Trust & security

Built for the standard your records are held to.

Clinical records carry real legal weight. Here is exactly how InstantNote handles security, data residency, and AHPRA / Dental Board of Australia compliance. For the full legal detail, see our Privacy Policy.

Security

Encryption

Data at rest is AES-256 encrypted. Data in transit uses TLS 1.3. Scanner file access uses short-lived signed URLs that expire after 5 minutes.

Australian data residency

Core clinical data, notes, transcripts, patient records and scanner images, is stored in Sydney-region infrastructure, not offshore.

Per-clinician access control

Role-based access control with data isolation per clinician. You can only see notes and patients associated with your own account.

Audit logs

Significant actions, note creation, export, approval, are logged for security and compliance review, alongside rate limiting on sensitive endpoints.

Penetration tested

InstantNote's infrastructure is penetration tested, and security practices are aligned to ISO 27001:2022 and the ACSC Essential Eight.

No AI training on your data

Your clinical content is never used to train AI models. This is a contractual requirement for every AI subprocessor InstantNote uses.

Compliance

AHPRA and Dental Board of Australia

Every generated note is checked against AHPRA health record standards and Dental Board of Australia record-keeping expectations before you approve it.

Compliance scoring on every note

Notes are scored against ADA Guidelines for Dental Records and the Dental Board's shared Code of Conduct. Missing fields, like consent elements, LA documentation, or follow-up plans, are flagged before approval, not after.

Privacy Act 1988 and the APPs

InstantNote is bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We are subject to the Notifiable Data Breach scheme and will notify you and the OAIC of any eligible breach.

Data handling

Audio discarded after transcription

Raw audio recordings are processed in real time and discarded immediately after transcription. We do not keep audio files.

Patient names never sent to AI providers

Patient identifying details stay in your database. Only clinical dictation, not names or other identifiers, is sent for AI transcription and note generation.

Minimal cross-border transmission

Where an overseas AI provider is used for transcription or note generation, only the minimum data needed is sent, under contractual data processing agreements, and it is never retained by the provider after the request completes.

Want the full detail?

Our Privacy Policy lists every subprocessor we use, what data they receive, where it is processed, and your rights under the Australian Privacy Principles.

Ready to start

Try InstantNote free.

No credit card. No setup. Works in any language.

Start free