Corti Assistant - AI Scribe for Clinical Documentation Creation
Corti Assistant is an AI-powered ambient clinical documentation solution that supports healthcare professionals during patient encounters by listening to conversations, transcribing them in real time, and extracting structured medical information. Clinicians can review and edit outputs to create clinical documents, reducing administrative burden and enabling more focus on patient care.
Features
- Real-time transcription: Instantly converts clinician patient conversations into text
- Ambient documentation: Automatically captures structured clinical information during consultations
- Structured fact extraction: Identifies symptoms, history, vitals, care plans
- AI driven summarisation: Generates concise clinical summaries from conversations
- Interactive feedback: Provides immediate clinical insights during encounters
- EHR integration: Exports notes into electronic health record systems
- Customisable templates: Supports SOAP notes and referral documents
- Chat style querying: Ask AI questions about encounter content
- Quality assurance checks: Flags care gaps and guideline compliance
- Cross platform access: Works across web, desktop, mobile devices
Benefits
- Reduce clinical documentation time during and after patient consultations
- Capture accurate clinical information automatically without manual note-taking
- Enable clinicians to focus attention fully on patients during encounters
- Generate high-quality clinical notes quickly with minimal editing required
- Standardise documentation quality across teams and care settings
- Improve clinical accuracy through structured, AI-extracted medical facts
- Streamline workflows by exporting notes directly into existing systems
- Support flexible working with secure access across devices and locations
- Reduce cognitive load and clinician burnout from administrative tasks
- Accelerate clinical decision-making with clear, structured summaries
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 7 1 3 6 8 5 5 9 9 2 4 4 8 0
Contact
CRESCENDO SYSTEMS LIMITED
John Bendall
Telephone: 01932 789433
Email: admin@crescendosystems.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
- Document
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Corti Assistant is an extension to existing clinical documentation systems and electronic health record (EHR) platforms, enhancing them with AI-powered ambient transcription, summarisation, and structured data extraction. It complements clinicians’ current workflows rather than replacing core clinical or patient record systems.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- Planned maintenance is performed periodically to deliver updates and improvements, with minimal service disruption. Some advanced features may depend on supported platforms, integrations, or regional regulatory requirements.
- System requirements
-
- Stable internet connection for real-time audio processing
- Microphone-enabled device for capturing clinical conversations
- Modern supported web browser or Corti mobile application
- Supported operating system with current security updates
- Secure network access compliant with healthcare data protection standards
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is available Monday to Friday 9am to 5pm, out of hours support available at an additional charge. Response time depends on SLA level. For level I Emergency and level 2 urgent situations Crescendo offers a one-hour response to support calls. For level 3 faults Crescendo will respond within four hours and for level 4 faults response time will be within one business day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AAA
- Web chat accessibility testing
- Crescendo have not directly tested our webchat with assistive technology users. We do however have a large amount of Access To Work and Reasonable Adjustment funded software users who use the web chat on a regular basis and have not received any negative feedback. The Crescendo live chat uses the tawk.to widget which was built with accessibility in mind and aligns with the Web Content Accessibility Guidelines (WCAG). The widget meets WCAG Level A and satisfies several Level AA success criteria.
- Onsite support
- No
- Support levels
-
Crescendo provides four defined support levels for Corti Assistant:
• Level 1 – Emergency: Critical system failure affecting all users. Response within 1 business hour.
• Level 2 – Urgent: Major functionality issues or degraded performance. Response within 1 business hour.
• Level 3 – Standard Fault: Non-critical issues affecting individual users. Response within 4 business hours.
• Level 4 – Minor: Cosmetic issues or general queries. Response within 1 business day.
Support is included in the Corti subscription with no additional charges. For Level 1 and Level 2 incidents that cannot be resolved by Crescendo, issues are escalated directly to Corti for urgent investigation. Organisations with 50 or more users receive a dedicated Account Manager for ongoing coordination and optimisation. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Crescendo provides a full onboarding service for Corti Assistant. While the software is designed to be simple to access and use, we follow a structured five-step plan to ensure successful adoption across all users:
1. Comprehensive welcome pack – Includes login details, access instructions, user guides, support contacts and a training-booking link.
2. Online training – Live remote sessions for individuals or teams covering Corti’s core features, consultation workflows, and guidance on the responsible and safe use of AI in clinical settings.
3. Template setup – Custom consultation templates and output structures configured by Crescendo to match organisational requirements.
4. Follow-up support – Post-training check-ins to answer questions, resolve early issues and ensure users feel confident using Corti.
5. Responsive support – Direct access to Crescendo’s helpdesk for troubleshooting, guidance and ongoing assistance, with escalation to Corti for issues requiring vendor input.
Users also have access to online user documentation and knowledge articles via the Corti Help Center, which explain how to use Corti Assistant and its features. In-product guidance and prompts help clinicians begin sessions and generate documentation with minimal setup. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- At the end of the contract, users can extract their data through agreed export processes.
