How DentalX protects a clinic's records
Where the data lives, what is encrypted, who can open it and what is recorded. Every line describes what the software does today, and one section lists what is not in place yet.
- Data in Google Cloud, in the United States
- Patient record fields encrypted with AES-256-GCM
- A second factor for every account, in the app
- Audit trail kept 7 years

Where the data lives
DentalX runs on Google Cloud in the United States: the database in Google's United States multi-region (nam5), and files and server functions in Iowa (us-central1). Backups are kept in the same Google Cloud project.
AI requests go to Google's Gemini models through Vertex AI, from DentalX's own Google Cloud project, and Google processes them in the United States, in Vertex AI's US multi-region (location “us”). No other AI provider receives them.
Every company that processes data for DentalX, what it receives and where, is on the sub-processors page. Sub-processors
Encryption
Information travels encrypted (TLS), and Google encrypts everything DentalX stores.
In addition, these fields of the patient record are encrypted with AES-256-GCM before they are stored, under a key held in Google Secret Manager that only the server functions read:
- Name
- Date of birth
- Telephone
- Address
- Emergency contact
- Medical history
- Insurance details
Consent forms and prescriptions are encrypted the same way: a consent form's text, the patient's name and signature and the details of how it was signed, and a prescription's patient name, medicines, notes and prescriber. Those saved before this encryption began may not be yet.
Not encrypted this way: the patient's email address; the copies of a patient's name on the other records that need it, such as appointments, invoices, treatments and recalls; the telephone number and email address on appointments and the telephone number on WhatsApp conversations; and treatment notes, images, documents and messages. Those rely on Google's encryption at rest and on the access controls below.
Signing in
The app asks every account for a second factor, an authenticator app, and does not open a clinic until the person has set one up and signed in with it. No one at the clinic can switch this off. VstreamX staff need one to open the administrative console too.
Today the app is what enforces this requirement. Requiring the second factor on every request to the server as well is not finished yet.
DentalX signs a person out after 8 hours without activity, including when the browser was closed in the meantime.
Isolation and access
Each clinic's data is kept apart by database and file rules that deny access by default, and each person sees and does only what their role allows: owner, manager, dentist or receptionist.
DentalX's administrative console does not show patient records to our support staff. The people who administer our Google Cloud project can technically reach stored data; they do so only to keep DentalX running or secure, at a clinic's request, or where the law requires.
Audit trail
Opening a patient's chart, changes to patient and treatment records, exports and deletions are logged with server timestamps no clinic user can alter: who did what, and when. It does not record every read, such as opening a stored file. Entries are kept 7 years.
Backups and recovery
The database is backed up daily, with 7 days of backups and 7 days of point-in-time recovery. Deleted information remains in those backups until they expire, within 7 days.
If you leave
A clinic can export its records, or a single patient's, at any time. When a subscription ends, we keep the clinic's data for 60 days, then prepare a complete export for the clinic owner. When 90 days have passed since it ended, we delete the clinic's patient information within 30 days, after telling the clinic owner by email at least 30 days before. Deleting it also deletes that export.
Security incidents
If a breach affects patient information we process for a clinic, we tell the clinic without undue delay, with what we know and more as we learn it, so that it can meet its own duties.
To report a suspected breach or a security problem, write to admin@vstreamx.com.
AI features
The AI features in the clinic app run only when a person at the clinic asks, on a plan that includes them, and only on Vertex AI as described above. Every answer is a draft for a person to check, labelled as AI. Dictation is the exception: it uses the speech recognition built into the browser, under its maker's terms, and is off where the Privacy Policy says. Our support staff may also use the same models to draft a reply to a support request, which a person reviews before it is sent.
We do not use patient information to train AI models or for any purpose of our own.
Data agreements
Which data agreement a clinic accepts depends on where it practises: the Business Associate Agreement in the United States and, elsewhere, the Master Data Processing Agreement with its schedules and, where the law asks for more, transfer clauses and a country annex. They are drafts under counsel's review: none is in effect yet.
A practice in the United States must not enter patient information until a Business Associate Agreement is signed with us.
Not in place yet
Said here, so that nobody has to find it in the fine print.
- Requiring the second factor on every request to the server, and not only in the app, is not finished yet.
- Text messages can be chosen as a second factor in the app, but codes cannot be sent by text message yet; use an authenticator app.
- The audit trail does not record every read, such as opening a stored file.
- The data agreements are drafts under counsel's review; none is in effect.