Toothvity · India
Security
Last updated: August 2026. A plain-language overview for clinic owners. This page describes our security practices. It is not a certification or compliance attestation.
Overview
Dental clinics handle sensitive patient information. Toothvity is designed so your team can work efficiently while keeping access controlled and records dependable. Plan feature comparisons live on Pricing; this page focuses on security-relevant controls.
How Clinic Data Is Protected
Encrypt Traffic
Browser and API connections to Toothvity use HTTPS (TLS). Do not ignore certificate warnings on clinic devices.
Control Staff Access
Starter includes a secure owner login. On Growth and above, owners invite staff with roles such as dentist, receptionist, admin, and owner. Permission checks run on the server for actions and APIs.
Isolate Clinic Data
Each clinic workspace is kept separate from other clinics. Server-side checks prevent one clinic from accessing another clinic’s records.
Require Verified Email
Users must verify email before creating a clinic or using product routes. Unverified sessions are blocked from product use.
Log Privileged Actions
Important admin actions (for example team invites and billing management) are logged. Security risk events such as login failures, rate limits, and access blocks are available for owner review.
Limit Abuse
Sign-in and invite flows apply rate limits to reduce credential stuffing and spam. Disposable email domains are blocked at signup. Platform operators monitor abuse signals internally.
Protect Billing Integrity
Subscription changes rely on server-side safeguards and payment-provider webhooks so billing status cannot be forged from the browser.
Soft Delete for Recovery
Patients, documents, and related records support soft delete so authorised staff can recover mistaken removals where the product allows. Soft delete is not permanent erasure.
Reconcile File Storage
Platform operators can reconcile clinic branding and support-attachment storage so usage counters stay aligned with what is actually stored.
Back Up for Disaster Recovery
Hosted infrastructure includes database backup capabilities. Branding and support attachments can be exported manually by platform operators for disaster-recovery drills. There is no automated clinic self-service restore UI today.
File Storage
Toothvity stores clinic branding files (logo, banner, signature) and support ticket attachments in private cloud storage with access controls. Clinical PDFs (prescriptions, invoices, consents, treatment plans) are generated on demand from your database records and are not kept as permanent upload objects.
- Per-plan storage quotas apply to branding and support attachments. Uploads that would exceed your allowance are blocked. Current limits are on Pricing.
- Replacing a logo, banner, or signature removes the previous image from active storage. Deleted or replaced files may persist in operational backups for a limited window per our Data Retention policy.
Compliance Status
Shared Responsibility
- Use individual logins for each staff member (Growth+ when inviting a team)
- Apply least-privilege roles (receptionist vs dentist vs owner)
- Remove or deactivate access promptly when someone leaves
- Do not share passwords or leave sessions open on shared front-desk PCs
- Invite only known staff and verify invite destinations
- Keep front-desk devices patched and screen-locked
- Retain copies of records you are legally required to keep outside the app
- Report suspected misuse immediately
Report a Security Incident
Email security@toothvity.com with a short summary, steps to reproduce, affected accounts, and timestamps. For privacy questions see support@toothvity.com or our Privacy Policy. Owners can review clinic-scoped risk events at Security Events (owner role, signed in).