- End-of-contract process
- At the end of the contract, access to Corti Assistant is ended in accordance with the agreed contractual terms. Any customer data is handled in line with the contract, applicable data protection legislation, and Corti’s data handling policies. Where required, Corti works with customers during an agreed offboarding period to support an orderly close of the service, including data handling activities as contractually defined. The contract price includes access to the Corti Assistant service, its core AI-powered clinical documentation functionality, secure cloud hosting, routine maintenance, updates, and standard support as specified in the agreement. It also includes access to user documentation and help resources. Additional costs may apply for services that fall outside the standard contract scope. These can include enhanced or premium support levels, faster response times, dedicated technical account management or cloud support engineering, bespoke system integrations, customised onboarding or training services, and any additional data handling or offboarding support not covered by the base contract. All included services and any optional additional costs are clearly defined and agreed as part of the contractual arrangement to ensure transparency for buyers.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Corti Assistant provides the same core functionality on both mobile and desktop, including real-time transcription and clinical documentation. The desktop service offers a larger interface suited for detailed review, editing, and multitasking in clinical workstations. The mobile service is optimised for portability, touch interaction, and on-the-go use, leveraging built-in device microphones and notifications. Mobile access supports flexible working, while desktop access is typically used for extended documentation and system integration.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Corti provides a web-based support service interface through its online Help Center. Users can access support articles, submit requests, and communicate with Corti’s support team via live chat and messaging. The interface supports issue reporting, ticket tracking, and follow-up communication within a single web environment. In-application messaging is also available, allowing users to contact support directly from within the Corti Assistant product. This ensures users can access help, submit support requests, and receive updates through accessible, browser-based interfaces.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Accessibility considerations and improvements are addressed as part of ongoing product development and user feedback, with issues identified through support channels used to inform future enhancements.
- API
- Yes
- What users can and can't do using the API
- Service setup via the API: Users can authenticate using OAuth 2.0 client credentials, establish tenant context, and initialise Corti Assistant sessions through the Embedded Assistant API. This allows organisations to embed Corti Assistant directly into their applications and manage user access securely. Making changes via the API: Through the API, users can create and manage sessions, start and stop recordings, receive real-time transcription events, access transcripts and generated documents, and adjust configuration options such as enabled features, language, and interface behaviour in embedded deployments.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise Corti Assistant to align with their clinical workflows and organisational requirements. Corti Assistant allows customisation of documentation outputs, including note structures and templates such as SOAP notes, summaries, and referral letters. Language settings and selected feature behaviour can be adjusted. For embedded or integrated deployments, aspects of session behaviour, enabled features, and interface configuration can also be customised. How users can customise: Customisation is carried out through the Corti Assistant user interface, where clinicians can review, edit, and tailor generated documentation. Additional configuration is available through Corti’s APIs for organisations embedding the service into their own systems, enabling programmatic control of session setup and feature configuration. Who can customise: Clinicians can customise documentation during their own sessions. Organisational administrators and authorised technical teams can manage broader configuration, integrations, and API-based settings, subject to role-based access controls and contractual agreements.
How users can customise:
Customisations are completed by the Crescendo support team. Organisations contact support with their requirements, and the configuration is applied securely on their behalf.
Who can customise:
Customisation requests can be raised by any user, but changes are normally approved and authorised by managerial or designated administrative staff, depending on the organisation’s internal permissions.
Scaling
- Independence of resources
- Corti is hosted on Microsoft Azure, which provides automatic scaling and resource isolation. Corti operates a cloud-based, multi-tenant service with logical tenant isolation to separate customer data and processing. The platform uses scalable cloud infrastructure to manage demand and maintain consistent performance across users. Continuous system monitoring and capacity management help ensure that one customer’s usage does not adversely impact others, in line with Corti’s service availability commitments.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Crescendo provides detailed usage metrics for Corti Assistant. Organisations can view the number of sessions conducted, broken down by department, team or individual users. Metrics include session volumes, feature usage, duration of interactions and adoption trends over time. These insights help organisations understand utilisation, monitor onboarding progress and identify training needs.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Corti
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export their data from Corti Assistant through contractually agreed mechanisms. Data such as clinical notes, summaries, and transcripts can be accessed and exported via the Corti application where functionality is available, or through API-based access for integrated or embedded deployments. For full or bulk exports, data export is coordinated with Corti’s support team in line with contractual terms, security requirements, and applicable data protection legislation. The specific export formats, scope, and process are defined by the contract and customer configuration rather than a single self-service export function.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Corti guarantees a minimum service availability of 99% uptime, as described in its public Support Commitments: Corti’s Support Commitments. Availability is measured at the service level and is designed to support continuous access to the Corti API for production healthcare workloads. If the guaranteed availability level is not met, remedies are handled in accordance with the Service Level Agreement and contractual terms agreed with the customer. Any service credits, refunds, or other remedies are defined in the contract or order form rather than in the public documentation. Planned maintenance and availability exclusions are also defined contractually to ensure transparency for buyers.
