Steno for Government

Meeting notes that never leave your perimeter.

Briefings, policy discussions, and internal reviews carry information that can't be handed to a cloud vendor. Steno records, transcribes, and summarizes entirely on the device — no third-party processor, no data crossing a border, no records leaving the machine they were captured on.

Nothing leaves the device Runs air-gapped / offline GDPR-aligned

Why cloud tools don't fit

  • Cloud meeting tools route audio through servers outside your control — and often outside your jurisdiction.
  • A bot joining the call is a participant you can't fully account for in a sensitive briefing.
  • Retention and access to recordings sit under a vendor's terms, not your records policy.

What happens when the data leaves

None of these were careless organisations. In each case the data was lost somewhere outside the walls of the organisation that owned it — at a cloud provider, at a processor, or inside a tool that quietly took a copy.

Microsoft Exchange Online · 2023

A stolen signing key opened government mailboxes

A China-linked actor, tracked as Storm-0558, used a stolen Microsoft consumer signing key to forge authentication tokens and read Exchange Online mailboxes belonging to 22 organisations and more than 500 individuals, including officials at the US State and Commerce Departments. Roughly 60,000 State Department emails were taken. The Cyber Safety Review Board concluded in 2024 that the intrusion was preventable and traced it to a cascade of avoidable failures at Microsoft.

What Steno changes

No tenant setting would have stopped this. The affected departments did nothing wrong — the compromise was inside the provider holding their mail. Steno removes that dependency for meeting content: there is no provider account, no key and no server holding your transcripts to be compromised.

Cyber Safety Review Board report (CISA, 2024)(opens in a new tab)

MOVEit Transfer · 2023

One file-transfer product, 2,500 organisations

From 27 May 2023 the CL0P group exploited a zero-day in Progress Software's MOVEit Transfer to steal data from every instance it could reach. More than 2,500 organisations were affected, among them multiple US federal agencies — the Department of Energy confirmed two of its entities were caught in it.

What Steno changes

Most of those organisations would not have named MOVEit if you had asked them to list their data path. Meeting recordings and transcripts are exactly the kind of data that accumulates in that sort of intermediary. Steno's pipeline has no intermediary: capture, transcription and summarisation all happen on the machine.

CISA advisory AA23-158A(opens in a new tab)

Otter.ai litigation · 2025

The notetaker itself became the exposure

Class actions consolidated as In re Otter.AI Privacy Litigation in the Northern District of California allege that the AI notetaker joined Zoom, Teams and Google Meet calls and recorded participants who were not its customers, transmitted call content to its servers, and used those conversations to train its models — without the consent of everyone in the room. The claims are unproven and Otter.ai disputes them.

What Steno changes

Whatever the outcome, the exposure is structural: once a notetaker sends audio off the device, consent, retention and model-training become somebody else's policy. Steno never sends the audio anywhere, so those questions stay yours to answer.

NPR, August 2025(opens in a new tab)

Each incident above is a matter of public record, summarised from the linked source and verified September 2026. Steno is not affiliated with any organisation named here.

Data sovereignty

Everything is processed and stored on the device. Nothing transits an external server, so residency and sovereignty obligations are supported by architecture, not a vendor promise.

Works air-gapped

After first-run setup, Steno needs no network. It runs on isolated and offline networks where cloud tools simply can't operate.

No bot in the room

Steno captures system and microphone audio directly — nothing joins the meeting as a participant.

Auditable by design

It's open source. Your security team can read exactly what touches the audio and confirm the no-network claim themselves.

On compliance

Steno runs entirely on your device. Your meeting recordings, transcripts, and summaries never reach our servers — there is no third-party processor handling your meeting data, which addresses a meaningful part of HIPAA, GDPR, and data-residency exposure. (Those frameworks also cover safeguards, agreements, and processes that remain your responsibility — no tool hands you compliance.) Steno itself isn't a certified cloud service, because there is no cloud service handling your meetings to certify — and that's the point: the vendor-breach risk that frameworks such as SOC 2 exist to assure against isn't in that path.

Questions

Because processing and storage happen on the device and nothing is uploaded, your data never leaves the machine — or the jurisdiction it's in. There is no cloud region to configure and no cross-border transfer to account for.

Yes. Once the models are downloaded during first-run setup, recording, transcription, and summarization all run offline. Steno makes no network requests with your meeting content.

Steno is open source (MIT). Your team can audit the code, build it from source, and confirm exactly what it does and doesn't send before deploying.

Also built for: Defence

Start keeping private notes.

Free. Open source.

macOS 14.4+ (Apple Silicon) · Windows 10/11 (x64, alpha — unsigned) · ~4 GB for the default model