# ElevenLabs

> Generates spoken audio from text, clones voices from recordings and transfers video and audio material into other languages, either through a web interface or through an API.

- Vendor: Eleven Labs Inc., New York
- Canonical URL: https://www.convios.com/en/toolbox/elevenlabs
- Language version: https://www.convios.com/de/werkzeugkasten/elevenlabs
- Area: Content & web · Cluster: speech synthesis
- Role: Building block · Origin: AI-native
- As of: 2026-09-07 · Reviewed: 2026-09-07 · Author: Dr. Oliver Gausmann, Convios GmbH
- Toolbox: https://www.convios.com/en/toolbox — Markdown: https://www.convios.com/en/toolbox.md

## Verdict

Efficiency only: A voice on tap saves the studio session and the second appointment as soon as the text changes. It moves nobody in the market, because a competitor signs up for the same subscription on the same day. What remains grows out of your own material: cleared rights to the voices, your own body of text, and a review loop that catches a drop in quality after a model change before the customer hears it. Where the voice sits on the product surface and speaks with end customers, the tool moves closer to the core. Responsibility travels with it: the use policy places disclosure towards end users and the classification under the KI-Verordnung (AI Act) on the customer.

## Suitability by company size

- Solo: suitable — The free tier gives 10,000 credits a month and expressly allows no commercial use. Anyone earning money with it starts at 6 US dollars a month, because that is where the commercial licence and instant voice cloning begin.
- Mid-market: suitable — Between 99 and 990 US dollars a month covers what an editorial team or a service desk needs. The friction sits in data protection: using content to improve the models is the default and ends only with an objection in the account, which works forwards only. Anyone processing recordings of identifiable people settles that before the first upload.
- Enterprise: suitable with caveats — Functionally the tool scales across the organisation; the hurdles sit in the contract. Single sign-on, a selectable storage location in the EU and operation without request retention all hang on the Enterprise plan, whose price is not published. Then there is the forum: even the European terms of service name the law of the State of New York and the courts in New York City for business customers.

## Vendor staying power

Funded: According to the company it was founded in 2022, putting the product around four years in the market. Two funding rounds are dated and announced by the vendor itself, the most recent on 04.02.2026. Development visibly continues; the changelog carries weekly entries. Revenue and profit figures are not publicly retrievable, and no company register extract for the New York entity exists in any European register. The rating therefore rests on dated announcements, audit evidence and the pace of development.

- Contracting party and address: Eleven Labs Inc., 169 Madison Ave #2484, New York, NY 10016. The privacy policy dated 20.05.2026 names as affiliates Eleven Labs Ltd. (United Kingdom), Eleven Labs Poland sp. z o.o., Eleven Labs Auto India Private Limited, Eleven Labs Technology Middle East Limited and Eleven Labs Japan Godo Kaisha. For voice data of people in the European Economic Area, the United Kingdom and Switzerland it names Eleven Labs Poland sp. z o.o. in Warsaw as the controller. (source: https://elevenlabs.io/privacy-policy, as of 2026-05-20)
- Funding 2025: USD 180 million, announced by the vendor on 30.01.2025, at a valuation of USD 3.3 billion. Led by a16z and ICONIQ Growth. Valuation and round size are vendor figures with no disclosed basis of valuation. (source: https://elevenlabs.io/blog/series-c, as of 2025-01-30)
- Funding 2026: USD 500 million, announced by the vendor on 04.02.2026, at a valuation of USD 11 billion, led by Sequoia Capital. The vendor puts total funding at USD 781 million across five rounds since its founding in 2022. Whether the round consists entirely of new capital paid into the company, or whether shares were bought from existing investors, is not apparent from the announcement. (source: https://elevenlabs.io/blog/series-d, as of 2026-02-04)
- Audit evidence over time: The trust portal dates three steps: certification under the French HDS standard for health data on 23.01.2026, certification under ISO 27701 and ISO/IEC 42001 on 10.02.2026, and a bridge letter for the SOC 2 Type II report dated 03.09.2026. Certificates under ISO 27001, 27017, 27018, 27701 and 42001 are retrievable there without an access request. (source: https://compliance.elevenlabs.io, as of 2026-09-07)
- Pace of development: The public changelog carries weekly entries with named API changes. The most recent entry when retrieved on 07.09.2026 is dated 31.08.2026, preceded by entries of 24.08., 22.08., 17.08. and 10.08.2026. (source: https://elevenlabs.io/docs/changelog, as of 2026-09-07)
- Documented incident: In January 2024 an automated call in New Hampshire carried a replicated voice of the then US president and advised against voting. An analysis by the security firm Pindrop pointed to this vendor's tools, and according to reports of 26 and 27.01.2024 the vendor suspended the account concerned. The incident is listed in the OECD incident register under number 63427. (source: https://fortune.com/2024/01/27/ai-firm-elevenlabs-bans-account-for-biden-audio-deepfake, as of 2024-01-27)

## Cost of leaving

Moderate: The generated files already sit in your own stock, so switching vendors costs no data migration. What stays behind is the voice itself. A cloned voice model can be deleted, but it can neither be exported nor re-used at the next vendor, and a voice from the library counts only here. Anyone switching sounds different, and the audience hears it. With the voice agents the configuration is added: conversation design, tool connections, telephony hook-up and retention settings are rebuilt.

