Most healthcare AI tools rely on standard TLS encryption. We go further with AES-256-GCM envelope encryption, ECDH key exchange, and enforcement mode that rejects plaintext PHI at the server level. Your patients trust you with their health. You can trust us with their data.
Zero
Data Breaches
Q1 2026
Last Security Audit
Health Insurance Portability and Accountability Act compliant with signed BAAs
SOC 2 controls framework implemented across the Scribeable platform; third-party audit planned. Infrastructure hosted on SOC 2 Type II certified providers (GCP).
General Data Protection Regulation compliant for EU data subjects
California Consumer Privacy Act compliant
Patient data is protected by five independent encryption layers on our enforced channels. CDN, edge infrastructure, and reverse proxies do not see plaintext PHI on those channels.
PHI in API requests is envelope-encrypted on your device before transmission. The server never receives plaintext patient data.
Your notes and patient information are encrypted before they ever leave your device.
PHI in API responses is envelope-encrypted on the server before delivery. Intermediary systems see only ciphertext.
Generated notes are encrypted before being sent back to you.
Real-time transcription and rounding data is encrypted per-message over WebSocket connections, for clients on an up-to-date app version.
Live transcription during patient encounters is encrypted in real time on a current app version.
Audio from an up-to-date app is encrypted in transit and while it is processed, then deleted under the BAA's audio-retention terms (section 3.13). The same version exception as Layer 3 applies to an outdated app.
Encounter audio is encrypted before leaving your device and deleted once the transcript exists.
Individual PHI fields are encrypted at rest with organization-scoped data encryption keys (DEKs), wrapped by a master key encryption key (KEK) in Google Cloud KMS.
Each data field is independently encrypted in the database.
Encryption keys are negotiated using Elliptic Curve Diffie-Hellman (ECDH) on the P-256 curve. Plaintext keys are never transmitted between client and server. Each session derives fresh ephemeral keys, providing forward secrecy.
Enforcement mode is active on our covered PHI endpoints — API requests, API responses, and WebSocket connections from an up-to-date app. The server rejects a request or response on those endpoints that is not properly encrypted. This is not optional or configurable. (Live audio from an outdated app version is a stated, tracked exception; see our security documentation.)
Because encryption happens at the application layer (above TLS), CDN nodes, edge proxies, load balancers, and reverse proxies only ever see ciphertext. A compromise of any intermediary infrastructure yields zero usable patient data.
Automated health checks run every 15 minutes to verify encryption integrity across all layers. Telemetry tracks encryption match rates, key exchange success, and enforcement compliance. Any anomaly triggers immediate alerts.
Your patient data is protected by 5 independent layers of encryption. Even our own servers cannot read it. Encryption keys never leave your device in plaintext, and our servers actively reject any attempt to send unencrypted patient data. CDN providers, network intermediaries, and even Scribeable employees have zero access to your patients' information.
Defense-in-depth security protecting your practice and patients at every level
PHI is encrypted using AES-256-GCM envelope encryption with ECDH P-256 key exchange. Five independent encryption layers cover API requests, responses, WebSocket messages, audio streams, and field-level storage. Enforcement mode rejects plaintext PHI on covered request, response, and WebSocket paths.
Full compliance with HIPAA Security Rule and Privacy Rule. We sign Business Associate Agreements (BAA) and maintain comprehensive audit trails.
Data stored in HIPAA-compliant data centers in the United States, hosted on SOC 2 Type II certified infrastructure (GCP), with automatic backups and disaster recovery.
We cannot access your unencrypted patient data. Encryption keys are exchanged via ECDH (Elliptic Curve Diffie-Hellman) so plaintext keys are never transmitted. CDN and edge infrastructure see only ciphertext.
Complete audit logging of all data access and modifications. Immutable logs stored securely for compliance and forensic analysis.
Annual penetration testing, quarterly vulnerability assessments, and continuous security monitoring by third-party experts.
Data Handling
Transparent data practices with patient privacy at the core
Raw audio is retained only as long as needed to generate the transcript and note, then it is deleted.
Audio submitted through the web portal or browser extension is processed in transient memory. It is never persisted to durable storage.
Audio submitted through the iOS app is stored only transiently during transcription. It is deleted promptly when transcription completes.
Section 3.13 of every customer BAA commits to this: raw audio is kept only as long as needed to generate the transcript, and in no event longer than twelve months. Deepgram also deletes audio after transcription and does not retain it. The encrypted note and transcript persist, not the raw audio.
Security Partners
Five vendors process PHI to provide Scribeable, and each has a Business Associate Agreement in place.
Provides AI note generation under a Business Associate Agreement, with processing in memory only and no training on customer data.
Provides medical speech-to-text under a Business Associate Agreement and deletes audio after transcription.
Provides primary infrastructure, database, storage, and authentication under a Business Associate Agreement in US data centers.
Provides warm-standby disaster recovery cloud infrastructure in Vint Hill, Virginia, with a signed Business Associate Agreement.
Provides encrypted backup storage under a Business Associate Agreement.
Cloudflare handles ciphertext only and persists nothing; Stripe and Apple never touch PHI.
See the full list, including certifications and data locations, at /legal/subprocessors.
Documentation
Download our compliance documents and review our policies
Security FAQ
Answers to frequently asked security and compliance questions
Yes. Scribeable is fully HIPAA compliant. We implement all required administrative, physical, and technical safeguards. We sign Business Associate Agreements (BAA) with all covered entities at no additional cost.
All data is stored in the United States on Google Cloud Platform (GCP) infrastructure, which is SOC 2 Type II certified. Data is protected by 5 layers of envelope encryption — at rest and in transit.
No. Our 5-layer envelope encryption with ECDH key exchange means plaintext encryption keys never leave your device. PHI is encrypted before it leaves your device on our enforced channels — API requests, API responses, and WebSocket messages from an up-to-date app. Our servers run in enforcement mode on those channels: a request or response that is not properly encrypted is rejected. (Live audio from an outdated app version is a stated, tracked exception while we sunset legacy clients.) Even with full server access, Scribeable employees see only ciphertext on encrypted channels. CDN providers and network intermediaries are equally blind to that data.
Most healthcare AI tools rely on standard TLS (transport-layer) encryption, which protects data in transit but leaves it readable at every server and CDN node in the chain. Scribeable adds application-layer envelope encryption on top of TLS: on our enforced channels, data is encrypted on your device, stays encrypted across every intermediary, and is only decrypted at the final destination. Enforcement mode makes this a server-enforced technical control on those channels, not a policy — with a stated, tracked exception for live audio from outdated app versions.
We have comprehensive incident response procedures including immediate containment, forensic analysis, and affected-party notification in line with HIPAA breach-notification requirements.
Absolutely not. Your patient data is never used to train AI models. Our AI models are pre-trained and your data is processed only for generating your clinical notes.
Notes and transcripts persist in encrypted form, and you can delete them at any time. Raw audio is transient: it is deleted once the transcript is generated, and the BAA (section 3.13) caps any retained audio at twelve months in all cases. If you delete your account, your data is permanently removed within 30 days.
Raw audio is retained only long enough to generate the transcript and note, then deleted. Web portal and browser extension audio is processed in transient memory and never persisted to durable storage; iOS audio is stored only transiently during transcription and deleted promptly when transcription completes. Deepgram also deletes audio after transcription and does not retain it. Section 3.13 of every customer BAA writes this into the contract, with a hard ceiling: in no event is raw audio retained longer than twelve months. What persists is the encrypted note and transcript, not the audio.