Trust Center

Security is Our Foundation

OneScribe is built with enterprise-grade security from the ground up. We protect your conversation data with industry-leading security standards and compliance certifications.

99.99%
Uptime SLA
🔐
256-bit
AES Encryption
👁️
24/7
Security Monitoring

Compliance & Certifications

We maintain rigorous compliance with global security standards and undergo regular third-party audits

GDPR Compliance

Compliant

Full compliance with EU data protection regulations

Valid until: Ongoing

Lawful basis for data processing
Data subject rights implementation
Privacy by design architecture
Data breach notification procedures
Cross-border data transfer safeguards

HIPAA Compliance

Compliant

Healthcare data protection standards

Valid until: Ongoing

Administrative safeguards
Physical security measures
Technical safeguards implementation
Business Associate Agreements (BAAs)
Audit controls and monitoring

CCPA Compliance

Compliant

California Consumer Privacy Act compliance

Valid until: Ongoing

Consumer rights implementation
Opt-out mechanisms
Privacy notice requirements
Data deletion processes
Non-discrimination policies

Comprehensive Security Features

Multiple layers of security protect your data at every level

🔐

Data Encryption

  • 256-bit AES encryption at rest
  • TLS 1.3 encryption in transit
  • End-to-end encryption for sensitive data
  • Encrypted backups with key rotation
  • Hardware security module (HSM) key management
🔑

Access Control

  • Multi-factor authentication (MFA)
  • Single Sign-On (SSO) support
  • Role-based access control (RBAC)
  • IP allowlisting capabilities
  • Session timeout controls
🏗️

Infrastructure Security

  • AWS cloud infrastructure
  • Multi-region data redundancy
  • DDoS protection
  • Web Application Firewall (WAF)
  • 24/7 security monitoring
🛡️

Data Privacy

  • Data residency options
  • Right to deletion (RTBF)
  • Data portability
  • Privacy-first architecture
  • Minimal data collection
📋

Compliance & Auditing

  • Annual third-party audits
  • Continuous compliance monitoring
  • Audit log retention
  • Compliance reporting
  • Vulnerability assessments
🚨

Incident Response

  • 24/7 security operations center
  • Incident response team
  • Automated threat detection
  • Security incident notifications
  • Disaster recovery planning

Our Security Practices

Security is embedded in everything we do

Development Security

Secure SDLC with security reviews at every stage
Regular security training for all engineers
Automated security testing in CI/CD pipeline
Code reviews with security focus
Dependency scanning and management
Regular penetration testing

Operational Security

24/7 security operations center (SOC)
Real-time threat monitoring and response
Regular security audits and assessments
Incident response team and procedures
Employee background checks
Security awareness training program

Your Data, Protected

We implement multiple layers of protection to ensure your conversation data remains secure and private

👤

Data Ownership

You own your data. We're just the custodians.

📦

Data Portability

Export your data anytime in standard formats.

🗑️

Data Deletion

Request deletion and we'll remove all your data.

🚫

No Data Sales

We never sell or share your data with third parties.

Questions About Security?

Our security team is here to answer your questions and provide detailed information about our security practices.

Report a security vulnerability:

support@onescribe.io

We take all security reports seriously and will respond within 24 hours.