Private transcription that can't read your meetings.
Conclave runs transcription inside confidential hardware the operator can't read at rest. It names a voice only with that person's consent, strips regulated data in-enclave, and signs every version so you can verify what happened offline.
The meetings that matter most go unrecorded.
Not because the tools are bad. Because using them is a liability. Your real competitor isn't another notetaker — it's the recorder staying off.
The record you needed is gone.
Keep the recorder off in a privileged call and the notes go with it. Hand-notes split your attention; a court reporter adds a third person to the room.
Record others and the liability is yours.
Bring a consumer notetaker into the room and you've taken everyone's voiceprint without consent. Non-users are suing Otter and Fireflies; the largest voice-privacy settlement reached $650M. It lands on whoever brought the tool.
Consent over your voice is a layer, like HTTPS.
Four properties, each enforced in the architecture and each shipped today — not a roadmap.
Consent-gated naming
No name touches a voice without a yes.
Speakers stay anonymous until the person agrees. Hear your own clips before you consent, export them anytime, and stay Speaker 2 forever if you decline.
Operator-blind at rest
The company running it holds only ciphertext.
Audio and voiceprints are sealed with AES-256 to a key born inside Intel TDX. Cryptographic evidence it was born in a sealed enclave — not a promise on a policy page.
Delete with proof
A deletion you can actually check.
Ask for erasure and get a signed Ed25519 receipt you can verify offline. Built for consent and privacy law — BIPA, GDPR forget-me — with the record itself signed per version.
Verifiable redaction
Strip regulated data, prove what left.
Detect cards, SSNs and PII in-enclave, redact, re-sign the transcript, and hand you a completeness receipt anyone can check with an offline Ed25519 verifier.
A trust boundary is an architecture.
One sealed box. Audio goes in, gets read once, regulated data is stripped, and it comes back as a signed record. What runs outside the box is drawn outside the box.
Voice
- Browser mic or file
- Speakers split live
plaintext never leaves
Signed private memory
- Redacted transcript
- Search · graph · receipt
Sealed on arrival
The operator holds only ciphertext the moment audio lands.
Redacted in-enclave
Cards, SSNs and PII are detected and stripped before anything is shared — raw data never leaves to a redaction vendor.
Signed & verifiable
Every version is Ed25519-sealed, and each redaction returns a receipt anyone checks offline.
We know where we are heading.
Telling speakers apart, on standard public meeting sets. We beat every free diarizer and are closing on the paid cloud — with the whole thing running operator-blind and no calls out on the read path.
Benchmark: AMI · AISHELL-4 · AliMeeting. Not customer data.
Telling speakers apart (AMI). Best free 19.9 · best paid 15.6.
Same voice 0.76 vs two voices 0.08. The ranges never touch.
To name a 2h19m meeting. A plain build runs 1,358.
Diarization error · AMI
lower is better
The law is catching up to the architecture.
United States · BIPA
Biometric-privacy law treats a voiceprint as protected data. Non-users are suing the consumer notetakers, and the liability follows whoever brought the tool into the room.
India · §63 evidence law
Since July 2024, an audio recording is admissible only with a signed, hash-certified record. The law now requires exactly the tamper-evident record this architecture produces.
The first tool you can bring into a privileged room
Get the record.
Hand over nothing.
Private transcription that names a voice only with consent, and proves what it did. Trust is enforced in hardware and signed, not promised.