Security is central to how TScribe is designed. Clinical information is sensitive by nature, and the architecture reflects that from first principles. This page describes the technical and organisational measures we use to protect your data and your patients' privacy.
1. Encryption in transit
All communication between the TScribe applications, the browser extension and our servers uses TLS. This applies to audio uploads, report retrieval and all account operations. We do not accept unencrypted connections.
2. Audio data handling
When you submit audio for transcription, it is sent over an encrypted connection to our processing service. Once the transcription is complete and the report draft is returned to your device, the audio is deleted from our systems. We do not cache, archive or store raw audio recordings.
3. Patient data
TScribe is built so that patient-identifiable information does not persist on our servers. Reports are generated, returned to your device, and not stored by us. If you include patient names or identifiers in your dictation, they are present only in the transient processing pipeline and are not retained after the report is returned.
4. Account data
Account details (name, email, specialty) are stored in encrypted databases in secured environments. Passwords are hashed with a modern one-way algorithm and never stored in a form we can read. Sign-in endpoints are rate limited to prevent brute-force attempts.
5. Account protection
Two-factor authentication by email is available on any account, and an organisation can make it mandatory for its members. New devices are approved before they can dictate, and an organisation can require approval across all of its members. Changing your password signs out every other device immediately. You can see and revoke your active sessions from the app, and “sign out everywhere” ends every session at once; sessions end on the server, not just in the app.
6. Access controls
Access to production systems is restricted to authorised personnel on a need-to-know basis, with multi-factor authentication for all internal access. Audit logs are kept for administrative operations.
7. AI model training
We do not use patient dictation content or clinical reports to train AI models. The pipeline processes your audio to generate a report and then discards the input. Product improvements are based on aggregated, anonymised usage signals unconnected to any patient data.
8. Files you send us
Any file attached to a support message is held in quarantine and is not readable by anyone until it has been checked. Images are re-encoded from their pixels, which removes anything hidden inside the file rather than trying to detect it. Documents are scanned before release. A file that cannot be checked is refused rather than accepted unchecked.
9. Records system connections
Where an organisation files reports into its own records system, the connection is authenticated with credentials the organisation controls and can rotate or revoke at any time from its console on UnityPulse. Revoking takes effect immediately. We log that a report was sent and when; we do not log or retain its clinical content.
10. The browser extension
The UnityPulse Dictation extension reads nothing from a page until you ask it to dictate into a field. Drafts it keeps are stored in your browser, not on our servers, and a retry cannot charge twice. Details are in the extension privacy notice.
11. Incident response
We maintain an incident response plan for security events. In the event of a confirmed data breach affecting user account data, we will notify affected users within the timeframe required by applicable law, including the NDPR (72 hours for notifiable breaches where applicable).
12. Reporting vulnerabilities
If you discover a security vulnerability in TScribe, please tell us responsibly at hello@tscribe.io. We will acknowledge your report within two business days and work with you to address the issue before any public disclosure.
13. Contact
Questions about security? Write to hello@tscribe.io or use the UnityPulse contact page.