## Regulation and data

| Point | Finding | Evidence | As of |
|---|---|---|---|
| Data processing agreement | publicly retrievable, applies to entity accounts with no further step — The data processing addendum is openly available online, dated 08.04.2026, and under its own clause 1 it also applies to self-booked plans, where the terms of use take the place of a master agreement. The terms of use confirm this for accounts entered into on behalf of an entity. This is also where the finding sits that is easily lost while reading: the same section expressly carves out processing for the vendor's own business purposes and lists data analysis, benchmarking, product development and research and development of its own AI models. The agreement therefore covers processing on instruction, and alongside it stands the vendor's own controllership over the same content. According to the price list, the Enterprise plan only adds individually negotiated commitments on contract and availability. | evidenced | 2026-04-08 |
| Storage location | selectable EU region only on the Enterprise plan, below that the vendor decides — The public sub-processor list separates two cases. For customers below the Enterprise plan it says data may be processed in the United States, the EU or Singapore, for latency and service performance reasons. Customers there have no choice. Enterprise customers may select from a list of locations, with availability expressly at the vendor's discretion. The documentation names the EU, India and Singapore as regions, excludes dubbing from this separation, and records that processing may occur outside the selected location even when one is chosen, through affiliates, through sub-processors, for customer support and for content moderation. | partially evidenced | 2026-09-07 |
| Subprocessors | complete public list with purpose and region, no access request needed — As of 07.09.2026 the trust portal lists twenty-nine entries, each with purpose and region, freely visible. Named among others are Google Cloud Platform, Amazon Web Services, Azure, Anthropic, OpenAI, MongoDB, Twilio, Stripe, Zendesk, and for content moderation Cinder and Hive. For the generation of synthetic media it also lists ByteDance with the regions Indonesia, Malaysia and EU, Kling with Singapore, plus Runway, Creatify, Sync and Fal marked global. The data processing addendum grants a general authorisation and commits to notice thirty days before a new sub-processor is engaged, with a right to object and to terminate the affected service. | evidenced | 2026-09-07 |
| Third-country transfer | transfer to the United States, basis named and anchored in the contract — The data processing addendum anchors the standard contractual clauses of implementing decision 2021/914 together with the UK addendum and the Brazilian clauses; they are deemed executed when the addendum takes effect, under Irish law and the courts of Ireland. Alongside this the vendor relies on the EU-US Data Privacy Framework. That reliance is verifiable: on 07.09.2026 the official participant list of the US Department of Commerce shows ElevenLabs, New York, as active for the EU-US framework, the Swiss framework and the UK extension, each covering HR data and non-HR data. One imprecision sits in the vendor's own documents: its framework policy names ElevenLabs Ltd. as the certified entity, while the official list and the contract name the New York company. | evidenced | 2026-09-07 |
| Training on customer data | use is the default; objection is possible in the account and works forwards only — Three documents together give the picture. The terms of use grant the vendor a licence over content that expressly covers improving the services and developing new products, and for voice recordings extends to the voice itself. The privacy policy lists research and development of the AI models as a separate purpose, based on legitimate interest and alternatively on consent. The public sub-processor list records for customers below the Enterprise plan that the LLM services may also be used for research, development, training and product improvement. The objection sits in the account under data use and, on the wording of both documents, applies only to content handed over afterwards; earlier uses and what came out of them remain untouched. | partially evidenced | 2026-09-07 |
| Retention and deletion | thirty days after the contract ends on the Enterprise plan, below that with no duty to delete — Clause 9 of the data processing addendum separates two cases. For customers with an enterprise licence, content is deleted within thirty days of expiry or termination. For self-booked plans the vendor reserves the right to delete content after one hundred and eighty days of inactivity and records in the same sentence that it is under no obligation to do so. Backups are expressly excluded and purged under the vendor's own retention rules; the documentation quantifies these at up to thirty days. For voice agents the documentation names two years as the default for conversation data and audio recordings, configurable to any number of days, to immediate deletion or to unlimited. Biometric data is kept for up to three years after the end of the relationship according to the privacy policy. | partially evidenced | 2026-04-08 |
| Certifications | several attestations with standard and version, certificates openly retrievable, some audit reports gated — As of 07.09.2026 the trust portal lists among others SOC 2 Type 2, ISO 27001:2022, ISO 27017:2015, ISO 27018:2019, ISO 27701:2019, ISO/IEC 42001:2023, PCI DSS 4.0.1 Level 1, CSA STAR Level 1, HIPAA, HDS and UK Cyber Essentials Plus, each assigned to the vendor itself. Retrievable without an access request are the certificates under ISO 27001, 27017, 27018, 27701 and 42001, the Cyber Essentials Plus certificate, the SOC 3 report, the security whitepaper, the model cards and the technical and organisational measures. Behind an access request sit the SOC 2 Type 2 report and its bridge letter, the three penetration test reports and the completed SIG questionnaire. | evidenced | 2026-09-07 |
| EU AI Act, Article 50 | own duties documented, commitment on machine-readable marking open — The vendor side carries more than most: certification under ISO/IEC 42001:2023 for the AI management system, openly retrievable model cards for the models in use, and a training data transparency disclosure dated 31.12.2025, which matches the duties for general-purpose models under Regulation (EU) 2024/1689. The use policy names the regulation and requires organisations running voice agents to disclose clearly and prominently to their users that they are speaking with an AI. The same policy expressly places classification of the customer's own use case and compliance with AI laws on the customer. The other half stays open: a named commitment that every generated audio track is marked machine-readably as artificially generated was not findable on 07.09.2026, neither in the terms of use nor on the safety page, the transparency page or the trust portal. The safety page instead relies on after-the-fact detection through the vendor's own classifier and refers to the C2PA standard. The dubbing watermark shown in the price list is a tier marker for free use and does not carry that duty. | partially evidenced | 2026-09-07 |
| Audit logging | content history with a configurable period documented, access and change log publicly open — What is documented is the history over content. The vendor keeps history preservation enabled by default, generations can be deleted through the API at any time, and for voice agents the period is configurable per agent. The zero retention mode is reserved for Enterprise customers, applies only to API calls and expressly does not cover traffic through the web interface or the playground; access to that mode also sits at the vendor's sole discretion. What the public documents lack is the other kind of log: whether and how a customer can trace who created, changed or retrieved which voice in the workspace and when, and over what period, was not named on 07.09.2026 either on the enterprise page or in the workspace administration documentation. Those pages carry roles and permissions and single sign-on, with no statement on the scope and retention of an audit log. | partially evidenced | 2026-09-07 |

