Bonded holds clinical records, diagnostic imaging and payment data for orthodontic practices. It is hosted in-region, encrypted in transit and at rest, and operated to the health-data regime of every market it serves.
Each region is an independent deployment with its own database. Your practice's data is stored and processed in your region.
Backups are encrypted and retained in the same region as the data they protect. Sub-processors and the safeguards governing any cross-border transfer are named in the privacy policy.
Bonded is operated to the standard that applies where your practice is.
AES-256 at rest across databases, object storage and backups. TLS 1.2 or higher in transit, including API traffic, the mobile applications and file transfer.
Identity-based access to production with mandatory multi-factor authentication. Inside a practice, staff see the records and functions their role permits, enforced server-side.
Every query against patient data is scoped to the clinic that owns it. Isolation is enforced in the data layer, not in the interface.
Independent penetration testing annually, vulnerability scanning quarterly, and continuous monitoring of the production stack.
Business Associate Agreements, data processing agreements, sub-processor lists and completed security questionnaires are available on request from our Privacy Officer.