Security
What is built, rather than what is planned. Every item here is something we can show you on a call.
Australian hosting
Practice and patient data is held in an Australian region. It does not leave the country.
One practice cannot see another
Every query is rewritten at the database layer to carry the practice it belongs to. It is not a filter a developer has to remember — a query reaching across practices is refused, and that refusal is tested against a real database with two practices in it.
Every record access is logged
Who opened which patient record, and when, in an append-only log. There is no delete path for it, deliberately.
Support cannot read your records by default
Helping with a problem that genuinely needs clinical data requires a time-boxed grant with a written reason. It expires on its own, and you can see every time it was used.
Passwords are hashed with Argon2
Not stored, not recoverable, not reversible by us. A reset sets a new password; it never tells you the old one.
Sessions can be revoked instantly
Signing a device out, or suspending a staff member, takes effect on the next request rather than whenever a token happens to expire.
What we do not claim
We do not hold ISO 27001 or SOC 2, and we have not had a third-party penetration test. Both come before we take on a practice group, and you should hear it here rather than discover it during procurement.
Found something? Email privacy@cadencedental.com.au. We respond within two business days, and we will not threaten you for telling us.