Legal

Application Security Measures

Reference document

Referenced by the Privacy Policy for patients and mirrored in the DPA for dentists and clinics.

Last updated: 4 August 2026

1. Technical and organisational measures

This page lists the technical and organisational measures Perioskoup applies to protect the data processed through the Services. It is the list referenced by the Privacy Policy and corresponds to Annex 2 of the Data Processing Agreement.

  • Encryption of communications. All communications between the applications and the Services, as well as those to the providers used, take place over encrypted channels, using TLS 1.2 or higher versions. Certificates are managed and renewed automatically.
  • Protection of credentials. Passwords are stored exclusively in hashed form, using an algorithm dedicated to this purpose, with a unique salt per user; they are not stored in, and cannot be reconstructed to, clear text. On the user's device, authentication data are kept in the secure storage mechanisms provided by the operating system.
  • Document integrity: each uploaded file is assigned a checksum.
  • Access control. Access to data is governed by roles. Before access to a patient's data, the existence of the relationship between the requesting dentist and that patient is verified. Sessions have a limited duration and can be revoked. The database and the backups are encrypted.
  • Infrastructure segmentation. The databases and internal services are not accessible from the public network. External access takes place exclusively through a dedicated entry component, which handles the termination of encrypted connections.
  • Execution isolation and secrets management. The application components run in isolation, with the minimum privileges necessary for their operation. Configuration secrets are managed separately from the application code.
  • Pseudonymisation: the data transmitted to artificial intelligence service providers are stripped in advance of names, e-mail addresses and other direct identifiers.
  • Location: hosting on a dedicated server in Helsinki, Finland, in the European Union.
  • Backups: encrypted, stored separately, with rotation at no more than 90 days and periodic testing of restoration.
  • Logging and monitoring: centralised logging, an audit log of changes for treatment plans and anamneses, automatic alerting for unauthorised access.
  • Incident management: internal procedures for the detection, escalation, investigation and notification of security incidents.
  • Personnel: contractual confidentiality obligations and periodic training on data protection and information security.
  • Testing: periodic vulnerability assessment and penetration testing before launch and periodically thereafter.
  • Continuity: business continuity and disaster recovery procedures, with documented recovery time objectives.

We use cookies to measure site performance and improve your experience. Privacy Policy