The BEFORE.Band founding batch is forming.Reserve yours
Security architecture

Protect the evidence. Keep the boundary narrow.

Audio contains voices and transcripts preserve private speech. BEFORE secures that path without becoming an agent or an action system.

BEFORE.Band worn by a speaker waiting backstage

What it hears stays under your control.

01

Intentional recording

No wake word, continuous listening or remote start. Only a physical action begins recording, with an indicator that must be verified on delivered hardware.

02

On-device audio processing

Raw audio is protected on the bracelet and iPhone. V1 English recognition runs on the iPhone; only a signed transcript and its provenance are sent to BEFORE’s service over encrypted transport.

03

Transcript-only MCP

MCP exposes clean transcripts with provenance. It never exposes raw audio, semantic entities, speaker identities, summaries, recommendations or action tools.

04

Least privilege

Every account, capture, transcript, cursor and connector is authorized server-side. Stable identifiers never grant access on their own.

05

Idempotent delivery

Opaque cursors make incremental polling repeatable, tenant-safe, deletion-safe and revocable without losing or duplicating transcripts.

06

Auditable access

Users can inspect transcript retrieval, revoke future connector access, export their data and request raw-audio, capture or account deletion.

07

Content-free operations

Logs, metrics and analytics exclude raw audio, transcript text, access tokens and presigned URLs. Development fixtures are fictional.

08

No action authority

Recorded speech is untrusted transcript content. It is never treated as authorization, never invokes a tool and never changes the meaning of the stored transcript.

An honest encryption promise

Captured audio stays in the protected bracelet-and-iPhone path and is not uploaded to BEFORE’s backend. The service necessarily reads transcript text to store it and deliver it through authorized MCP calls, so we do not call that transcript path server-blind end-to-end encryption.

Production readiness

This is an intended baseline, not a certification. Production release still requires acceptance of the exact on-device recognition path, threat modeling, penetration testing, incident ownership, deletion and recovery drills, and renewed human review of the exact source digest.

Security should be visible before the first real capture.

Reserve your band