Security Policy

Vault protection

Each vault uses a random 256-bit data-encryption key. The key is wrapped separately for passphrase and recovery-key access. Passphrase keys are derived using Argon2id, and vault data is stored using SQLCipher.

Astralcyte has no cloud recovery copy or administrative backdoor. If both the passphrase and recovery key are lost, the vault cannot be recovered.

The vault locks when the application exits, the operating-system session locks or signs out, or the configured inactivity period expires. Sensitive key material is kept in memory only while required by an unlocked operation and is cleared on a best-effort basis when the vault locks.

Recording protection

Audio is encrypted and authenticated incrementally as it is captured. Each recording uses a separate random audio key.

Temporary audio exists only for transcription and interrupted-session recovery. Once a complete transcript is stored, Astralcyte Notes cryptographically destroys the audio. Temporary audio cannot be played or exported.

Local model isolation

Transcription and note generation run locally using verified model and runtime files.

On desktop, model execution runs behind supervised process boundaries. A stalled model process can be stopped without deleting its encrypted input or freezing the application interface.

Updates and downloaded components

Application updates require a valid publisher signature before installation.

Model and runtime downloads are verified with cryptographic hashes.

Logs and diagnostics

Operational logs and crash reports use restricted formats intended to exclude clinical content and other sensitive content.

Diagnostics are not automatically transmitted to Astralcyte. Users should review any diagnostic material before sending it to support.

Security incidents

Astralcyte investigates reported or detected security incidents affecting systems under our control. Where required, we will notify affected individuals and regulators in accordance with applicable law.

Report a vulnerability

Report suspected vulnerabilities to security@astralcyte.com.

Include the affected component, application version, platform, reproduction steps, and observed behaviour.

Do not include client information, recordings, transcripts, notes, prompts, vault files, passphrases, recovery keys, or licence keys.

Researchers must not access or modify information belonging to others, disrupt services, use social engineering, or publicly disclose an unresolved vulnerability before Astralcyte has had a reasonable opportunity to investigate and respond.

Changes to this Policy

We may update this Security Policy as the product, threat model, infrastructure, or legal requirements change. The effective date above identifies the current version.

Contact

Care of Astralcyte Inc. 5255 Yonge St Suite 201 Toronto M2N 6P4 Canada

support@astralcyte.com