LabLink Smile
Data security
A laboratory entrusts us with its activity and its clients. Here is, plainly, what we do to protect it, and what you can check.
Last updated: September 22, 2026
- 1
No patient identity at the laboratory
The laboratory never sees a patient’s name: every case carries an anonymous code, including cases received from intra-oral scanners, whose name is replaced on reception. A breach on our side would expose order references and 3D files without identity, not a patient file.
- 2
Hosted in France
The platform and its database are hosted in Paris by Clever Cloud, a French host, with the HDS (health data hosting) certification process under way. Data does not leave the European Union.
- 3
Every laboratory is isolated
Each laboratory’s data is separated at the core of the software: every read is filtered by laboratory before it reaches a screen, and an unforeseen operation is refused by default. No laboratory, no practice, can read another’s data. Each laboratory connects its own scanner and carrier accounts.
- 4
Access that has to be earned
Passwords stored hashed (bcrypt), never readable. Sign-in attempts limited per account and per address. Two-factor authentication by app, that anyone can enable and that the laboratory can require from its whole team. Sessions closed after 12 hours of inactivity. Profiles and rights per member: the workshop does not see billing, a subcontractor sees only their files.
- 5
Files and documents
Uploaded files (impressions, photos, documents) are renamed on arrival, checked for type and size, and served only to a signed-in person entitled to see them. PDFs (purchase orders, invoices, certificates) follow the same rule.
- 6
Everything is traced
Every access to patient data, every status change, every action of the publisher inside a laboratory’s space is logged with its author and date. So is every sign-in: a sign-in from an unusual country, repeated failed attempts or a mass export trigger an e-mail alert to the person concerned and to the laboratory’s management.
- 7
Backups and continuity
The database is backed up automatically every day by the host and kept for several days. A full restore of a backup was tested in September 2026, and the test is repeated every quarter. The platform is updated continuously, with no installation or server on your side: nothing to maintain, nothing left on a workstation.
- 8
You remain the owner
Your data is yours. You can export your orders, clients and invoices at any time, and take all your data with you at the end of the contract.
- 9
Audit and continuous improvement
The core underwent a security audit before going live, whose fixes were applied before any real use. Dependencies are monitored and updated. A third-party penetration test is planned before opening at scale.
- 10
Report a vulnerability
Spotted something? Write to us: we answer within 48 hours and fix as a priority. Should an incident affect your data, you are notified within 72 hours.
Security contact: contact@lablink-group.com