Security and privacy, by design
Scriva protects you and your patients.
Security and compliance are the foundation of everything we build. When you handle patient data there is no room for shortcuts, and that principle shapes every decision we make — from the features we develop to how our models work.
Standards and compliance
Meets the EU's stringent requirements for safety, performance, and clinical documentation.
A documented framework for information security, risk management, and continuous improvement.
Developed with privacy as a foundational principle — privacy by design.
Regular penetration tests are carried out by external security firms.
How we keep your data safe
Our system combines multiple security measures so that personal and health data are handled with the highest level of protection.
No audio data is stored
Transcription happens in real time. Audio recordings are never saved — once the note is generated, the audio is gone.
No personal data is used for AI training
Your data and your patients' data are never used to train our models or for any other purpose beyond providing the service.
Data is deleted automatically
Transcriptions and notes are removed after 24 hours, and you can delete your data manually at any time before then.
Strict access control
Access to data is limited by role and based on the principle of least privilege, with logging and monitoring of every operation.
Encryption
All data is encrypted both in transit and at rest using industry-standard protocols.
Frequently asked questions about security
Is Scriva safe to use?
Yes. Scriva is built around privacy by design: audio is never stored, data is encrypted in transit and at rest, and notes are deleted automatically after 24 hours.
How do you handle AI errors or 'hallucinations'?
Notes are always presented as a draft for you to review and approve before they enter the medical record. You stay in control of the final documentation at all times.
Where is my data stored?
Data is processed and stored on secure infrastructure within the European Economic Area, in line with GDPR requirements.
Does Scriva have access to my data?
Access is strictly limited and governed by a data processing agreement. Data is never used to train models or shared with third parties for their own purposes.
