Security & Confidentiality
Dictalex is built for attorney-client confidentiality — not retrofitted to it. This page explains how your dictations, transcripts, and documents are protected. Honest, precise, without marketing phrases.
This page is a translation provided for convenience — the German version is authoritative.
AI processing without US companies
Transcription and summarization run exclusively through Mistral AI (Paris, EU) — contractually without training on your data. There is no US company in the AI processing chain.
Audio encrypted before it leaves our house
Recordings are encrypted in the browser (AES-256-GCM) before they are uploaded. The storage provider receives ciphertext only — we hold the key, not them.
Deleting means deleting — in backups too
On deletion, the recording's encryption key is additionally destroyed (crypto-shredding). Audio ciphertext in old backups thereby becomes retroactively unreadable.
The original remains untouchable
The original transcript is technically immutable (database trigger). Every AI output is a draft for review — never automatically final. Every change creates a new revision; history is never rewritten.
Strict client separation
Every firm is isolated at the database and application level (deny-all lockdown plus authorization on every single query). Cross-firm isolation is tested automatically per module.
Audit log & full portability
Access and changes are logged content-free and can be reviewed by firm admins. Your data belongs to you: fully exportable at any time (Markdown, Word, PDF, Obsidian vault).
The ÖRAK checklist, point by point
The Austrian Bar Association (ÖRAK) provides law firms with a checklist for the use of AI. These are our answers.
Professional secrecy (§ 9 (2) RAO)
Every processor in the chain is bound by contractual confidentiality: a data processing agreement (Art. 28 GDPR) and an agreement within the meaning of § 40 (3) RL-BA — with us and with our sub-processors. We do not use providers that will not commit to this.
Where is the data processed?
Database and storage: Frankfurt am Main (Supabase on AWS, region eu-central-1). AI processing: Mistral AI, EU. No processing takes place outside the EU.
Is AI trained on our data?
No. Contractually excluded — at Mistral as with us. Your dictations, transcripts, and documents are processed exclusively to provide the service.
Recording meetings (§ 120 StGB)
Meeting recordings only start after a mandatory consent step (participant list + confirmation), which is stored documented together with the recording. Solo dictations require no consent step.
Duty to review AI output
Dictalex is built so that the attorney's review is enforced: AI results are always drafts in an editor, the immutable original transcript sits alongside for comparison, and every version remains traceable.
GDPR data subject rights, erasure (Art. 17)
Deletion cascades completely: matter → recordings → audio → transcripts → documents → versions → search index. Optionally, a retention rule deletes raw audio automatically N days after transcription — including key destruction.
Traceability
Access- and change-relevant actions are logged (who, what, when) — deliberately content-free: the log contains IDs and statuses, never content.
The honest answers
Security pages tend to overpromise. Instead, we describe precisely which data is protected how — and where protection rests on contracts rather than cryptography.
Audio: cryptographically protected
Recordings are encrypted client-side; the storage in Frankfurt contains ciphertext only. The keys are held by us in a three-tier scheme — the master key outside the storage infrastructure. Even a complete copy of the storage or a backup is worthless without our keys, and crypto-shredding makes deleted recordings retroactively unreadable.
Text: operationally and contractually protected
Transcripts and documents are stored as searchable text in a locked-down database (deny-all access model, no anonymous access, authorization on every query). They are not additionally content-encrypted — German full-text search across your matters is a core feature and cannot run over encrypted content. We name this difference deliberately instead of hiding it behind the phrase “encryption at rest”.
And the CLOUD Act?
Precisely put: there is no US company in Dictalex's AI processing chain — transcription and summarization run through Mistral AI (EU). The hosting infrastructure (Supabase on AWS) is operated by US companies, even though the data never leaves Frankfurt; US authorities could theoretically compel these companies to hand data over. What that means in concrete terms: for audio, the answer would be unreadable ciphertext, because the keys are not held by the hoster. For text, the protection is contractual and operational, not cryptographic. Firms that want to exclude even this residual risk run Dictalex in the enterprise model on their own or EU-owned infrastructure — then the database, too, sits entirely out of reach of US providers.
The technology in detail
- Client-side encryption in the browser (WebCrypto, AES-256-GCM) before every upload
- Three-tier key hierarchy (master → firm → recording), rotatable without re-encrypting the audio data
- Database lockdown: row level security without a single allow policy, no client API, privileges revoked from anonymous roles
- Immutability of the original transcript as a database trigger, not just an application rule
- Automated isolation tests (cross-firm) for every API module in CI
- Content-free application logs and a content-free audit log — IDs and statuses, never client content
- No US services touching client content: no Google Analytics, no font CDNs, no error trackers with US endpoints. The application itself runs no analytics script at all — only this website measures visits cookie-free, without personal data, and exclusively via EU servers (Fathom, full EU isolation). Transactional emails (sign-in links, invitations — never client content) are currently sent via Postmark (US); a switch to an EU provider is planned
- Retention rules with key destruction (crypto-shredding) and a complete GDPR deletion cascade
Questions about security?
We provide the DPA and the agreement pursuant to § 40 (3) RL-BA on request. For in-depth technical questions — for instance as part of a firm-internal review — simply get in touch.
Get in touch