Skip to main content
Plenty of people install OpenWhispr on a work machine. This is what to do when that machine has opinions.

If your company manages OpenWhispr

Your normal setup should be short:
  1. Install and open OpenWhispr.
  2. Enter your work email and choose the company SSO option.
  3. Finish sign-in in your browser.
If IT assigned you through SCIM, the app immediately receives your workspace, teams, policies, and managed Amazon Bedrock or Azure OpenAI defaults. You do not need an invitation, AWS CLI profile, cloud API key, role ARN, tenant ID, or model name. During a company pilot, email/password sign-in may still appear as a secondary option. It lets existing employees test OpenWhispr before IT enforces SSO. Once Require SSO is enabled for the verified company domain, that fallback is blocked. If sign-in says you are not assigned, contact your OpenWhispr workspace owner. Your directory administrator needs to activate your SCIM assignment; there is nothing to repair on the computer.

If you can’t run an installer

Nothing OpenWhispr installs requires administrator rights to run, and everything it writes stays in your user account — see where your files live.

If the network is filtered

The app makes outbound HTTPS connections on port 443, and everything else it runs binds to your own machine by design. It honours system proxies on all three platforms. Network allowlist is written to be forwarded to a firewall administrator: the hostnames, split into what’s required and what’s optional. Local transcription needs the internet exactly once — to download the model. After that it works offline entirely.

If security software blocks it

New signed applications get flagged before they build reputation, and OpenWhispr’s Windows build has been caught by Norton in the past. Antivirus blocks OpenWhispr covers what to check and what to send us.

If your policy says nothing may leave the device

That’s a supported configuration, not an argument. Choose Local for transcription and a local model for AI, and no audio or text reaches our servers — or anyone else’s. Two settings worth pairing with it:
  • Data Retention off, if nothing should be written to disk either.
  • Cloud backup stays off unless you turn it on. It already is by default.
Where your data goes has the full picture, mode by mode.

What to send your security team

One page: answering a security review. It collects the DPA, privacy policy, security overview, trust centre and compliance posture, plus what the product does with data — the questions a vendor review asks, answered in the order they usually arrive. If your organisation is on an active Enterprise workspace, its owners can configure SSO, SCIM lifecycle management, provider allowlists, retention, sharing, and managed Bedrock or Azure OpenAI access in the admin portal. Business workspaces keep the ordinary sign-in and provider setup flows.