Built for Healthcare. Secured for Trust.
Smile PreVue is designed with HIPAA compliance, encryption, and audit logging from the ground up. Not bolted on after the fact.
HIPAA-Aligned Workflows
Built on Google Cloud under a Business Associate Agreement. Google lists Cloud Run, Cloud SQL, Cloud Storage, and its generative AI platform, where Vertex AI runs our smile previews, dictation transcription, and clinical note drafting, among the products its BAA covers.
Encrypted Storage
Patient photos and data live on Google Cloud, which encrypts all stored customer data at rest by default using AES-256. Every image is served through a signed URL that expires.
Role-Based Access Control
Four distinct roles (provider, nurse, office admin, owner) ensure team members only access what they need.
Audit Logging
Changes your team makes to patients, simulations, consent, share links, treatment plans, payments, team members, and agreements are logged with the user, the time, and the IP address and user agent of the request.
Consent Management
Consent is recorded per type, with who recorded it, the signature, and any revocation. Practices can require HIPAA consent, and when they do, a simulation cannot run until that consent is on file.
Expiring Share Links
Patient preview links automatically expire. No patient data persists publicly beyond the configured window.
Clinical Notes and Recordings
Dictation audio, transcripts, and notes live on the patient record with clinic-level isolation. Audio plays back only for signed-in staff through links that expire after 15 minutes, opening a recording is logged, and it is deleted with the note.
Previews Are Graded, Not Just Generated
Every AI preview is checked by a second model against the patient's original photo, on the same BAA-covered infrastructure. The grader is instructed to assess only the teeth, the framing, and whether everything else was left unchanged, and never to describe the patient. The resulting Fidelity Score is visible to the clinical team only.
PCI-Compliant Payments
Patient payments are processed by Stripe, certified to PCI DSS Level 1, the highest level of payment-card security. Card details are entered directly into Stripe and never touch our servers.
Architecture Built for Isolation
Row-Level Clinic Isolation
Each clinic's data is strictly isolated through row-level filtering. There is no multi-tenant data mixing. One clinic's patients, simulations, and records are never accessible to another.
Firebase Authentication
Team members sign in through Firebase with email and password, Google, or Sign in with Apple. Every signed-in request to our API is verified against a Firebase token on the backend.
AI Processing Under BAA
AI smile simulations are generated through Google Vertex AI (Gemini 3 Pro Image), which is covered by our Google Cloud Business Associate Agreement. Google's terms for Vertex AI state that it will not use customer data to train or fine-tune its AI models without the customer's permission. Billing is handled through Stripe with no patient data exposure.
Payments Without Card-Data Exposure
Patient payments run on Stripe, a PCI DSS Level 1 certified provider, the highest level of payment-card security. Card details are captured directly by Stripe and never reach Smile PreVue. Just as patient records never enter the payment system, card data never enters ours.
How Patient Data Is Handled
What happens to patient information inside Smile PreVue, from the signed agreement to the moment a record is deleted.
A Signed BAA for Every Practice
The practice owner signs our Business Associate Agreement inside the dashboard, on the subscription page, alongside the service agreement. Once signed, the agreement can be viewed and downloaded as a PDF at any time. Practices that collect patient payments also sign a separate Payments Services Agreement before payments can be set up.
Patient Photos and AI Processing
A patient photo uploads directly to Google Cloud Storage through a signed upload link. Before the photo reaches any AI model, Smile PreVue strips its embedded EXIF metadata and replaces the upload with the cleaned file. Every AI task, from smile previews to clinical note drafts, runs on Google Cloud Vertex AI under our Google Cloud Business Associate Agreement. Finished previews are saved under your clinic's own storage path and shown through signed links, not public ones.
Audit Logs Without Patient Details
Key actions, including treatment plan and payment activity, are written to a clinic audit log that the practice owner can review from the Audit Log page. The log records identifiers rather than health information: treatment plan entries carry IDs and amounts, and a patient's email address is never stored in the log, only its domain. Audit records are retained for HIPAA purposes even after an account is deleted.
Access Limited by Role and Clinic
Every dashboard request must carry a verified sign-in token. Apart from the sign-in screens, the only pages open without an account are a patient's own share and pay links. Your team signs in with email and password, Google, or Sign in with Apple, and the iOS app adds Face ID or Touch ID quick sign-in. Roles are enforced on the server as well as in the app, and clinic settings, payment setup, team management, the subscription, and the audit log are limited to the practice owner. Production database connections must run through the Cloud SQL Auth Proxy or require SSL, and the service will not start otherwise.
What Is Stored, and What Is Not
Your clinic's records hold patient photos and previews, consent records, share links, post-procedure photos, treatment plans, and clinical notes with their dictation audio and transcripts, plus the past notes a provider adds to set up their writing style. Card numbers are never stored by Smile PreVue. Patient health information never enters Stripe or the financing partners: Stripe receives only opaque IDs, the amount, and a receipt email. The dashboard's analytics never receive patient data either. Deleting a patient purges that patient's records, and deleting an account purges all of its patient data from both our database and file storage.