15Five Security, Privacy, and AI Data Handling

15Five publishes security, privacy, and AI data handling information across two resources: 15five.com/terms for contractual and legal documents, and trust.15five.com for operational evidence, certifications, and security reports. This article explains what each resource covers and how to find what you need.

AI Data Handling

15Five uses AI across several product features, including Kona Meeting Assistant, AI-Assisted Reviews, Amaya, and 15Five Agents. The following commitments apply to all AI-powered features:

  • No third-party model training: 15Five does not permit OpenAI, Anthropic, or any other sub-processor to use your data to train or improve their AI models.
  • Content ownership: You retain ownership of all input you provide to AI features. 15Five assigns to you all right, title, and interest in AI-generated output.
  • Sub-processors: AI features are powered by sub-processors listed on the Platform Sub-Processors page. As of July 2026, AI sub-processors include Anthropic (AI-enabled services), OpenAI (AI-enabled functionality), and Pinecone (vector database for semantic search and context retrieval).

Full terms governing AI features are in the Supplemental AI Terms of Service.

Data Retention by Feature

Data type Retention Details
Kona meeting transcripts 30 days, then permanently deleted Used for coaching quality assurance only. No audio or video is recorded. See Kona privacy and transcript retention.
1-on-1 notes (including Kona-generated notes) Account lifetime Retained until the company account is sanitized (90 days after deactivation) or until a participant's account is PII-deleted.
Platform data (reviews, check-ins, objectives, engagement surveys, etc.) Governed by the DPA See the Data Processing Addendum for full retention and deletion terms.

Compliance and Certifications

15Five maintains the following compliance certifications, all accessible at trust.15five.com:

  • SOC 2 Type II and SOC 3 (2026 audit includes AI functionality in scope)
  • CCPA (California Consumer Privacy Act)
  • GDPR (General Data Protection Regulation)
  • PIPEDA (Personal Information Protection and Electronic Documents Act)
  • TX-RAMP Level 2 (Texas Risk and Authorization Management Program)
  • VPAT (Voluntary Product Accessibility Template)

The Trust Center also provides penetration test reports, network diagrams, data flow diagrams, a security whitepaper, and downloadable policy documents.

Access the SOC 2 Report

  1. Go to trust.15five.com.
  2. Click Documents in the navigation menu.
  3. Locate SOC 2 Report in the document list.
  4. Click Get Access next to the SOC 2 Report.
  5. Complete the request form and submit it.

When your request is approved, you will receive an email with a link to access the report. No 15Five login is required to access the Trust Center.

Sub-Processors

15Five maintains a public list of all sub-processors that handle customer data. The list is organized by category:

  • Platform sub-processors — used across all 15Five applications (AWS, Anthropic, OpenAI, Snowflake, Intercom, and others)
  • Engage and Transform sub-processors — additional processors used by those specific products
  • Special categories sub-processors — limited set used when processing sensitive personal data under GDPR Article 9

View the current list at 15five.com/terms/data-processing-addendum/sub-processors.

Where to Find What

If you need Go to
Contractual terms (MSA, DPA, AI terms, sub-processor list) 15five.com/terms
Security certifications, audit reports, policies, pentest results trust.15five.com
Privacy policy 15five.com/privacy
Kona-specific data handling (transcripts, notes, coaching prompts) Kona privacy and transcript retention (this Help Center)
Security practices overview 15five.com/security

Related Articles

Was this article helpful?

Sorry to hear that. Tell us what was missing →