SECURITY & ARCHITECTURE

Your notes stay under your control.

DocketVox is built so the most sensitive part of the system — the content of your notes — never lives on our infrastructure in readable form.

✓

Client-side encryption

Drafts are encrypted in your browser with AES-256-GCM before anything leaves the device. Regular dictation note body is never stored on our servers.

✓

Hardware-keyed vault

With Face ID, Touch ID, or Windows Hello, your vault key is derived from secure hardware (WebAuthn PRF). We cannot reconstruct it under any circumstance.

✓

Device-key fallback

When hardware keys aren't available, DocketVox generates a random 256-bit device key on first sign-in and shows you a one-time recovery code. The key never leaves your device — the server holds only ciphertext.

✓

Capability-token Secure Send

Messages to external recipients are encrypted with a random per-message key, wrapped with a 256-bit capability token delivered only in the link fragment and discarded by the server. Access is gated by email 2FA verification.

✓

OAuth only

Google and Microsoft sign-in. We never see or store your password. An optional PIN adds a second factor and is stored only as an Argon2id hash — never in plaintext.

✓

Time-limited sharing + 2FA

External recipients receive a short-lived link and must enter a one-time code sent to their email. No permanent access.

✓

Self-hosted & minimal

Runs on dedicated infrastructure under our control. No third-party analytics or tracking pixels. Audit logs contain metadata only, retained for security monitoring — automated 90-day pruning is planned but not yet implemented.

✓

Data minimization

We collect only what is required to operate the service, and never the content of your dictations.

Honest compliance posture

DocketVox is not SOC 2 Type II or ISO 27001 certified. If your firm requires those certifications as a condition of adoption, DocketVox is not yet the right fit. We would rather be transparent about this than imply otherwise.