## Cost

- Entry: Six tiers drawing on one shared credit pool, as of 07.09.2026 and excluding tax: free with 10,000 credits a month and no commercial use, Starter 6 US dollars with 30,000, Creator 11 US dollars with 121,000, Pro 99 US dollars with 600,000, Scale 299 US dollars with 1.8 million and Business 990 US dollars with 6 million credits. The API is billed in US dollars: text to speech 0.10 US dollars per 1,000 characters for v3 and v2 and 0.05 for the fast models, speech to text 0.22 US dollars per hour, dubbing 0.33 US dollars per minute with watermark and 0.50 without. The Enterprise plan has no published price. (as of 2026-09-07)
- Where it gets expensive: What gets expensive is what procurement asks about, and all of it sits on the Enterprise plan with no published price: single sign-on, individually negotiated commitments on contract and availability, the agreement for health data, the choice of storage location and operation without request retention. The shared credit pool is the second place: text to speech costs one credit per character, dubbing between 2,000 and 10,000 credits per minute depending on the method, so a single translated video can use up an editorial team's month. Anyone running the brand with its own voice also needs professional voice cloning from the Creator plan upwards.

## Three routes compared

### Speech synthesis from a hyperscaler, studio recording for anything promotional

The established route is Amazon Polly or Microsoft Azure AI Speech, and for commercials and brand films still a recording with human voice talent. Large organisations stay with it for three reasons that appear on no feature list: the contract runs through a European entity and already sits inside the existing framework agreement, the price is a fraction, and for a wrong statement in an advertising video there is a named party to hold liable. For comparison, as of 07.09.2026: Amazon Polly charges 16 US dollars per million characters for neural and 30 US dollars for generative voices, while ElevenLabs charges 100 US dollars per million characters over the API for v3 and v2 and 50 US dollars for the fast models. The difference is paid for in expressiveness, in the range of languages, and in dubbing, which the established route does not offer in this form.

