Security
This page is for whoever at your organisation has to approve a new supplier. It says what is true today, including the parts that are not flattering.
What NDIScribe does not have
NDIScribe holds no security certification of any kind. There is no ISO/IEC 27001 certificate, no SOC 2 report, no IRAP assessment and no third-party penetration test. Nobody independent has examined this service. If your procurement process needs one of those documents, we are not that supplier yet, and it is better that you know now than after you have moved your notes across.
NDIScribe is built and run by one person. That person holds administrative access to the hosting account and could, in principle, read the records in any workspace. There is no second operator, so there is no separation of duties to claim, and we will not describe our own access as restricted when it is not.
We do not yet keep a request-by-request access log for this service, so we cannot hand you a list of who read which record and when. That is a real gap, we know about it, and it is on the list to close.
Where your records are
The shared workspace runs on Amazon Web Services in its Sydney region, ap-southeast-2. Records sit in a single database table with server-side encryption at rest, point-in-time recovery switched on and deletion protection on the table itself. Traffic to this service is HTTPS only, and this origin asks browsers to refuse an unencrypted connection to it for a year.
One exception to Australian handling matters and is set out in full on the privacy page: while a workspace leaves AI review switched on, a draft a worker deliberately sends for review is transmitted word for word to an external writing assistant outside Australia. An owner can switch that off for the whole organisation, and while it is off the service refuses every such request.
How somebody signs in
There are no passwords to steal, reuse or leak. Signing in emails a six-digit passcode to a work address, it is valid for 10 minutes, and NDIScribe stores a keyed hash of it rather than the code. A browser session is a cookie that page scripts cannot read, that is sent only over HTTPS, and that lasts 30 days. A change made from a browser is refused unless the request came from this site, and no other website is permitted to call this service from a browser at all. Sign-in attempts are limited per email address, per network address and across the whole service.
Payments
Stripe hosts the checkout page and holds the card. The full card number never reaches NDIScribe and is not stored here.
Who else can see workspace data
Amazon Web Services, for hosting and for delivering sign-in passcodes. Stripe, for subscription billing. The external writing assistant described above, and only for the text of a draft a worker deliberately sent it. Nobody else. There is no analytics, advertising or session-recording code on any NDIScribe screen, and we do not sell personal information.
Keeping and deleting records
A signed record has no expiry set on it. It stays in the workspace until somebody deletes the workspace, which an owner can do from the account screen without asking us. Passcodes expire after 10 minutes, ordinary sessions after 30 days, and the transient records behind AI review after 48 hours. Application logs are kept for 30 days and are not written with note text, passcodes or session tokens in them.
Reporting a vulnerability
Email the address below with "security" in the subject line. The same contact is published in machine-readable form at /.well-known/security.txt. We will acknowledge within two business days, Australian eastern time, and tell you what we intend to do and roughly when. There is no bug bounty and no payment. We will not pursue or support legal action against anyone who reports a problem in good faith, works only against their own test workspace, does not access, change or keep another organisation's records, and gives us a reasonable chance to fix it before describing it publicly.
If something goes wrong
If we come to believe that records in your workspace have been exposed or altered, we will email the workspace owner with what we know and when we knew it, rather than waiting until the picture is complete.
Contact mitsi@keenshift.ai.
Last updated 13 August 2026.