Patient records deserve a straight answer.
What follows is what is actually in place today. Where something is planned rather than built, it says so.
Where the data lives
Patient data is stored in an encrypted database in an Indian region. It is encrypted in transit with TLS 1.3 and at rest with AES-256. Backups are continuous and are encrypted with the same keys policy as the primary.
Who can read it
Access is role-based — front desk, doctor, assistant, owner — and scoped per location for clinics running more than one. A user sees the records their role needs and no others. Access is removed the moment an account is disabled, not at the next sync.
What is logged
Every read and every write of a patient record is logged with the user, the record and the time. The log is queryable by the practice owner without asking us, because an audit trail you have to request is not an audit trail.
What we do not do
We do not sell clinic or patient data, share it with advertisers, or use it to train models. Support staff do not have standing access to clinic records; access for a specific support request is time-boxed, requires the clinic's approval, and appears in the same audit log.
Getting it back
Every record type exports to CSV from Settings at any time, with no charge and no notice period, and the full clinical record is available as a structured export. This is deliberate: we would rather a clinic leave with its data than stay because it cannot.
Certifications
Not yet certified. Dently has no ISO 27001 or SOC 2 report at this time, and we would rather say so than imply otherwise. The controls above are in place; the external audit is not. If a formal report is a requirement for your practice, tell us and we will give you a date rather than a maybe.
Questions we have not answered
Ask us something specific.
Security questionnaires, data residency requirements and DPA reviews go straight to the people who built the system, not to a form.