Odontia

DATA & SECURITY

Your patients’ data is sacred

We handle patients’ medical data, so security is not a feature — it is the foundation. What follows is implemented, not promised.

You will not find certification logos on this page, nor uptime percentages. You will find exactly what we do and how it is checked — because those are the only things you can verify before trusting us with your patients.

Per-clinic isolation, enforced by the database

Isolation does not rest on the application behaving well: it is enforced inside the database itself, by a separate, non-privileged role that has no right to bypass the fence.

If that fence were ever missing, the system refuses to start. And on every build an isolation test suite runs that deliberately tries to break it.

Your browser reaches only the API The Odontia API every request is identified The database role has no right to bypass the fence permitted Your clinic's data Another clinic's data the database itself refuses If that fence were ever missing, the system refuses to start. Each clinic's secrets are stored encrypted and are not sent to the browser.
Per-clinic isolation does not rest on the application behaving well: the database enforces it, one layer further down.

Encryption

Every sensitive secret — provider, telephony and AI keys — is stored encrypted, with a separate key per domain. User passwords are stored only as a cryptographic hash, and secrets are not sent to the browser.

Where the data lives

The system runs with a European provider, in a French region; the encrypted backups are kept in a second European region, in the Netherlands. We are precise rather than convenient about the two places that are not absolute: email leaves from our provider’s European region, but that provider keeps our account metadata outside the EU; and the language-model step may run outside the EU, under processing agreements with no retention and no training. Speech recognition runs in a European region.

A sub-processor register, by name

Who they are, what they see, where they are. You get it before you sign and we notify you before it changes — you do not discover it afterwards.

Access logging

Every access to a patient record is logged. The policy is IDs-only: we record who touched which record, not what it said — and that is enforced by an automated check on every change.

Multi-factor authentication

Security keys and passkeys, an authenticator app, codes by email — with “remember this device for 30 days” so it does not become a burden for the front desk.

3-2-1 backups

Encrypted backups every four hours, plus a second independent copy off the infrastructure that stays unreadable even if the whole server is breached. And — most importantly — a quarterly restore drill: a backup is not trustworthy until it has been tried.

A failure has to be visible

Messages carry delivery status, money reconciles, and monitoring fires when something did not happen — not only when something broke.

No public telephony port

The phone system exposes no port to the internet, and recording of inbound calls starts after the greeting that tells the caller.

Who is who, under the GDPR

You are the controller of your patients’ data; we are the processor and act only on your instructions.

The Article 28 data-processing agreement is signed before the first patient record goes in — not afterwards, and not with a tick on a form.

Deletion and the ten-year duty

The law requires you to keep the clinical record for ten years. Odontia respects that instead of promising something that is not permitted: when you “delete” a patient, the record leaves every screen, list and message immediately, and is deleted for good when the retention duty expires.

When the relationship ends, your clinic’s data is either handed back to you as a full export or deleted — you choose, and the data-processing agreement sets out how. Backups expire on their own cycle.

And the artificial intelligence

It never writes to the record or the calendar on its own: it drafts, and a person confirms with one tap — with every confirmation logged.

Everything it writes is marked as such, on screen and in the data. AI runs with your own key and a monthly cost ceiling in euros.

The audio and transcript of calls stay on our own infrastructure in Europe, with a European speech-recognition provider — not an American speech service. Only the language-model step (Claude Sonnet 5) runs under a no-retention, no-training agreement, and it is named in the sub-processor register.

The data-processing agreement and the named sub-processor register are available on request — and you read them before you say yes.

Join the list