Softspoken onmanaged devices.
Below are the network requirements for Softspoken: what the app connects to, and what to allow if you need to.
The short version
- Audio never leaves the machine. Speech-to-text runs entirely on the device.
- Core use needs no account and no network: recording, transcription and dictation work fully offline with the bundled speech model.
- AI features are optional and text-only. When used, transcript text is processed in Sydney, Australia, and not stored.
- Outbound HTTPS only, on port 443 for every Softspoken host, to the short list below. No inbound listening ports. A calendar link you supply is fetched at whatever https address you give it.
- Updates are signature-verified inside the app, so update integrity does not depend on the transport.
- Credentials and tokens live in the operating system's keychain, never in files or logs. One stated exception: a calendar link you supply is kept in the app's settings file on the device.
Network requirements
| Host | Purpose | Needed for | When |
|---|---|---|---|
ai.softspoken.ioport 443 | Sign-in, plan and entitlements, Softspoken AI requests. Text only, never audio. | Account and AI features (optional) | When you sign in or use an AI feature. A signed-in app also refreshes its plan at launch. |
updates.softspoken.ioport 443 | Update manifest (primary): latest-darwin.json or latest-windows.json. With Early bird updates switched on, preview-darwin.json or preview-windows.json is tried first, then the regular file. | Automatic updates | While automatic checks are on: 20 seconds after launch, then every 6 hours, and when the window is brought to the front (at most once every 45 minutes). After a failed check it retries at 5 and 15 minutes, then every 45 minutes until one succeeds. Also once, immediately, when the user switches between regular and Early bird updates, even with automatic checks off. |
raw.githubusercontent.comport 443 | Update manifest (fallback) | Automatic updates | Only if the primary host does not answer or does not serve the requested file |
github.com, and GitHub's release-asset CDN it redirects to (currently release-assets.githubusercontent.com)port 443 | Update payloads; the one-off meeting speech model download (about 480 MB, SHA-256 verified) | Automatic updates; the first meeting | When you confirm an update; the first meeting, or the setup step that fetches the meeting model |
huggingface.co, and *.xethub.hf.co if the model is Xet-hosted (only if configured)port 443 | Alternative speech models | Only if you change the speech model from the bundled defaults | Once per model you select |
api.anthropic.com, or bedrock-runtime.<your region>.amazonaws.com (default ap-southeast-2) (only if configured)port 443 | Bring-your-own-key AI, in place of Softspoken AI | Your own AI key only | Every AI feature, if you configured your own key. One endpoint; the device never contacts a second region. |
The calendar address you supply (an https ICS link; the port its address names, usually 443) (only if configured)port 443 | Meeting reminders from your calendar | Calendar-link reminders only | Every 5 minutes while a link is configured, signed in or not |
With every connection blocked
Recording, transcription and dictation carry on with the bundled models. AI, sign-in, updates and the first-run meeting-model download switch off, and the app says so rather than failing silently.
TLS inspection
Softspoken uses the operating system's trust store on both platforms, for every connection: the app and its bundled AI and speech runtime alike. A corporate root deployed to the macOS Keychain or the Windows certificate store is honoured with nothing to configure. Integrity does not rest on TLS alone: the meeting speech model download is SHA-256 verified and app updates are signature verified, so a proxy that alters bytes fails the integrity check, not merely the certificate check.
Proxies
Standard HTTPS_PROXY, HTTP_PROXY and NO_PROXY environment variables are honoured by every component. The app does not read the macOS System Settings proxy or the Windows WinINET proxy, and there is no PAC-file support. On macOS an app launched from Finder inherits the launchd environment rather than a shell profile, so set proxy variables through MDM or launchctl setenv.
Signing status
Windows builds (the installer, the app and every first-party executable inside it) are Authenticode-signed by River Edge Ventures Pty Ltd through Azure Artifact Signing, and timestamped. macOS beta builds are signed with our own development identity while Apple notarisation is being completed under the company; devices under Gatekeeper policy may need an explicit allow until then. Managed Windows fleets should allowlist by publisher: see App approval below.
App approval / allowlisting
Send your IT team the email below. Everything they need to approve Softspoken, the publisher subject, the install path and which engines it works with, is on this page.
Publisher (Subject Name)
CN=River Edge Ventures Pty Ltd, O=River Edge Ventures Pty Ltd, L=Sydney, S=New South Wales, C=AU
- Allow by publisher or signer, never file hashes: our signing certificates rotate every few days by design, so hash rules break on every release.
- Install path: %LOCALAPPDATA%\Softspoken\. This is a per-user install, so a policy that only allows Program Files and Windows blocks it by default, with no judgment about us at all. If your policy also allows by path, allow this one alongside the publisher rule to cover the bundled runtime too.
- Engine families: AppLocker, WDAC, Microsoft Defender (Attack Surface Reduction rules and MDE certificate indicators), Airlock Digital and ThreatLocker all support allowing by publisher or signer.
- Signature scope: the installer, the app and every first-party executable inside it, including the bundled Python runtime, are signed. Runtime DLLs and .pyd files are not individually signed; if your policy enforces DLL-level rules, allow them through your fleet's own catalog file.
Questions: security@softspoken.io.
Send this to your IT team
I've started using an app called Softspoken for meeting notes and dictation (I'm part of their beta), but it's being blocked on my laptop. Could you review and approve it for me? The vendor has a page for IT with the security overview, network requirements and app-approval details: softspoken.io/network. They'll answer questions at security@softspoken.io.
The full pack, on request
Everything above plus the detail your IT or security team will ask for, as one PDF:
- The network and data-flow diagram: every connection the app can make, on one page
- IT and network overview: what connects where, when, and what to allow
- TLS inspection and proxies: what works out of the box on a managed network
- Data handling and data at rest: what stays on the device, how it is protected there, what leaves, and where it is processed
- Application security and supply chain: signing, updates, dependency scanning
- Answers to the questions IT reviewers ask most