Security & compliance

Security and privacy are engineered into the platform: independently certified, audited every year, and hosted on infrastructure secured for health data.

View certifications
Certifications
ISO 27001
ISO 13485
HDS
Compliance
HIPAA
GDPR
Certificates verified by accredited third-party auditors.

Certifications & attestations

Our security and quality management systems are certified against international standards and audited annually by independent bodies.
Certificates are available for download.

ISO/IEC 27001Certified
ISO/IEC 27001

Information security management system covering the development, hosting, and operation of the DentalMonitoring platform.

Accredited certification body
Download certificate ↓
HDS (Hébergeur de Données de Santé)Certified
HDS (Hébergeur de Données de Santé)

French health-data hosting certification, required to store and process personal health data for patients in France.

Health data hosted on HDS-certified AWS infrastructure
Download certificate ↓
ISO 13485Certified
ISO 13485

Quality management system for medical devices, governing how our software is designed, validated, released, and monitored.

Medical device QMS
Download certificate ↓
HIPAACompliant
HIPAA

Administrative, technical, and physical safeguards for protected health information of patients in the United States.
We sign BAAs with covered entities.

Self-assessed compliance. BAA available on request
Request BAA ↓
GDPRCompliant
GDPR

Full compliance with the EU General Data Protection Regulation, including data processing agreements, records of processing, and patient rights handling.

Self-assessed compliance. DPA available on request
Request DPA ↓
Continuous verification

Security never stands still

Certification is the baseline, not the finish line. We continuously test, monitor, and improve the platform: independent specialists probe it, vulnerabilities are tracked to resolution, and clear processes govern how we respond when something is found or reported.

Annual CREST-certified penetration test
Independent, accredited specialists test the web platform, APIs, and mobile apps every year. Findings are remediated on tracked timelines.
Continuous vulnerability management
Dependencies and infrastructure are scanned continuously; critical patches are deployed on priority timelines.
Incident response
A dedicated Incident Response Team qualifies and investigates security events. Personal data breaches are notified to supervisory authorities and affected clients within the timelines required by applicable law in each jurisdiction.
Coordinated vulnerability disclosure
Security researchers are invited to report vulnerabilities in good faith under our published Coordinated Vulnerability Disclosure Policy. Reporting channels are listed in our security.txt.

Questions to our security team?

Reach out to our security team directly if you have any security-related questions

Found a vulnerability? Report it in good faith following our Coordinated Vulnerability Disclosure Policy
Reporting channels are published in our security.txt