Skip to main content
PA
Parlytics
Security & Trust

Security you can present to your board.

Parlytics is built for healthcare-adjacent environments where data integrity, access control, and audit trails aren't optional.

Questions? hello@parlytics.ai

All systems operational

View live status and uptime history

View Status Page →

Data Protection

Your DSO's data is encrypted and isolated

  • Parlytics encrypts all data in transit (TLS) and at rest
  • Each DSO's data is logically isolated — your data is never commingled with another organization's
  • Parlytics stores no data outside the United States
  • The vendor and pricing data you upload is yours — Parlytics never shares it with other organizations or vendors

Access Controls

The right people see the right data

  • Role-based access control — admins, regional managers, and office managers each have different permission levels
  • Office managers can only see data for their assigned practice
  • Every login is authenticated — no shared passwords or guest access
  • Session management with automatic timeouts

HIPAA Posture

Built with HIPAA in mind

  • Parlytics is a supply chain platform, not an EHR — it does not store protected health information (PHI) as a primary function
  • Where patient-adjacent data appears (implant lot traceability, procedure-based planning), access is logged with user, timestamp, and action
  • Business Associate Agreements (BAAs) are available for signed client agreements
  • Audit logs are append-only and tamper-resistant

Audit & Compliance

Every action in your dental supply chain leaves a trace

  • Comprehensive audit logging across all data operations
  • Logs capture who accessed what, when, and from where
  • FDA recall traceability — implant lot numbers tracked from receipt through patient placement
  • Export-ready compliance reports

Vulnerability Management

We take security vulnerabilities seriously

  • Dependencies are monitored and updated regularly
  • Security findings are addressed on a priority basis
  • Report a security concern to support@parlytics.ai
  • Parlytics responds to all security reports within 48 hours

Infrastructure

Enterprise-grade infrastructure for dental DSOs

  • Hosted on SOC 2 Type II–certified cloud infrastructure (Supabase), targeting 99.9%+ uptime
  • Documented Business Continuity and Disaster Recovery policy (POL-DR-001) with validated restore procedures — backup restore drill completed July 2026
  • Our infrastructure provider (Supabase) holds SOC 2 Type II certification — audit reports available upon request for enterprise evaluations
  • Zero-downtime deployments
  • US-based infrastructure only

Engineering Rigor

Built to enterprise standards

  • 415 automated tests (including 43 end-to-end) run on every code change — CI/CD gates prevent broken code from reaching production
  • Row-Level Security enforced on every database table, with tenant isolation verified at the database level
  • Financial-grade data integrity — historical spend is never retroactively rewritten; every action is logged, append-only, and tamper-resistant

Penetration Testing

Independent security review

  • Zero critical findings across extensive internal security review — external penetration test planned Q4 2026
  • Internal security audits conducted on an ongoing basis, expanding to third-party assessment ahead of enterprise tier launch
  • Vulnerability disclosure program active (support@parlytics.ai)

Built on trusted infrastructure

Powered by the same systems trusted across healthcare and government.

FDA openFDA Recall DatabaseNLM AccessGUDID Device RegistryAnthropic Claude AISupabase (SOC 2 Type II)

Security FAQ

Security questions dental groups ask before signing.

Enterprise & DSO Security

Have specific security requirements? Let's talk.

Whether you need a signed BAA, a vendor security questionnaire completed, or a walkthrough of our access controls — our team is ready to help your dental group get to yes.

Contact our team →