Dragon Legal Anywhere (DLA) AI-Powered Speech Recognition
Dragon Legal Anywhere (DLA) is an enterprise, mobile, cloud-based speech recognition solution empowering legal professionals to create high-quality documentation all by voice. Organisations can streamline repetitive and manual documentation processes, while saving time and boosting productivity and efficiency for busy legal professionals across work teams and work groups.
Features
- AI-driven legal speech recognition with accuracy up to 99%
- Fast, highly accurate, cloud-based, enterprise-wide speech recognition
- No voice profile training, automatic accent detection, continuous adaptation improvement
- Supports customised vocabulary, auto-texts and voice commands
- Fast, accurate dictation into office productivity applications & web browsers
- Supports enterprise deployments through virtual environments
- Built-in analytics provide usage, adoption dashboards and user metrics
- Nuance Management Centre central user administration
- Installs in minutes on any workstation or laptop
- Speech-related data securely communicated over TLS 1.2
Benefits
- Legal Professionals are more productive with fast, accurate, responsive dictation
- No speech profile training ensures an optimal experience immediately
- AI-powered technology maximises accuracy and productivity
- Custom voice commands automate repetitive tasks and increase efficiencies
- Access to data, analytics, and insights to optimise performance
- Reduced transcription time and costs
- More time to focus on clients and drive your business
- Mobile Smartphone App increases productivity when away from the office
- Secure and easy to install and maintain
- Installable using MSI technologies
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 7 5 2 3 1 5 4 6 7 4 7 5 9 8
Contact
CRESCENDO SYSTEMS LIMITED
John Bendall
Telephone: 01932 789433
Email: admin@crescendosystems.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
- Document
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No constraints other than technical specifications.
- System requirements
-
- 32-bit: Microsoft Windows 10
- 64-bit: Microsoft Windows 10 and Windows 11
- 64-bit: Microsoft Windows Server 2016, 2019 and 2022
- Microsoft .NET Framework 4.7.2 (or higher)
- Minimum processor speed: 1.7 Ghz, Recommended: 2.8 Ghz
- Minimum RAM: 512 MB, Recommended: 2 GB
- Network latency < 50ms
- Web Browser: Microsoft Edge & Google Chrome
- Port Communication: Ports 443
- High quality microphone
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is available Monday to Friday 9am to 5pm, out of hours support available at an additional charge. Response time depends on SLA level. For level I Emergency and level 2 urgent situations Crescendo offers a one-hour response to support calls. For level 3 faults Crescendo will respond within four hours and for level 4 faults response time will be within one business day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 A
- Web chat accessibility testing
- Not as such, however we deal with multiple organisations on a regular basis that have assistive technology users.
- Onsite support
- No
- Support levels
- Crescendo Support Services are included within the (Annual/Monthly) Dragon Legal Anywhere (DLA) Subscription Fee. The DLA solution is supported by Crescendo’s full time technical support team who operate the Customer helpline and support centre in the UK. The technical support team’s normal hours are Monday-Friday, 9am-5pm GMT Crescendo SLA: Crescendo also extends industry-standard 24 x 7 emergency support to its customers. For level 1 Emergency and level 2 urgent situations Crescendo offers a one-hour response to support calls. For level 3 faults Crescendo will respond within four hours and for level 4 faults response time will be within one business day.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- Prior to a customer purchase we provide online or onsite demonstrations to familiarise the organisation with the service features.On receipt of a PO we co-ordinate delivery of the software with the Clients IT team, checking specification and any other relevant factors. In parallel, we will liaise with the project team to ensure that goals are achieved and that workflow is consistent with the organisations expectations. Planning Services include project management activities such as definition and management of project goals; development and tracking of implementation plans; training plans and scheduling; change management; managing and driving resolution of issues log; regular status calls and post training follow up activities; strategic alignment to make sure the project is aligned to the organisational goals. Once the software is delivered we offer both onsite and online training modules, dependent upon the customers requirement (this can also include a Train-the-Trainer course if the client wishes to train internally). We also supply electronic 'Quick Start' training materials at no extra cost.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- When a contract terminates all user data is deleted. There is no requirement to extract the data as this was simply the audio to create the text which is not kept in the system for future reference. The resultant text remains stored in the customer's document management or other system.
