Ambient Voice Technology
TORTUS is the first UKCA Class IIa Medical Device Ambient Voice Technology for clinicians - capturing consultation audio and creating instant drafts of summaries and letters. Integrated into Epic and other EHRs, TORTUS saves time, improves documentation quality, and improves clinician and patient experience.
Features
- Speech to text AI
- Instant medical note generation
- Customisation of templates
- Instant referral letter generation
- Instant patient communication content generation
- Quick, accurate dictation
- Proprietary living safety standard to protects all outputs
- EPR intergrations, native & via SDK
- Near real-time reporting
Benefits
- Reduced administrative burden
- Increased clinician time
- Decreased clinician cognitive load
- Improved clinician experience
- Double the quality of documentation
- Increased cost capture
- Increased consistency of documentation for audit
- Improved coding
- Better patient experience
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 4 4 3 0 0 7 6 6 8 3 3 8 5 6
Contact
TORTUS AI LTD
Dom Pimenta
Telephone: 07886643301
Email: dom@tortus.ai
About the service
- Service categories
-
Application Development and Deployment
AI platforms
AI software services
- Conversational AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- N/A
- System requirements
-
- MacOS11 or later
- Windows 10 OS or later
User support
- Email or online ticketing support
- Yes
- Support response times
- Based on P score and service offering.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
If implementation support is needed, we will provide this. This is determined on a case by case basis.
A support team is in place, available 9am-6pm, Monday to Friday and email 24 hours a day.
A point of contact for support will be appointed for each account. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- We have a mixture of on-site training and user documentation to onboard users, with a named account manager and helpdesk support available.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- The user can request for their data to extracted via email.
- End-of-contract process
- The user will cease ability to use TORTUS at the end of the contract, they will have the option to extend their contract. All services are included in the price of the contract for individual users. For enterprise users the licence includes access to the software and a capped limitation on total number of audio hours used for the organisation, additional hours are paid for and rolled into the next contract price, or payable upon termination of the contract if non renewal.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- TORTUS is a reactive web apps. There are no visible, feature, or performance differences between the mobile and desktop services.
- Service interface
- Yes
- User support accessibility
- EN 301 549
- Description of service interface
- The interface is a browser-based cloud platforms, where the user can start recordings and start other actions.
- Accessibility standards
- EN 301 549
- Accessibility testing
- N/A. EN 301 549 for User Support Documentation is in place.
- API
- No
- Customisation available
- Yes
- Description of customisation
- Users can customise the clinical note templates used to produce the consultation summary.
Scaling
- Independence of resources
- For individual contracts, we use several layers of redundancy across services in order to manage load effectively. For enterprise customers, we spin up a dedicated cluster of compute for each large customer to ensure demand is separated.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Number of consultations, hours of consultations, number of clinical letters generates, user login frequency.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Users can request a copy of their data by emailing support@TORTUS.ai.
This will include any information we hold on them, such as their self submitted user profile.
We can also provide their history of consultations on request - timestamps and duration, but not the content of a consultation. - Data export formats
- CSV
- Data import formats
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Our TORTUS SLA is 99.5% uptime. If the service goes below that, the user can request a refund for lost time as discussed with their account manager.
- Approach to resilience
- New deployments are protected by using a blue-green serverless model, with automated tests. Should a new deployment fail, the pod won't be made available. In the event that this does not catch an issue, we have internal monitoring to indicate failures. We can then instantly roll back to a previous healthy version. Load is handled by automatic scaling of our instances, with a load balancer to direct requests.
- Outage reporting
- In the event that our service is down, we will email our users, providing them updates on the service.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- OAuth2 authentication with RBAC based authorisation for admin tools, with limited access to select employees
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
Information security policies and procedures are implemented as part of our ISMS (Information Security Management System) to which we are UKAS accredited ISO 27001:2022 certified. Having this robust ISMS in place ensures we are protecting our digital assets, we are complying with regulations and we are managing operational risks. The ISMS covers all aspects of the business operations and all team members are trained on information security policies and procedures on first onboarding and again with annual refresher sessions. The TORTUS Compliance Team oversee the ISMS and ensure that team members are trained on policies and procedures, retaining training completion records.
Our ISMS is audited both internally and externally on an annual basis to ensure compliance. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Versioned control (git) is used for both infrastructure and application changes. Secondary reviews are required before merging, and another review step before deployment.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Regular external pen tests carried out by 8Fold Governance, with all major issues resolved and deployed, and then a follow-up penetration test conducted.
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- Automatic alerting of incidents from our monitoring tool Datadog and Google Cloud Platform. If data has been breached, we assess the impact, provide a fix, and alert users via email if necessary. We then also work with our Pentest organisation 8Fold Governance to ensure we have correctly patched the breach.
- Incident management type
- Supplier-defined controls
- Incident management approach
- In the event of an incident, once notified we aim to resolve the issue within 3 hours during working hours (9-6pm Mon-Friday) and 6 hours out of those hours. Users may report incidents to the email: support@tortus.ai. Once we have identified and fixed the incident, we run an internal review, identifying corrective actions we can take, and any further correspondence that may need to be conducted with our users.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We are able to offer a one month, full service for free.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 3%
- Over £5,000,001
- 3%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- LRQA Limited
- ISO/IEC 27001 accreditation date
- Monday 25 August 2025
- What the ISO/IEC 27001 doesn’t cover
- No exception.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 50c80f72-4cc0-447c-9521-dfc15f9a131b
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- 6459f048-8ccc-4058-90c6-b8ceff112deb
- Other security certifications
- Yes
- Any other security certifications
- ISO/IEC 27001:2022 certification (UKAS accredited)
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion