What AI voice and ambient-scribe vendors serving Australian and New Zealand healthcare have published on their own public pages about data residency, model provenance, subprocessors, certifications and regulatory status — with a source URL on every entry and a verbatim quote wherever the vendor published one.
Read this first: This tracker records only what each vendor has published on its own public pages. It is not an assessment, audit, certification or endorsement. Vendors change their documentation — always verify directly before making a procurement decision.
Vendors tracked
39
Facts recorded
406
Sources cited
169
Last checked
25 Sept 2026
Why this exists
Storage region and processing region are not the same thing.
Data storage region and data processing / inference region are frequently different in AI systems. Storage and processing locations can both matter for cross-border obligations under APP 8 and the New Zealand Health Information Privacy Code. This is general information, not legal advice.
This tracker records both separately wherever a vendor publishes them, and shows a verbatim quote from the vendor's own page so you can read exactly what they said.
What we track
Data storage region
Data processing region
Model provenance
Subprocessors
Certifications
TGA status
PMS integrations
ANZ entity
Support hours
A vendor can have multiple entries for the same field with different sources. We do not pick a winner — every source stands on its own.
Values shown are truncated for the matrix. Click any cell to see the full statement, the verbatim quote from the vendor's page, the source URL, and the date checked.“Not found on public pages” — We could not find this on the vendor's public pages as at the check date. This is not a statement that the vendor lacks the capability or has not disclosed it elsewhere.
Change log
Recent changes
When a vendor's page or our summary of it changes, we record the old and new values with both check dates.
Trust centre lists 'Data Service Vendors': Zendesk, Amplitude, Sentry, OpenAI, Google Cloud (names displayed as labels/logos; no per-vendor purpose text)
Now — checked 2026-09-25
Trust centre's Data Service Vendors table lists 13 vendors, each with a purpose and a US location: Google Cloud (cloud hosting), OpenAI and Anthropic (interim text summarization), Microsoft Azure (backup OpenAI model hosting), Baseten (running Abridge-created models), LiveKit (verbatim voice stream support), Temporal (encounter processing orchestration), Sentry (application performance monitoring and error tracking), Amplitude (application analytics), Zendesk (user support), Braze (user support and messaging), Sigma Computing (data management and analytics) and dbt Labs (data handling). The table notes PHI and/or PII involvement for every vendor except Temporal.
Proprietary 'Contextual Reasoning Engine' AI framework described on Abridge's site; specific model providers not stated on that page (OpenAI appears on the trust centre vendor list)
Now — checked 2026-09-25
Vendor presents its Contextual Reasoning Engine as 'leading healthcare AI infrastructure'; the page names no model providers. Separately, the trust centre's Data Service Vendors table lists OpenAI and Anthropic for interim text summarization, Microsoft Azure for backup OpenAI model hosting and Baseten for running Abridge-created models.
HIPAA, GDPR, SOC 2, ISO 27001 stated; badge logos also displayed for ISO 13485, ISO 42001, ISO 27017, ISO 27018, ISO 14971, ISO 62366, CE, NHS DSPT/DTAC/DCB0129, Cyber Essentials Plus, EU AI Act, NIS2, DORA, ISAE 3000, BSI C5, US FedRAMP
Now — checked 2026-09-25
Safety page states Corti's security meets or exceeds market and regulatory requirements, including compliance with several strict frameworks, and displays framework logos (images without text labels) for ISO 27001, ISO 27017, ISO 27018, ISO 42001, ISO 13485, ISO 14971, ISO 62366, SOC 2, HIPAA, GDPR, CE, NHS DSPT, NHS DTAC, NHS DCB0129, Cyber Essentials Plus, EU AI Act, NIS2, DORA, ISAE 3000, BSI C5, US FedRAMP and EU-U.S. Privacy Shield.
Vendor states it may disclose limited personal information to third-party service providers outside Australia for its AI Virtual Receptionist
Now — checked 2026-09-25
Vendor states it may disclose limited personal information to third-party service providers outside Australia for its AI Virtual Receptionist and AI-assisted electronic communications products
AI virtual receptionist supported by Open AI, LiveKit, Langfuse and Twilio (cloud hosting and speech recognition)
Now — checked 2026-09-25
Privacy policy names OpenAI, LiveKit, Langfuse, ClickSend and Twilio among third-party service providers supporting its AI virtual receptionist and AI-assisted electronic communication functionality, such as cloud hosting and speech recognition
AWS (hosting, Australia); privacy policy also notes software and other service providers in the United States subject to confidentiality restrictions
Now — checked 2026-09-25
Privacy policy says all personal information is hosted and stored on HotDoc's Australian servers, but may be sent to overseas recipients, including software and other service providers located in the United States and the United Kingdom, and other service providers and sub-processors described in its Trust Centre. Its security page states hosting in Australia on Amazon Web Services (AWS).
Help centre article (dated May 2024) states transcription is performed in real time on the vendor's servers in Sydney.
Now — checked 2026-09-25
Help centre article (dated 13 August 2026) states all transcription is performed in real time on servers located in the user's region, and that data is processed and stored within the region it originates from.
Privacy policy (effective 16 February 2026) states language processing via Azure OpenAI in the European Union, using de-identified health information only, with region-pinning where available.
