Scribara handles PHI. That fact shapes the architecture, the team, the audit posture, and the contracts. Nothing about our security program is bolted on.
Continuous controls — Drata-monitored. Report available under NDA.
End-to-end PHI handling. De-identification at ingress. Auditable retention.
AI management system certified — the only standard built for clinical AI.
Information security management. Certified annually.
Healthcare-aligned controls. Validated assessment in flight.
EU residency on Enterprise. AI Act conformity declared.
Card data handled by Stripe; Scribara never touches a PAN.
Cloud Security Alliance self-assessment published.
Scribara treats every customer as a regulated tenant. Data never crosses tenant boundaries — at compute, storage, or model layers.
WorkOS-powered SSO, fine-grained RBAC, and per-action policies that line up with your compliance officer's requirements — not the model's preferences.
The team behind the security posture, the cadence of testing, and the people you'll talk to during a procurement review.
Request our trust packet: SOC 2 Type II report, HIPAA BAA, DPA, pen-test summary, architecture diagram, and AI model card.