Zero-trust dictation
assume no cloud
Zero trust starts from one assumption: the network is already compromised. Dictation that keeps speech on the endpoint honours that assumption — it removes the cloud from the data path, so there is no vendor to trust, verify, or contractually bind for the words you speak. This is the architectural mapping to NIST SP 800-207. Informational, not legal advice — confirm specifics with your security or compliance team.
Zero trust says assume no cloud
No implicit trust — not even on your network
NIST SP 800-207 defines zero trust as a paradigm that grants no implicit trust to assets or user accounts based solely on their physical or network location, with authentication and authorization as discrete functions performed before a session to an enterprise resource is established (NIST SP 800-207). Trust is per-session and resource-focused — never granted by network position. That is the canonical basis for "keep data on the endpoint so no cloud path is ever trusted."
Assume breach, always verify
NIST summarizes the model as "never trust, always verify — for every access request!" and states it assumes the system will be breached and designs security as if there is no perimeter, evaluating each request in real time against policy, credential, and device state (NIST). Even verified users are reverified for each resource. The dictation corollary writes itself: assume breach ⇒ assume no cloud is trusted.
Cloud dictation is an avoidable trust grant
If the environment is already compromised, every hop your audio takes to a vendor cloud is a network a breach could laterally traverse, and a processor you must vet, contract, and audit. On-device inference keeps content off every one of those paths — the architectural answer zero trust keeps asking for, delivered by removing the cloud from the data path rather than trusting it harder.
On-device removes the cloud from the chain
No payload leaves, so no processor is engaged
When speech recognition and language-model cleanup both run on your own CPU or GPU, no audio or transcript is transmitted to anyone. Under GDPR Article 28, a written Data Processing Agreement is mandatory whenever a controller engages a processor for personal data, and the processor must act only on documented instructions (gdpr-info.eu). When there is no processor touching the dictated content, there is no DPA, no sub-processor list, and no cross-border transfer mechanism triggered for that content. The DPA surface collapses to whatever handles updates — and that is independently disableable.
Data residency, by construction
With no payload leaving the endpoint, residency and localization obligations for the dictated content are satisfied by definition. Region-pinning and cross-border mechanisms (SCCs, Schrems II) come off the STT procurement checklist because there is nothing to pin or transfer. The only outbound call Blabb makes is the licence check — roughly once a day, or every 30 days offline — and it carries no dictation content. Optional crash reports are off by default and scrubbed of sensitive strings.
Offline, even air-gapped
The models ship inside the installer and run locally, so dictation keeps working on disconnected or regulated endpoints where cloud STT cannot operate at all. A verified subscription runs for 30 days without reaching the licence server. For locked-down environments, see our locked-down dictation guide and the Citrix & RDP notes — Blabb types at the cursor through four selectable input methods, so it works where clipboard paste is blocked.
A signed, certified binary, not a blind download
Signed and tamper-evident
Microsoft requires that all MSIX packages be signed before installation, and the AppxSignature.p7x combined with AppxBlockMap.xml lets Windows verify package integrity at install time and at runtime, with packaged apps running in a lightweight container (Microsoft Learn). Blabb ships as a signed MSIX through the Microsoft Store — not an unsigned installer pulled from a vendor CDN. Tamper-evident from download to runtime.
Microsoft-vouched and malware-scanned
Store certification runs security tests that check an app's packages for viruses and malware, and at publishing the packages are digitally signed by Microsoft to protect them against tampering, with continued spot-checks after release (Microsoft Learn). Vendor-review and procurement get a publisher-identified, integrity-checked binary rather than a blind download — the trust anchor is Microsoft's certificate, not the vendor's marketing.
Deploys through the MDM you already run
IT pros use Configuration Manager and Intune to manage MSIX apps, can preconfigure devices using provisioning and DISM, and control app access with Group Policies and AppLocker (Microsoft Learn). It is a least-privilege fit: security teams scope the dictation app's own privileges on the endpoint, instead of granting a remote SaaS broad data-access scopes and API keys. No new SaaS surface to review, license, or budget for.
Assume breach. Then remove the cloud from the path.
Two weeks free. Your audio and transcripts stay on the machine.
FREE TIER 2,000 WORDS/DAY · 14-DAY UNLIMITED TRIAL IN-APP · CANCEL ANY TIME
