Trust
Security & Compliance
This is the page your IT and compliance team will open first. Here's exactly how Scribely handles protected health information — no marketing gloss, just the policy.
Encryption everywhere
TLS 1.3 in transit, AES-256 at rest, on US-only HIPAA-eligible infrastructure.
Audio isn't kept
Audio is streamed in short chunks directly to our transcription provider for speech-to-text and is never written to Scribely's database or storage — there is no recording file to retain, extend, or delete.
BAA on every account
Every customer practice operates under a signed Business Associate Agreement. Available before you subscribe.
SOC 2
SOC 2 Type I attested. Type II observation period in progress — badge and completion date will be published here as milestones land.
Access & audit logs
Full audit logs are available to practice administrators for every note view, edit, and export.
Breach notification
Any suspected incident affecting your data is disclosed to the affected practice without undue delay, consistent with HIPAA breach notification requirements.
Subprocessors
Every subprocessor below operates under a signed BAA or DPA with Scribely.
| Subprocessor | Role |
|---|---|
| Supabase (AWS-hosted) | Database, auth, and application storage |
| Vercel | Application hosting |
| ElevenLabs | Speech-to-text transcription |
| Google (Gemini API) | Clinical note, billing, and summary generation |
Need a full security questionnaire answered?
Email us directly and we'll return a completed questionnaire, our BAA template, and our current SOC 2 status letter.
security@scribely.healthSee also our full Privacy Policy.