Security starts with a smaller data path
Whisperstream performs core speech recognition on the Windows PC. Dictation does not need an internet connection after the selected speech model is downloaded. Initial model downloads, automatic update checks, periodic Pro license validation, user-enabled remote enhancement, and explicit external actions use the network.
Current as of September 3, 2026. You may share this page and security material we provide within your organization for evaluation, security, and procurement review. Product use remains governed by the Whisperstream EULA.
Data path and security boundary
Flow of dictation data: Microphone audio moves to on-device speech recognition, then to local text processing, all within the local PC boundary. By default, completed text passes temporarily through the Windows clipboard before it is pasted into the destination app. Keystroke delivery avoids the clipboard. An optional branch from local text processing exists for user-enabled remote enhancement, which is off by default and sends transcript text to the provider the user configures.
Clipboard is the default and temporarily holds the completed text before paste. Keystroke mode types text without using the clipboard. The destination app receives the result.
Off by default. When a user enables remote enhancement, transcript text is sent to the provider they configure.
Controls you can review
On-device transcription
Speech-to-text runs on the local CPU. After the selected model is downloaded, core dictation does not require the internet.
Encrypted local history
New installs save transcript text and source audio locally for 7 days by default. Both are encrypted at rest. Users can disable either setting or change retention; new Managed Lockdown setups start with history off.
Signed Windows installer
Release installers are signed under the publisher name Lanreal Technologies Inc.
Managed Lockdown
An optional administrator-owned policy keeps Lockdown on and restricts enhancement to local processing for standard users.
Know where the boundary ends
The destination app controls what happens to text after insertion. User-enabled remote enhancement sends transcript text to the configured provider. Product operations such as model downloads, updates, license validation, and user-submitted feedback also use external services. Whisperstream does not automatically upload diagnostics or native app analytics.
This security summary is a factual description of the current product, not a warranty, certification, SLA, dedicated support promise, deployment or configuration commitment, or commitment to future features.
Continue your review
- Product documentation
Feature guides, installation details, and system requirements.
- Managed Lockdown for organizations
Policy controls, lockdown behavior, and deployment guidance.
- Privacy Policy
How software and website data is handled.
- EULA
End user license agreement for Whisperstream software.
- Service providers
External services and infrastructure providers.
Need the detailed security overview?
For an active organizational review, request the detailed overview for your deployment and app version. Tell us which version you are evaluating so we can confirm which material applies.