Trust & security
Access should be narrow. Actions should be visible. Authority should stay human.
Chairside is being built for sensitive dental workflows and the scrutiny that comes with them. We limit access to what a workflow requires, preserve review and approval history, and design the system to fail visibly rather than silently.
- Pre-launch
- HIPAA-aligned design
- BAAs before covered PHI
- SOC 2 Type II readiness underway
What we do not claim
Chairside does not currently claim a SOC 2 Type II attestation or any form of HIPAA certification. This page describes our current security program and the controls required for covered production deployments.
Protect the data throughout its use.
Covered production deployments require encryption in transit and at rest, controlled credential and secret management, customer-data isolation, secure backups, and documented retention and deletion rules. Protected data is not routed to any vendor or AI service that lacks the contractual and security posture the workflow requires.
Give people and systems only the access they need.
The production control baseline includes unique user identities, role-based access, least-privilege permissions, minimum-necessary access, prompt revocation, periodic access review, and narrowly scoped service credentials for integrations. Shared credentials and broad, undocumented access are not acceptable substitutes for proper authorization.
Preserve the full decision path.
Trust-sensitive actions preserve who accessed the information, what source inputs were used, what the system generated, what a person changed, who approved the final result, when it happened, and whether the connected system accepted it. Audit history exists to support practice review, incident response, and integration troubleshooting.
AI begins with advice, not authority.
Sensitive workflows start in an advisory posture. Clinical decisions and signed clinical records remain with licensed providers. Your office controls whether a bounded, non-clinical workflow earns assisted behavior after accuracy, exception handling, and office confidence have been established — and can pause or reverse that decision.
Contractual protection follows the data.
Before covered PHI is processed, Chairside executes the appropriate business associate agreement with the dental organization and requires compatible agreements with relevant subprocessors. A current subprocessor inventory and data-flow summary are available during diligence.
Compliance is an operating program, not a badge.
The readiness program covers risk assessment, workforce training, vendor diligence, access review, incident response, business continuity, retention, and vulnerability management. SOC 2 Type II readiness is underway; claims on this page will be updated only as evidence becomes available.
A failure should be visible before it becomes a surprise.
PMS connections, clearinghouse services, communication rails, and AI services can become unavailable. Chairside is designed to show stale data, queue writes that cannot complete, disclose degraded states, prevent false-success behavior, and preserve the work needed for recovery.
Keep Chairside outside the card-data boundary.
Chairside is designed not to store full payment-card numbers or initiate charges. Card capture, storage, and processing remain with your authorized payment processor under that processor's PCI DSS program.
Report a suspected security issue.
If you believe you have found a security vulnerability in a Chairside AI service, tell us. We acknowledge every report we receive.
Do not include patient information in your report.
Describe the issue, the affected page, the steps to reproduce it, and a safe way to reach you.
We do not publish a remediation timeline. We would rather tell you honestly where a report stands than commit to a date we cannot hold.
Additional materials are available for qualified reviews.
Depending on review stage and confidentiality requirements, Chairside provides:
- security-program overview
- data-flow summary
- BAA
- subprocessor list
- access-control summary
- incident-response overview
- business-continuity summary
- vulnerability-management process
- penetration-test summary when available
- SOC 2 readiness status
