Legal transcription software for audio evidence

Every item below is a behaviour you can check on the page it produces. Where something is a limit rather than a feature, it is written as a limit.

The transcript

What ends up on the page

Untranscribed audio is marked

Every stretch the system returned no transcript for renders as an explicit marker where the words would have been, in every export. The one exception is audio it measured as silence, which is recorded but not rendered — a page full of markers for a quiet room would bury the ones that matter.

Limit: the marker records that nothing came back for that span. Where something did come back but almost nothing is in it, there is no absence on the page to mark — that case is caught by the near-empty-entry check further down, which holds the recording for review instead of marking a line.

A speaker label carries its provenance

Labels derived from a call's channel describe a role rather than a person. A speaker the system could not verify carries no proper name at all. This is a constraint in the database, not a style rule, so no later step can quietly promote a guess into a name.

Limit: speakers are separated only when the recording keeps them on separate channels. On a single microphone every line is attributed to one unidentified speaker, whatever the number of people heard — you can name that speaker, and the review pane's split tool lets you move lines onto a new track yourself, but the product will not split it into the people it heard on its own: a split is your judgment, recorded as yours, never the machine's claim about who spoke. And because the channel thresholds are uncalibrated, an ambiguous file is routed to the single-speaker path deliberately rather than guessed at.

Timestamps on every line

Each line carries the time it was spoken, and the page and line numbering is stable for the stored transcript, which is what makes a passage something you can point at.

A digest record

Each transcript carries a SHA-256 chain-of-custody record over three things: the source file exactly as your firm delivered it, the audio submitted for transcription part by part, and the produced text. A recording ingested before source hashing says so on the certificate's face rather than leaving the field blank. The two audio digests are not expected to match — the submitted audio is re-encoded from the delivered file — and the record says what was done to it beside them.

What it refuses to do

The checks that stop a transcript

The failure a transcript can have that you cannot see is missing content. These are the places the system stops rather than hand you a page that looks complete.

Where a job can stop

01 Probe

The file is read and measured before anything is transcribed.

Stops here Unreadable

An error code, and no partial transcript.

02 Transcribe

Each part is submitted and assembled in order.

Stops here Coverage

Below threshold, no PDF renders at all.

03 Render

The transcript, its markers, and the digest record.

The two accented stages are the ones that refuse. Both fail the whole job rather than returning the portion that worked, because a partial transcript is the one failure a reader cannot see.

Coverage is measured against the source file

Each transcript is checked against a measurement of the source audio rather than against the transcription provider's own accounting. Below threshold, the job goes to needs_attention and no PDF renders at all.

Limit: this catches whole-part and whole-channel loss. It does not catch content displaced within a channel, it counts as transcribed the seconds the check below flags, and clearing it is not the same as being verified.

A near-empty transcript entry is a finding

Coverage counts transcribed time as the span each entry covers, and an entry's span runs from its first word to its last — so an entry that runs a long stretch on a single word accounts for that whole stretch and the total reads clean over a hole. An entry that runs long while carrying almost no words is flagged on its own evidence, and the flag is a disclosure rather than a block: the seconds are reported beside the coverage figure rather than folded into it, they are printed on the certificate, and the transcript is delivered. It does not hold the recording, because the check reads the shape of the transcript and cannot tell a pause that one long entry was drawn over from speech that was dropped.

Limit: it catches the nearly empty entry, not the merely thin one — a stretch that came back with a few words in it passes. It cannot separate lost speech from hold music, an announcement, or dead air the transcriber correctly declined to transcribe, and its thresholds are uncalibrated, set to miss rather than to withdraw a transcript that is fine. What it reports is seconds of transcript, not a measurement of what was said in them.

Unreadable audio fails loudly

A file the media path cannot read fails at the probe, with an operator error code, before any transcription is attempted. A loud failure on the whole file is safer than a partial transcript of the portion that happened to decode.

An empty result is not a clean result

A recording that returns no speech does not certify as a complete transcript of nothing. The condition is detected and surfaced rather than rendered as success.

There is no cancel

Once audio is submitted there is no cancel button, by design. The upstream operation cannot be cancelled, so a button claiming otherwise would be a lie about the state of your material. Jobs run to a terminal state and say what happened.

The workspace

Working with a matter

The tools around the record. Each one runs inside the same boundaries as the transcript itself, and each is listed with its limit.

Find in a transcript never leaves the page

The review pane's find runs in the browser, against the transcript the page already holds. The query — a phrase typed about a recording's content — is never sent to any endpoint and never enters a URL, so it appears in no server log and dies with the page.

Limit: it is a case-insensitive plain-text match, not a pattern language, and it matches within a line — a phrase that spans two lines is not found. Searching across recordings is the matter search, which is a request to the server.

Matter search returns the line, not just a hit

One search runs across every transcript in a matter and returns each matched line as an excerpt with the hits marked, grouped by recording — you read the sentence around the term before opening anything. It works by decrypting and scanning the matter at the moment you search, which is the same reason there is no plaintext index.

