Trust & Security

Last updated: August 4, 2026

You certify the record, so you carry the confidentiality duty — and any tool you run case audio through carries it with you. This page states plainly how Stenobox protects your work. Every claim here is specific on purpose: no vague badges, no marketing language, and nothing we haven't verified.

The short version: Only you can see your transcripts — enforced by the database itself, not just policy. Uploaded source audio is deleted within a day. Nothing you upload is ever sold, shared for advertising, or used to build or improve any other product.

Only you can see your work

Your transcripts, audio, and review data are tied to your account by security rules enforced at the database and storage layer. A request from any other user's account is refused by the infrastructure itself — this is not an access policy an employee follows; it is a rule the system cannot be asked to ignore. Ownership of every uploaded file is established server-side, never trusted from the uploading device.

What happens to your audio

Never used to train anything

Your recordings and transcripts are never sold, never shared for advertising, and never reused to build or improve any other product. That includes the outside speech and language services our pipeline uses to produce your draft: none of them use audio or text processed for Stenobox to train or improve their systems — a commitment we have confirmed in each provider's written commercial terms or in our account's data-control settings. Where a provider offered a data-sharing program, we opted out; where exclusion required a per-request setting, it is written into our code with a note that it must never be removed.

Where your data lives

Storage and processing run on Google Cloud, with your files stored in the US-East region and encrypted in transit and at rest. One transcription step runs on a provider's global infrastructure, which may route processing outside the United States. We say that because it is true — a page that told you "everything stays in the US" would be overclaiming, and in legal work an honest gap beats a polished overstatement.

Certifications — attributed honestly

Google Cloud, the infrastructure Stenobox runs on, holds SOC 2 and ISO 27001 certifications, among others. Those are Google's certifications, not ours — Stenobox is a small company and does not claim them directly. If you ever see a transcription product wearing a compliance badge, it is worth checking whose certification it actually is.

HIPAA, stated plainly

Stenobox does not claim HIPAA compliance and does not offer Business Associate Agreements today. Court reporting generally sits outside HIPAA's chain of covered entities — the confidentiality duties on deposition and hearing records come from court rules and protective orders, which is exactly the work Stenobox is built around. If your situation genuinely requires a BAA, tell us at hello@stenobox.com — we would rather hear the requirement than have you assume a compliance we haven't claimed.

Payments

Checkout and billing are handled by Stripe. Your card number goes to Stripe directly; Stenobox never sees or stores it.

Built by someone with the same license on the line

Stenobox is built and run by a working, Michigan-certified electronic recorder who processes his own case audio through the same pipeline his customers use — under the same confidentiality obligations you carry. That is not a security control, but it is the reason the controls above exist: this product was built by someone whose own name goes on the certificate.

Questions

Anything on this page you want evidence for, ask: hello@stenobox.com. The full legal detail lives in the Privacy Policy and Terms of Use.