How we hold the line.
These are the design commitments the product is being built to. They are architectural — enforced by where code runs and what can physically cross the network — not policy promises layered on top.
the boundary
- Audio is processed inside the practice. Speech is transcribed on a device on the practice's own network. The audio stream is never written to any external system.
- The recording is destroyed at the boundary. Once transcribed, the audio ceases to exist. It is not stored, not archived, not used for training. Only text continues.
- The cloud receives words, never sound. Note drafting operates on text-only payloads. The drafting service has never heard anything.
the record
- Nothing becomes the record until a clinician signs it. Every draft requires human review and an explicit signature. Nothing auto-commits — this is documentation software, not a medical device, and that distinction is enforced in the workflow.
- The audit trail is append-only. Session start, consent, draft generation, every edit, and the signature are recorded with actor and timestamp, and can never be rewritten.
- Consent comes first. No audio processing begins before patient consent is captured. The consent gate is ahead of the microphone, not behind it.
residency
Clinical text is processed and stored in Australia. We treat Australian data residency as table stakes for practising here — a compliance baseline, not a marketing claim.
what we don't claim
Optilic is pre-launch, so we hold no product certifications today — no TGA registration, no ISO 27001, no SOC 2. We would rather tell you that plainly than imply otherwise. Formal certification work is planned as the product matures, and this page will state exactly what has been achieved, when it has actually been achieved.
found something?
If you're a security researcher or a practice IT consultant and you see a hole in this design — or in this site — we want to know.
operations@optilic.com →