Legal references Back to overview

Data Handling & Security

This page explains how Evidentity Dentistry handles clinic-level information, governance data, operational access and service infrastructure across Canonical AI Clinic Profiles, Clinical Intelligence, AI Sites, AI Demand Mapping and managed Recommendation Control.

Data handling and service integrity

Evidentity Dentistry is designed principally around business, clinic, clinician, treatment, evidence and commercial-pathway information. The system maintains a governed representation of the organisation and observes how that organisation is interpreted across AI-mediated provider-selection environments.

This infrastructure is intentionally separated from the clinic's clinical record system. Evidentity does not need routine access to a clinic's practice-management system, EHR, patient database or diagnostic archive in order to operate the standard service.

The standard service does not require individual patient records, medical histories, radiographs, CBCT files, treatment plans or patient-identifiable clinical documentation.

Clinic onboarding and ongoing governance should therefore focus on organisation-level information: clinic identity, clinicians, locations, treatment scope, capability, technology, evidence, pricing structures, financing, warranty, aftercare, international pathways and other facts required to represent the clinic accurately.

Patient-identifiable health information should not be provided through ordinary Evidentity workflows unless a separate documented arrangement expressly establishes an appropriate scope for that information.

Clinic information is maintained through governed service workflows rather than treated as unrestricted content. Material facts can carry clinical state, evidence state, publication state, provenance, clinician and location relationships, review dates and conditions.

This architecture allows Evidentity to distinguish information intended for public AI-facing publication from information retained internally for governance, operator interpretation or change control.

Access to non-public service information is limited according to task and operational relevance. Evidentity personnel and systems should access only the information required to construct, maintain, monitor or support the applicable service.

Operational access may support profile governance, publication, monitoring, troubleshooting, reporting, recommendation analysis, intervention and customer support.

Evidentity applies administrative, technical and operational measures designed to protect service integrity and the information entrusted to the platform. Depending on the relevant system, these measures can include access controls, credential discipline, controlled production workflows, service-provider security controls, infrastructure logging, monitoring, change tracking and operational review.

Security architecture is intended to reduce unnecessary access, preserve traceability and maintain continuity across public and non-public service layers.

Public AI Sites and machine-readable surfaces are not treated as mirrors of all information held inside the Canonical AI Clinic Profile. Publication status determines which information may be exposed.

A clinic can therefore maintain internal information, unresolved evidence, conditional relationships or operator context without automatically publishing those details.

Evidentity may rely on selected third-party providers for hosting, database infrastructure, security, communications, analytics, billing and other operational functions. Current infrastructure may include providers such as Cloudflare and Supabase, together with additional services required for service delivery.

Provider access and processing are limited to the functions for which those services are used.

AI Demand Mapping and recommendation monitoring can involve interaction with independent AI systems and public information environments. Evidentity's testing architecture is designed around clinic-level recommendation scenarios rather than individual patient identities.

Scenario testing uses controlled or synthetic requirements representing classes of patient demand rather than live patient medical records.

Clinic information changes over time. Clinicians join or leave, treatment scope changes, locations acquire different capabilities, commercial conditions change and new evidence becomes available. Evidentity maintains a governed change process so material updates can propagate through the Canonical AI Clinic Profile, AI Site, recommendation context and monitoring programme without relying on disconnected manual edits across multiple surfaces.

Security and data-handling requests should be sent to:

hello@evidentity.ai

Please include the organisation name, affected service or system and sufficient information to allow the request to be triaged accurately.

Effective date September 9, 2026
Last updated September 9, 2026