Identity
01Security and access review
Workspace membership, account roles, and privileged access are reviewed on a defined cadence with evidence collected through continuous monitoring.
Compliance
CortexaNote runs its documentation platform under a SOC 2 Trust Services Criteria control framework with continuous monitoring. The Type II observation window is in progress, and a security review packet is available for procurement review today.
Mapped signals
CortexaNote keeps framework, security control, workflow ownership, and review responsibility visible on one page.
Trust packet
A serious safety page makes compliance proof inspectable. CortexaNote keeps that rhythm without pretending gated reports are public downloads.
Security reviews, agreement requests, status checks, and framework evidence are separate artifacts. Keeping them explicit prevents the page from collapsing procurement, operations, and legal review into one vague trust claim.
SOC 2 packet
Ask for the current control summary, security questionnaire, and progress evidence while the Type II observation window completes.
Trust center
Live posture, control summaries, security policies, and procurement evidence are published in the CortexaNote trust center.
Procurement
Ask for the right questionnaire response, agreement, or architecture summary for your procurement workflow.
Operations
Uptime and incident communication live outside marketing copy so operations teams can inspect them directly.
Controls
Operational controls for security, availability, and confidentiality.
Identity
01Workspace membership, account roles, and privileged access are reviewed on a defined cadence with evidence collected through continuous monitoring.
Release
02Product changes that affect capture, drafting, import, billing, or authentication require explicit operational review before release.
Reliability
03Status communication, capacity planning, and dependency monitoring keep the service inspectable so teams know where workflow risk lives.
Data
04Clinical content is encrypted at rest and in transit and handled as sensitive work product through capture, draft, review, and export.
Operations
05Detection, logging, and on-call rotations route through the trust and status surfaces rather than being buried in product copy.
Procurement
06Hosting, communication, AI, and analytics subprocessors are reviewed before they enter the workflow and re-evaluated on a defined cadence.
Data lifecycle
The boundary is not one database table. It is the whole journey from patient conversation to approved note.
01
Clinicians record only inside the authorization, consent, and operating policies required by their organization.
02
Audio moves from Recorder or browser capture through encrypted transfer into a protected clinical workspace.
03
AI output stays draft work until a qualified clinician checks the note, edits it, and approves the final record.
04
Teams can move approved text into the EHR and keep retention decisions explicit instead of hidden in the tool.
CortexaNote works best when clinical, operations, procurement, and trust owners evaluate the same Recorder + AI scribe + EHR workflow.