Security at Dentanaut
Clinical data is among the most sensitive information a person can share. We treat it that way, with enterprise-grade security practices built into every layer of our platform.
DPDPA Compliant
Digital Personal Data Protection Act, 2023
TLS 1.3
All data in transit
AES-256
All data at rest
PITR Backups
Hourly point-in-time recovery
Encryption at Every Layer
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Patient records, X-rays, and clinical notes are encrypted before storage. Encryption keys are rotated regularly and managed using hardware security modules (HSMs).
Secure Infrastructure
Dentanaut runs on ISO 27001-certified cloud infrastructure within India. We use network segmentation, private subnets, and strict firewall rules. Database servers are never exposed to the public internet.
Access Control
Role-based access control (RBAC) ensures that team members can only access data relevant to their role. All admin actions are logged with full audit trails. Multi-factor authentication is available and recommended for all accounts.
Backups & Recovery
Patient data is backed up with point-in-time recovery (PITR) every hour. Backups are encrypted and stored in geographically separate locations. We test recovery procedures quarterly, with a target RTO of 4 hours.
Vulnerability Management
We run automated security scans on every code deployment. Our infrastructure is penetration tested annually by an independent security firm. Critical vulnerabilities are patched within 24 hours; high severity within 7 days.
Incident Response
We maintain a 24/7 security incident response process. In the event of a data breach, affected users are notified within 72 hours as required by DPDPA. All incidents are documented, investigated, and used to improve our defenses.
Responsible Disclosure
If you believe you have found a security vulnerability in Dentanaut, we encourage responsible disclosure. Please do not publicly disclose the issue until we have had a chance to address it.
We commit to acknowledging your report within 48 hours and providing a resolution timeline within 7 business days.
Report a Vulnerability: security@dentanaut.com