Security Policy
Effective date: August 24, 2026
Astralcyte Notes uses local encryption, signed software, restricted diagnostics, and isolated model runtimes to protect sensitive clinical work. This page describes the product's technical safeguards. Data handling and user obligations are covered separately in our Privacy Policy and Terms of Use.
Vault protection
Each vault uses a random 256-bit data-encryption key. The key is wrapped separately for passphrase and recovery-key access. Passphrase keys are derived using Argon2id, and vault data is stored using SQLCipher.
Astralcyte has no cloud recovery copy or administrative backdoor. If both the passphrase and recovery key are lost, the vault cannot be recovered.
The vault locks when the application exits, the operating-system session locks or signs out, or the configured inactivity period expires. Sensitive key material is kept in memory only while required by an unlocked operation and is cleared on a best-effort basis when the vault locks.
Recording protection
Audio is encrypted and authenticated incrementally as it is captured. Each recording uses a separate random audio key.
Temporary audio exists only for transcription and interrupted-session recovery. Once a complete transcript is stored, Astralcyte Notes cryptographically destroys the audio. Temporary audio cannot be played or exported.
Local model isolation
Transcription and note generation run locally using verified model and runtime files.
On desktop, model execution runs behind supervised process boundaries. A stalled model process can be stopped without deleting its encrypted input or freezing the application interface.
Updates and downloaded components
Application updates require a valid publisher signature before installation.
Model and runtime downloads are verified with cryptographic hashes.
Logs and diagnostics
Operational logs and crash reports use restricted formats intended to exclude clinical content and other sensitive content.
Diagnostics are not automatically transmitted to Astralcyte. Users should review any diagnostic material before sending it to support.
Security incidents
Astralcyte investigates reported or detected security incidents affecting systems under our control. Where required, we will notify affected individuals and regulators in accordance with applicable law.
Report a vulnerability
Report suspected vulnerabilities to security@astralcyte.com.
Include the affected component, application version, platform, reproduction steps, and observed behaviour.
Do not include client information, recordings, transcripts, notes, prompts, vault files, passphrases, recovery keys, or licence keys.
Researchers must not access or modify information belonging to others, disrupt services, use social engineering, or publicly disclose an unresolved vulnerability before Astralcyte has had a reasonable opportunity to investigate and respond.
Changes to this Policy
We may update this Security Policy as the product, threat model, infrastructure, or legal requirements change. The effective date above identifies the current version.