Your notes stay under your control.
DocketVox is built so the most sensitive part of the system — the content of your notes — never lives on our infrastructure in readable form.
Client-side encryption
Drafts are encrypted in your browser with AES-256-GCM before anything leaves the device. Regular dictation note body is never stored on our servers.
Hardware-keyed vault
With Face ID, Touch ID, or Windows Hello, your vault key is derived from secure hardware (WebAuthn PRF). We cannot reconstruct it under any circumstance.
Device-key fallback
When hardware keys aren't available, DocketVox generates a random 256-bit device key on first sign-in and shows you a one-time recovery code. The key never leaves your device — the server holds only ciphertext.
Capability-token Secure Send
Messages to external recipients are encrypted with a random per-message key, wrapped with a 256-bit capability token delivered only in the link fragment and discarded by the server. Access is gated by email 2FA verification.
OAuth only
Google and Microsoft sign-in. We never see or store your password. An optional PIN adds a second factor and is stored only as an Argon2id hash — never in plaintext.
Time-limited sharing + 2FA
External recipients receive a short-lived link and must enter a one-time code sent to their email. No permanent access.
Self-hosted & minimal
Runs on dedicated infrastructure under our control. No third-party analytics or tracking pixels. Audit logs contain metadata only, retained for security monitoring — automated 90-day pruning is planned but not yet implemented.
Data minimization
We collect only what is required to operate the service, and never the content of your dictations.
Honest compliance posture
DocketVox is not SOC 2 Type II or ISO 27001 certified. If your firm requires those certifications as a condition of adoption, DocketVox is not yet the right fit. We would rather be transparent about this than imply otherwise.