewing AI-generated or AI-assisted outputs before relying on or acting on them.
-
Controlled access to AI context
AI functionality operates within applicable workspace permissions and configurations. Customer Personal Data made available to AI Features remains subject to workspace-level access controls.
Murmurly supports EU and US deployment regions. The applicable region is selected as part of the customer’s Subscription Agreement.
Core application data is processed according to the configured deployment region, subject to the applicable infrastructure service and functionality.
For EU-configured deployments, server-side text-based AI and embeddings are processed using EU-configured Google Cloud infrastructure.
Certain functionality may have service-specific processing locations or technical architectures. Current processing locations and configurations are disclosed through our Subprocessor List.
Murmurly relies on selected infrastructure, cloud and AI providers to deliver the Services.
Where a provider processes Customer Personal Data on Murmurly’s behalf, that provider is treated as a subprocessor and is subject to the requirements of our Data Processing Addendum.
We maintain a public Subprocessor List with current information about our subprocessors, their processing purposes and applicable processing locations.
-
Optional integrations stay optional
Customers control whether supported third-party integrations are enabled.
Connecting an optional integration does not automatically make that provider a Murmurly subprocessor; its role depends on the actual data flow and processing relationship.
Our legal and privacy documentation is publicly available so customers can understand how Murmurly operates before entering into an agreement.
Security and privacy reviews should not require guesswork.
If your organisation is evaluating Murmurly and needs additional information for a security, privacy, legal or vendor due-diligence review, our team can help.