Compliance
This document provides information about various compliance requirements that your organization might need to confirm before installing Utterly Voice. If you have requirements that are not listed here, or you have questions about our compliance information, please contact us via the email address on the about page.
Utterly Voice goes above and beyond many types of compliance requirements. As detailed in User Data Processing and Retention, the only user data transmitted from your local machine to Utterly Voice LLC servers is the following:
- License key from settings file
- Configured recognizer name from settings file
- Utterly Voice Application version
Utterly Voice LLC does not have access to any of your microphone audio data or data derived from microphone audio data. This means that certain compliance requirements are not applicable to Utterly Voice LLC, and these are explained in detail below.
Contents 
Disclaimer 
In sections below, Utterly Voice LLC provides recommendations for using Utterly Voice to support your legal compliance obligations. This is for informational purposes only. Utterly Voice LLC does not intend the information or recommendations to constitute legal advice.
HIPAA 
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that establishes data privacy and security requirements for organizations that are charged with safeguarding individuals' Protected Health Information (PHI). It is important to note that there is no certification recognized by the US Department of Health and Human Services (HHS) for HIPAA compliance and that complying with HIPAA is a shared responsibility between software providers and their users.
While you might provide PHI to the locally running Utterly Voice Application in the form of microphone audio input, Utterly Voice LLC does not have access to this local data or derived data, and the data is not transmitted to any Utterly Voice LLC server. This means that Utterly Voice LLC is not a Business Associate under HIPAA. In addition, Utterly Voice LLC is not a healthcare provider. Therefore, no Business Associate Agreement is required between your organization and Utterly Voice LLC.
However, HIPAA compliance might apply to your choice of third-party systems and how you manage the security of your local computer systems.
Details:
- The Utterly Voice Application which runs on your local computer does not transmit microphone audio data or any data derived from microphone audio data to the remote Utterly Voice Server.
- By default, the Utterly Voice Application does not save any audio or transcript data locally. If you change the default settings to configure the Utterly Voice Application to save transcripts or audio files on your local computer's drive, or you directly enter PHI in local Utterly Voice Application settings files, it is your responsibility to secure access and encrypt this local computer data in a way that is HIPAA compliant. This data is entirely in your control, and Utterly Voice LLC does not have access to this data.
-
When you use the Utterly Voice Application with third-party systems,
and these third-party systems process or retain
PHI,
it is your responsibility to confirm that
these third-party systems are
HIPAA compliant, and to possibly obtain Business Associate Agreements with
the third-parties you choose to use.
In the case of third-party speech recognition systems, the Utterly Voice Application might transmit PHI directly to and from these third-party systems in the form of microphone audio data and derived utterance transcripts. For an offline speech recognition system, the Utterly Voice Application communicates with the third-party system directly on your local computer, and this data is not transmitted to other systems. For an online speech recognition system, the Utterly Voice Application transmits data on the network using HTTPS encryption, as required by the third-party system. If you choose to use an online speech recognition system, we recommend that you verify HIPAA compliance for the third-party service.
SOC 2 
The Service and Organization Controls (SOC) 2 is a report based on the Auditing Standards Board of the American Institute of Certified Public Accountants (AICPA) SSAE 18, which evaluates the service organization's controls relevant to the Trust Services Criteria of security, availability, processing integrity, confidentiality, or privacy.
As detailed in User Data Processing and Retention, the only user data transmitted from the Utterly Voice Application running on your local machine to Utterly Voice LLC servers is the following:
- License key from settings file
- Configured recognizer name from settings file
- Utterly Voice Application version
While you might provide various types of personal or sensitive user data to the locally running Utterly Voice Application in the form of microphone audio input, Utterly Voice LLC does not have access to this local data or derived data, and the data is not transmitted to any Utterly Voice LLC server. In addition, the Utterly Voice Application is not a remote web service or cloud service. This means that Utterly Voice LLC is not acting as a Service Organization under SOC 2, and Utterly Voice LLC does not require an SOC 2 audit.
However, SOC 2 compliance might apply to your choice of third-party systems and how you manage the security of your local computer systems.
Details:
- The Utterly Voice Application which runs on your local computer does not transmit microphone audio data or any data derived from microphone audio data to the remote Utterly Voice Server.
- By default, the Utterly Voice Application does not save any audio or transcript data locally. If you change the default settings to configure the Utterly Voice Application to save transcripts or audio files on your local computer's drive, or you directly enter user data in local Utterly Voice Application settings files, it is your responsibility to secure access and encrypt this local computer data in a way that is SOC 2 compliant. This data is entirely in your control, and Utterly Voice LLC does not have access to this data.
-
When you use the Utterly Voice Application with third-party systems,
and these third-party systems process or retain
user data,
it is your responsibility to confirm that
these third-party systems are
SOC 2 compliant, and to possibly verify an SOC 2 audit was performed
for the third-parties you choose to use.
In the case of third-party speech recognition systems, the Utterly Voice Application might transmit user data directly to and from these third-party systems in the form of microphone audio data and derived utterance transcripts. For an offline speech recognition system, the Utterly Voice Application communicates with the third-party system directly on your local computer, and this data is not transmitted to other systems. For an online speech recognition system, the Utterly Voice Application transmits data on the network using HTTPS encryption, as required by the third-party system. If you choose to use an online speech recognition system, we recommend that you verify SOC 2 compliance for the third-party service.
Export Control Classification 
Utterly Voice falls under the EAR99 export control classification. Software of this type is not listed in the Commerce Control List (CCL).
Country of Origin 
All versions of Utterly Voice are developed, compiled, and tested in the United States.
Authorized Resellers 
There are no authorized resellers for Utterly Voice.