Security & compliance

Every practice runs in an isolated tenant with row-level security, encrypted storage and full audit history.

Data protection

  • TLS 1.2+ in transit and AES-256 encryption at rest.
  • Row-level security enforces per-practice isolation at the database layer.
  • Least-privilege service credentials; no patient data in client-side bundles.

Access control

Role-based permissions for owners, dentists, front desk and hygiene staff, invitation-only practice membership, session expiry and optional two-factor authentication.

Auditing

Every automation run, message sent and record change is written to an append-only audit log that owners can export.

HIPAA

We sign business associate agreements on paid plans and restrict subprocessors to those that do the same. Compliance also depends on your own policies, training and consent practices.

Reporting a vulnerability

security@dentalflow.shop — we acknowledge reports within one business day.