Configure your network for Wispr Flow

Last updated: September 17, 2026

Available on: managed corporate networks using SSL/TLS inspection. Configured by your IT or network-security team.

If dictation on your work network is slow, delayed, or inconsistent, your security tools may be inspecting Flow's encrypted traffic, which forces Flow onto a slower fallback connection. Your IT team can restore full speed with a permanent SSL-inspection bypass for Flow's service endpoints. All Flow traffic stays encrypted.


How to configure your network

  1. Create an SSL-inspection bypass on outbound port 443 for these endpoints:

    • *.wisprflow.com

    • *.api.baseten.co

    • *.grpc.api.baseten.co

    • *.us-east.modal.direct

    If your security team prefers a narrower rule than a wildcard, email security@wispr.ai and we'll provide the exact hostnames to bypass instead.

  2. Apply the bypass everywhere TLS inspection runs:

    • Your SASE or SSE platform, such as Zscaler, Netskope, Palo Alto Prisma Access, or Cloudflare

    • Your secure web gateway or web-filtering gateway

    • Your ZTNA broker, if TLS inspection is enabled

    • Your perimeter firewall or any other layer performing deep packet inspection

  3. Save it as a permanent policy across relevant office locations, VPN egress points, and remote-user policies. It does not need to be reapplied per user, device, or session.

  4. Verify by dictating from the affected network once the policy has propagated. If dictation is faster and the network notification no longer appears, you're done. If it persists, contact Flow support.


What changes, and what stays the same

  • Scope: the exception covers only Flow's dictation and inference traffic; your inspection policy still covers every other outbound TLS session.

  • Encryption: TLS stays enabled on every bypassed connection. Your gateway stops intercepting and re-encrypting the session, and traffic is never sent in the clear.

  • DLP visibility: DLP tools that rely on TLS decryption cannot inspect Flow's traffic to these endpoints. Traffic still passes through your gateway, and endpoint DLP, DNS-based controls, egress-volume monitoring, and other controls that don't require decryption remain available.


FAQs

What should IT allowlist?

An SSL-inspection bypass on outbound port 443 for the endpoints listed above. This is an endpoint-specific TLS-inspection exception, not an IP allowlist.

Can we bypass specific hostnames instead of a wildcard?

Yes. Email security@wispr.ai and we'll share the exact hostnames so you can write the narrowest possible rule.

Does this apply to every network?

No. It applies to managed networks that perform SSL/TLS inspection. Networks that don't intercept Flow's connection need no bypass.

What if we use a different security vendor?

Menu names and configuration steps vary by vendor, but the endpoints and port stay the same. Apply the bypass wherever SSL/TLS inspection runs.

What happens if we don't make this change?

Flow keeps working over its fallback connection, with higher or less consistent delays and weaker recovery from brief network interruptions.

Where do I go if sign-in or downloads fail instead?


Still need help?

Reach out to the Flow support team if:

  • You're not sure which inspection layer owns the policy.

  • Users still see the network notification or slow dictation after the rule has propagated.

  • Your security team wants to review the DLP or data-handling implications before rollout.

Include your network-security vendor, the layers where you applied the bypass, and any error details. You can also review our Trust Center for more on data handling.

Reporting a security vulnerability? Please don't email it. Submit it through our coordinated disclosure program so it reaches the right team and is tracked correctly. The security@wispr.ai address above is for network-configuration and compliance questions only.