Security & Trust
Security you can present to your board.
Parlytics is built for healthcare-adjacent environments where data integrity, access control, and audit trails aren't optional.
Questions? hello@parlytics.aiAll systems operational
View live status and uptime history
Data Protection
Your DSO's data is encrypted and isolated
- Parlytics encrypts all data in transit (TLS) and at rest
- Each DSO's data is logically isolated — your data is never commingled with another organization's
- Parlytics stores no data outside the United States
- The vendor and pricing data you upload is yours — Parlytics never shares it with other organizations or vendors
Access Controls
The right people see the right data
- Role-based access control — admins, regional managers, and office managers each have different permission levels
- Office managers can only see data for their assigned practice
- Every login is authenticated — no shared passwords or guest access
- Session management with automatic timeouts
HIPAA Posture
Built with HIPAA in mind
- Parlytics is a supply chain platform, not an EHR — it does not store protected health information (PHI) as a primary function
- Where patient-adjacent data appears (implant lot traceability, procedure-based planning), access is logged with user, timestamp, and action
- Business Associate Agreements (BAAs) are available for signed client agreements
- Audit logs are append-only and tamper-resistant
Audit & Compliance
Every action in your dental supply chain leaves a trace
- Comprehensive audit logging across all data operations
- Logs capture who accessed what, when, and from where
- FDA recall traceability — implant lot numbers tracked from receipt through patient placement
- Export-ready compliance reports
Vulnerability Management
We take security vulnerabilities seriously
- Dependencies are monitored and updated regularly
- Security findings are addressed on a priority basis
- Report a security concern to support@parlytics.ai
- Parlytics responds to all security reports within 48 hours
Infrastructure
Enterprise-grade infrastructure for dental DSOs
- Hosted on SOC 2 Type II–certified cloud infrastructure (Supabase), targeting 99.9%+ uptime
- Documented Business Continuity and Disaster Recovery policy (POL-DR-001) with validated restore procedures — backup restore drill completed July 2026
- Our infrastructure provider (Supabase) holds SOC 2 Type II certification — audit reports available upon request for enterprise evaluations
- Zero-downtime deployments
- US-based infrastructure only
Engineering Rigor
Built to enterprise standards
- 415 automated tests (including 43 end-to-end) run on every code change — CI/CD gates prevent broken code from reaching production
- Row-Level Security enforced on every database table, with tenant isolation verified at the database level
- Financial-grade data integrity — historical spend is never retroactively rewritten; every action is logged, append-only, and tamper-resistant
Penetration Testing
Independent security review
- Zero critical findings across extensive internal security review — external penetration test planned Q4 2026
- Internal security audits conducted on an ongoing basis, expanding to third-party assessment ahead of enterprise tier launch
- Vulnerability disclosure program active (support@parlytics.ai)
Built on trusted infrastructure
Powered by the same systems trusted across healthcare and government.
FDA openFDA Recall DatabaseNLM AccessGUDID Device RegistryAnthropic Claude AISupabase (SOC 2 Type II)
Security FAQ
Security questions dental groups ask before signing.
Enterprise & DSO Security
Have specific security requirements? Let's talk.
Whether you need a signed BAA, a vendor security questionnaire completed, or a walkthrough of our access controls — our team is ready to help your dental group get to yes.
Contact our team →