Security starts with a smaller data path

Whisperstream performs core speech recognition on the Windows PC. Dictation does not need an internet connection after the selected speech model is downloaded. Initial model downloads, automatic update checks, periodic Pro license validation, user-enabled remote enhancement, and explicit external actions use the network.

Current as of September 3, 2026. You may share this page and security material we provide within your organization for evaluation, security, and procurement review. Product use remains governed by the Whisperstream EULA.

Data path and security boundary

Flow of dictation data: Microphone audio moves to on-device speech recognition, then to local text processing, all within the local PC boundary. By default, completed text passes temporarily through the Windows clipboard before it is pasted into the destination app. Keystroke delivery avoids the clipboard. An optional branch from local text processing exists for user-enabled remote enhancement, which is off by default and sends transcript text to the provider the user configures.

On-device boundary
Stage 1Microphone audio
Stage 2On-device speech recognition
Stage 3Local text processing
Primary delivery
Windows clipboard or keystroke delivery

Clipboard is the default and temporarily holds the completed text before paste. Keystroke mode types text without using the clipboard. The destination app receives the result.

Optional branch
User-enabled remote enhancement

Off by default. When a user enables remote enhancement, transcript text is sent to the provider they configure.

With the default Clipboard input style, Windows clipboard history, clipboard sync, and organizational clipboard policy apply. Keystroke input avoids the clipboard. The destination app's storage, sync, and sharing policies apply after insertion.

Controls you can review

On-device transcription

Speech-to-text runs on the local CPU. After the selected model is downloaded, core dictation does not require the internet.

Encrypted local history

New installs save transcript text and source audio locally for 7 days by default. Both are encrypted at rest. Users can disable either setting or change retention; new Managed Lockdown setups start with history off.

Signed Windows installer

Release installers are signed under the publisher name Lanreal Technologies Inc.

Managed Lockdown

An optional administrator-owned policy keeps Lockdown on and restricts enhancement to local processing for standard users.

Know where the boundary ends

The destination app controls what happens to text after insertion. User-enabled remote enhancement sends transcript text to the configured provider. Product operations such as model downloads, updates, license validation, and user-submitted feedback also use external services. Whisperstream does not automatically upload diagnostics or native app analytics.

This security summary is a factual description of the current product, not a warranty, certification, SLA, dedicated support promise, deployment or configuration commitment, or commitment to future features.

Continue your review

Need the detailed security overview?

For an active organizational review, request the detailed overview for your deployment and app version. Tell us which version you are evaluating so we can confirm which material applies.