Corti

Denmark · owned by Independent (Denmark) · corti.ai · 21 vendors

Corti is an AI platform for healthcare developers, providing clinical-grade APIs for speech-to-text transcription, medical coding (ICD-10 & CPT), and clinical documentation. The company's Symphony model is purpose-built for clinical language, trained on real patient interactions and validated against real outcomes. Corti serves over 100 million patients annually and is HIPAA, GDPR, SOC 2, and ISO 27001 compliant.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 21 sub-vendors.

Insights

Last updated 2026-09-13 · revision 2

21 direct vendors, 296 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Corti exhibits very high migration readiness, primarily driven by its highly modern and cloud-native technology stack. The use of Microsoft Azure, Kubernetes, Envoy Gateway, and modern programming languages (Python, TypeScript, Go, C#) indicates an architecture that is containerized, microservices-oriented, and highly portable. This foundation significantly reduces the technical complexity and effort typically associated with large-scale migrations. Their existing infrastructure is designed for HIPAA and GDPR compliance, which means they already possess the necessary controls and processes to meet stringent regulatory requirements during and after a migration. The 'Sovereign Cloud' product, offering EU or US data hosting with no cross-border data transfer, demonstrates their capability to address strict data residency requirements, which is a critical factor in many migrations. While the 'Vendor Lock-in Risk' is unknown and the number of vendors for 17 services is ambiguous, the adoption of open-source technologies like Kubernetes and a multi-cloud-friendly approach (Azure) suggests a degree of flexibility. The main challenge in assessing migration readiness fully is the absence of financial data (revenue concentration, growth history), which would provide insight into their capacity to fund a significant migration effort.

Compliance

16 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Compliant

Corti explicitly lists ISO 27001 certification on its homepage and safety page. ISO 27001 is a formal, third-party audited certification (unlike self-declared frameworks), meaning Corti has undergone an independent audit by an accredited certification body. This is one of the strongest indicators of information security maturity. The company also lists related standards ISO 27017 (cloud security) and ISO 27018 (cloud privacy), indicating a comprehensive ISO 27000-series compliance program. Risk is Low because ISO 27001 certification requires rigorous third-party assessment and ongoing surveillance audits.

Evidence: https://corti.ai/safety, https://corti.ai, https://app.drata.com/trust/9cc6d701-0c38-11ee-865f-029d78a187d9, https://corti.ai/sovereign-cloud

GDPR (source) — Compliant

Corti is headquartered in Denmark (EU), making GDPR universally applicable. However, the company explicitly lists GDPR compliance on its safety page, operates a public Trust Center (via Drata), implements privacy-by-design architecture, enforces data minimization by default, offers EU-only data hosting options with no cross-border transfer, maintains transparent data deletion and retention practices, and uses trusted subprocessors meeting rigorous privacy standards. The combination of proactive compliance posture, published privacy policy, and sovereign cloud architecture significantly reduces residual risk. Risk is rated Low because Corti has demonstrably embedded GDPR controls into its core product and infrastructure rather than treating it as an afterthought.

Evidence: https://corti.ai/safety, https://corti.ai/legal/privacy-policy, https://app.drata.com/trust/9cc6d701-0c38-11ee-865f-029d78a187d9, https://corti.ai/sovereign-cloud, https://corti.ai

NIS2 (source) — Compliant

Corti explicitly lists NIS2 compliance on its homepage and safety page, indicating active compliance posture. As a Danish-headquartered healthcare AI platform processing 1M+ interactions weekly and serving NHS, hospital networks, and emergency services across Europe, Corti almost certainly qualifies as an Important or Essential Entity under NIS2 (health sector). The company's proactive display of NIS2 compliance, combined with its Drata-backed continuous monitoring, ISO 27001 certification, and robust security infrastructure (FIPS-compliant encryption, geo-distributed redundancy, incident response plans, penetration testing), substantially reduces residual risk. Risk is Low because Corti has publicly committed to NIS2 compliance and has the technical controls to support it.

Evidence: https://corti.ai/safety, https://corti.ai, https://app.drata.com/trust/9cc6d701-0c38-11ee-865f-029d78a187d9, https://corti.ai/sovereign-cloud

Financials

Three-year financials

Financial Resilience Score: 6/10

Corti is a well-funded, growth-stage Danish healthcare AI company backed by top-tier venture investors including Prosus Ventures, Atomico, and EIFO. The November 2022 Series B of approximately USD 60 million, following a USD 27 million Series A in 2020 led by EQT Ventures, provides multi-year cash runway to support continued R&D and go-to-market investment. The company has built strong strategic assets including marquee customers (NHS, Microsoft, Dedalus, Ramsay Santé), broad regulatory certifications (HIPAA, GDPR, ISO 13485, ISO 27001, ISO 42001, SOC 2, EU AI Act readiness, NHS DTAC/DSPT, FedRAMP, CE marking), and a diversified product suite spanning speech-to-text, medical coding, text generation, and agentic frameworks. However, as a typical Series B SaaS company, Corti is very likely still loss-making with substantial cash burn, meaning ongoing financial health depends on continued VC funding or reaching profitability. The company faces intense competition from Microsoft/Nuance DAX, Abridge, Ambience Healthcare, Suki, Nabla, and DeepScribe, as well as commoditization risk from foundational-model providers. Customer concentration in large national health systems introduces procurement cycle and churn risks, while FX exposure (DKK reporting vs. USD/GBP/EUR revenue) and evolving EU AI Act / FDA / MDR compliance costs add further uncertainty. Detailed financials from the Danish CVR filings were not accessible in this session, limiting quantitative assessment.

Key strengths: USD ~60M Series B (Nov 2022) led by Prosus Ventures, Atomico, EIFO, USD ~27M Series A (2020) led by EQT Ventures, Marquee customers: NHS, Microsoft, Dedalus, Ramsay Santé, Region Hovedstaden, Broad regulatory/compliance moat (HIPAA, GDPR, ISO 13485/27001/42001, SOC 2, FedRAMP, CE), Diversified product suite (speech-to-text, coding, generation, agentic framework), Consumption-based credit pricing scales with usage, Over 1 million interactions per week processed

Risk factors: Likely still loss-making with typical growth-stage cash burn, Dependence on continued VC funding for runway, Intense competition from Microsoft/Nuance DAX, Abridge, Ambience, Suki, Nabla, DeepScribe, Commoditization risk from foundational-model providers offering medical ASR, Customer concentration in slow-moving national health systems, EU AI Act high-risk classification for clinical AI adds compliance cost, FX exposure: DKK reporting vs USD/GBP/EUR revenue

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report