Steno for Defence

Built for the discussions that can't touch a cloud.

Operational planning and sensitive discussions run on hardware you control, on networks you control. Steno does the entire pipeline — capture, transcription, summary — on the device, offline, with nothing transiting an external server. It's designed for air-gapped, local-only deployments — the environment cloud notetakers structurally can't serve. (Accreditation for any specific classified environment is a function of your own deployment and authorization process, not the app alone.)

Runs air-gapped / offline Nothing leaves the device

Why cloud tools don't fit

  • Cloud transcription is a non-starter when the audio can't leave the enclave.
  • SaaS meeting assistants require connectivity and a vendor relationship you can't extend to classified work.
  • A meeting bot is an external participant — unacceptable in an operational context.

What happens when the data leaves

The pattern is consistent: the compromise happens at a link in the chain that isn't yours. A contractor's system, a vendor's build server, a file that left the enclave and couldn't be recalled.

UK Ministry of Defence, Afghan relocations · 2022, disclosed 2025

A spreadsheet that left the building

In February 2022 a member of staff at UK Special Forces headquarters emailed out a dataset holding the names and details of roughly 19,000 Afghans who had applied for relocation under ARAP. It was not discovered until August 2023, when part of it surfaced in a Facebook group. The government obtained an unprecedented superinjunction that kept the breach — and a secret resettlement scheme built in response — out of public view until July 2025.

What Steno changes

Nothing was hacked. A copy was made and sent, and it could not be recalled. Steno cannot stop a person emailing a file, and doesn't claim to — but it adds no copies of its own: no vendor-side duplicate, no automatic sync, no export step in the pipeline. Recordings, transcripts and summaries are ordinary local files, held under whatever controls you already run on that machine.

House of Commons Defence Committee report(opens in a new tab)

UK MoD payroll provider · 2024

The contractor was the way in

Disclosed to Parliament in May 2024: an external payroll system operated by contractor Shared Services Connected Ltd was accessed by what the Defence Secretary called a malign actor, exposing names and bank details of up to around 270,000 serving personnel, reservists and veterans. The MoD's own networks were not the entry point — the third party's system was.

What Steno changes

Defence security is bounded by the least-defended system holding the data, and that system frequently belongs to someone else. Every SaaS notetaker adds one. Steno adds none: there is no vendor holding your meeting content, so there is no vendor to breach.

AP / SecurityWeek, May 2024(opens in a new tab)

SolarWinds Orion · 2020

A trusted update carried the attacker in

An actor the US government attributed to Russia's SVR compromised SolarWinds' build process and planted a backdoor in signed Orion updates shipped between March and June 2020. CISA issued Emergency Directive 21-01 ordering federal civilian agencies to disconnect the product; agencies including Treasury, Commerce and DHS were breached through it.

What Steno changes

Steno does not make supply-chain risk disappear — no software does, and any vendor claiming otherwise is selling you something. What it removes is the standing data flow a compromise could ride: Steno makes no network calls with your meeting content, so there is no established channel out. And it is MIT-licensed, so your security authority can review the source and build it themselves rather than trusting a binary.

CISA advisory AA20-352A(opens in a new tab)

Each incident above is a matter of public record, summarised from the linked source and verified September 2026. Steno is not affiliated with any organisation named here.

Fully offline

No network dependency after setup. Steno runs on air-gapped and disconnected systems where SaaS tools cannot.

Nothing leaves the device

Audio, transcripts, and summaries stay on the machine. There is no upload path and no vendor in the data flow.

On-device models

Transcription (Parakeet, Whisper) and summarization run locally on your hardware — no external inference service is ever called.

Open and inspectable

MIT-licensed source your security authority can review and build in a controlled environment.

On compliance

Steno runs entirely on your device. Your meeting recordings, transcripts, and summaries never reach our servers — there is no third-party processor handling your meeting data, which addresses a meaningful part of HIPAA, GDPR, and data-residency exposure. (Those frameworks also cover safeguards, agreements, and processes that remain your responsibility — no tool hands you compliance.) Steno itself isn't a certified cloud service, because there is no cloud service handling your meetings to certify — and that's the point: the vendor-breach risk that frameworks such as SOC 2 exist to assure against isn't in that path.

Questions

Yes — that's a primary design target. After the one-time model download, everything runs with no network connection at all.

No. Steno makes no network calls with your meeting content. Recordings, transcripts, and summaries are ordinary files in local storage on your device.

Yes. It's open source, so it can be audited and built from source in your own environment before deployment.

Also built for: Government

Start keeping private notes.

Free. Open source.

macOS 14.4+ (Apple Silicon) · Windows 10/11 (x64, alpha — unsigned) · ~4 GB for the default model