Continuity
Backup & disaster recovery
This page is maintained by ScribeMDPro to explain how clinical data is protected, how quickly service is restored after a disruption, and how the platform scales internationally.
What is and is not stored
- Audio recordings
- Not retained. Consultation audio is processed to produce a transcript and is not kept as a stored recording, so there is no audio archive to back up or breach.
- Transcripts and notes
- Stored against the owning clinician or clinic workspace and protected by database-enforced access rules.
- Account data
- Email, name, specialty, preferred language and subscription state.
- Operational metadata
- Aggregate usage counters and export records used for billing accuracy and workspace accountability.
- Support and analytics
- Product analytics carry page and interaction metadata only — never transcripts, note content or patient identifiers.
Backup
Managed, encrypted backups of the production database.
Automated daily backups of the production database, plus continuous transaction logging that enables point-in-time recovery between daily snapshots.
Backups are encrypted at rest by the managed database platform and are not accessible from the application runtime.
Scheduled restore drills that verify a backup can be recovered into a clean environment, with the result recorded.
Recovery objectives
Targets we design and operate against. Contractual objectives for hospital deployments are agreed in writing during procurement.
- RPO — Recovery Point Objective
- Target of under 24 hours from daily snapshots, reduced toward minutes where point-in-time recovery is available.
- RTO — Recovery Time Objective
- Target of under 4 hours to restore core consultation, transcription and note functionality after a declared incident.
- Degraded mode
- If generation services are unavailable, previously created notes remain readable and exportable — clinicians never lose access to documentation they already completed.
- Contractual SLAs
- Enterprise and hospital agreements can set specific availability and recovery commitments; the targets above are operational, not a public guarantee.
Data retention & deletion
- Active accounts
- Transcripts and notes are retained while the account or workspace is active, so clinicians can revisit past documentation.
- Deletion requests
- Clinicians can delete their own consultations and patient records; workspace owners and admins can remove records within their clinic.
- Backup lag
- Deleted data may persist in encrypted backups until those backups age out of the retention window, after which it is unrecoverable.
- Account closure
- Contact us to close an account and remove its data. Aggregate, non-identifying usage counters may be retained for billing and statutory record-keeping.
Incident response
- 1
Detect
Automated error and availability monitoring, plus reports through the support channel.
- 2
Triage
Severity assessed against clinical impact first: can clinicians record, generate and export?
- 3
Contain
Restrict the affected surface, revoke compromised credentials, and roll back or disable the failing change.
- 4
Recover
Restore service from backup or a known-good deployment and verify with end-to-end checks.
- 5
Notify
Affected workspace owners are informed with what happened, what data was involved and what to do — without exposing patient content in the notification.
- 6
Review
Written post-incident review with corrective actions tracked to completion.
Report a suspected security issue or outage to scribemdpro@gmail.com. Please do not include patient-identifying information in the report.
Global scalability
How the platform is architected to serve clinicians across regions.
The application is served from a globally distributed edge network, so pages and assets load close to the clinician regardless of country.
Server work runs on stateless, horizontally scalable workers with no machine-local state, so capacity grows with demand.
Dates render in the viewer's locale and pricing is presented per region; per-workspace timezone and currency preferences are planned.
Region-pinned data storage for jurisdictions that require it, offered per enterprise deployment.
Lower-latency reads for large hospital networks operating far from the primary region.
Dictation already spans many languages; a translation framework for the interface itself is prepared, and languages are enabled only once fully translated.
Related
See also Enterprise Security, Trust Center and Compliance.
Continuity questions before you deploy?
We will walk your IT team through the architecture in detail.