Skip to main content

    Legal · Security

    Security Overview

    This document summarises the technical and organisational measures Circlemount Dental Technology Ltd uses to protect customer and patient data. It supports our Data Processing Agreement and is reviewed at least annually.

    v1.0Effective 27 April 2026Reviewed 27 April 2026
    Table of contents▾

    1. Data residency

    Patient data is stored in UK regions for primary storage and EU regions for redundancy. We do not use US-only processors for patient data.

    2. Encryption

    • TLS 1.3 across every endpoint and integration.
    • AES-256 at rest, with rotating per-tenant keys.
    • Backups encrypted with separate keys, geographically isolated.

    3. Access control

    • Role-based access aligned to dental team roles (clinical, admin, owner, external).
    • MFA enforced on all accounts; SSO available for groups.
    • Tamper-evident audit log of every privileged action.
    • Session controls including device approval and IP allowlisting (groups).

    4. Patient identity verification

    • Risk-based verification (e.g. DOB + postcode + last visit).
    • Verified WhatsApp Business API for branded comms.
    • AI Receptionist identity checks before any data disclosure.
    • Per-patient consent ledger by channel and purpose.

    5. Secure engineering

    • Code review on every change; protected production branches.
    • Dependency and vulnerability scanning in CI.
    • Secrets management via the platform's vault — never in source control.
    • Least-privilege production access; just-in-time elevation.

    6. Monitoring and response

    • Continuous logging of authentication and privileged actions.
    • Alerting on anomalous access patterns.
    • Documented incident response with on-call rotation.
    • 72-hour breach notification commitment to controllers.

    7. Backups, BC/DR

    • Encrypted, automated backups with point-in-time recovery.
    • Restore procedures tested at least every six months.
    • RTO / RPO targets published in the customer security pack.

    8. People and process

    • Background checks for personnel with production access.
    • Annual security and UK healthcare-data training.
    • Confidentiality and acceptable-use obligations in every contract.

    9. Certifications roadmap

    We publish progress quarterly alongside the product roadmap.

    • Cyber Essentials Plus — in progress.
    • ISO 27001 — targeted post-GA.
    • SOC 2 Type II — to follow.

    10. Reporting a vulnerability

    If you believe you've found a security issue, please follow our Responsible Disclosure policy and contact marcus@dentorb.ai.

    Questions about this document?

    Email marcus@dentorb.ai.

    Circlemount Dental Technology Ltd · Company No. 17188772 · Registered in England & Wales
    Incorporated 29 April 2026 · Registered office: The Squires, 5 Walsall Street, Wednesbury, West Midlands, England, WS10 9BZ

    © 2026 Circlemount Dental Technology Ltd · Company No. 17188772 · Registered in England & Wales