Run your lab on Toothmatrix.Request a demo
· Trust Center · v 2026-06-12

Your patients’ data,
audited & encrypted.

Toothmatrix is built for clinical labs that take security seriously. We publish our compliance posture, sub-processor list, encryption attestation, and a 1-click CISO-grade audit pack — generated live from production.

· Company

Who you’re trusting

Legal entity
Toothrocket Labs / Toothmatrix
Headquarters
Doha, Qatar
Data Protection Officer
Security contact
Uptime target
99.9% (rolling 90-day)
Bug bounty
security@toothrocket.com — responsible disclosure rewarded
· Section 02 · compliance frameworks

Where we stand.

We mark each framework honestly: compliant, controls implemented, or aligned. We never claim a certification we don’t hold.

Qatar PDPPL
Qatar Personal Data Privacy Protection Law (Law No. 13 of 2016)
Compliant
SOC 2 Type II
AICPA SOC 2 Type II — Security, Availability, Confidentiality
Controls implemented · audit in progress
Target audit · Q3 2026
ISO/IEC 27001:2022
ISO/IEC 27001:2022 — Information Security Management Systems
Controls implemented · audit in progress
Target audit · Q4 2026
EU GDPR
EU General Data Protection Regulation (2016/679)
Aligned
US HIPAA
Health Insurance Portability and Accountability Act
Aligned
· Section 03 · sub-processors

The vendors we use.

Updated quarterly. We give 30 days’ written notice before adding a new sub-processor.

VendorPurposeData classesLocation
MongoDB AtlasPrimary application databasecase data, user identifiers, audit logsMulti-region (configurable)
Stripe, Inc.Credit-card processing for credit pack top-upspayment card metadata (PCI tokens only), billing addressUnited States / Ireland
Google (Gmail SMTP)Outbound transactional email (magic-link, invoices)recipient email, case metadataUnited States
Twilio Inc.SMS + WhatsApp lab-alert notifications (optional)phone number, case status updatesUnited States / EU
Emergent CloudApplication hosting + Kubernetes runtimeall application data (encrypted at rest)Multi-region
Cloudflare, Inc.DNS, DDoS protection, CDNIP address (24-hour retention)Global edge
Encryption

TLS 1.2+ in transit · AES-256 at rest · HSTS preloaded · bcrypt-12 for credentials.

Tenant isolation

Every database query is row-level filtered by tenant_id. Cross-tenant reads are physically blocked at the data layer.

Tamper-evident audit log

Every administrative action is hash-chained (SHA-256). Modifying any row invalidates every entry that follows it.

Need the full audit pack?

Tenant-admins can download a CISO-grade PDF with hash-chain verification, SBOM, access-control review, and encryption attestation — one click from your admin console.

Last updated · 2026-06-12 06:00:03 UTC
Original text
Rate this translation
Your feedback will be used to help improve Google Translate