Trust
Security & compliance.
Oralstack handles dental clinic records, so its security claims need evidence and clear boundaries. This summary reflects repository evidence reviewed through 6 August 2026; the latest recorded production-flag snapshot is dated 20 July 2026. Deployment details must be reconfirmed during procurement.
Start a review
Get the current evidence boundary for your clinic review.
Tell us whether you need a questionnaire, controls walkthrough, agreement, data processing terms, subprocessor detail, or a current deployment check. The response will separate implemented controls from open work.
- Evidence reviewed
- Through 6 August 2026
- Deployment record
- Singapore region
- Tenant boundary
- Postgres RLS evidenced
- Attestations
- CE-HIMS, SOC 2 and ISO 27001 not held
Where data lives
Documented deployment, database-enforced tenant scope, layered encryption.
Review where data lives
Documented deployment · Singapore
The latest repository deployment record places the application and primary data services in Google Cloud's Singapore region. Deployment-specific processors and outbound data paths are reconfirmed during procurement.
Tenant isolation · database-enforced
Postgres Row-Level Security, a non-owner application role, and request-scoped clinic binding enforce tenant boundaries in the database. Isolation tests cover missing scope and cross-clinic access.
Encryption · layered controls
Transport encryption and cloud-managed encryption at rest cover the deployed data services. Selected high-risk fields also use application-layer AES-256-GCM. We do not claim that every field is application-encrypted.
Documented deployment · Singapore
The latest repository deployment record places the application and primary data services in Google Cloud's Singapore region. Deployment-specific processors and outbound data paths are reconfirmed during procurement.
Tenant isolation · database-enforced
Postgres Row-Level Security, a non-owner application role, and request-scoped clinic binding enforce tenant boundaries in the database. Isolation tests cover missing scope and cross-clinic access.
Encryption · layered controls
Transport encryption and cloud-managed encryption at rest cover the deployed data services. Selected high-risk fields also use application-layer AES-256-GCM. We do not claim that every field is application-encrypted.
Product data lifecycle
Record ownership, exports, retention, and offboarding are part of the rollout decision.
Review product data lifecycle
Record ownership · deployment-specific
The clinic rollout records which patient, appointment, clinical, billing, and audit records Oralstack owns natively and which records remain authoritative in an optional connected system. A code path is not treated as enabled clinic capability.
Exports and offboarding · confirmed before go-live
Operational reports support CSV where exposed in the product. The broader patient, clinical, billing, document, and audit export package is confirmed in the clinic agreement rather than inferred from a walkthrough.
Retention and deletion · agreed in writing
Retention, source-system archives, rollback, account closure, deletion timing, and any legally required hold are agreed for the deployment. The public marketing-site privacy notice does not replace those product terms.
Record ownership · deployment-specific
The clinic rollout records which patient, appointment, clinical, billing, and audit records Oralstack owns natively and which records remain authoritative in an optional connected system. A code path is not treated as enabled clinic capability.
Exports and offboarding · confirmed before go-live
Operational reports support CSV where exposed in the product. The broader patient, clinical, billing, document, and audit export package is confirmed in the clinic agreement rather than inferred from a walkthrough.
Retention and deletion · agreed in writing
Retention, source-system archives, rollback, account closure, deletion timing, and any legally required hold are agreed for the deployment. The public marketing-site privacy notice does not replace those product terms.
How access is controlled
MFA support, scoped access, and tamper-evident audit integrity.
Review how access is controlled
Multi-factor authentication · supported
TOTP enrolment, encrypted secret storage, and sign-in gates are implemented. The latest recorded production state does not enforce MFA for every staff account.
Role and clinic-scoped access
Active organization membership, bounded organization roles, and exact clinic access protect multi-clinic routes. Google and Microsoft SSO, SCIM, and granular custom-permission enforcement are not enabled in the latest recorded configuration.
Audit integrity · tamper-evident
Audited actions are linked with an HMAC chain so integrity checks can detect alteration. The latest recorded production evidence also marks audit verification and immutable backup controls as active.
Multi-factor authentication · supported
TOTP enrolment, encrypted secret storage, and sign-in gates are implemented. The latest recorded production state does not enforce MFA for every staff account.
Role and clinic-scoped access
Active organization membership, bounded organization roles, and exact clinic access protect multi-clinic routes. Google and Microsoft SSO, SCIM, and granular custom-permission enforcement are not enabled in the latest recorded configuration.
Audit integrity · tamper-evident
Audited actions are linked with an HMAC chain so integrity checks can detect alteration. The latest recorded production evidence also marks audit verification and immutable backup controls as active.
Backups, recovery, and incidents
Recorded backup controls, a dated status snapshot, and a disclosure channel.
