Encrypted data handling
Consultation data is protected in transit and at rest using modern encryption, secure transport, and managed access controls.
- TLS-secured transmission
- Encrypted storage configuration
- Controlled access to clinical records
Notly.ai is designed for clinical documentation workflows where patient information, clinician control, and secure data handling matter. Capture consults, generate draft notes, and keep every output review-ready before it enters the medical record.
Security foundation
Notly.ai keeps the message simple: Protect clinical data, keep clinicians in control, and make governance visible.
Consultation data is protected in transit and at rest using modern encryption, secure transport, and managed access controls.
Notly.ai keeps the clinician as the final decision-maker before any AI-generated note, letter, summary, or coding prompt is used.
Platform on Google cloud infrastructure with monitoring, availability planning, and documented operational controls.
Support accountability with operational logging, incident processes, access review, and periodic security assessment.
Data is retained only where required to complete the note, support clinical documentation, or meet agreed operational, audit, and legal requirements.
Use AI to assist documentation while protecting patient information and avoiding unsupported automated clinical decision-making.
Controls
| Area | Notly.ai approach | Publication status |
|---|---|---|
| Encryption | Encrypted transport and storage for clinical data handled by the platform. | Technical details |
| Access control | Limited access by role, team, for authorised workflow needs. | Configure per practice |
| Audio and transcript handling | Recordings are kept only until the note is processed, then deleted with user control. | Retention policy |
| Subprocessors | Google-supported infrastructure for AI processing, analytics, support, and communications. | Final list |
| Compliance commitments | Aligned with Australian privacy standards. Progressing toward SOC 2 compliance. | Ongoing Process |
| Incident response | Notly.ai maintain a defined process for assessing, containing, reporting, and learning from security events. | Incident Response |
Privacy and compliance
Notly.ai protects clinical information using secure encryption, controlled processing, and restricted system access.
Notly.ai keeps access clinician-controlled and practice-configurable.
Notly.ai is designed to minimise unnecessary storage of clinical recordings.
Notly.ai uses selected service providers only where needed to deliver the platform safely and reliably.
Notly.ai is being designed around Australian healthcare privacy expectations and responsible AI use.
Notly.ai maintains a defined process for managing security events.
FAQ
Ready to review security?
Start with a simple workflow, then scale Notly.ai across your team with review-ready notes, clear privacy controls, and governance that supports clinical practice.