Ambient Scribes
S

S10.AI

S10.AI sells a multi product clinical automation suite around CRUSH, its ambient scribe, alongside BRAVO, a front office agent handling phone triage, scheduling, refills and insurance verification, and SHINE, which audits notes for quality, compliance and medico legal risk while flagging missed HCC and CDI revenue. Two things distinguish it. Its integration architecture is server side robotic process automation rather than APIs, which is how it claims compatibility with more than 100 EHRs including legacy and non standard systems that larger vendors do not support, and it says it will build a missing one in roughly two weeks.

And it publishes a flat 99 US dollars per month rate, positioned explicitly as a challenge to enterprise pricing in a category where most competitors publish nothing. It holds ISO 27001 certification and claims HIPAA, PIPEDA and GDPR compliance. Treat its published comparison content with the caution this index applies to any vendor that ranks its own competitors.

AI Health Index verifiedJuly 23, 2026
Compare S10.AI with other vendors
Founded
Headquarters
Website
s10.ai/
Categories
ambient-scribes
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
AA on AI CentralityThe artificial intelligence is the product. Remove the model and there is nothing left to sell.
Vendor Published

The generated artifacts across all modules are model output: the note, the code suggestions, the phone conversation and the chart audit. Worth separating one thing that is often conflated in its marketing: the integration reach comes from robotic process automation, which is scripted automation rather than intelligence, so the breadth claim and the AI claim rest on different technology.

CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.
Vendor Published

Several autonomous surfaces, none with published limits. CRUSH delivers billing ready codes into the record. BRAVO answers every call, books, reschedules and cancels directly in the EHR, handles refill requests and prior authorisation follow ups, and triages symptoms with what the vendor calls clinical guardrails without describing what they are. SHINE flags where revenue is being left on the table.

No confidence threshold, escalation path, abstention behaviour or accuracy figure is published for any of them, and symptom triage by an autonomous phone agent is the same undisclosed escalation problem this index graded C for Hello Patient in the voice lane.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

Mixed. The integration architecture is disclosed unusually specifically, as server side robotic process automation rather than vague talk of connectivity, and that is a genuine technical statement a buyer can evaluate. Against that, the performance claims are unsubstantiated and internally inconsistent: 99 percent transcription accuracy with no methodology or reference standard, 95 percent of documentation automated, 75 percent faster charting, and language coverage stated as 16 or more in some materials and 60 or more in others. No model card, named models or evaluation protocol was located.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

Nothing identifies any party in the chain. No model or model family is named, no foundation model provider or version is disclosed, no hosting or cloud arrangement is published for the product, and no sub processor list was located in two passes.

Compliance is claimed against the United States health privacy regime, Canadian federal privacy law and European data protection law, and a security management certification is held, which together suggest processing across several jurisdictions without stating which content goes where or who holds it.

That combination is worth noticing rather than glossing: a vendor asserting three regimes at once is describing a multi jurisdiction footprint, and the absence of any residency statement or party list makes that footprint unmappable from outside. The integration architecture adds a second layer to the question.

Robotic process automation operates inside the record system on the customer's behalf, so the vendor's software holds working access to the record environment itself rather than only receiving content pushed to it, and the scope of what it can reach there is not published. Ask for a sub processor list, a residency statement per jurisdiction, and the precise scope of record access the automation holds.

CC on Clinical and Operational EvidenceNamed customers, or vendor reported percentages with no method, denominator or reference standard. Scale of use is recorded here and is not treated as evidence of benefit.
Vendor Published

No peer reviewed study, controlled evaluation, third party performance rating or named health system outcome data located. Claims are vendor generated and supported by physician testimonials. A specific caution applies to sourcing here: much of the comparative material about this vendor appearing in search results is published by S10.AI itself in the form of competitor rankings and pricing comparisons, which is the self interested source pattern this index already flags for Mentalyc and Ordr. Use it for the vendor's own product claims and nothing else.

