Skip to content
Trust & security

You are about to let software answer your phone. Here is exactly what happens to what it hears.

Written for a dentist, not a lawyer. The legal documents are linked at the bottom if you want them.

HIPAA

What HIPAA means for this product

When a patient calls and says their name, their date of birth, and why their tooth hurts, that is protected health information. From the second our system hears it, we are handling PHI on your behalf, which makes us a business associate under HIPAA.

That is not a checkbox. It means we are legally bound to safeguard that information, to use it only to provide the service you hired us for, to tell you promptly if it is ever exposed, and to hold our own vendors to the same standard in writing.

It also means the responsibility does not transfer away from you. You remain the covered entity. What a BAA does is make our obligations enforceable, so that the trust you extend to us has something behind it.

We sign a BAA. Here is what that means for you.

  • We only use what we hear to run your receptionist — never to sell, never to advertise, and never to train a general-purpose model.
  • If PHI is ever exposed, we notify you without unreasonable delay, and we tell you what was affected rather than issuing a vague statement.
  • Every subprocessor that could touch PHI has signed a BAA with us before we send them anything.
  • When you leave, we return or destroy your data — your choice — and confirm it in writing.
Read our BAA template
Recording and AI disclosure

What every caller hears, before anything else.

This plays at the start of every single call. It cannot be turned off, shortened, or moved later in the conversation — not by you, and not by us.

Mandatory, on every call

Thank you for calling Cedar Ridge Family Dental. This call is recorded, and you're speaking with an AI assistant.
Hear it in a different voice

Female · General American · Warm, unhurried. Our default.

0:00 / 0:06

Sample audio is not bundled with this build, so playback is disabled here. In the product this plays the real render of the line.

Why it is not optional

Eleven states — California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania and Washington — require all parties to consent before a call is recorded. Massachusetts is the strictest of them.

Separately, a growing list of states now requires disclosure when a caller is speaking with an AI rather than a person. California’s bot disclosure law and Utah’s AI disclosure requirements are the ones most practices encounter first.

Rather than maintaining a per-state configuration that a practice could get wrong, we announce both things on every call in every state. It costs about four seconds. In our experience patients mind it far less than being sent to voicemail.

Controls

How the data is actually protected.

Encrypted in transit and at rest

TLS 1.2 or better on every connection, including the media stream carrying call audio. Data at rest is encrypted with AES-256. Call recordings and transcripts sit in storage that is encrypted with keys we rotate.

Separated by practice

Every record in our database is scoped to one practice, and that scoping is enforced in the data layer rather than remembered by each screen. We have an automated test that sweeps every list endpoint and fails the build if a new one is added without it.

Access is logged

Every read of a call recording, transcript, or patient detail is written to an audit log with who, what, and when. You can request your practice's audit log at any time, and we will send it as a CSV.

You hold the keys to your PMS

For Open Dental, the Customer API Key is generated by you inside your own system, and you can revoke it instantly without contacting us. We never receive your Open Dental password and cannot log into it.

Retention you control

You choose how long call recordings and transcripts are kept — from 30 days to seven years. When the window closes, the recording is deleted automatically and the deletion is recorded in the audit log.

Export and deletion on request

Ask and we will export everything we hold for your practice as JSON and CSV, usually within two business days. Ask us to delete it and we will, and confirm in writing when it is gone.

Subprocessors

Everyone who could touch your data.

Published openly, because you cannot assess a vendor whose own vendors are a secret. We give 30 days notice before adding one.

Subprocessors and their role
SubprocessorWhat they doLocationBAA signed
Google Cloud (Vertex AI)Speech recognition and language model inferenceUnited StatesSigned
TwilioTelephony and SMS deliveryUnited StatesSigned
Amazon Web ServicesApplication hosting, database, and encrypted storageUnited States (us-east-1)Signed
StripePayment processing (no PHI)United StatesNo PHI
SentryError monitoring (PHI scrubbed before transmission)United StatesSigned
PostmarkTransactional email to practice staff (no PHI)United StatesNo PHI

“No PHI” means that subprocessor is structurally unable to receive protected health information — Stripe sees a practice name and a card, never a patient. Where a vendor could conceivably see PHI, we have a signed BAA regardless of how unlikely it is.

Where we actually stand

HIPAAIn place
Compliant, with a signed BAA available before you connect anything. This is the one that governs your patients' information.
SOC 2 Type IIIn progress
In progress. Our observation window closes in Q1 2027. We will not claim it before the report is issued, and we are happy to share the auditor's name now.
HITRUSTNot pursued
Not pursued. It is expensive and slow, and for a practice of your size it would not tell you anything the BAA and SOC 2 do not.

Security question we have not answered here? security@dentelo.com

Read the BAA before you sign anything.

We would rather you read it now than discover a surprise in month three. Ask us anything, and we will answer it in writing.

No contract. Month to month. Cancel from the billing page.