SOC 2 is a security standard. Holding it means our controls were examined by a third party, not simply described by us.
Our security controls were examined by an independent auditor, not described by us.
Those controls cover how systems are secured, who can reach what, and how that access is managed.
For a practice review or a procurement process, that is third-party evidence rather than a marketing claim.
NirvaScribe holds SOC 2 Type 1. An independent auditor examined our security controls and verified they were designed appropriately and were in place. That is third-party evidence, not our own description.
SOC 2 covers security controls: how systems are secured, who can reach what, and how that access is managed. It sits alongside the Privacy Act obligations that govern Australian practice, rather than replacing them.
A SOC 2 Type 1 report verifies that security controls were designed appropriately and were in place at a point in time. A Type 2 report additionally tests how those controls operated across a period, usually several months. NirvaScribe currently holds Type 1.
If you need documentation for a practice review, a procurement process or your own privacy officer, ask. We will send what you need.
Talk to our teamNothing is recorded, patient data is held in Australia, and nothing trains our models.
Type 1 verifies that controls were designed appropriately and were in place at a point in time. Type 2 tests how they operated over a period, usually several months. NirvaScribe currently holds Type 1.
Ask us. If you need documentation for a practice review, a procurement process or your own privacy officer, we will send what you need.
Not on its own. SOC 2 covers security controls. The Privacy Act 1988 and the Australian Privacy Principles govern how patient information must be handled here. NirvaScribe meets both.
Sixty sessions a month, free forever. Two minutes to set up. No card.