BB on AI Safety and PHI StewardshipCategorical commitments are published, such as no training on customer data, without the retention schedule or the safety engineering behind them.
Vendor Published

ISO 27001 certification and compliance claims across HIPAA, PIPEDA and GDPR give this more substance than most at this price point. One architectural consequence deserves specific diligence rather than assumption: robotic process automation drives the EHR through its interface, which generally means the system authenticates and acts within the record environment on the clinician's behalf.

Establish whose credentials it uses, how they are stored, and how its actions appear in the EHR audit log, because a bot operating under a named user's identity makes access logs harder to interpret. No retention schedule or training use statement was located.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Vendor Published

Claims compliance across three regimes, HIPAA, PIPEDA and GDPR, which is broader regulatory coverage than most vendors at this price point attempt. Specific business associate agreement terms are not published for inspection before contracting.

BB on Security Certifications and Trust CenterA recognised certification is named in the vendor own material without the artefact, or with a scope or renewal question the buyer has to raise. A certification has a scope and a clock, and both are part of this grade.
Vendor Published

ISO 27001 certification is named, which is a real external audit standard rather than a marketing phrase and puts this ahead of most of the small and mid market vendors in this category. Held at B rather than A because no certification date, scope statement or certificate reference was located, and no SOC 2 Type II report was found, which is the attestation most United States health system security reviews will actually ask for.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

No clearance claimed and none required for the documentation product. The flag raised in the earlier assessment about autonomous phone triage is confirmed, and the platform around the scribe has grown well past the point where a documentation framing covers it.

BRAVO is described as a fully autonomous receptionist handling round the clock phone triage with patients, alongside insurance verification and scheduling. Triage is a clinical function and the party on the other end of the call is a patient. The reasoning that keeps clinical decision support outside device regulation rests on a professional being able to review the basis of an output, and a patient is not a professional. Where an autonomous system performs triage directly with patients, no professional is in the loop at the moment the judgement is made.

SHINE is the second and less obvious boundary. It is described as auditing every note for quality, compliance and medical legal risk, back checking clinical decisions against current guidelines and literature, and flagging missed revenue including hierarchical condition category capture and documentation improvement. Back checking a clinician's decisions against the literature is decision support. Doing it in the same pass that identifies missed revenue means one system evaluates the clinical adequacy and the reimbursement value of the same artefact. Where a vendor markets revenue uplift alongside clinical quality, the question is whether the clinical output and the revenue output are the same object. Here they plainly are.

The scribe itself also produces billing ready codes, and the platform documents prescription orders.

Markets are wider than United States only. The vendor claims alignment with the Canadian and European regimes and supports a large language set, so establish whether it sells into the United Kingdom or European Union. Ambient documentation is treated as software as a medical device in those markets, and an autonomous patient triage agent would classify well above a scribe.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

Two governance relevant designs, no governance disclosure. SHINE explicitly audits notes to flag missed HCC and CDI revenue, which carries the same coding gradient this index graded down for Charta Health and Solventum, though framed as compliance audit rather than revenue optimisation and therefore milder than MarianaAI. BRAVO performs symptom triage under undefined clinical guardrails. Against both, no fairness statement, subgroup analysis or accent and dialect performance disclosure was located, despite a marketed language range in the dozens.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Vendor Published

Two passes located no terms, warranty, indemnity or remediation commitment, and the published performance claims are unsubstantiated and internally inconsistent, with 99 percent transcription accuracy given without methodology or reference standard, 95 percent of documentation automated, 75 percent faster charting, and language coverage stated as 16 or more in some materials and 60 or more in others.

Inconsistent numbers on a vendor's own pages are a poor basis for any representation a buyer might rely on. The distinctive finding here is architectural and it works directly against recourse, which is why it decides the grade rather than merely colouring it. The integration is driven by robotic process automation operating the record system through its interface, which generally means the software authenticates and acts within the record environment on a clinician's behalf.

Where an automated agent acts under a named person's identity, the audit log stops being a reliable record of who did what. If a wrong entry is later disputed, the evidence that would allocate responsibility between the clinician and the software has been degraded by the design itself, and that is a materially worse position than a simple absence of published commitments.

It is the same class of problem this index has recorded where a closed architecture removes the evidentiary basis for a claim. Establish whose credentials the automation uses, how they are stored, and whether its actions are separately identifiable in the record audit trail before deployment rather than after an incident.

