Security & data

Patient data deserves a straight answer.

This page describes controls that exist in the product today. Where something is an operational practice rather than a certification, we say so — a dental clinic choosing software should not have to decode marketing language to find out what is actually protecting its patients.

Controls in the product

What protects your clinic’s data.

Every record belongs to one clinic

Clinic context is resolved from the request and applied across the product's workflows. One clinic's patients, invoices, messages and images are not reachable from another clinic's session.

Role-based access, enforced server-side

Nine clinic roles and twenty-two permissions. The check runs on the server for pages, actions and API routes alike — not in the browser, where it could simply be skipped.

Encrypted WhatsApp credentials

The tokens that let us send on your behalf are stored encrypted and scoped to your clinic. They are never exposed to the browser.

Signature-verified webhooks

Inbound WhatsApp traffic is verified against an HMAC-SHA256 signature before anything is persisted. An unsigned request is rejected outright.

Activity records

Sensitive actions write audit records, so there is an operational trail of who did what. Clinical corrections are recorded rather than silently overwriting the original.

Your data can leave

Operational exports are part of the product. Choosing ConphiDent does not mean your clinic's history becomes hostage to it.

Accounts & files

The details underneath.

The parts of the system most likely to be asked about in a procurement conversation, stated plainly.

Authentication
Staff sign in with their own account. Sessions are cookie-based and server-verified on every protected request.
Failed attempts
Repeated failed sign-ins increment a counter and can lock the account for a period.
Password resets
Reset tokens are single-purpose and time-limited, delivered by email.
Forced rotation
An administrator can require a staff member to change their password at next sign-in.
Clinical files
Radiographs and private clinical documents are held in access-controlled storage, reached through short-lived authorised links rather than public URLs.
Laboratory portal
External labs get a revocable link scoped to their own cases — not an account inside your clinic.

Being straight with you

What we do not claim.

No certification claims
We do not hold or claim ISO 27001, SOC 2, HIPAA certification or regulatory clearance. If a certification matters to your practice, ask us where we are before you buy, not after.
No clinical claims
ConphiDent does not diagnose, does not make autonomous clinical decisions and does not claim diagnostic accuracy. Clinical judgement remains with your qualified team.
Demonstration data is fictional
Every example, patient name and figure shown across this site is invented for demonstration. None of it comes from a real clinic.

Questions before you commit

Ask us the hard ones.

We would rather answer a difficult security question on a call than have you find the answer later.

See also our privacy policy and data deletion process.