- End-of-contract process
- Upon termination of the contract the organisations users no longer have access to the speech recognition software, DPA, (and microphones if bought on subscription) and would not be able to use the software to dictate in to their computer. The contract price includes the access to the software and the updates during the contract period, all of which ceases at the end of the contract.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Customer is provided with electronic and hard copies of the documentation. There is also very helpful support and FAQ's provided on the Crescendo Systems website.
Using the service
- Web browser interface
- No
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- DLA includes Dragon Anywhere Mobile (DAM), a professional grade, cloud based dictation app for busy legal professionals who want to work faster and smarter using their mobile device. Dragon Anywhere Mobile lets you customise words and create boilerplate text or commands to dictate and edit documents of any length by voice – quickly and accurately – directly on your iOS or Android device. Your documents can be shared and custom words and auto-texts synced up with your Dragon desktop, so you can continue your work seamlessly wherever you go.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The interface is a simple, small menu bar (Dragon Tool Bar) which displays a microphone icon to show user whether it is on or off, together with a drop down list of features and help menus. The Dragon tool bar can be moved or hidden.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Dragon Legal Anywhere isn't typically certified as WCAG, but it supports accessibility and helps users meet WCAG/accessibility goals by enabling voice control for systems, letting users dictate, navigate, and code hands-free, which is crucial for users with disabilities or needing workplace adjustments under laws like the Equality Act 2010.
- Accessibility testing
- We provide Dragon Medical One Speech Recognition to a wide variety of users who require assistive technology. Examples of these include Access to Work, DSA schemes and 'Reasonable Adjustments' requests.
- API
- Yes
- What users can and can't do using the API
- The API is designed for IT partners and developers to embed speech recognition and AI capabilities into their own applications.
- API documentation
- No
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
DLA can be customised to suit end users workflow and documentation requirements through the implementation of autotexts and step-by-step commands.
AutoTexts:
Customised voice commands which allows the user to insert frequently used text into their documents. These can also be customised with variable fields which allow the clinician to dictate information into specific fields. Fields can also contain default values and can be amended on a case by case basis.
Step-by-step commands:
Customised macros that can be setup into a users profile. You can start with simple commands to do things like insert text, open a document or program and even combine them into more advanced functions.
AutoTexts and step-by-step commands can be setup and customised by end users and system administrators.
Scaling
- Independence of resources
- This is a highly scaleable solution, housed in a secure UK Microsoft Azure data centre environment, which enables thousands of users from single organisations to be active on the system concurrently.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The customer has access to DLA's built-in administration, analytics and insights, a web-based admin portal that simplifies system management and offers data insights to ensure doctors are using the solution as effectively as possible. DLA feeds data into an analytics portal so the organisation can make more informed decisions. This comprehensive portal provides access to an intuitive dashboard that displays key metrics and trends, like active users, hours of audio and peak usage. Usage details allow you to drill down to user level utilisation statistics to provide a good indicator of individual user efficiency, voice command usage, AutoText usage, etc.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft Nuance
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Not applicable. The textual data generated by the software is created directly into the customers systems/applications so no export is necessary.
- Data export formats
- Other
- Data import formats
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- 24/7 365 days a year. Organisations are refunded based on an hourly compensation relative to the monthly subscription charge.
- Approach to resilience
- Microsoft Azure UK regions (UK South, UK West) with Availability Zones for high availability, redundancy, and disaster recovery.
- Outage reporting
- We developed a real-time Service Status Page to provide more transparency to our end users/IT administrators in the event of a service disruption. The page shows an up-to-the-minute status on the health of our Dragon Medical Cloud services. In the event of a service disruption, administrators and users can go to this page to review the services affected. We encourage users to bookmark the status page URLs: UK: https://status.uk.dragon.com/
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
- Active Directory Authentication
- Access restrictions in management interfaces and support channels
- Via username and password. - Nuance enforces two-factor authentication/jump hosts. When accessing the data centre, all Nuance employees are required to use two-factor authentication. In addition, all production access is via an intermediate “jump host,” which provides an extra level of insulation. – Nuance has deployed Trend Micro anti-virus to proactively protect the Nuance cloud services from virus or malware infection. – Intrusion detection and protection system (IDPS). Nuance leverages Trend Micro’s IDS solution, which examines every packet that is transmitted to the data centre for potential irregularities.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
Nuance (a Microsoft company) operates a "defense-in-depth" security strategy, ensuring Dragon services meet rigorous UK public sector standards.
