Trust & Security
Our technical and organisational security measures tenant isolation, authentication, audit logging, and incident response.
Last Updated: 30 April 2026
At The Smile Grid (“SmileGrid,” “we,” “us,” or “our”), security is a core part of how we design, build, deploy, and operate our platform.
This Security Overview describes the security principles, controls, and operational practices we apply to protect the SmileGrid platform, customer workspaces, and data processed through the Services.
This page is intended to provide a high-level description of SmileGrid’s security approach. It is not a guarantee that the Services are immune from all vulnerabilities, outages, or threats.
No internet-connected platform can be guaranteed to be completely secure. SmileGrid applies reasonable technical and organizational safeguards designed to reduce risk and strengthen resilience.
This Security Overview applies to:
Where customer organizations use SmileGrid to manage clinic or patient-related information, this Security Overview should be read together with the applicable customer agreement, Terms of Use, and Privacy Policy.
SmileGrid is designed around the following principles:
SmileGrid is designed as a multi-tenant SaaS platform. The platform may use shared infrastructure while applying logical separation and access controls between customer environments.
Security architecture measures may include:
Where relevant, SmileGrid distinguishes between:
SmileGrid uses access controls intended to ensure users can only access the parts of the platform they are authorized to use.
Security practices may include:
Access to administrative functions may be restricted to authorized roles only.
Users are responsible for:
SmileGrid is designed to apply logical isolation between customer environments.
This may include:
SmileGrid aims to prevent users from accessing records outside their authorized tenant and clinic scope.
SmileGrid uses technical and organizational measures designed to help protect data processed through the platform.
These may include:
SmileGrid seeks to minimize unnecessary exposure of sensitive data in APIs, dashboards, logs, and user interfaces.
SmileGrid follows secure development and hardening practices designed to reduce common application security risks.
These practices may include:
Security reviews and remediation may be performed periodically as the product evolves.
SmileGrid may be deployed using cloud-hosted infrastructure and managed services.
Infrastructure-level protections may include:
Where relevant, infrastructure components may include web servers, application processes, managed databases, and supporting storage services.
Where SmileGrid supports file or asset uploads, SmileGrid applies validation and handling controls intended to reduce misuse.
These controls may include:
SmileGrid may refuse or discard files that do not meet permitted validation requirements.
SmileGrid maintains logs and audit records intended to support platform security, troubleshooting, and operational accountability.
Depending on the feature and deployment, SmileGrid may record events such as:
Logs and audit records are intended to support operational review, incident response, and accountability, while seeking to avoid unnecessary exposure of sensitive payload data.
SmileGrid aims to investigate and respond to suspected security events in a timely and structured manner.
Incident response activities may include:
Where applicable, security incidents may be handled in accordance with legal or regulatory obligations, including applicable cyber incident reporting requirements.
Incident response timelines may vary depending on the severity, scope, and nature of the event.
SmileGrid is designed with operational continuity in mind, but no service can guarantee uninterrupted availability at all times.
Operational resilience measures may include:
Planned maintenance, infrastructure events, third-party outages, or security events may affect service availability.
Security is a shared responsibility. Customer organizations and users are expected to support secure use of the platform.
Customer responsibilities include:
Customer organizations remain responsible for their own legal and professional obligations in relation to data they submit to the platform.
While SmileGrid applies reasonable safeguards, the platform cannot guarantee:
For this reason, SmileGrid treats security as an ongoing process of improvement rather than a one-time control exercise.
If you believe you have identified a security issue or vulnerability related to SmileGrid, please contact us through the designated security or support channel.
Please include, where possible:
We request that suspected vulnerabilities be reported responsibly and not exploited, publicly disclosed, or used to access data without authorization.
We may update this Security Overview from time to time to reflect changes in the platform, infrastructure, operations, or security practices.
Where we make updates, we will revise the effective date and publish the updated version.
For security-related questions or reports, please contact:
The Smile Grid [Legal Entity Name] [Registered Address] Email: [security@thesmilegrid.com] Phone: [●]
For privacy-related concerns, please refer to the Privacy Policy or Grievance page.
Questions about this policy? Contact us at our contact page or write to legal@thesmilegrid.com.