Better safe. Never sorry.

Privacy is a human right. This is why our technology is built around protecting it.

Certified for your peace of mind

From privacy to performance, every certification reflects our commitment to doing things the right way - so you can focus on care, knowing the details are protected.

Great power comes with great privacy

What’s said in the room, stays in the room. Every detail is protected by uncompromising security.

Discover everyday privacy protections

Private by default
Every interaction is designed to protect your data, automatically.

Data stays local to you
Stored securely in trusted, compliant data centres, wherever you are.

You’re in control
Multi-factor authentication safeguards available.

No selling. No sharing
Your sessions belong to you and no one else.

Note Dr minds it's business. Not yours

Note Dr never uses your data to train AI models. Ever.

Note Dr is powered by rules, not your recordings. Every word it writes is shaped by templates you control - not by hidden training on your patient data. You decide the tone, the structure, and the style, so your notes always sound like you. Safe. Consistent. Completely yours.

Patient consent made simple

Your patients’ permission matters. You decide how to ask, and we give you the tools to capture and honour it, every time.

Compliance, without the complexity

Artificial intelligence has the potential to benefit nearly every aspect of our lives - so it must be developed and deployed responsibly.

Evidence for Assurance

We provide DPIAs, PIAs, risk assessments, and security reports upfront - giving your governance team assurance without starting from scratch.

Operational Fit

Our processes are designed to fit into existing IG workflows, with templates and checklists that cut down paperwork and speed up approvals.

Audit-Ready Support

When regulators or auditors ask questions, you’ll have clear, credible answers. We supply the proof so you’re never left scrambling.

International Standards

From GDPR to HIPAA - we align with international frameworks so compliance works wherever you operate.

Partnership, Not Burden

IG is about trust. We act as an extension of your team, helping you meet requirements with less stress and more confidence.

With privacy built in, every
consultation brings peace of mind

Product Security

MFA can be enabled for user accounts via an SSO provider.

Note Dr implements Role-Based Access Control (RBAC) to manage permissions.

Customers can authenticate using SSO, including SAML.

Customer data is not used in non-production environments.

Access Control

Access to internal systems is granted based on the principle of least privilege and is reviewed on a regular basis.

All important security events in our environment are monitored.

We have a strong internal password policy that includes a requirement for MFA for accounts that do not support SSO. Passwords are stored in a company managed password manager.

Endpoint Security

Full-disk encryption is used to protect employee endpoints.

Employee endpoints are protected from malicious web traffic.

All employee endpoints are protected with an advanced EDR solution.

All employee endpoints are centrally managed and secured using an MDM solution.

Note Dr's Security Defense and Intelligence proactively monitors for known attacker TTPs, known malicious binaries, and suspicious activity in the environment. Our team also review anomalous activity and hunt for unknown threats on a regular cadence.

Network Security

We restrict removable media on endpoints and have tools to monitor for suspicious activity, including data exfiltration.

Our domain has DMARC enabled to reduce the risk of spoofing attacks.

We use Firewalls to monitor and control traffic in our infrastructure.

Network activity is centrally logged and arbitrary detection logic has been defined to identify attackers and other anomalous behavior and generate alerts for further investigation.

Important infrastructure logs are centrally stored and monitored.

Corporate Security

We restrict removable media on endpoints and have tools to monitor for suspicious activity, including data exfiltration.

Personnel perform security and privacy awareness training on an annual basis. Topics covered include: Passwords, Mobile devices, Social engineering, Physical security, Phishing, GDPR and CCPA.

We have a documented Incident Response Plan that is reviewed, tested and approved at least annually.

We conduct an annual risk assessment to identify major gaps in our environment.

We perform frequent penetration testing.

Our policies

PRIVACY & COOKIES

WEBSITE TERMS OF USE

Our values lead the way

Smarter appointments. Stronger practice.

Book your demo today and see how Note Dr can save your time tomorrow. Whether you're #1 in your field or just getting started, our Clinical Care team are experts in tailoring Note Dr for you.

Member SpotlightPractice Owner
Read More
"From the very first setup, the Clinician Care team made everything feel simple. They were there through every step. They're answering the small questions and even supporting us as we grew from just me to more team members. It never feels like ‘support’, it felt like they were genuinely invested in my practice." — Dr Clarke

UPGRADE & SAVE

Same power. Smarter choice.

per month
paid annually

Please log in to upgrade your plan.

Oops! You need to be logged in to use this form.

This field is hidden when viewing the form

We're sad to see you go!

Here's what you'll be missing:

Upgrade & Save

Oops! We could not locate your form.

Add Member

This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
Share this secret link to invite people to this team. Only users who can invite members can see this.

Lets Get You Ready

Help us tailor your demo to match your clinical practice. Select your role, documentation type, and preferences to see how Note Dr can work for you.

Login to Note Dr to test your microphone.