Trust & security
Clinical records carry real legal weight. Here is exactly how InstantNote handles security, data residency, and AHPRA / Dental Board of Australia compliance. For the full legal detail, see our Privacy Policy.
Security
Data at rest is AES-256 encrypted. Data in transit uses TLS 1.3. Scanner file access uses short-lived signed URLs that expire after 5 minutes.
Core clinical data, notes, transcripts, patient records and scanner images, is stored in Sydney-region infrastructure, not offshore.
Role-based access control with data isolation per clinician. You can only see notes and patients associated with your own account.
Significant actions, note creation, export, approval, are logged for security and compliance review, alongside rate limiting on sensitive endpoints.
InstantNote's infrastructure is penetration tested, and security practices are aligned to ISO 27001:2022 and the ACSC Essential Eight.
Your clinical content is never used to train AI models. This is a contractual requirement for every AI subprocessor InstantNote uses.
Compliance
Every generated note is checked against AHPRA health record standards and Dental Board of Australia record-keeping expectations before you approve it.
Notes are scored against ADA Guidelines for Dental Records and the Dental Board's shared Code of Conduct. Missing fields, like consent elements, LA documentation, or follow-up plans, are flagged before approval, not after.
InstantNote is bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We are subject to the Notifiable Data Breach scheme and will notify you and the OAIC of any eligible breach.
Data handling
Raw audio recordings are processed in real time and discarded immediately after transcription. We do not keep audio files.
Patient identifying details stay in your database. Only clinical dictation, not names or other identifiers, is sent for AI transcription and note generation.
Where an overseas AI provider is used for transcription or note generation, only the minimum data needed is sent, under contractual data processing agreements, and it is never retained by the provider after the request completes.
Want the full detail?
Our Privacy Policy lists every subprocessor we use, what data they receive, where it is processed, and your rights under the Australian Privacy Principles.