Toothvity · India

Security

Last updated: August 2026. A plain-language overview for clinic owners. This page describes our security practices. It is not a certification or compliance attestation.

← Back to Home

Overview

Dental clinics handle sensitive patient information. Toothvity is designed so your team can work efficiently while keeping access controlled and records dependable. Plan feature comparisons live on Pricing; this page focuses on security-relevant controls.

How Clinic Data Is Protected

  • Encrypt Traffic

    Browser and API connections to Toothvity use HTTPS (TLS). Do not ignore certificate warnings on clinic devices.

  • Control Staff Access

    Starter includes a secure owner login. On Growth and above, owners invite staff with roles such as dentist, receptionist, admin, and owner. Permission checks run on the server for actions and APIs.

  • Isolate Clinic Data

    Each clinic workspace is kept separate from other clinics. Server-side checks prevent one clinic from accessing another clinic’s records.

  • Require Verified Email

    Users must verify email before creating a clinic or using product routes. Unverified sessions are blocked from product use.

  • Log Privileged Actions

    Important admin actions (for example team invites and billing management) are logged. Security risk events such as login failures, rate limits, and access blocks are available for owner review.

  • Limit Abuse

    Sign-in and invite flows apply rate limits to reduce credential stuffing and spam. Disposable email domains are blocked at signup. Platform operators monitor abuse signals internally.

  • Protect Billing Integrity

    Subscription changes rely on server-side safeguards and payment-provider webhooks so billing status cannot be forged from the browser.

  • Soft Delete for Recovery

    Patients, documents, and related records support soft delete so authorised staff can recover mistaken removals where the product allows. Soft delete is not permanent erasure.

  • Reconcile File Storage

    Platform operators can reconcile clinic branding and support-attachment storage so usage counters stay aligned with what is actually stored.

  • Back Up for Disaster Recovery

    Hosted infrastructure includes database backup capabilities. Branding and support attachments can be exported manually by platform operators for disaster-recovery drills. There is no automated clinic self-service restore UI today.

File Storage

Toothvity stores clinic branding files (logo, banner, signature) and support ticket attachments in private cloud storage with access controls. Clinical PDFs (prescriptions, invoices, consents, treatment plans) are generated on demand from your database records and are not kept as permanent upload objects.

  • Per-plan storage quotas apply to branding and support attachments. Uploads that would exceed your allowance are blocked. Current limits are on Pricing.
  • Replacing a logo, banner, or signature removes the previous image from active storage. Deleted or replaced files may persist in operational backups for a limited window per our Data Retention policy.

Compliance Status

Shared Responsibility

  • Use individual logins for each staff member (Growth+ when inviting a team)
  • Apply least-privilege roles (receptionist vs dentist vs owner)
  • Remove or deactivate access promptly when someone leaves
  • Do not share passwords or leave sessions open on shared front-desk PCs
  • Invite only known staff and verify invite destinations
  • Keep front-desk devices patched and screen-locked
  • Retain copies of records you are legally required to keep outside the app
  • Report suspected misuse immediately

Report a Security Incident

Email security@toothvity.com with a short summary, steps to reproduce, affected accounts, and timestamps. For privacy questions see support@toothvity.com or our Privacy Policy. Owners can review clinic-scoped risk events at Security Events (owner role, signed in).