Trust & security

Security and data handling

How we approach infrastructure, encryption, access control, and HIPAA-related questions for marketing and pre-contract discussions—not a substitute for a signed BAA or legal counsel.

Overview

Dentalytica AI is built as a modern, cloud-hosted application. We use industry-standard encryption for data in transit, restrict access to production systems, and design for least-privilege operation. Exact controls may evolve as the product and hosting environment mature—ask for the latest detail during your evaluation.

HIPAA and PHI

Dentalytica AI is not a covered entity under HIPAA. Information you submit through this marketing site or a sales discovery call is treated as business contact data, not patient health information. If you later contract for a product environment that processes PHI, data protection expectations—including whether a business associate agreement (BAA) is required—should be documented in your order form or separate agreement. Nothing on this page constitutes legal advice.

Encryption

Traffic between your browser and our services is encrypted using TLS. Stored application data is protected using the safeguards provided by our cloud and database providers, consistent with common SaaS practice.

Access control

Administrative and operational access to production systems is limited to people who need it for their role. Internal administrative areas of the product use authenticated sessions with role checks where applicable.

Backups and availability

We rely on managed database and infrastructure services that offer backup and redundancy options. Specific recovery point and recovery time objectives should be confirmed for your deployment tier during contracting.

Incident response

If we become aware of a security issue that affects customer data, we assess impact, remediate where appropriate, and notify affected customers as required by applicable law or contract. Report security concerns to [email protected].