Now — checked 2026-09-25
Privacy policy lists overseas transfers to the United States for payment processing (Stripe), system monitoring (Sentry, Honeycomb) and website analytics (Segment), and says all other personal information, including transcripts and speech processing, remains stored in Australia (AWS Asia-Pacific Sydney region) and is not transferred overseas. It names Azure OpenAI (Microsoft) for language processing; no processing location for it is stated on the page checked.
Vendor lists Best Practice and MedicalDirector (copy-paste + browser extension), Genie and Helix (copy-paste), Cliniko (allied health)
Now — checked 2026-09-25
Vendor lists Best Practice and MedicalDirector (copy-paste + browser extension), Genie and Helix (copy-paste) and Cliniko (allied health), and lists direct API integration as on its roadmap
Privacy policy names Open AI among third-party service providers supporting the AI virtual receptionist's functionality, alongside LiveKit, Langfuse and Twilio. Specific models are not named.
Now — checked 2026-08-12
AI virtual receptionist supported by Open AI, LiveKit, Langfuse and Twilio (cloud hosting and speech recognition)
No consolidated subprocessor register published. Third parties named in the privacy policy include Open AI, LiveKit, Langfuse and Twilio (AI virtual receptionist), Braze Inc., Cloudstaff Pty Ltd, Google Analytics, Hotjar, Intercom Inc, Gong.io Inc, Best Practice Software Pty Ltd, Telstra Health Pty Ltd, eRx Script Exchange Pty Ltd, Medication Knowledge Pty Ltd, Oexa Pty Ltd and First Focus IT.
Now — checked 2026-08-12
Braze, Inc. (customer engagement) hosts and processes primarily in the United States; policy names further providers incl. Cloudstaff, First Focus IT, Stripe Australia, Tyro, Gong.io
Trust Center subprocessor table states Azure speech-to-text operations occur in U.S. Regions, and Google Cloud infrastructure hosting in Central Region (USA) for U.S. clients and Belgium for all non-USA clients.
Now — checked 2026-08-12
GCP infrastructure hosting: Central Region (USA) and Belgium (all non-USA); Azure speech-to-text operations in U.S. regions
3 subprocessors published on the Trust Center: Google Cloud (Infrastructure Hosting), Azure (Speech to Text Operations), Front (Support Ticketing, No PHI).
Now — checked 2026-08-12
Core vendors listed on trust centre: Google Cloud (infrastructure hosting), Azure (speech to text), Front (support ticketing, no PHI)
SOC2 Type 2 certified; HIPAA compliant (as stated on suki.ai home page). Suki also links a Trust Portal at https://trust.suki.ai/ (Vanta-hosted); its contents render only with JavaScript and could not be retrieved, so no certification detail is recorded from it.
Now — checked 2026-08-12
SOC 2 Type 2 certified and HIPAA compliant (stated on website)
AU site states Australian Privacy Principles, HIPAA standards, SOC 2, PCI and ISO 27001 certified. No certificate numbers, audit scope or report access are stated on the page; the site FAQ states security details are provided during security review under NDA.
Now — checked 2026-08-12
Website states certification against Australian Privacy Principles, HIPAA standards, SOC 2, PCI and ISO 27001
Australia, stated for personal information held by Healthengine. The same policy states some third party service providers may store personal information on servers located overseas, including the US and European Union.
Now — checked 2026-08-12
Vendor states secure servers in Australia; its policy says some service providers may store data overseas
United States — website privacy policy states Personal Data may be transferred to Company offices and servers located in the United States. Policy does not separately state where clinical/PHI data is stored.
Now — checked 2026-08-12
Privacy policy says personal data may be transferred to company and authorised third-party offices and servers in the US
Are we missing something, or has this changed? Vendors and their representatives can submit a correction, and we note each change and credit the source. We review every correction request and update the entry when the source supports it.
Corrections address: hello@gocadence.ai
We verify against the source URL you provide and credit it in the update.
If the change is material we note it in the public change log above.
Sources. Vendor trust centres, security pages, privacy policies, subprocessor lists, DPAs, product documentation, official registers and vendors' own announcements. Not competitor claims.
Robots & access. We respect robots.txt. Where a vendor's pages disallow automated access, we record that and do not work around it.
Point-in-time. Every entry carries the date it was checked. Vendors update documentation frequently — an entry is a snapshot of what a specific page said on a specific day.
Absence. We could not find this on the vendor's public pages as at the check date. This is not a statement that the vendor lacks the capability or has not disclosed it elsewhere.
No scoring, no ranking. This is a reference, not a scorecard. We do not compute a “transparency score”, a grade, a star rating or a percentage-complete. Vendors are listed alphabetically. We do not rank them.
Corrections. Any vendor or their representative can submit a correction using the form above. We review every correction request and update the entry when the source supports it.
Payment disclosure. No vendor pays to appear in or be omitted from this tracker. How we're paid. You pay the fixed fees in our pricing table. If you select a platform, that vendor may also pay Cadence a success fee, at the same rate whichever platform you choose. Before an engagement starts we tell you which vendors we have fee agreements with. Platform licences are paid to the vendor directly.
Answers by question
Reading one question across every vendor
The matrix above reads vendor by vendor. If you would rather read one question across all of them, each topic has its own page with the same quotes, sources and check dates.
This tracker records what vendors have said. If you need help deciding which vendor to sign — inside your specific network, integrations and risk posture — that is what our advisory engagements are for.