Security & privacy

Security and privacy, by design

Scriva protects you and your patients.

Security and compliance are the foundation of everything we build. When you handle patient data there is no room for shortcuts, and that principle shapes every decision we make — from the features we develop to how our models work.

Standards and compliance

GDPR by design

Built to meet GDPR requirements: data stored in the EU, a Data Processing Agreement under Art. 28, and support for data-subject rights.

How we keep your data safe

Our system combines multiple security measures so that personal and health data are handled with the highest level of protection.

No audio data is stored

Transcription happens in real time. Audio recordings are never saved — once the note is generated, the audio is gone.

No personal data is used for AI training

Your data and your patients' data are never used to train our models or for any other purpose beyond providing the service.

You decide what is kept

Transcripts and notes stay available for your clinical record for as long as you need them, and you can delete individual sessions, notes or entire patient records at any time, directly from the app.

Strict access control

Every account can access only its own patients and sessions — data is strictly scoped to the authenticated professional, following the principle of least privilege.

Encryption

All data is encrypted both in transit and at rest using industry-standard protocols.