How do you talk about the ASR decrypt window without fake E2EE?

by

I’m a maker shipping meeting transcription with a hard constraint: after a job finishes, even we shouldn’t be able to read the archive (device-bound keys / dual-wrap).

The awkward part every privacy AI hits: cloud ASR still needs a short in-memory plaintext window. We call that out instead of marketing “E2EE everywhere.”

On the buyer side we also keep risk low: within 7 days, if you’ve used ≤30 hours of transcription, unconditional refund.

Curious how others handle the buyer conversation:

  1. Do you name the processing window explicitly, or keep it in the fine print?

  2. For “root on the inference host mid-job” — is job-scoped keys + wipe enough for you, or is attestation mandatory before you’d trust it?

  3. What’s the one residual people forget (queues, logs, retries, support exports)?

Not looking for upvotes — looking for holes and better framing.

Context: we launched a meeting product built around this constraint — details on my Product Hunt profile / launch if useful.

17 views

Add a comment

Replies

Be the first to comment