SECURITY & ENTERPRISE · UPDATED JULY 2026

Security review, in plain facts.

Everything an IT or InfoSec team needs to evaluate LockedIn Flow for a corporate deployment: where data goes (nowhere), what it touches (almost nothing), how it's signed, and how to roll it out.

The one-sentence posture

LockedIn Flow has no vendor backend — no server of ours ever receives audio, transcripts, vocabulary, screen content, or telemetry. The largest breach surface in this category simply does not exist here.

Data flow (complete)

StageWhere it happensLeaves the device?
Microphone captureIn-process, 16 kHz mono, in-memoryNo
Speech recognitionParakeet TDT v3 on the Apple Neural EngineNo
Text cleanupRules engine + Apple FoundationModels, on-deviceNo
InsertionOS APIs (Accessibility / pasteboard)No
History & vocabularyAES-256-GCM files, Keychain-held keyNo
Model downloadOne time, ~600 MB, huggingface.coOutbound, once
Update checkOptional, HTTPS, Ed25519-signed appcastOutbound, optional

Permissions — the whole list

Code signing & supply chain

Offline enforcement for locked-down fleets

After the one-time model download, the app works with all egress blocked — verified in our self-test with network fetches refused at the library level. Models can be pre-seeded via MDM into ~/.cache/fluidaudio, and there is no account, activation, or revalidation heartbeat for a firewall to learn to hate.

Data governance

Deployment

What we don't claim

No HIPAA, FedRAMP, or SOC 2 certification is claimed. The architecture removes the largest compliance surface — no third party ever receives data — and your own device management (FileVault, screen lock, MDM) completes the posture. We're happy to answer your security questionnaire: security@lockedinflow.com.

FREE 14-DAY TRIAL · NO CARD · NO ACCOUNT

Pilot it with your team this week.

Everything unlocked for 14 days. Nothing to configure, nothing to whitelist except one model download.

Download for macOS

Architecture statements verified against the shipping build, July 26, 2026. The full whitepaper (threat model, dependency inventory) ships inside the app repo and is available on request.