Technical Controls:
Encryption: Data is secured in transit via HTTPS/TLS 1.2+ (256-bit AES) and at rest using Azure Storage Service Encryption (SSE) and SQL Transparent Data Encryption (TDE).
UK Sovereignty: Cloud services (e.g., Dragon Medical One) are hosted in UK-based Microsoft Azure data centers, ensuring compliance with UK GDPR and Data Protection Act 2018.
Identity Management: Supports Multi-Factor Authentication (MFA) and Single Sign-On (SSO). Administrative access uses secure "jump hosts."
Governance & Compliance:
Certifications: Maintained standards include ISO 27001, ISO 27017, ISO 27018, SOC 2 Type II, and Cyber Essentials Plus.
Healthcare Standards: Fully compliant with the NHS Data Security and Protection Toolkit (DSPT) and DCB0129 accreditation.
Secure Development: Follows a Secure SDLC (Microsoft SDL), including threat modeling and static code analysis.
Operational Assurance:
Vulnerability Management: Weekly automated internal/external scans and annual third-party penetration testing.
Resiliency: Active/active configurations across redundant regions provide 99.9% availability.
Monitoring: 24/7 security operations center (SOC) monitoring with integrated intrusion detection (IDPS). - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Dragon Legal Anywhere follows a well-defined change management process for handling changes within the production environment. Updates are carefully tested before being applied to the data centre. These updates undergo pre-testing in an external environment to ensure compatibility. Additionally, all changes made to the live environment are internally monitored and tracked to ensure any issues are quickly identified and resolved.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Vulnerability scans and penetration tests are performed. Vulnerability scans are done weekly, the results are evaluated, and corrective actions are taken based on risks. Certified third-party penetration tests are performed annually. Microsoft Azure provides denial of service and intrusion detection and performs routine penetration testing. System monitoring is in place and leverages internally developed tools as well as industry standard tools. Alerts generated by these tools are routed to pagers, which are covered 24x7 by Nuance Data Centre Operations staff.
All aspects of the Solution are within the scope of penetration tests. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- System state is monitored 24/7 by our Site Reliability Centre (SRC). SRC monitors MS Azure via a tool called System Centre Operations Manager (SCOM). Microsoft Network Monitoring is utilised to detect changes in network loss, latency, and the availability of devices in Nuance’s network topology; SRC monitors these alerts. Monitoring includes virtual machines and storage. Heartbeat monitoring is used to monitor remote hosts. Microsoft Azure monitoring provides denial of service and intrusion detection and performs routine penetration testing. Alerts generated by tools are automatically routed to mobile phones which are covered 24x7 by Nuance Data Centre Operations staff.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- The Nuance Critical Incident, Privacy and Security Event Response Process specifies the actions to be taken in the event that a new threat is detected, an attack is attempted or a breach is detected. The Critical Incident management process is a cross functional initiative to realize a step change in the strategic planning of critical incidents through standardization and adoption across Global Operations. There are Incident Managers that serve as the single process owner and one consistent status provided to customers. Incident Managers cover 24/7, 365 days a year coverage.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
30-day trial of software for up to 10 users (licenses).
Online training overview and trial support included but individual training is an additional cost. Trialists may need to purchase a microphone - Link to free trial
- https://crescendosystems.co.uk/free-trial/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5.0%
- Between £250,000 and £500,000
- 5.0%
- Between £500,001 and £1,000,000
- 10.0%
- Between £1,000,001 and £2,500,000
- 10.0%
- Between £2,500,001 and £5,000,000
- 20.0%
- Over £5,000,001
- 20.0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E14bfe8a-e51a-4494-a377-8c82e6e01d49
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-