Security: Clinical documentation technology built around trust, privacy, and control.
Security and Privacy

Clinical trust, protected from the first note.

Notly.ai is designed for clinical documentation workflows where patient information, clinician control, and secure data handling matter. Capture consults, generate draft notes, and keep every output review-ready before it enters the medical record.

Built for privacy-aware clinical teams, review-ready notes, and controlled documentation workflows.

Security foundation

Protection built into the documentation workflow.

Notly.ai keeps the message simple: Protect clinical data, keep clinicians in control, and make governance visible.

Encrypted data handling

Consultation data is protected in transit and at rest using modern encryption, secure transport, and managed access controls.

  • TLS-secured transmission
  • Encrypted storage configuration
  • Controlled access to clinical records

Clinician control

Notly.ai keeps the clinician as the final decision-maker before any AI-generated note, letter, summary, or coding prompt is used.

  • Review before finalisation
  • Edit and approve workflows
  • No automatic clinical sign-off

Reliable infrastructure

Platform on Google cloud infrastructure with monitoring, availability planning, and documented operational controls.

  • Australian-hosted data.
  • Monitored uptime and incidents
  • Secure, and ready for everyday clinical use.

Monitoring and auditability

Support accountability with operational logging, incident processes, access review, and periodic security assessment.

  • Access logs
  • Vulnerability review
  • Incident response process

Data retention control

Data is retained only where required to complete the note, support clinical documentation, or meet agreed operational, audit, and legal requirements.

  • Limited retention windows
  • Manual deletion controls
  • Practice-level policy settings

Responsible AI safeguards

Use AI to assist documentation while protecting patient information and avoiding unsupported automated clinical decision-making.

  • Human review required
  • De-identification where applicable
  • No training-use commitments
Encrypted pathways
Secure transport and storage principles.
Review-ready drafts
Clinician edits before use.
Operational oversight
Monitoring, review, and audit trails.
Team governance
Roles, workflows, and accountability.

Controls

Security controls at a glance.

AreaNotly.ai approachPublication status
EncryptionEncrypted transport and storage for clinical data handled by the platform.Technical details
Access controlLimited access by role, team, for authorised workflow needs.Configure per practice
Audio and transcript handlingRecordings are kept only until the note is processed, then deleted with user control.Retention policy
SubprocessorsGoogle-supported infrastructure for AI processing, analytics, support, and communications.Final list
Compliance commitmentsAligned with Australian privacy standards. Progressing toward SOC 2 compliance.Ongoing Process
Incident responseNotly.ai maintain a defined process for assessing, containing, reporting, and learning from security events.Incident Response

Privacy and compliance

Clear commitments for healthcare teams.

EncryptionTechnical details

Notly.ai protects clinical information using secure encryption, controlled processing, and restricted system access.

  • Data encrypted in transit and at rest
  • Secure handling of consultation recordings, transcripts, and generated notes
  • Clinical data processed only for preparing the note
  • Patient information is not used to train AI models
  • Security controls designed for healthcare documentation workflows
Access controlConfigure per practice

Notly.ai keeps access clinician-controlled and practice-configurable.

  • Role-based access for clinicians, admins, and practice teams
  • Practice-level controls for users and workflows
  • Support access only when required and authorised
  • Access activity is logged and reviewed
  • Clinician remains in control of every generated note before use
Audio and transcript handlingRetention policy

Notly.ai is designed to minimise unnecessary storage of clinical recordings.

  • Recordings are retained only while the note is being processed
  • Audio is deleted once the clinical note has been generated
  • Notes and transcripts are retained only as required for the workflow
  • Retention settings can be aligned with practice policy
  • Users remain in control of reviewing, editing, exporting, and deleting content
SubprocessorsFinal list

Notly.ai uses selected service providers only where needed to deliver the platform safely and reliably.

  • Subprocessors used for AI processing, analytics, support, hosting, and communications
  • Google LLC may be used for AI processing, analytics, support, and communication services
  • Subprocessors are reviewed for security and privacy suitability
  • Clinical data sharing is limited to what is required to deliver the service
Compliance commitmentsLocal data processing

Notly.ai is being designed around Australian healthcare privacy expectations and responsible AI use.

  • Australian Privacy Principles aligned approach
  • Data processed and stored locally in Australia
  • SOC 2 compliance pathway in progress
  • Clear documentation for consent, privacy, data handling, and retention
Incident responseSecurity events

Notly.ai maintains a defined process for managing security events.

  • Security events are assessed, contained, and documented
  • Incident response responsibilities are assigned internally
  • Relevant events are reviewed and escalated when required
  • Corrective actions are tracked after security events

FAQ

Security questions clinicians ask before getting started.

No. Notly.ai should be presented as a documentation assistant. Clinicians remain responsible for reviewing, editing, and approving any generated note, letter, or coding prompt before use.
Audio is temporarily processed, stored, and automatically deleted.
Healthcare data is hosted in Australia.
Yes. Detailed security, purchasing, compliance, and integration questions should be directed to the Notly.ai team for practice-specific responses.

Ready to review security?

Bring secure, clinician-controlled documentation into everyday care.

Start with a simple workflow, then scale Notly.ai across your team with review-ready notes, clear privacy controls, and governance that supports clinical practice.