Skip to main content

Join the Waitlist

Enter your email below and we'll notify you as soon as early access opens.

We’ll use your work email to manage the waitlist and notify you about early access. See our Privacy Policy.

Trust, built into every workspace

Security, privacy and responsible AI controls for high-stakes engagement.

Murmurly is designed to help teams manage sensitive, high-impact engagements with clear control over data, access and AI. We combine technical safeguards, configurable workspace controls and transparent data practices to help customers use Murmurly with confidence.

Security designed around your data

Protecting the information behind every engagement

Security is part of how Murmurly is designed and operated. We use layered access controls, encryption, monitoring and operational safeguards to protect Customer Personal Data and the systems used to process it.

  • Access and identity

    Murmurly uses workspace-level role-based access controls and configurable permissions. Access to Customer Personal Data depends on workspace membership, assigned roles and permissions.

    Supported authentication mechanisms include email-based authentication, passkeys, supported single sign-on and multi-factor authentication where available.

  • Workspace isolation

    Customer workspaces are logically separated from one another. Access controls are designed to prevent users from accessing Customer Personal Data in a workspace unless they have been granted access to that workspace.

  • Encryption

    Data transmitted between customer clients and Murmurly backend services is protected using TLS 1.2 or higher and secure WebSockets where applicable.

    Customer Personal Data stored within the cloud infrastructure used by Murmurly is encrypted at rest using the encryption mechanisms of the applicable infrastructure provider. Backups containing Customer Personal Data are also subject to applicable encryption controls.

Secure operations

Security goes beyond authentication

Protecting a production SaaS platform requires controls across infrastructure, software development, monitoring and operational access.

  • Monitoring and vulnerability management

    Murmurly maintains technical, operational and security logging appropriate to operating and protecting the Services. Relevant infrastructure and application components are monitored for availability, errors and security-relevant events.

    We use vulnerability and dependency scanning and review identified security issues as part of our security processes. Additional security assessments may be performed where appropriate to the nature, risk and maturity of the Services.

  • Restricted production access

    Access to production systems and Customer Personal Data is restricted to authorised personnel and only permitted where reasonably necessary for legitimate purposes such as maintenance, troubleshooting, security investigations, incident response or customer-requested support.

  • Development and testing

    Murmurly does not intentionally use Customer Personal Data for software development or testing except where reasonably necessary for troubleshooting or another authorised purpose and subject to appropriate safeguards.

    Production systems are logically separated from development and testing environments as appropriate to the architecture of the Services.

  • Backup and recovery

    Murmurly uses backup and recovery mechanisms designed to support the availability and recovery of relevant production data and Services following technical failures or other incidents.

  • Incident response

    We maintain processes for identifying, investigating, assessing, containing and remediating security incidents and Personal Data Breaches.

Privacy with clear responsibilities

Your data remains under your control

When a customer uses Murmurly to process personal data for its own business purposes, the customer generally acts as controller and Murmurly acts as processor under our Data Processing Addendum.

Murmurly may separately act as controller for limited purposes such as account administration, authentication, security and support, as described in our Privacy Policy.

  • Data minimisation

    We limit Customer Personal Data disclosed or transmitted to third-party providers to the information reasonably necessary for the relevant functionality or processing purpose.

    Where information is retrieved from optional integrations or other third-party services, we do not intentionally retain raw source data beyond what is reasonably necessary for the relevant functionality, except where otherwise instructed or required by law.

  • Trusted service providers

    Providers that process Customer Personal Data on Murmurly’s behalf are assessed and subject to contractual and security safeguards in accordance with our Data Processing Addendum.

Responsible AI

AI that helps your team — with safeguards around your data

AI is deeply integrated into Murmurly, but control stays with the customer.

Murmurly includes AI-assisted functionality such as Murble, summarisation, content generation, information extraction, semantic search and real-time voice.

Customers control whether and how AI functionality is used within their workspaces.

Where AI Features process Customer Personal Data, that processing remains subject to the same workspace permissions, security measures and data-protection requirements that apply elsewhere in Murmurly.

  • No general-model training where supported

    Murmurly configures third-party AI services, where supported by the provider, so that Customer Data submitted through the Services is not used to train or improve general-purpose AI models.

  • No emotion or psychological profiling

    Murmurly does not use AI to infer, score or classify a person’s emotional or psychological state and does not create voiceprints or biometric templates.

  • Human oversight stays in the loop

    AI-assisted functionality is designed to support users, not replace their judgment. Users remain responsible for reviewing AI-generated or AI-assisted outputs before relying on or acting on them.

  • Controlled access to AI context

    AI functionality operates within applicable workspace permissions and configurations. Customer Personal Data made available to AI Features remains subject to workspace-level access controls.

Data residency and infrastructure

Choose the region that fits your organisation

Murmurly supports EU and US deployment regions. The applicable region is selected as part of the customer’s Subscription Agreement.

Core application data is processed according to the configured deployment region, subject to the applicable infrastructure service and functionality.

For EU-configured deployments, server-side text-based AI and embeddings are processed using EU-configured Google Cloud infrastructure.

Certain functionality may have service-specific processing locations or technical architectures. Current processing locations and configurations are disclosed through our Subprocessor List.

Transparent subprocessors

Know who helps us deliver Murmurly

Murmurly relies on selected infrastructure, cloud and AI providers to deliver the Services.

Where a provider processes Customer Personal Data on Murmurly’s behalf, that provider is treated as a subprocessor and is subject to the requirements of our Data Processing Addendum.

We maintain a public Subprocessor List with current information about our subprocessors, their processing purposes and applicable processing locations.

  • Optional integrations stay optional

    Customers control whether supported third-party integrations are enabled.

    Connecting an optional integration does not automatically make that provider a Murmurly subprocessor; its role depends on the actual data flow and processing relationship.

Security and vendor review

Evaluating Murmurly?

Security and privacy reviews should not require guesswork.

If your organisation is evaluating Murmurly and needs additional information for a security, privacy, legal or vendor due-diligence review, our team can help.