Security architecture

Local processing. Encrypted vault. No telemetry. At all.

Noter Vault is designed for confidential meeting workflows where the record should remain on a device the organisation controls. Transcription, structured notes, and Theia run locally with no cloud upload required.

Short answer

The security boundary is the room-owned device.

Audio, transcripts, structured notes, session snapshots, and Theia conversations stay in the local workflow. Production devices contain no Wi-Fi hardware, and your Noter Vault shares no information with anyone - not even Noter - unless you explicitly choose to export or share it.

How it works

Plain-English data flow

  1. 01 Microphone captures audio in the room
  2. 02 Local ASR transcribes the meeting
  3. 03 On-device tooling adds diarisation and speaker-aware evidence
  4. 04 Local note generation creates structured notes and session snapshot
  5. 05 Theia answers against the local meeting record
  6. 06 The encrypted device vault stores the session
  7. 07 The user approves any PDF, DOCX, or TXT export
Requirement fit

Security posture at a glance

Cloud account required No
Cloud upload required for transcription No
Cloud upload required for structured notes No
Cloud upload required for Theia No
Wi-Fi hardware No
Telemetry None at all
Vault encryption AES-256-GCM
Vault password protection Configurable
User-approved export boundary PDF, DOCX, TXT
Vault model

What the encrypted vault protects

The verified software layer uses AES-256-GCM encryption for canonical device-vault records. Exported files are deliberate user-created copies and should be handled under the buyer policy.

AES-256-GCM with hardened key derivation

The encrypted device vault uses AES-256-GCM with PBKDF2-HMAC-SHA256 key derivation at 240,000 iterations. Session metadata, transcript segments, full transcript, structured notes, structured note JSON, session snapshots, Theia conversation messages, the session index, and any retained audio are all encrypted inside the vault.

Configurable password protection

Teams can enable vault password protection for shared rooms or higher-sensitivity workflows. With it enabled, the vault must be unlocked before sessions can be listed, loaded, recorded, or saved.

No Wi-Fi hardware

Production devices are built without Wi-Fi hardware, reducing accidental network exposure and reinforcing the local-first posture.

No telemetry at all

Your device does not phone home. Noter receives no meeting content, transcripts, prompts, usage data, notes, or device activity unless you explicitly choose to share something.

Export boundary

Exports are an explicit user action.

User-approved PDF, DOCX, and TXT exports. Exported files are deliberate copies outside the encrypted vault.

A Noter Vault PDF-style export generated from a confidential local session
Clear limits

What we should say carefully

Trust pages are strongest when they are precise. These boundaries keep the public claim defensible.

Not a legal privilege guarantee

Noter Vault is designed for privileged and confidential work, but whether privilege is preserved depends on facts, jurisdiction, and professional duties.

Exports live outside the vault

PDF, DOCX, and TXT exports are user-created copies. Once exported, they should be handled according to the organisation records policy.

Device key-hardening is configuration-specific

The public baseline should stay precise: AES-256-GCM encrypted device vault with configurable vault password protection. Any additional hardware-bound layer should be described after production verification.

FAQ

Questions buyers ask

Does Noter Vault upload audio or transcripts to the cloud?

No. No cloud upload is required for transcription, structured notes, or Theia. Meeting content is processed locally and stored in the encrypted device vault unless a user deliberately exports a copy.

Is the vault encrypted?

Yes. The Noter Vault device vault uses AES-256-GCM encryption for session records including transcripts, structured notes, snapshots, Theia messages, and the session index.

Does Noter Vault have telemetry?

No. Noter Vault has no telemetry at all. Your device shares no meeting content, transcripts, prompts, notes, usage data, or device activity with anyone - not even Noter - unless you explicitly choose to export or share it.

What encryption does Noter Vault use?

Noter Vault uses AES-256-GCM encrypted vault storage with configurable vault password protection. Vault keys are derived with PBKDF2-HMAC-SHA256 at 240,000 iterations. The vault encrypts every session artefact: metadata, transcript segments, full transcript, structured notes, structured note JSON, session snapshots, Theia conversation messages, the session index, and any retained audio.

Book a private security and workflow demo.

Noter Vault is configured around your industry, meeting types, templates, ASR context, glossary, and deployment needs.