Softspoken onmanaged devices.

Below are the network requirements for Softspoken: what the app connects to, and what to allow if you need to.

The short version

  • Audio never leaves the machine. Speech-to-text runs entirely on the device.
  • Core use needs no account and no network: recording, transcription and dictation work fully offline with the bundled speech model.
  • AI features are optional and text-only. When used, transcript text is processed in Sydney, Australia, and not stored.
  • Outbound HTTPS only, on port 443 for every Softspoken host, to the short list below. No inbound listening ports. A calendar link you supply is fetched at whatever https address you give it.
  • Updates are signature-verified inside the app, so update integrity does not depend on the transport.
  • Credentials and tokens live in the operating system's keychain, never in files or logs. One stated exception: a calendar link you supply is kept in the app's settings file on the device.

Network requirements

HostPurposeNeeded forWhen
ai.softspoken.io
port 443
Sign-in, plan and entitlements, Softspoken AI requests. Text only, never audio.Account and AI features (optional)When you sign in or use an AI feature. A signed-in app also refreshes its plan at launch.
updates.softspoken.io
port 443
Update manifest (primary): latest-darwin.json or latest-windows.json. With Early bird updates switched on, preview-darwin.json or preview-windows.json is tried first, then the regular file.Automatic updatesWhile automatic checks are on: 20 seconds after launch, then every 6 hours, and when the window is brought to the front (at most once every 45 minutes). After a failed check it retries at 5 and 15 minutes, then every 45 minutes until one succeeds. Also once, immediately, when the user switches between regular and Early bird updates, even with automatic checks off.
raw.githubusercontent.com
port 443
Update manifest (fallback)Automatic updatesOnly if the primary host does not answer or does not serve the requested file
github.com, and GitHub's release-asset CDN it redirects to (currently release-assets.githubusercontent.com)
port 443
Update payloads; the one-off meeting speech model download (about 480 MB, SHA-256 verified)Automatic updates; the first meetingWhen you confirm an update; the first meeting, or the setup step that fetches the meeting model
huggingface.co, and *.xethub.hf.co if the model is Xet-hosted (only if configured)
port 443
Alternative speech modelsOnly if you change the speech model from the bundled defaultsOnce per model you select
api.anthropic.com, or bedrock-runtime.<your region>.amazonaws.com (default ap-southeast-2) (only if configured)
port 443
Bring-your-own-key AI, in place of Softspoken AIYour own AI key onlyEvery AI feature, if you configured your own key. One endpoint; the device never contacts a second region.
The calendar address you supply (an https ICS link; the port its address names, usually 443) (only if configured)
port 443
Meeting reminders from your calendarCalendar-link reminders onlyEvery 5 minutes while a link is configured, signed in or not

With every connection blocked

Recording, transcription and dictation carry on with the bundled models. AI, sign-in, updates and the first-run meeting-model download switch off, and the app says so rather than failing silently.

TLS inspection

Softspoken uses the operating system's trust store on both platforms, for every connection: the app and its bundled AI and speech runtime alike. A corporate root deployed to the macOS Keychain or the Windows certificate store is honoured with nothing to configure. Integrity does not rest on TLS alone: the meeting speech model download is SHA-256 verified and app updates are signature verified, so a proxy that alters bytes fails the integrity check, not merely the certificate check.

Proxies

Standard HTTPS_PROXY, HTTP_PROXY and NO_PROXY environment variables are honoured by every component. The app does not read the macOS System Settings proxy or the Windows WinINET proxy, and there is no PAC-file support. On macOS an app launched from Finder inherits the launchd environment rather than a shell profile, so set proxy variables through MDM or launchctl setenv.

Signing status

Windows builds (the installer, the app and every first-party executable inside it) are Authenticode-signed by River Edge Ventures Pty Ltd through Azure Artifact Signing, and timestamped. macOS beta builds are signed with our own development identity while Apple notarisation is being completed under the company; devices under Gatekeeper policy may need an explicit allow until then. Managed Windows fleets should allowlist by publisher: see App approval below.

App approval / allowlisting

Send your IT team the email below. Everything they need to approve Softspoken, the publisher subject, the install path and which engines it works with, is on this page.

Publisher (Subject Name)

CN=River Edge Ventures Pty Ltd, O=River Edge Ventures Pty Ltd, L=Sydney, S=New South Wales, C=AU
  • Allow by publisher or signer, never file hashes: our signing certificates rotate every few days by design, so hash rules break on every release.
  • Install path: %LOCALAPPDATA%\Softspoken\. This is a per-user install, so a policy that only allows Program Files and Windows blocks it by default, with no judgment about us at all. If your policy also allows by path, allow this one alongside the publisher rule to cover the bundled runtime too.
  • Engine families: AppLocker, WDAC, Microsoft Defender (Attack Surface Reduction rules and MDE certificate indicators), Airlock Digital and ThreatLocker all support allowing by publisher or signer.
  • Signature scope: the installer, the app and every first-party executable inside it, including the bundled Python runtime, are signed. Runtime DLLs and .pyd files are not individually signed; if your policy enforces DLL-level rules, allow them through your fleet's own catalog file.

Questions: security@softspoken.io.

Send this to your IT team

I've started using an app called Softspoken for meeting notes and dictation (I'm part of their beta), but it's being blocked on my laptop. Could you review and approve it for me? The vendor has a page for IT with the security overview, network requirements and app-approval details: softspoken.io/network. They'll answer questions at security@softspoken.io.

The full pack, on request

Everything above plus the detail your IT or security team will ask for, as one PDF:

  • The network and data-flow diagram: every connection the app can make, on one page
  • IT and network overview: what connects where, when, and what to allow
  • TLS inspection and proxies: what works out of the box on a managed network
  • Data handling and data at rest: what stays on the device, how it is protected there, what leaves, and where it is processed
  • Application security and supply chain: signing, updates, dependency scanning
  • Answers to the questions IT reviewers ask most
Request the IT pack

Be first when the doors open.

Join the waitlist