Skip to content
Ayliea — AI Security Assessment & Compliance Consulting

Nabla Copilot

Nabla · Ambient AI medical scribe

Ayliea's assessment: Medium RiskAyliea recommends: ApproveIn Ayliea's curated list

Verified . Risk classification and recommended policy are Ayliea's subjective assessments — not vendor certifications.

Data residency
United States or EU (Google Cloud; region fixed at org creation)
Zero retention available
No
Certifications
SOC 2 Type II, ISO 27001

Why this rating

Among the stronger scribe postures: signs a published BAA, holds SOC 2 Type II and ISO 27001 (with dated reports in its trust center), does not store audio by default, and does not train on identified PHI. Speech-to-text runs on a self-hosted Whisper derivative; the note-generation LLM and its hosting boundary are not publicly named.

Considerations before deploying

  • Confirm the BAA flows down to Azure (used for speech-to-text) and to any note-generation LLM sub-processor
  • Request the current SOC 2 Type II + ISO 27001 reports and the live subprocessor list naming the note-generation LLM
  • Provision the org in the correct US/EU residency region at setup; set the 14-day note retention per your policy
  • A de-identified-data opt-in carve-out exists for model improvement — confirm the de-identification standard

Sources

Want this for every tool on your network?

A scoping call starts an expert assessment that maps your full AI surface — sanctioned and shadow — from the log metadata you share.