Limit: one matter at a time, inside that matter's encryption boundary — there is no search across matters. And the match is a plain substring, case-insensitive, not a query language.

Speakers can be merged, unmerged, and split

Two tracks that turn out to be one person can be merged; a merge is a reversible pointer, and unmerge is the reversal. A track that holds more than it should can be split from a chosen line onward onto a new track, and the new track records which speaker it was split from, so that is reversible too. Nothing is destroyed either way.

Limit: a split is your judgment, recorded as yours — the new track starts unnamed, with no claim about who is on it, and the product still will not split one microphone into the people it heard on its own. Channel-derived tracks cannot be merged at all, in either direction: channel identity is separation the recording itself established, and a merge would destroy it.

A video source plays beside the transcript

When the uploaded file is video, the review pane plays that original file next to the transcript, and the video element becomes the pane's clock — one clock, not two, so the line and the picture cannot drift apart.

Limit: the transcript still comes from the audio alone; nothing is read from the picture. Video is detected from the uploaded file's name, and the decision is presentational — an audio-only file in a video container plays as sound over a black frame, and transcription behaves identically either way.

A matter is shared on the record

An admin on a matter can grant a colleague access to it by their email address, at a level — read, write, or admin — and revoke it the same way. Every grant and every revoke appends a row to an audit log recording who gave what to whom, and when. Those rows carry no client content, which is what lets them survive even the matter's deletion.

Limit: sharing stays inside your firm — the address must belong to a user of the firm, and nothing is emailed anywhere. Firm-wide roles do not bypass the wall: a firm owner who needs a matter grants themselves access through the same audited path, leaving a row that says so.

The cost is quoted before it is spent

Every recording is quoted on the upload page in the unit the price is charged in: its audio minutes, split into the minutes the firm's remaining free grant covers and the minutes it does not. The same arithmetic is enforced at an admission gate at the last instant before the first paid transcription call — a job held there has spent nothing while it waits.

Limit: no quote exists until the file has been measured, and until then the page shows the unknown rather than a zero, because a zero that means "not yet measured" reads as "free". The rate itself is on the pricing page and nowhere else — this page included.

In Claude

The transcript is the thing that travels

No Anthropic surface accepts an audio file, so a recording cannot be handed to Claude directly. Pincite Audio connects to claude.ai as a custom connector, which makes the transcript — not the audio — the thing that arrives.

One permission, and every tool is a read

The connector requests a single scope, to read transcripts, and the server supports no other. Nothing behind it writes to a matter, edits a transcript, or changes a speaker label.

Limit: it cannot upload audio either. Recordings are added in the application, not from a conversation.

The no-name rule follows the transcript

Every response states whether the recording has been verified. While it has not, the connector instructs the model in the response itself not to substitute a person's name for a machine speaker label — not when the surrounding text makes the identity look obvious, and not when the person asking supplies the name.

Limit: that is an instruction to a model, not a database constraint. The constraint is what stops a name being stored; this is what stops one being volunteered.

Citations come from the server

A passage is returned with a citation on each line, produced by the server rather than composed by the model, and quoted text is rendered byte-identical to the stored transcript. Nothing needs to be retyped out of a chat window.

A summary is precomputed, not generated on the call

The short per-recording summary is produced once, after transcription, and stored. Asking for it in a conversation reads that stored record — no model is run at call time. Which vendor produces it is named in the terms.

Handling

What happens to your material

Encrypted per matter

Transcript content is stored as AES-256-GCM ciphertext under a key held per matter. Backups are therefore ciphertext too, rather than a plaintext copy sitting outside the protection the live database has.

Deletion destroys the key

Deleting a matter destroys that matter's key, which renders its stored content unreadable including in existing backups. What you get back is a deletion certificate — a content-free record of identifiers, counts, and timestamps, written only after a residue audit has checked that nothing readable remains, and built to survive the deletion it records. Deletion that leaves readable copies behind is not deletion.

Search without a plaintext index

Search decrypts and scans within a matter. There is no plaintext search index, because an index of the words in a transcript is a copy of the transcript wearing a different name.

Reads your Clio matters, writes nothing

The Clio connection is not available yet — no deployment has it configured, so no firm can connect one today.

The Clio connection is read-only: matters and documents are searched live at the moment you search them. Nothing is synced, mirrored, or written back, and it operates under your own permissions.

Honesty

What this page does not claim

Pincite Audio is in an open beta. Nothing here is an accuracy figure, and nothing here should be read as one: a transcript's value in this product comes from disclosing what it could not hear, not from a percentage.

A transcript is reproducible from the stored artifact, not by re-running the model. The transcription service exposes no version pinning, so nothing may imply that re-submitting the same audio later returns the same text.

For what the format guarantees line by line, see the transcript format. For how the system behaves in specific situations, see resources.

Pincite Audio is in an open beta. You can create an account and start with the free minutes today, or leave an email and we will contact you instead.