A closed folder and a pen on a dark desk

Technology & privacy

Choosing dictation when someone else has to sign it off

"No audio leaves the endpoint" and "processed only by a certified processor" are different requirements. They select different products, and most procurement conversations go wrong by conflating them.

Last updated

The two requirements, which are not the same

"No transfer""Governed transfer"
The sentenceThe audio never leaves the endpointProcessing is by an assessed, certified processor
Satisfied byOn-device recognitionA certified cloud vendor with a DPA
EvidenceA demonstration you can repeatA certificate, a scope statement, an audit report
Fails onProcurement gates that require a certificateA policy that forbids transfer at all
Typical inLegal, journalism, security, R&DHealthcare, financial services, large enterprises

Both are legitimate. They are answered by different kinds of product and an evaluation that has not decided which it is asking for will waste everyone's time and probably end in a rejection late in the process.

Working out which one you have

  1. Find the actual policy sentence Not what someone remembers it saying. The information security policy, the data protection policy, the professional regulator's guidance, or the client contract. The wording decides this.
  2. Look for the word "processor" If the policy is built around assessing and contracting with processors, you are in the second world and the process expects a vendor to assess. If the policy forbids transfer of certain categories, you are in the first.
  3. Ask who signs it off and what they need to see A security team usually accepts a demonstration. A procurement function usually needs a document. These are different people with different evidence standards.
  4. Ask whether the client has a say In professional services the client's own policy often flows down through the engagement terms, and it may be stricter than yours.
  5. Then evaluate products Not before. The architecture question is settled by the policy, not by a feature comparison.

What on-device recognition answers

When recognition runs on the endpoint, most of a standard security questionnaire stops applying — not because the answers are good but because the questions are about a transfer that does not occur.

  • Subprocessors handling voice data: none.
  • Data residency of transcripts: the endpoint.
  • Retention by the vendor: none; the vendor never receives it.
  • Vendor breach exposure: no dictation content.
  • Cross-border transfer: none.
  • Training on customer data: not possible; never received.
  • Evidence: disconnect networking and dictate. Repeatable by the reviewer.

That last point is unusual and worth using. Most vendor assurances have to be taken on trust. This one can be tested by the person doing the review, in their own hands, in two minutes.

What it does not answer

  • Central policy enforcement. If you need to guarantee every user's history retention, an app with per-machine settings cannot do that. Vaitly Voice has no MDM profile and no admin console.
  • Audit logging. There is no central record of who dictated what. For some regulated environments that is disqualifying.
  • Certification. Architecture is not an audit. If the gate is a certificate, it is a certificate.
  • Endpoint security generally. On-device means on the device. Disk encryption, device management and physical security remain yours.
  • Where the text ends up. Dictating into a cloud system puts the text in that system, governed separately.

The note to write

Whatever you choose, write down what you can demonstrate rather than what you believe. A short factual note survives a review far better than a vendor's marketing page, and it is what a regulator or a client would ask for.

A workable template

  • Speech recognition runs on the endpoint. Verified on date by dictating with networking disabled.
  • Any automatic rewriting also runs locally. Verified the same way, separately.
  • No audio or transcript is transmitted to the vendor.
  • Transcripts and audio are retained locally for n days at path, on a FileVault-encrypted disk.
  • The application contacts the vendor for licence validation and update checks only. Analytics disabled on date.
  • The vendor is name, company number number, and claims no security certifications.
  • Residual risks: endpoint compromise, physical access, and being overheard while dictating.

The risk nobody puts in the questionnaire

You are speaking confidential information aloud. In an open-plan office, a shared room, a train or a café, the architecture is irrelevant — the sentence is in the room.

This is, in practice, the most likely confidentiality failure associated with dictation, and no product addresses it. The mitigations are physical: a door, a close headset microphone that lets you speak quietly, and judgement about which material is dictated where.

Questions

Is on-device dictation enough for regulated work?

It depends entirely on whether your requirement is about transfer or about certification. On-device recognition answers the first completely and the second not at all. Find the policy sentence before evaluating products.

Do you sign a data processing agreement?

For dictation content there is nothing to process — the audio and text never reach us. We hold account and billing data for purchased licences, which our privacy policy covers and which we will discuss.

Can we enforce retention settings across a team?

No. VV has no MDM configuration profile and no admin console; settings are per machine. If central enforcement is a requirement, we do not meet it.

What evidence can we give our auditor?

A dated record of the offline demonstration, the local paths and retention setting, the network activity observed, and the vendor's published statement of what it does and does not claim. The demonstration is the strongest item because the auditor can repeat it.