Enterprise dictation
that clears IT review
Cloud dictation turns every spoken word into a vendor review: a processor to vet, a data-processing agreement to negotiate, a breach surface to assess. On-device dictation removes the cloud from the data path, so there is nothing for procurement to trust and nothing for security to assume will be breached. This page maps the architecture to the questions IT and vendor review actually ask. Informational, not legal advice — confirm specifics with your counsel or compliance team.
Cloud dictation turns your voice into a vendor to trust
Assume breach — assume no cloud is trusted
NIST SP 800-207 defines zero trust as a model that grants no implicit trust based on physical or network location, evaluating each access request in real time (NIST SP 800-207). NIST summarizes it as "never trust, always verify" and states the model assumes the system will be breached and designs security as if there is no perimeter (NIST Taking Measure). Routing dictated audio to a vendor cloud is an avoidable trust grant: every network hop is one a breach could laterally traverse. On-device inference keeps content off every one of them.
The DPA is the deliverable
Under GDPR Article 28, any processor handling personal data must operate under a written Data Processing Agreement and may process only on documented instructions from the controller — which drags in a sub-processor list, audit rights, and a cross-border transfer mechanism (GDPR Art. 28). Cloud speech and LLM vendors trigger all of it. When the processing happens on the user's own CPU, the controller has no processor for the dictated content — and the DPA, sub-processor, and Schrems II negotiations drop off the procurement checklist for that content.
Residency by construction
With no payload leaving the endpoint, data-residency and localization obligations for the dictated content are satisfied by definition — there is no region to pin and no transfer to govern. The only network call Blabb makes is a licence check (roughly once a day, and at most every 30 days) through Polar that carries no dictation content, and optional crash reports that are off by default and scrub sensitive strings. The data path vendor review exists to police simply is not there.
A signed MSIX package, not a blind download
Store-signed and Microsoft-vouched
Microsoft requires that all MSIX packages be signed before installation, and the AppxSignature.p7x combined with AppxBlockMap.xml lets Windows verify package integrity at install time and runtime, with packaged apps running inside a lightweight container (Microsoft Learn — What is MSIX?). Store certification also runs security checks for viruses and malware and re-signs your package with a Microsoft certificate so it installs without security warnings, with continued spot-checks after release (app certification process). Vendor review gets a publisher-identified, tamper-evident binary rather than an installer pulled from a vendor CDN.
Deploys through your existing MDM
IT pros manage MSIX apps with Configuration Manager and Intune, can pre-provision devices using provisioning and DISM, and scope access with Group Policies and AppLocker (Microsoft Learn — Manage your MSIX deployment). Blabb rolls out through the endpoint-management channels you already operate, and adds no new SaaS surface to license, review, or retire — one MSIX, no separate agent, no tenant to stand up.
Offline and air-gap friendly
Both models ship inside the installer and run on the user's CPU or GPU — Cohere Transcribe for speech recognition, IBM Granite (an instruction-following enterprise LLM, not a chatbot) for text cleanup. A verified subscription works for 30 days without reaching the licence server, and MSIX can be provisioned via DISM or Intune without a live Store session. Dictation keeps working on disconnected or regulated endpoints where cloud STT cannot operate at all.
Encrypted history and least privilege
Local history is SQLite with row-level DPAPI + HMAC-SHA256 encryption, keys tied to the Windows account; audit logging carries a cryptographic chain of custody; PHI and secret strings are masked in logs by default. Retention is user-set — don't save, 1 day, 1 week (the default), 1 month, or forever. The MSIX container plus Intune and AppLocker let security scope the app's own privileges on the endpoint, instead of handing a remote SaaS broad data-access scopes and long-lived API keys.
What Blabb doesn't claim
Not "HIPAA certified" — no software is
HIPAA compliance is a property of an organization's practices, not a product badge. What the architecture gives you: dictated PHI and client content never leave the machine, which removes the transmission risk and the Business Associate relationship for that content entirely. For the full analysis — encryption, audit logging, and the PHI egress inventory — see our HIPAA & Security page.
Locked-down reach, with one Windows boundary
Blabb types at the cursor through four selectable input methods — set globally or overridden per app — so it works in RDP, Citrix, and VDI sessions where clipboard paste is blocked. The honest limit: it cannot type into elevated or admin (UIPI-protected) windows. That is a Windows boundary, not a Blabb bug, and it applies identically to every input-simulation tool. See the Citrix & RDP guide and the locked-down desktop guide.
x64 Windows 11 only
Blabb runs on Windows 11 on Intel/AMD x64. Arm and Snapdragon machines run it only under slower x64 emulation — a constraint of the on-device model runtimes, not a choice we'd hide. We would rather say so up front than have IT discover it midway through a pilot.
The fastest vendor review is the one with no data path to argue over.
Two weeks free. Your audio and transcripts stay on the machine.
FREE TIER 2,000 WORDS/DAY · 14-DAY UNLIMITED TRIAL IN-APP · CANCEL ANY TIME
