SECURITY ARCHITECTURE

Built for clinical data. No shortcuts.

Encryption, zero-trust access, audit logging, and three distinct AI privacy modes so you choose where your data goes.

256-bit
AES-GCM KEYS
24h
AUDIO RETENTION
5yr
AUDIT RETENTION
MediScribe VaultENC
Illustrative examplePLAINTEXT
Sample clinical record

No patient data is shown in this illustration.

Draft for clinician review
ENCRYPTED AT RESTAES-256-GCM
✓ SEALED · ZERO PLAINTEXT AT REST
AES-256-GCMAudio auto-delete · 24hHIPAA READY · NOM-004 SUPPORTED

Nothing is kept longer than it must be. Audio is deleted 24 hours after the consultation. Retention for transcripts and notes follows your policy — configurable per clinic, per record type.

Audio · 24h auto-deleteTranscripts · your policyNotes · your policyAudit log · 5 yearsKeys · rotated 90dBackups · encryptedExports · signed
AI PRIVACY TIERS

Three tiers. Honest wording.

01SaaS · DPA

Cloud AI

Records on MediScribe infrastructure. AI via enterprise LLM provider under DPA (no training use). Audio auto-deleted after 24 hours.

Audio purged · 24h
02Data Sovereign

Local AI

Records remain on MediScribe servers. In Local AI mode, supported AI processing runs on your device; consultation audio is not sent to a third-party AI provider.

Works with the network off
03Your Infra

Self-Hosted

Entire MediScribe stack on your infrastructure. Your servers, database, AI runtime. We ship the software.

You own the stack
ENCRYPTION ARCHITECTURE

Three layers, zero plaintext.

Records are encrypted on the device, in transit, and at rest — with keys that rotate on schedule and retire on schedule.

E · 01

AES-256 Encryption

All data encrypted at rest (AES-256-GCM) and in transit (TLS 1.3). BYOK supported on enterprise tier.

E · 02

Encrypted in transit

All connections use TLS 1.3 with modern cipher suites only. There is no plaintext hop — not between the app and the API, not between internal services.

E · 03

Key management

Key rotation and retirement follow a defined policy.

Key managementILLUSTRATIVE
Protected clinical data
Key rotation and retirement follow a defined policy.
ACCESS CONTROL

Every access, on the record.

Least-privilege roles, authenticated calls, and an append-only audit log that even administrators can't rewrite.

Audit Log · Append-OnlyEXAMPLE LOG
10:41:07clinician-01record.viewrecordALLOW
10:41:22clinician-01note.signnoteALLOW
10:47:50clinician-02record.viewrecordALLOW
10:52:36clinic-staffrecord.exportrecordDENY
11:03:59systemkey.rotatekeyOK
11:15:02adminaudit.readlogALLOW
RETAINED 5 YEARS
S · 01

Zero-Trust Access

Every API call and every database query is authenticated and authorized. Role-based access control. No trust by network location.

S · 02

Multi-Factor Authentication

TOTP and hardware-key MFA for all clinical users. Biometric unlock on mobile. Configurable session timeouts.

S · 03

Audit Logging

Forensic-level logging of every interaction with a patient record. 5-year retention. Tamper-evident.

COMPLIANCE

Standards, as configuration.

The controls above map directly onto the frameworks your regulators ask about — not as an afterthought, as architecture.

C · 01US

HIPAA ready

Administrative, physical, and technical safeguards mapped to the HIPAA Security Rule. Encryption, access control, and audit are defaults, not add-ons.

BAA available on request
C · 02MX

NOM-004-SSA3-2012

Support for regional clinical-record standards like Mexico's NOM-004: required note structure, clinician identification, and signature fields are native to every generated note.

Field-mapped note schema
C · 03AES-256

Encryption standards

AES-256-GCM at rest, TLS 1.3 in transit, SHA-256 for integrity chains, and BYOK on the enterprise tier. Cipher suites are pinned — downgrades are refused, not negotiated.

Suite pinned · no downgrade
PDPA supported (Singapore / Thailand)
Security Review

Need more detail?

We produce security briefs on request, tailored to your regulator and your architecture questions.