Skip to content

Pre-launch · Controlled practice pilots and additional PMS integrations in preparation

Chairside AI

Trust & security

Access should be narrow. Actions should be visible. Authority should stay human.

Chairside is being built for sensitive dental workflows and the scrutiny that comes with them. We limit access to what a workflow requires, preserve review and approval history, and design the system to fail visibly rather than silently.

What we do not claim

Chairside does not currently claim a SOC 2 Type II attestation or any form of HIPAA certification. This page describes our current security program and the controls required for covered production deployments.

Protect the data throughout its use.

Covered production deployments require encryption in transit and at rest, controlled credential and secret management, customer-data isolation, secure backups, and documented retention and deletion rules. Protected data is not routed to any vendor or AI service that lacks the contractual and security posture the workflow requires.

Give people and systems only the access they need.

The production control baseline includes unique user identities, role-based access, least-privilege permissions, minimum-necessary access, prompt revocation, periodic access review, and narrowly scoped service credentials for integrations. Shared credentials and broad, undocumented access are not acceptable substitutes for proper authorization.

Preserve the full decision path.

Trust-sensitive actions preserve who accessed the information, what source inputs were used, what the system generated, what a person changed, who approved the final result, when it happened, and whether the connected system accepted it. Audit history exists to support practice review, incident response, and integration troubleshooting.

The audit chain: source input, generated output, human edit, approval, and the connected system accepting it SOURCEwhat the record said GENERATEDwhat Chairside drafted EDITEDwhat a person changed APPROVEDwho signed off ACCEPTEDthe PMS confirmed EVERY TRUST-SENSITIVE ACTION KEEPS THE WHOLE THREAD Seven-year retention target. Tamper-resistant.

AI begins with advice, not authority.

Sensitive workflows start in an advisory posture. Clinical decisions and signed clinical records remain with licensed providers. Your office controls whether a bounded, non-clinical workflow earns assisted behavior after accuracy, exception handling, and office confidence have been established — and can pause or reverse that decision.

Contractual protection follows the data.

Before covered PHI is processed, Chairside executes the appropriate business associate agreement with the dental organization and requires compatible agreements with relevant subprocessors. A current subprocessor inventory and data-flow summary are available during diligence.

Compliance is an operating program, not a badge.

The readiness program covers risk assessment, workforce training, vendor diligence, access review, incident response, business continuity, retention, and vulnerability management. SOC 2 Type II readiness is underway; claims on this page will be updated only as evidence becomes available.

A failure should be visible before it becomes a surprise.

PMS connections, clearinghouse services, communication rails, and AI services can become unavailable. Chairside is designed to show stale data, queue writes that cannot complete, disclose degraded states, prevent false-success behavior, and preserve the work needed for recovery.

An approved write cannot reach the PMS, so it queues visibly and is recorded on retry APPROVEDby a person PMSunreachableright now QUEUED · 1visible to you retry RECORDEDtrail intact No false success. Ever.
Illustrative — not the product interface.

Keep Chairside outside the card-data boundary.

Chairside is designed not to store full payment-card numbers or initiate charges. Card capture, storage, and processing remain with your authorized payment processor under that processor's PCI DSS program.

Report a suspected security issue.

If you believe you have found a security vulnerability in a Chairside AI service, tell us. We acknowledge every report we receive.

security@chairside.solutions

Do not include patient information in your report.

Describe the issue, the affected page, the steps to reproduce it, and a safe way to reach you.

We do not publish a remediation timeline. We would rather tell you honestly where a report stands than commit to a date we cannot hold.

Additional materials are available for qualified reviews.

Depending on review stage and confidentiality requirements, Chairside provides:

  • security-program overview
  • data-flow summary
  • BAA
  • subprocessor list
  • access-control summary
  • incident-response overview
  • business-continuity summary
  • vulnerability-management process
  • penetration-test summary when available
  • SOC 2 readiness status

Request security materials