### Cartesia as the AI-native counterpart

Cartesia is the nearest AI-native counterpart and comes with the same ladder: free, 5, 49 and 299 US dollars a month, above that an Enterprise plan with no published price, as of 07.09.2026. The same threshold stands out. Data processing agreement, health data agreement, single sign-on and answers to security questionnaires all begin on the Enterprise plan there as well, whereas ElevenLabs publishes its data processing addendum openly and applies it to every entity account. What is given up is breadth: dubbing, the studio interface, the voice library, and the certificates and model cards retrievable without an access request. Switching therefore answers the price question and leaves the procurement question standing.

### An open speech model on rented GPU in front of your own pipeline

Concretely: an open speech synthesis model such as Kokoro or XTTS on a rented GPU, LiteLLM as a router in front of several providers for the text side, Langfuse to evaluate the output, Sanity as the source of the texts and Cloudflare to deliver the files. Building it takes ten to fifteen person-days, so at a daily rate of 1,000 euros between 10,000 and 15,000 euros, plus 300 to 800 euros a month for compute. It fails in two places. The first is the rights to the voice: anyone cloning needs the person's consent, its documentation, and a way to withdraw it, and nobody builds that administration on the side. The second is load. Real-time speech synthesis has hard latency requirements, and a GPU that copes in the afternoon stops coping when the newsletter goes out. Add on-call duty for a pipeline the daily business depends on, and maintenance after the person who built it has left.

Recommendation by size:

- Solo: Buy. From the first commercial use take the 6 US dollar tier, because that is where the licence for it sits.
- Mid-market: Buy, and set the objection to training use in the account before the first upload, because it works forwards only.
- Enterprise: Buy on the Enterprise plan. Storage location, deletion period, single sign-on, audit log and forum belong before the signature.

## Context

- Implements method: [Calibrated Evaluation Loop for AI Outputs (Criteria Drift)](https://www.convios.com/en/methods/eval-calibration) — Voice quality can only be compared with a calibrated review loop, and without that comparison neither a move to a cheaper vendor nor building your own can be judged. Otherwise a model change at the vendor is first noticed by the audience.
- Implements method: ["Context: Moat or Wall?" Test](https://www.convios.com/en/methods/context-moat-or-wall-test) — The test separates a purchased capability from your own distance, and that is exactly what the investment decision turns on here: the subscription is open to anyone, while cleared voice rights and your own body of text arise only in house.
- Implements method: [Regulatory Density Test](https://www.convios.com/en/methods/regulatory-density-test) — A voice is personal data and, depending on the jurisdiction, biometric, and disclosure duties for voice agents come on top. The test shows whether the use case moves into the zone where plan choice, storage location and deletion period decide usability.
- Displaces: Studio recording for standard texts and announcements, Re-recording after every change to the text, A separate voice recording for each target language

## Evidence

- Plans, credit allowances, exclusion of commercial use on the free tier, contents of the Enterprise plan — https://elevenlabs.io/pricing (as of 2026-09-07)
- Prices per character and per minute over the API, surcharge for dubbing without watermark — https://elevenlabs.io/pricing/api (as of 2026-09-07)
- Data processing, applicability to self-booked plans, sub-processor procedure, deletion periods, standard contractual clauses, reservation on storage location — https://elevenlabs.io/dpa (as of 2026-04-08)
- Licence over content, objection to training use and its effect, law of the State of New York for businesses, carve-out for the vendor's own business purposes — https://elevenlabs.io/terms-of-use-eu (as of 2026-09-07)
- Purposes of processing, controller for voice data in the European Economic Area, affiliates, retention of biometric data — https://elevenlabs.io/privacy-policy (as of 2026-05-20)
- Sub-processor list with purpose and region, certificates and model cards, training data transparency disclosure, dated announcements on certifications — https://compliance.elevenlabs.io (as of 2026-09-07)
- Disclosure duty of deployers towards their users, reference to Regulation (EU) 2024/1689, assignment of classification to the customer — https://elevenlabs.io/use-policy (as of 2026-09-07)
- Zero retention mode: plan binding, covered endpoints, exclusion of the web interface, vendor reservation — https://elevenlabs.io/docs/eleven-api/resources/zero-retention-mode (as of 2026-09-07)
- Selectable storage locations, restriction to the Enterprise plan, processing outside the selected location — https://elevenlabs.io/docs/overview/administration/data-residency (as of 2026-09-07)
- Participation in the EU-US Data Privacy Framework, status and categories of data covered — https://www.dataprivacyframework.gov/list (as of 2026-09-07)
- Price per million characters at the established counterpart — https://aws.amazon.com/polly/pricing/ (as of 2026-09-07)
- Plan ladder of the AI-native counterpart and the binding of data processing terms and single sign-on to the Enterprise plan — https://cartesia.ai/pricing (as of 2026-09-07)
