Trust Centre
Clinical photography contains sensitive patient information. SmileSort is designed to protect it throughout its lifecycle — from upload and storage to sharing and deletion.
Last reviewed 25 September 2026
HTTPS only, encryption at rest, and each practice's data kept strictly separate.
Learn moreYour practice controls its patients' data. SmileSort processes it for you, keeps it only as long as set out, and uses it for nothing else.
Learn moreWhat the AI does with a photograph, and what our AI provider keeps: no training, deleted within 30 days.
Learn moreAn administrative tool for clinical photography, not a medical device. SmileSort doesn't diagnose or recommend treatment.
Learn moreExternal security testing and certification as SmileSort progresses towards wider deployment.
Learn moreFive services, each checked and bound by its own data processing agreement.
Learn moreSecurity
Protection at every stage of the clinical photography workflow.
Clinical data is encrypted in transit — every page is served over HTTPS only — and at rest, with AES-256.
Sessions are verified against the identity provider on every request, not just decoded from a cookie — a revoked or expired session can't be replayed.
Every table and every photo file is protected by rules in the database itself: anything done on a dentist's behalf reaches their own practice's data and nothing else, whatever the application asks for. The few server tasks that run without a signed-in dentist — opening a share link, the nightly clean-up — are limited to one practice in code.
A share link uses a 192-bit random token, opens only the folders or photographs it was created for, stops working after 7 days unless you extend it, and can be revoked at any time.
No SmileSort tool — including our internal admin portal — can show our team your patients' photographs, folders or notes; that's enforced in the database, not just hidden in the interface. Direct access to the production database is limited to SmileSort's co-founders.
The database is backed up daily, with a week of backups kept. Photograph files are not currently covered by a separate file-level backup — a gap we've assessed and disclose rather than assume away.
Privacy & Data
Designed around data minimisation, transparency and controlled processing of patient photography.
SmileSort's data protection programme is built around UK GDPR, with a Data Protection Impact Assessment (signed September 2026) and a Record of Processing Activities, both kept internally.
SmileSort Ltd's registration with the Information Commissioner's Office is being processed. The registration number will be published here once it's issued.
Your practice determines why clinical photographs are processed; SmileSort processes that data to provide the service, as your processor. SmileSort separately acts as controller for its own account and billing information.
AI classification never receives a patient name, date of birth or other structured identifier — only the photograph itself. Location data in a photograph's file is never read.
Deleted records stay in Trash for 28 days, then are permanently removed. A cancelled account stays read-only and exportable for 30 days; then every patient record, photograph and login is permanently deleted. Billing records stay with Stripe, as tax law requires, and usage statistics are kept only in anonymous form. Your practice remains responsible for its own clinical record-keeping obligations.
Every filed photograph, patient record and folder can be exported as a single archive at any time, including during the 30 days after cancelling — you're not locked into SmileSort to keep your own records.
Anthropic (AI classification), Supabase (database & storage), Cloudflare (hosting), Stripe and Resend (billing and email — no patient data) — every one individually checked, none holding patient data outside the UK/EU without an EU SCC + UK Addendum transfer mechanism in place.
AI
What SmileSort's AI actually does with a clinical photograph, and what it doesn't.
AI does two things in SmileSort: it recognises which standard view each photograph is, and helps group photographs taken at the same appointment. It doesn't interpret what a photograph shows.
You check every AI result. A batch upload waits for your approval before anything is filed. In a Clinical Series, recognised views go straight into their slots for you to check — drag any photograph to another slot or take it out — and anything SmileSort can't place waits under Needs review.
Photographs go to Anthropic, our AI provider, for those two tasks only, under Anthropic's Data Processing Addendum, which includes the EU Standard Contractual Clauses and the UK Addendum for the transfer to the US. Anthropic deletes what it receives within 30 days, and keeps it longer only if its safety systems flag a request or the law requires it.
Anthropic doesn't train its models on data sent through its API, and SmileSort hasn't joined the opt-in programme that would change that. SmileSort doesn't use your patients' photographs for marketing, research or improving its own AI.
Clinical & Regulatory
SmileSort is not a medical device. It stores, organises and shares clinical photographs — every clinical judgement stays with you.
SmileSort is an administrative tool for storing, organising and communicating clinical photographs. Under the UK Medical Devices Regulations 2002, software limited to storage, archiving, communication and simple search isn't a medical device, and SmileSort's intended purpose stays within that.
SmileSort's AI recognises which standard view a photograph is — an upper occlusal, a smile, a left buccal — and groups photographs taken at the same appointment. That's how it knows where to file them. It doesn't assess the teeth, detect conditions, measure anything or suggest a diagnosis.
Sharing sends photographs to a lab or colleague as you see them in SmileSort, through a secure link that expires. The file is the one you stored; a rotation or flip you applied travels with it as the standard orientation tag that photo software reads. SmileSort adds no interpretation or annotation.
SmileSort doesn't recommend treatment, highlight areas of concern or automate clinical decisions. A photograph filed in the wrong place is a filing error you can correct, not a clinical output.
Before any new AI feature is built, it's checked against SmileSort's intended purpose. Anything that would interpret the clinical content of a photograph would need a fresh regulatory assessment first.
We're putting the NHS clinical risk management standard for health software in place, led by co-founder Dr Abdelrahman Mohamed, a GDC-registered dentist, as Clinical Safety Officer. It covers the ways a filing or sharing mistake could affect a patient's care — a photograph filed to the wrong patient, or shown the wrong way round.
Assurance
A status roadmap, not a certification wall — what's done, in progress, and planned.
UK government-backed baseline cyber security certification.
A third-party security assessment of the live application.
The audited tier of Cyber Essentials, following the base certification.
Formal information security management certification.
Documents
Published in full, not gated behind a request form.
How SmileSort handles your own account data.
The full Article 28 terms governing your patients' data.
The contract governing your use of SmileSort.
Every cookie SmileSort sets, and why.
Every third party, what it receives, and its transfer mechanism.
How long data is kept, and what happens when it's deleted.
How to report a security issue directly to us, and how to test safely.
If you're reviewing SmileSort for your practice or have a security question, we'd be happy to help.
Contact securityFound a vulnerability? Read our Responsible Disclosure Policy before you test.
Last reviewed 25 September 2026.