LabLinkSmile

LabLink Smile

Data security

A laboratory entrusts us with its activity and its clients. Here is, plainly, what we do to protect it, and what you can check.

Last updated: September 22, 2026

  1. 1

    No patient identity at the laboratory

    The laboratory never sees a patient’s name: every case carries an anonymous code, including cases received from intra-oral scanners, whose name is replaced on reception. A breach on our side would expose order references and 3D files without identity, not a patient file.

  2. 2

    Hosted in France

    The platform and its database are hosted in Paris by Clever Cloud, a French host, with the HDS (health data hosting) certification process under way. Data does not leave the European Union.

  3. 3

    Every laboratory is isolated

    Each laboratory’s data is separated at the core of the software: every read is filtered by laboratory before it reaches a screen, and an unforeseen operation is refused by default. No laboratory, no practice, can read another’s data. Each laboratory connects its own scanner and carrier accounts.

  4. 4

    Access that has to be earned

    Passwords stored hashed (bcrypt), never readable. Sign-in attempts limited per account and per address. Two-factor authentication by app, that anyone can enable and that the laboratory can require from its whole team. Sessions closed after 12 hours of inactivity. Profiles and rights per member: the workshop does not see billing, a subcontractor sees only their files.

  5. 5

    Files and documents

    Uploaded files (impressions, photos, documents) are renamed on arrival, checked for type and size, and served only to a signed-in person entitled to see them. PDFs (purchase orders, invoices, certificates) follow the same rule.

  6. 6

    Everything is traced

    Every access to patient data, every status change, every action of the publisher inside a laboratory’s space is logged with its author and date. So is every sign-in: a sign-in from an unusual country, repeated failed attempts or a mass export trigger an e-mail alert to the person concerned and to the laboratory’s management.

  7. 7

    Backups and continuity

    The database is backed up automatically every day by the host and kept for several days. A full restore of a backup was tested in September 2026, and the test is repeated every quarter. The platform is updated continuously, with no installation or server on your side: nothing to maintain, nothing left on a workstation.

  8. 8

    You remain the owner

    Your data is yours. You can export your orders, clients and invoices at any time, and take all your data with you at the end of the contract.

  9. 9

    Audit and continuous improvement

    The core underwent a security audit before going live, whose fixes were applied before any real use. Dependencies are monitored and updated. A third-party penetration test is planned before opening at scale.

  10. 10

    Report a vulnerability

    Spotted something? Write to us: we answer within 48 hours and fix as a priority. Should an incident affect your data, you are notified within 72 hours.

Security contact: contact@lablink-group.com