HikayatScribe
Log inStart free

Security

Last updated: 16 August 2026

Hikayat Scribe handles clinical consultation data, so security isn’t an add-on - it’s the product. This page summarizes the measures we take today. Full detail, including our sub-processors and your rights, is in our Privacy Policy.

Encryption

Clinical data - transcripts, generated notes, patient reference text - is encrypted at the field level (AES-256-GCM) before it is written to our database. All traffic to and from the app is encrypted in transit (TLS).

Audio handling

We do not store audio. Recording/dictation audio is sent to our transcription provider and discarded as soon as the text transcript is returned; only the text is kept.

Access control and audit logging

Access to clinical records requires an authenticated account. We keep an audit log of who accessed, generated or deleted what, when, and from what IP address, for every consultation record.

Data retention and deletion

Consultation transcripts and notes are retained for 180 days and then automatically and permanently deleted.

Sub-processors

We use a small, named set of providers to run the service - OpenAI, Anthropic, Firebase/Google, Vercel and Neon - each bound by a Data Processing Addendum incorporating the EU Standard Contractual Clauses. Full detail is in our Privacy Policy.

If something goes wrong

If we become aware of a data breach affecting your data, we will notify you without undue delay.

Compliance posture

We are a UK-registered data controller and processor, and we design our data handling around UK GDPR principles. We are still building out full UK GDPR compliance (DPIA, breach process, processor agreements) and do not yet claim full compliance. We are not currently a HIPAA Business Associate - if you are a US-based practice and require a BAA, contact us to discuss.

Questions

Email ceo@hikayatai.com.