Integration and Deployment
BB on EHR and Interoperability DepthNamed systems with read access or one directional writing, or standards support with named deployments behind it.
Vendor Published

Broad reach achieved by a structurally different route, and the difference matters more than the number. Rather than building API integrations, S10.AI uses server side robotic process automation to operate the record system through its own interface, which is why it can claim more than 100 EHRs including legacy and non standard platforms such as Practice Fusion and OpenEMR that larger vendors decline to support, and why it can add an unsupported system in roughly two weeks.

For a solo or small practice on an obscure EHR this is genuinely the widest door in the category. But RPA is not equivalent to native integration: it depends on the interface staying where it was, is more brittle across vendor updates, and reads and writes as a user rather than through a sanctioned data channel. Graded B on reach with that architecture stated plainly rather than penalised.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

This vendor answers more of this axis than most in the category, and what it answers is architecturally unusual, so it needs reading carefully rather than crediting at face value.

The stated position is that server side robotic process automation processes data directly within the clinician's existing environment, that sensitive audio is not permanently stored on external servers beyond the time required for processing, and that data is erased automatically once the chart is complete.

Two things follow. The phrase beyond the time required for processing concedes that encounter audio does leave the practice environment, so the data sovereignty framing describes where data comes to rest rather than where it travels. The question this index asks first of any ambient scribe, whether inference runs on a third party model service and what that provider retains, is not answered. Ask which providers process the audio and the transcript, and under what retention terms.

The robotic process automation approach is the second point and it deserves diligence of its own, because it is a materially different integration posture from an application interface. The system is described as logging into the record system and navigating charts as a human staff member would, offered as a universal layer over any electronic record. Actions therefore reach the chart through the user interface rather than through a permissioned interface. Establish whose credentials the automation uses, how its actions appear in the record system's audit log, and whether the permission model that constrains a human user constrains the automation in the same way.

Nothing published names a hosting region, offers a residency option, or lists subprocessors. ISO 27001 certification is claimed elsewhere in the vendor's material, while SOC 2 is described as readiness rather than as an attestation. Readiness is not certification.

Commercial
AA on Commercial TransparencyPublished tiers with figures, a stated unit of charge, and a route to start without a sales conversation.
Vendor Published

Publishes a flat rate prominently and builds its market positioning on it: 99 US dollars per provider per month, with no enterprise gate and no quote required, explicitly aimed at clinicians priced out of enterprise contracts. In a category where most vendors publish nothing and buyers cannot compare quotes, a public flat rate is the strongest form of commercial transparency and it is doing competitive work rather than sitting in a footnote. One thing to confirm at contracting, because the vendor markets five products on one contract: exactly which modules the flat rate includes and which are additional.

BB on Setting and Specialty CoverageCoverage is named with validation behind part of it.
Vendor Published

Broad in claim and thin in enumeration. Positioned across any specialty with specialty specific templates, covering in person, telehealth and chat encounters, and sold from solo practitioners through to enterprises, with chronic care and remote monitoring billing capture included. Language coverage is claimed but stated inconsistently across the vendor's own materials, which is exactly the kind of detail a multi language buyer needs settled before contracting.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
$99 per provider per month, published flat rate
$99 baseline
Flat per provider per month, published publicly with no enterprise quote gate. Multi product bundling available on one contract. Claims HIPAA, PIPEDA and GDPR compliance. BAA terms not published. None published. Vendor positions setup as requiring no EHR integration project, since the RPA layer drives the existing system rather than connecting to it. Vendor Published

One of the few vendors in this category whose price is a public fact rather than a negotiation, and the flat rate is the product strategy rather than a detail. Against enterprise ambient scribes quoted in the hundreds per provider per month, 99 dollars is a different market position, not a discount.

Two things to settle at contracting: which of the five marketed products the flat rate actually covers, since CRUSH, BRAVO and SHINE are described both separately and as a bundle, and whether the robotic process automation integration for a non standard EHR carries any build cost, given the vendor offers to construct missing integrations in around two weeks.