Trust Centre

Security and privacy, built into SmileSort.

Clinical photography contains sensitive patient information. SmileSort is designed to protect it throughout its lifecycle — from upload and storage to sharing and deletion.

In place today
ActiveCompleteReviewedAssessedManaged
Tracked, not yet in place
In progressPlanned

Last reviewed 25 September 2026

Security

Security

Protection at every stage of the clinical photography workflow.

Encryption

Clinical data is encrypted in transit — every page is served over HTTPS only — and at rest, with AES-256.

Access control

Sessions are verified against the identity provider on every request, not just decoded from a cookie — a revoked or expired session can't be replayed.

Practice isolation

Every table and every photo file is protected by rules in the database itself: anything done on a dentist's behalf reaches their own practice's data and nothing else, whatever the application asks for. The few server tasks that run without a signed-in dentist — opening a share link, the nightly clean-up — are limited to one practice in code.

Secure sharing

A share link uses a 192-bit random token, opens only the folders or photographs it was created for, stops working after 7 days unless you extend it, and can be revoked at any time.

Staff access

No SmileSort tool — including our internal admin portal — can show our team your patients' photographs, folders or notes; that's enforced in the database, not just hidden in the interface. Direct access to the production database is limited to SmileSort's co-founders.

Backups & recovery

The database is backed up daily, with a week of backups kept. Photograph files are not currently covered by a separate file-level backup — a gap we've assessed and disclose rather than assume away.

Privacy & Data

Privacy & Data

Designed around data minimisation, transparency and controlled processing of patient photography.

UK GDPR

SmileSort's data protection programme is built around UK GDPR, with a Data Protection Impact Assessment (signed September 2026) and a Record of Processing Activities, both kept internally.

ICO registration

In progress

SmileSort Ltd's registration with the Information Commissioner's Office is being processed. The registration number will be published here once it's issued.

Controller & processor roles

Your practice determines why clinical photographs are processed; SmileSort processes that data to provide the service, as your processor. SmileSort separately acts as controller for its own account and billing information.

Data minimisation

AI classification never receives a patient name, date of birth or other structured identifier — only the photograph itself. Location data in a photograph's file is never read.

Retention & deletion

Deleted records stay in Trash for 28 days, then are permanently removed. A cancelled account stays read-only and exportable for 30 days; then every patient record, photograph and login is permanently deleted. Billing records stay with Stripe, as tax law requires, and usage statistics are kept only in anonymous form. Your practice remains responsible for its own clinical record-keeping obligations.

Export & portability

Every filed photograph, patient record and folder can be exported as a single archive at any time, including during the 30 days after cancelling — you're not locked into SmileSort to keep your own records.

Sub-processors

Anthropic (AI classification), Supabase (database & storage), Cloudflare (hosting), Stripe and Resend (billing and email — no patient data) — every one individually checked, none holding patient data outside the UK/EU without an EU SCC + UK Addendum transfer mechanism in place.

Full sub-processor register — DPA, Annex 3

AI

AI & your data

What SmileSort's AI actually does with a clinical photograph, and what it doesn't.

Purpose-limited AI

AI does two things in SmileSort: it recognises which standard view each photograph is, and helps group photographs taken at the same appointment. It doesn't interpret what a photograph shows.

Human control

You check every AI result. A batch upload waits for your approval before anything is filed. In a Clinical Series, recognised views go straight into their slots for you to check — drag any photograph to another slot or take it out — and anything SmileSort can't place waits under Needs review.

Provider governance

Photographs go to Anthropic, our AI provider, for those two tasks only, under Anthropic's Data Processing Addendum, which includes the EU Standard Contractual Clauses and the UK Addendum for the transfer to the US. Anthropic deletes what it receives within 30 days, and keeps it longer only if its safety systems flag a request or the law requires it.

No secondary use

Anthropic doesn't train its models on data sent through its API, and SmileSort hasn't joined the opt-in programme that would change that. SmileSort doesn't use your patients' photographs for marketing, research or improving its own AI.

Clinical & Regulatory

Clinical & Regulatory

SmileSort is not a medical device. It stores, organises and shares clinical photographs — every clinical judgement stays with you.

Not a medical device

Assessed

SmileSort is an administrative tool for storing, organising and communicating clinical photographs. Under the UK Medical Devices Regulations 2002, software limited to storage, archiving, communication and simple search isn't a medical device, and SmileSort's intended purpose stays within that.

Sorting is filing, not clinical analysis

SmileSort's AI recognises which standard view a photograph is — an upper occlusal, a smile, a left buccal — and groups photographs taken at the same appointment. That's how it knows where to file them. It doesn't assess the teeth, detect conditions, measure anything or suggest a diagnosis.

Sharing is communication

Sharing sends photographs to a lab or colleague as you see them in SmileSort, through a secure link that expires. The file is the one you stored; a rotation or flip you applied travels with it as the standard orientation tag that photo software reads. SmileSort adds no interpretation or annotation.

No influence on care

SmileSort doesn't recommend treatment, highlight areas of concern or automate clinical decisions. A photograph filed in the wrong place is a filing error you can correct, not a clinical output.

New features are checked first

Before any new AI feature is built, it's checked against SmileSort's intended purpose. Anything that would interpret the clinical content of a photograph would need a fresh regulatory assessment first.

Clinical safety (DCB0129)

In progress

We're putting the NHS clinical risk management standard for health software in place, led by co-founder Dr Abdelrahman Mohamed, a GDC-registered dentist, as Clinical Safety Officer. It covers the ways a filing or sharing mistake could affect a patient's care — a photograph filed to the wrong patient, or shown the wrong way round.

Assurance

Independent assurance

A status roadmap, not a certification wall — what's done, in progress, and planned.

  1. Cyber Essentials

    Planned

    UK government-backed baseline cyber security certification.

  2. Independent penetration testing

    Planned

    A third-party security assessment of the live application.

  3. Cyber Essentials Plus

    Planned

    The audited tier of Cyber Essentials, following the base certification.

  4. ISO 27001

    Planned

    Formal information security management certification.

Security questions?

If you're reviewing SmileSort for your practice or have a security question, we'd be happy to help.

Contact security

Found a vulnerability? Read our Responsible Disclosure Policy before you test.

Last reviewed 25 September 2026.