Security you don't have to take our word for.
Patient data deserves more than a filtered query. Here's how it's actually protected — and what we don't claim yet.
Data isolation, enforced by the database
Your practice data stays your practice data.
Every organization's data is isolated at the database level, using PostgreSQL row-level security — not just filtered in application code, which a bug could bypass. The database role your application runs as is barred from bypassing these policies, enforced at startup, not just at query time.
What someone can do is checked on every request
What a staff member can do is enforced everywhere, not just hidden in the UI.
Permissions are enforced server-side for every action, matching each staff member's actual role.
Who you are and what you're allowed to do are never the same check.
Authentication and authorization are handled as two separate systems, so a flaw in one can't silently widen the other.
A record of what happened, kept automatically
Every important action leaves a record.
Sensitive actions — patient record access, clinical edits, billing changes — are recorded automatically by the database itself, not left to application code to remember to log.
Protected in transit and at rest
Identity and document storage are hosted in AWS's Mumbai (ap-south-1) region.
Encrypted in transit, always.
Every connection to the platform is encrypted over TLS, with certificates that renew automatically — never a plain HTTP fallback.
Documents are never publicly reachable.
Uploaded documents and images live in private object storage with no public access configured. Every read or write goes through a short-lived, single-use link your session requests — never a public URL.
What we claim, and what we don't
We don't claim HIPAA, SOC 2, or ISO 27001 certification. None of them apply cleanly to an India-market dental platform, and HIPAA in particular has no certifying body — any vendor claiming to be "HIPAA certified" is already overstating it. We'd rather tell you exactly what's built, above, than borrow a label that doesn't mean what it sounds like.
For India's Digital Personal Data Protection Act (DPDP), 2023: your practice is the Data Fiduciary responsible for patient consent and data-subject requests. OralTree acts as your Data Processor — built with the isolation, access-control, and audit controls above specifically to support that responsibility, not to take it over.