Bank-level securityfor Norwegian healthcare

Stenoly follows the same security standards as Norwegian banks, with full GDPR compliance and automatic data deletion.

BankID security
Buypass security
GDPR

Our security promise

Zero data storage
EEA-approved data centers
Automatic deletion after 24h

Secure authentication and encryption

Same security standards as Norwegian banks, with military-grade encryption and EU/EEA compatibility

BankID
Buypass
GDPR
Bank level

BankID and Buypass security

Same authentication standards as Norwegian banks for maximum security and access control.

Military grade

Encrypted data processing

All data is encrypted with AES-256 from your device to our systems and back again.

EU-approved

GDPR-compliant

Full compliance with data protection regulations with documented data processing and user rights.

Continuous security monitoring

Our dedicated security team monitors systems around the clock and performs regular security tests to ensure we always maintain the highest standards.

Our data security principles

We have built an architecture that ensures your data is never stored permanently - everything is processed in real-time and deleted automatically

EU/EEA servers

All our servers are located within the EU/EEA area for maximum data security and legal protection.

Automatic deletion

All consultations are automatically deleted after 24 hours - no permanent storage of patient data.

Zero-storage architecture

We never store data on our servers. Everything is processed in real-time and deleted immediately after use.

Real-time processing

All data processing happens in real-time without intermediate storage or permanent retention.

GDPR-compliant

Full compliance with data protection regulations with documented data processing and user rights.

24-hour cycle

Guaranteed deletion of all data within 24 hours, with automatic verification of the deletion process.

Secure transcription process

Our transcription technology is designed for maximum security and privacy.

1

Only last 5 seconds

We only send the last 5 seconds of recording for processing

2

Real-time processing

Everything happens in real-time - no audio clips are ever stored

3

Automatic anonymization

Transcriptions are automatically anonymized if personal data is detected

0 MB

Data stored permanently

Technical security measures

Advanced security systems that complement our zero-storage architecture

AES-256 encryption

End-to-end encryption

All data is encrypted with AES-256 standard from your device to our systems and back again.

MFA + SSO

Multi-factor authentication

BankID and Buypass ensure that only authorized healthcare personnel gain access to the system.

Full audit trail

Audit logging & compliance

Complete logging of all activity for audit and compliance with healthcare regulations.

24/7 SOC monitoring

Continuous monitoring

Round-the-clock security monitoring and automatic alerting of suspicious activity.

RBAC + least privilege

Access control

Role-based access with least privilege principle and detailed activity logging.

External pen testing

Penetration testing

Regular security tests performed by external experts to identify vulnerabilities.

Defense in Depth security strategy

We implement multiple layers of security, so that even if one layer is compromised, the data is still protected by the other layers.

Perimeter security: Firewall and DDoS protection
Application security: Secure coding and input validation
Data security: Encryption and access control
Monitoring: Continuous threat detection
Military-grade security

Same technologies used by defense sector and critical infrastructure

Technical security questions

Thorough answers to the most critical security questions from IT departments and data protection officers

Our zero-storage architecture guarantees that no patient data is stored permanently on our servers. The process works like this:

  • Audio recordings are encrypted on your device before transmission
  • Data is processed in real-time in memory (RAM) - never written to disk
  • Transcribed text is returned immediately to your device
  • All data is deleted from memory within seconds after processing

Technical implementation: Stateless microservices with ephemeral containers that automatically terminate.

Have questions?

We are available to answer all your questions about data security and privacy

General inquiries

For general questions about security and privacy

hei@stenoly.no

Response time: < 24 hours

Technical support

For technical questions and implementation support

support@stenoly.no

Response time: < 24 hours

Security questions

For specific security questions and compliance

sikkerhet@stenoly.no

Response time: < 48 hours

Security you can trust

Start your secure digital transformation today, or get a personal review of our security measures

100%
GDPR-compliant
24/7
Security monitoring
0
Data storage

Trust from doctors who prioritize security

Zero-storage: security for healthcare – Stenoly