Configure your network for Wispr Flow
Last updated: September 19, 2026
For: IT and network-security teams configuring Wispr Flow on managed networks. Organization IP restrictions require Enterprise access with the feature enabled by Wispr.
Use the relevant section below to allow outbound connections, fix slow dictation caused by SSL/TLS inspection, or limit access to approved office and VPN networks. These are separate controls: allowing a service hostname through your firewall does not add a user's network to your organization's IP allowlist.
Allow outbound access to websites and downloads
If your organization restricts outbound traffic, allow these domains:
| Domain | Purpose |
|---|---|
wisprflow.ai | Web app and account management. |
admin.wisprflow.ai | Admin portal, MDM downloads, and team management. |
dl.wisprflow.ai | Installer downloads. |
This is not the complete outbound host list. Flow also uses third-party services for authentication, error reporting, and HIPAA BAA document delivery. If you enforce a strict outbound firewall, ask your Wispr representative for the full list. Plan download bandwidth and caching for large deployments.
Fix slow dictation caused by SSL/TLS inspection
Flow respects system proxy settings and organizational root certificates, including TLS inspection, for dictation, uploads, and SSO session management.
On networks that inspect encrypted traffic, Flow may use a slower fallback connection. If dictation is slow, delayed, or inconsistent, your IT team can configure a permanent inspection bypass for Flow's dictation and inference endpoints. Networks that do not intercept the connection do not need this bypass.
Create an SSL-inspection bypass on outbound port 443 for:
*.wisprflow.com*.api.baseten.co*.grpc.api.baseten.co*.us-east.modal.direct
For exact hostnames instead of wildcard rules, email security@wispr.ai.
Apply the bypass wherever inspection runs: your SASE/SSE service, secure web or web-filtering gateway, ZTNA broker if inspection is enabled, and perimeter firewall or other deep-packet-inspection layer. Examples include Zscaler, Netskope, Palo Alto Prisma Access, and Cloudflare. Vendor menus differ; the endpoints and port stay the same.
Save a permanent policy covering relevant offices, VPN egress points, and remote-user policies. It does not need reapplying per user, device, or session.
Once the policy has propagated, test dictation from the affected network. If dictation is faster and the network notification disappears, the change is working. If the problem remains, contact support.
TLS stays enabled. The gateway stops intercepting and re-encrypting these connections; traffic is not sent in the clear. This exception covers Flow's dictation and inference traffic, while other TLS sessions remain subject to your inspection policy. DLP tools that need decrypted traffic cannot inspect these endpoints. Endpoint DLP, DNS controls, egress-volume monitoring, and other controls that do not require decryption remain available.
Without the bypass, Flow continues over its fallback connection, with higher or less consistent delays and weaker recovery from brief network interruptions.
Restrict organization access to approved networks
Enterprise admins can configure an IP allowlist in the admin portal at Settings → Organization → Network access. The setting appears only when Wispr has enabled the feature for your organization. Enforcement works on Mac and Windows; Android users are not signed out or shown a lockout screen when their network is outside the list.
- Include expected office IPs, VPN exit IPs, and remote locations.
- Wildcard CIDRs
0.0.0.0/0and::/0are not accepted. - To disable the allowlist, remove the setting entirely; an empty list is not allowed.
- A self-lockout safeguard requires your current IP to be inside the existing allowlist before a change or removal applies. Use an allowed network to reach the admin portal and review the approved addresses.
If a user sees “Your network isn't allowed”
A Mac or Windows user on an unapproved network is signed out and shown a lockout screen. The message can read, “Your admin at <org> only allows Wispr on approved networks. Switch networks or contact your admin.” This can happen even when the user has already been provisioned through SCIM.
Switch to an approved network, then choose Retry. Retry reopens browser sign-in; it blocks again if the network is still disallowed, or may sign the user straight back in from an allowed network. The lockout screen clears after a successful allowed-network sign-in. Sign out clears the blocked state and forces the login form.
If the expected network is missing, ask your admin to review Network access from an allowed network.
Get help with a network problem
Contact the Flow support team if you cannot identify the inspection layer, dictation stays slow after the rule propagates, or your security team needs to review DLP and data-handling implications. Include your network-security vendor, the layers where you applied the bypass, and any error details. Review the Trust Center for data-handling information.
For browser-specific sign-in or download failures, see Wispr Flow website loads but sign-in and downloads fail in one browser. For managed-device installation, see Deploy Wispr Flow via MDM. For broader security questions, see the Security and compliance FAQ.
Reporting a security vulnerability? Use our coordinated disclosure program. The security@wispr.ai address above is for network-configuration and compliance questions, not vulnerability reports.