Dicta
Join the waitlist

Do you have SOC 2, a BAA, or a DPA?

Usually this question is about how a vendor handles data you send it. Cloud dictation tools receive your audio or transcript on their servers, so buyers reasonably want a certification and a signed agreement covering that handling. Dicta does not hold a SOC 2 report, a signed DPA or a BAA today, and we are not going to claim any of them before we have earned them.

The honest reason it matters less here: dictation content never leaves your Mac. Speech recognition, corrections and the AI rewrite all run on-device, so there is no server processing your voice or your text, and no content-processor relationship to certify or contract around. A SOC 2 report audits a vendor’s controls over data it holds; we hold none of your dictation, which is a different threat model, not a shortcut around one. The only data we do hold is limited account and billing information (your email and license activations) plus the aggregate usage statistics described on the Privacy page: daily counters linked to your license, never your content, on by default with an off switch in Settings. If your organization needs a formal DPA, a SOC 2 report or other compliance paperwork before it can adopt Dicta, email [email protected] and we will tell you honestly where we stand; this is not legal advice.

← All questions