Review backups, recovery, and incidents
Backups · recorded controls
The latest production-state record marks immutable backup storage and audit-integrity verification as active. Recovery objectives, restore cadence, and deployment-specific evidence are confirmed during procurement.
Status & uptime
The status page publishes a dated capability snapshot and its evidence boundary. It is not presented as a live telemetry or uptime monitor.
Vulnerability disclosure
Report a vulnerability to security@oralstack.com. Include a concise reproduction and a safe contact method. Response timing depends on severity and will be confirmed when the report is triaged.
Backups · recorded controls
The latest production-state record marks immutable backup storage and audit-integrity verification as active. Recovery objectives, restore cadence, and deployment-specific evidence are confirmed during procurement.
Status & uptime
The status page publishes a dated capability snapshot and its evidence boundary. It is not presented as a live telemetry or uptime monitor.
Vulnerability disclosure
Report a vulnerability to security@oralstack.com. Include a concise reproduction and a safe contact method. Response timing depends on severity and will be confirmed when the report is triaged.
Compliance posture
Implemented controls are separate from readiness work and certifications not held.
Review compliance evidence
- Implemented
Security controls in the deployed stack
Tenant RLS, audit-integrity checks, origin controls, managed encryption, and selected-field application encryption are evidenced in the latest recorded platform snapshot. These controls are not a certification.
- In progress
Singapore PDPA and CE-HIMS readiness
The product is being developed to support Singapore privacy and health-system obligations. Formal CE-HIMS readiness work still has material open items, so Oralstack does not claim CE-HIMS certification or blanket PDPA compliance.
- In progress
External vulnerability assessment
Internal security rehearsals and automated checks exist. A formal, accepted independent vulnerability assessment and penetration test is not yet evidenced as complete.
- Not held
CE-HIMS certification
Not currently held. Repository readiness materials record a no-go for certification submission until the remaining technical, operational, and evidence gaps are closed.
- Not held
SOC 2, ISO 27001, and HIPAA attestation
No SOC 2 report, ISO 27001 certification, or independent HIPAA attestation is claimed on this page.
“Implemented” describes evidenced product controls, not legal compliance, certification, or an independent attestation.
- Implemented
Security controls in the deployed stack
Tenant RLS, audit-integrity checks, origin controls, managed encryption, and selected-field application encryption are evidenced in the latest recorded platform snapshot. These controls are not a certification.
- In progress
Singapore PDPA and CE-HIMS readiness
The product is being developed to support Singapore privacy and health-system obligations. Formal CE-HIMS readiness work still has material open items, so Oralstack does not claim CE-HIMS certification or blanket PDPA compliance.
- In progress
External vulnerability assessment
Internal security rehearsals and automated checks exist. A formal, accepted independent vulnerability assessment and penetration test is not yet evidenced as complete.
- Not held
CE-HIMS certification
Not currently held. Repository readiness materials record a no-go for certification submission until the remaining technical, operational, and evidence gaps are closed.
- Not held
SOC 2, ISO 27001, and HIPAA attestation
No SOC 2 report, ISO 27001 certification, or independent HIPAA attestation is claimed on this page.
“Implemented” describes evidenced product controls, not legal compliance, certification, or an independent attestation.
Legal documents
Contracts, processing agreements, and the subprocessor list.
Review documents and request paths
- Marketing-site privacy noticeCookie policy, marketing analytics, contact-form data — covers oralstack.com only.
- Marketing-site termsTerms of use for the public marketing site.
- Product agreementRequest the current pilot or production terms for legal review.
- Data processing termsConfirm the current controller/intermediary terms and deployment scope during procurement.
- Security evidence packRequest the current control summary, open-gap register, and evidence review boundary.
- Deployment-specific subprocessor informationRequest the current list for the services and optional providers in your deployment.
The marketing-site Privacy and Terms cover oralstack.com only. Product customers sign the current commercial and data-processing terms agreed for their deployment.
- Marketing-site privacy noticeCookie policy, marketing analytics, contact-form data — covers oralstack.com only.
- Marketing-site termsTerms of use for the public marketing site.
- Product agreementRequest the current pilot or production terms for legal review.
- Data processing termsConfirm the current controller/intermediary terms and deployment scope during procurement.
- Security evidence packRequest the current control summary, open-gap register, and evidence review boundary.
- Deployment-specific subprocessor informationRequest the current list for the services and optional providers in your deployment.
The marketing-site Privacy and Terms cover oralstack.com only. Product customers sign the current commercial and data-processing terms agreed for their deployment.
Security questionnaire or controls walkthrough?
Procurement teams can request the current evidence boundary, open-gap register, a security questionnaire, and a controls walkthrough. We will distinguish implemented controls from planned work in the response.