Pricing
Request a demo Sign up
APIs
Real-time STT First fully multilingual real-time transcription engine with <300ms latency
Batch STT Asynchronous transcription and add-ons with no hallucinations
Models
Solaria-3 Built for real production audio — noisy, fast-paced, and conversational
New

Feature: Partials

Achieve faster, smoother real-time conversations with partial transcripts in <100 ms.

Learn more
Use Case
Customer experience Real-time AI to boost productivity of contact center agents
Sales intelligence AI transcription and insights to supercharge sales calls
Meeting assistants Flawless transcription for LLM-based AI assistants with note-taking capabilities
Media Streamlined editing and subtitles with time-stamped transcription
Industry
Voice agents AI-powered productivity for voice-based customer interactions
Contact center as a service (CCaaS) Flexible AI transcription for scalable contact center solutions
Business process outsourcing (BPO) Smart transcription tools for efficient outsourced operations
Playground Explore our APIs with a dedicated playground app
Documentation All you need to know to get started with Gladia
Discord Where our community lives
Status Real-time updates on the status and performance of our services
Free tier

Test Gladia in action

Take a tour of our playground and explore core API features — no credit card required.

Try for free
Blog Read our latest articles about speech-to-text, LLMs and more
Library Discover our ebooks, webinars, guides, and more
Whisper TCO Calculator Calculate the cost of ownership of hosting open-source Whisper ASR
Real-time API benchmarks Comparing Gladia's performance against pure players
Changelog Product updates, improvements, and new releases
Compliance Hub See how Gladia protects and manages your data
Featured

STT Voice agent buyer's guide

A clear framework for technical leaders evaluating STT vendors — all essential criteria in one guide.

Get the copy
About us Our team and company story
Careers For current job openings
Press Our latest press features, media kit and boilerplate
Partners Join our ecosystem of partners
Testimonials Hear the voices that shape our story
Series A

Our road to real-time audio AI

$16M in series A funding — speed, accuracy, and insight, finally delivered at scale.

Learn more
Security

Bug bounty program

Report a vulnerability, get rewarded, and help protect the data our customers trust us with.
Last updated: 01/07/2026

Why we run this program

Gladia processes audio for enterprises — sales calls, medical consultations, customer support, and voice agents. That data is often sensitive, sometimes regulated, and always someone else's. We're SOC 2 and ISO 27001 certified, independently audited for HIPAA compliance, and GDPR compliant, because our customers can't afford a breach.

No internal team catches everything — our API surface is large and constantly evolving. We run this program because we'd rather hear about a vulnerability from a researcher than from a customer. If you find one, we want to know, and we'll reward you for it.

In-scope assets

Asset Priority
api.gladia.io Highest
app.gladia.io High
Official SDKs (npm, PyPI) Medium
gladia.io Low

Out-of-scope

  • All other *.gladia.io subdomains
  • Third-party services (Intercom, Stripe dashboard, Google Workspace)
  • Social engineering or phishing attacks on staff
  • Physical security
  • Denial of Service (DoS/DDoS)
  • Assets not owned or operated by Gladia
  • Vulnerabilities requiring physical access
  • Reports from automated scanners without manual validation

Qualifying vulnerabilities

  • Authentication or authorization bypass
  • Cross-tenant data access
  • SQL/NoSQL injection
  • Remote code execution
  • Server-side request forgery (SSRF)
  • Cross-site scripting (XSS)
  • Cross-site request forgery (CSRF)
  • Webhook signature bypass or replay
  • Audio data leakage across accounts
  • API key or token leakage
  • Any vulnerability impacting the confidentiality, integrity, or availability of user data

Non-qualifying issues

  • Missing or invalid HTTP headers (without demonstrated impact)
  • Cookie flags
  • Clickjacking (without demonstrated impact)
  • SSL/TLS configuration issues
  • Account enumeration
  • SPF/DKIM issues
  • Rate-limiting issues
  • Password policy issues
  • Self-exploitation
  • Issues with no demonstrable security impact
  • Results from automated scanning tools without manual validation

Research guidelines

Do

  • Test only against assets explicitly listed as in-scope
  • Use your own test accounts, and only your own data
  • Stop as soon as you confirm a vulnerability, and report it promptly
  • Keep the details confidential until we've deployed a fix
  • Give us reasonable time to remediate before any disclosure

Do not

  • Access, modify, or delete data belonging to other users
  • Exfiltrate or retain any data you encounter, including audio and transcripts
  • Degrade or disrupt our services (no DoS/DDoS, spam, or load testing)
  • Use social engineering, phishing, or physical attacks against Gladia staff or facilities
  • Run automated scanners that generate high volumes of traffic without prior agreement
  • Publicly disclose a vulnerability before it is resolved and coordinated with us

Rewards

Severity Reward
Critical $2,000
High $1,000
Medium $250
Low $50

Rewards are determined by the Gladia security team based on severity and impact. Non-security issues are not eligible for monetary rewards.

Response SLAs

Stage Timeline
Acknowledgment 5 business days
Triage decision 15 business days
Payment (after fix verification) 30 business days

Safe harbor

Gladia SAS and Gladia Inc. consider security research conducted in good faith under this policy to be authorized activity. If you comply with this policy, we will:

  • Consider your research authorized and lawful, and will not initiate or support legal action against you for it
  • Not report your activity to law enforcement, and will make it known that your actions were conducted in compliance with this policy should any third party pursue legal action
  • Work with you to understand and resolve the issue quickly
  • Protect your identity and keep your report confidential, and not share your personal information without your consent

This authorization applies only to activity that:

  • Is limited to the in-scope assets listed above
  • Acts in good faith and complies with this policy and applicable law
  • Does not access, disclose, alter, or delete data belonging to other users
  • Does not disrupt or degrade Gladia services
  • Reports vulnerabilities promptly and does not publicly disclose them before resolution

If in doubt about whether a specific action is authorized, contact us at security@gladia.io before proceeding.

Coordinated disclosure

Researchers may publicly disclose vulnerability details 90 days after the fix is deployed, or sooner with written mutual agreement. Disclosure must:

  • Not include exploit code that could harm Gladia customers
  • Reference the Gladia Bug Bounty Program
  • Be shared with us in draft form 5 business days before publication

How to report

Submit all reports through our dedicated form at gladia.io/bug-bounty-report. Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Affected asset and endpoint
  • Impact assessment
  • Any supporting evidence (screenshots, logs, proof of concept)

Please submit vulnerabilities through the form rather than by email — we use it to ensure fair precedence. For any questions about the program, reach us at security@gladia.io.

Eligibility

  • Must not be a current or former Gladia employee
  • Must not violate any applicable law
  • Must be the first to report the vulnerability
  • Must not publicly disclose before fix

Hall of fame

With permission, we credit researchers who responsibly disclose valid vulnerabilities.

Product Real-time STT Batch STT Solaria-3 Pricing
Solutions Voice Agents Customer Experience Sales Intelligence Meeting Assistants Media
Developers Documentation Playground Status Discord
Company About us Blog Careers Press Partners
© 2025 Gladia. All rights reserved.
Privacy Policy Terms of Service Cookie Policy