- Approach to resilience
- Corti Assistant is designed to be resilient and reliable through the use of cloud-native architecture and fully managed infrastructure. The service operates on scalable cloud platforms that are engineered to minimise single points of failure and maintain availability during fluctuations in demand. Core components are designed with redundancy, and capacity is managed dynamically to support continuous service delivery. Corti continuously monitors service health, performance, and availability using automated monitoring and alerting. This enables early detection of issues and rapid response to incidents. Defined incident management and escalation processes ensure that critical issues are prioritised and addressed promptly to reduce service impact. Customer data and processing are logically isolated by tenant, helping protect workloads and prevent cross-customer impact during operational issues. Regular maintenance and updates are performed in a controlled manner to minimise disruption. Datacentre resilience is provided by Corti’s third-party cloud hosting providers, which operate multiple geographically distributed data centres with built-in redundancy for power, networking, and physical security. These providers comply with recognised industry standards for security and resilience. Further details on datacentre locations, disaster recovery arrangements, and resilience measures are available on request and governed by contractual and security requirements.
- Outage reporting
- Customers are informed of significant incidents and outages via email and direct support communications, in line with Corti’s support commitments. Incident updates and resolution communications are coordinated by Corti’s support team, with escalation handled according to severity and contractual support arrangements.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Corti Assistant does not currently provide a management interface. Access to support channels, including our ticketing system and remote support tools, is restricted to authorised Crescendo staff operating under least-privilege permissions. Identity is verified before accessing or discussing customer data, and all support access is logged. These controls ensure that only appropriate personnel can access or interact with customer information.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Other
- Description of management access authentication
- Corti Assistant has no management interface. Support access is restricted to authorised Crescendo staff, and identity is verified where required through email confirmation before discussing or accessing customer information. All support actions are logged for security.
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Corti operates a risk-based information security management framework across governance, operations and product development. Corti maintains documented policies and procedures covering, at a minimum: Information Security Policy – setting overall security objectives, principles and responsibilities. Access Control Policy – least-privilege access, role-based access controls and authentication requirements. Data Protection and Privacy Policy – aligned with GDPR and healthcare data protection obligations. Secure Development Policy – secure-by-design principles applied throughout the software lifecycle. Incident Management and Breach Response Policy – detection, escalation, investigation and notification. Supplier and Third-Party Security Policy – proportionate due diligence and contractual security requirements. Acceptable Use Policy – governing staff use of systems, devices and information assets. Policies are reviewed periodically and updated in response to changes in risk, technology or regulatory requirements. Processes and implementation Information security is operationalised through: Secure software development practices, including peer review, testing and controlled deployment. Access management processes, ensuring only authorised personnel have access to systems and data. Monitoring and logging of systems to support security oversight and incident detection. Incident response procedures, including defined escalation paths and post-incident review. Supplier risk management, leveraging enterprise-grade cloud providers and contractual safeguards. Business continuity and resilience measures, appropriate to Corti’s delivery model
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Corti manages configuration and change through controlled processes aligned with a secure development lifecycle. Service components are versioned and tracked throughout their lifecycle using internal tooling. All changes are assessed for security, privacy, and operational impact prior to release, including review and testing. These practices are described in Corti’s Data Processing Agreement, which references secure development, change management, and risk controls: Data Processing Agreement. Detailed deployment and change procedures are not publicly documented but are available on request, subject to contractual and security requirements.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Corti manages vulnerabilities through an internal security programme aligned with a secure development lifecycle. Potential threats are identified using automated security tooling, monitoring, testing, and risk assessment. Vulnerabilities are prioritised based on severity and impact, with critical issues addressed as a priority and patches deployed as quickly as possible following testing. Threat intelligence is sourced from cloud provider security advisories, vulnerability databases, dependency alerts, and penetration testing results.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Corti operates protective monitoring through continuous logging, monitoring, and alerting as part of its operational security programme. Potential compromises are identified by monitoring system activity, performance metrics, and security events for anomalous behaviour. Automated alerts notify relevant teams for investigation. When a potential compromise is detected, incidents are triaged, contained, and remediated according to severity, with escalation to specialist teams where required. Critical incidents are addressed immediately, while non-critical issues follow defined response processes. These practices align with Corti’s secure development lifecycle and operational controls, as described in its Data Processing Agreement: Data Processing Agreement.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We have a defined incident management process for handling security/privacy events and common incidents. Users can report incidents through our chat widget, ticket portal, or by email. Each report includes a clear description, steps to reproduce, and severity. Incidents are investigated, prioritised, and tracked, with coordinated responses and root cause analysis. Incident reports are documented, and summaries are available upon request.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Crescendo provides a 30-day free trial of Corti Assistant, including full setup, onboarding, remote user training and basic workflow customisations. All core features are included.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5.0%
- Between £250,000 and £500,000
- 5.0%
- Between £500,001 and £1,000,000
- 10.0%
- Between £1,000,001 and £2,500,000
- 10.0%
- Between £2,500,001 and £5,000,000
- 20.0%
- Over £5,000,001
- 20.0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E14bfe8a-e51a-4494-a377-8c82e6e01d49
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-