Skip to content

Security

You are being asked to move patient records. Here is everything we know.

The controls you can switch on today, every third party that touches your data and why, what we will never do with it — and, at the bottom, the things we have not built yet. That last section is the one worth reading.

Available now

What you can turn on today

Two-factor authentication

Time-based one-time passcodes (TOTP), set up from your account settings and usable with any standard authenticator app.

Device management

See every device signed in to your account, remove any one of them, or sign out everywhere except the device you are holding.

Security activity log

A record of security-relevant events on your account, visible to you — so a sign-in you did not make is something you can actually find.

Licence verification

Dentists are verified against their registration before they can accept bookings on the network. Verification is a gate, not a badge.

Self-serve deletion

Account and data deletion can be requested from inside the app or from the website, without going through a support queue to be talked out of it.

No card data on our systems

Card and UPI details are handled by Razorpay, our payment processor. EnamDoc does not receive or store card numbers.

What we do not do

We do not sell data. Not to advertisers, not to insurers, not to anyone. There is no line item in our business model that depends on it.

We do not run ads on clinical surfaces. Nothing in a patient record or a clinical view is monetised by attention.

We do not sell patient leads to the highest bidder. A verified dentist’s visibility on EnamDoc is not an auction. This is a deliberate difference from the marketplace model, and it is the reason we can say the patient relationship belongs to the clinic.

We do not hold your records hostage. Export and deletion are available on request, at any time, whether or not you are still paying.

Third parties

Everyone who touches your data, and why

Most vendors will not give you this list without an email chain. It is on a public page because you should not have to ask.

Amazon Web Services
Application hosting, database and file storage
Google Firebase
Authentication and parts of the application datastore
Razorpay
Payment processing — card and UPI details are handled here, not by us
OpenAI
AI features, including X-ray analysis
Brevo
Transactional email

AI features send the relevant content to OpenAI for processing. If you have a specific concern about what leaves our systems for a particular feature, raise it on a demo call and we will answer precisely rather than generally.

What we have not built yet

A security page listing only strengths is a marketing page. These are the honest gaps, and you should weigh them.

  • We do not hold ISO 27001 or SOC 2 certification. Any vendor telling you they are "SOC 2 aligned" without a report is telling you they are not certified.
  • We are not HIPAA-covered. HIPAA is US legislation and does not apply to an Indian clinic; we mention it only because the question comes up.
  • We do not currently publish a formal penetration-test report.
  • We do not yet offer clinic-configurable data-retention periods. Deletion is all-or-nothing today.
  • We do not offer on-premise or self-hosted deployment.

FAQ

Security questions we get asked

01
Is EnamDoc HIPAA compliant?
HIPAA is United States legislation and does not apply to a dental clinic operating in India. We are not a HIPAA-covered entity and do not claim to be. The framework that matters for Indian clinics is the Digital Personal Data Protection Act.
02
Do you hold ISO 27001 or SOC 2 certification?
No. We would rather say so plainly than describe ourselves as "aligned with" a standard we have not been audited against. If a certification requirement is a condition of your purchase, tell us on a demo call and we will give you a straight answer about timelines rather than a vague one.
03
Where is my patient data stored?
On Amazon Web Services and Google Firebase infrastructure. If your practice has a specific data-residency requirement, raise it before you sign up rather than after, and we will tell you precisely what we can and cannot commit to today.
04
Does patient data go to OpenAI?
Content relevant to an AI feature is sent to OpenAI to be processed — for example, a radiograph submitted for X-ray analysis. Our privacy policy lists OpenAI as a sub-processor for exactly this reason. If you would prefer not to use AI features, they are not required in order to use the rest of EnamDoc.
05
Can I get my data out?
Yes. You can request an export or a full deletion at any time from the app or from the delete-account page on this site, whether or not you have an active subscription.
06
How do I report a security issue?
Email support@enamdoc.com with the details. If you believe you have found a vulnerability, please include enough detail to reproduce it and give us a reasonable window to fix it before disclosing it publicly.

Ask us the hard version.

If your practice has a specific security or data-handling requirement, put it to us directly. A precise answer is more useful to both of us than a reassuring one.