OralTree

Security you don't have to take our word for.

Patient data deserves more than a filtered query. Here's how it's actually protected — and what we don't claim yet.

Isolation

Data isolation, enforced by the database

Your practice data stays your practice data.

Every organization's data is isolated at the database level, using PostgreSQL row-level security — not just filtered in application code, which a bug could bypass. The database role your application runs as is barred from bypassing these policies, enforced at startup, not just at query time.

PostgreSQL row-level security + non-bypassing database role
Access control

What someone can do is checked on every request

What a staff member can do is enforced everywhere, not just hidden in the UI.

Permissions are enforced server-side for every action, matching each staff member's actual role.

Server-side role-based access control

Who you are and what you're allowed to do are never the same check.

Authentication and authorization are handled as two separate systems, so a flaw in one can't silently widen the other.

Separated identity and authorization
Audit

A record of what happened, kept automatically

Every important action leaves a record.

Sensitive actions — patient record access, clinical edits, billing changes — are recorded automatically by the database itself, not left to application code to remember to log.

Database-trigger audit trail
Encryption & infrastructure

Protected in transit and at rest

Identity and document storage are hosted in AWS's Mumbai (ap-south-1) region.

Encrypted in transit, always.

Every connection to the platform is encrypted over TLS, with certificates that renew automatically — never a plain HTTP fallback.

TLS via automatically-renewing certificates

Documents are never publicly reachable.

Uploaded documents and images live in private object storage with no public access configured. Every read or write goes through a short-lived, single-use link your session requests — never a public URL.

Private object storage, presigned-URL access only
Compliance posture

What we claim, and what we don't

We don't claim HIPAA, SOC 2, or ISO 27001 certification. None of them apply cleanly to an India-market dental platform, and HIPAA in particular has no certifying body — any vendor claiming to be "HIPAA certified" is already overstating it. We'd rather tell you exactly what's built, above, than borrow a label that doesn't mean what it sounds like.

For India's Digital Personal Data Protection Act (DPDP), 2023: your practice is the Data Fiduciary responsible for patient consent and data-subject requests. OralTree acts as your Data Processor — built with the isolation, access-control, and audit controls above specifically to support that responsibility, not to take it over.