Privacy & SafetyStated plainly.
For the owner dentist who signs, and the person they ask first. What is in place, what we are still building, and what we do not claim.
One cloud account, in the United States, under a BAA.
Every part of a call that touches patient data runs in one place, and we can name it.
- In place
On AWS, in a United States region
All practice data lives on Amazon Web Services (AWS), in a United States region, under our Business Associate Addendum with AWS.
- In place
One account, not a chain of vendors
The voice line, the speech model and the database run inside one AWS account, and file storage will be added to the same account. The speech model runs through AWS’s managed model service in that account. Our AWS organization has the AI-services opt-out policy set.
- In place
The improvement clause is off
An optional supplier clause that would allow our content to be used to improve their services is off, and it stays off.
- In place
The BAA comes before the first call
No call is answered before the practice signs a BAA with Leady.
- In place
Nobody at Leady listens
Nobody at Leady listens to call audio. Audio recording is off in every state until counsel clears that state.
Where we stand today.
Ten things a security reviewer asks first, with the honest status of each.
- In place
- Runs today, with evidence we can show you.
- Being built
- Designed and written down, not yet running for a practice.
- Not claimed
- We do not have it, and we do not imply it.
- Being built
Business Associate Agreement
Our standard BAA is drafted and being finalized with counsel. No call is answered and no practice data is touched before yours is signed. One BAA covers every license.
- In place
United States data residency
All practice data lives on AWS, in a United States region, under our Business Associate Addendum with AWS.
- In place
Call recording off
Off in every state. A state is switched on only after counsel clears its consent rules. No state is cleared today.
- In place
No voice prints
No voice-print or speaker-identification feature, on any license, now or later.
- Being built
Minimum-necessary reads
Your PMS is read only for what booking needs. Clinical notes, imaging, ledgers, payments and payroll are not read.
- Being built
Access logging
A record of every read of patient data: who, what, when and why. Nobody at Leady reads patient data before it exists.
- Being built
Role-based permissions
Separate permissions for the owner dentist, office manager, front desk and hygienist, set by your practice.
- Not claimed
SOC 2
Not certified.
- Not claimed
Penetration test
No third-party penetration test yet. We will say so here until we have had one.
- Not claimed
Uptime figure
Not published. We will not publish one until we measure one.
"Being built" means designed and written down, not yet running for a practice. We mark it that way everywhere on this site until it is live.
How we protect a practice, in five parts.
Each part has its own page, written for the person who reviews vendors for your practice. Start with the one they will ask about first.
Less data, by design.
What we collect and what we never read, where it is stored, how long it is kept and how it is deleted.
Read about data protectionYour practice decides who sees what.
Each person gets their own account and a role. Today the portal separates administrators from staff; per-role permissions are being built.
Read about access and rolesAgreements first. Calls last.
Going live happens in a fixed order, the same for every license. The agreement always comes first.
- STEP 01
BAA signed
Before anything else. No call is answered and no practice data is touched until it is.
- STEP 02
Your PMS connected
With a key your practice enables. We read only what booking needs.
- STEP 03
Digital Twin and test calls
Your rules written down with you, then tested on staged calls. You hear it before a patient does.
- STEP 04
First patient call
Only after the first three steps, and only in a state our legal review has cleared.
- One BAA for every license
- Audio off until your state is cleared
- Test calls before go-live
The sentences you will not find here.
A trust page is only useful if it is honest about its gaps. These are ours.
Not claimedNo SOC 2 certification
Not certified. We plan the audit after our first practices go live. No audit date is published until an auditor is engaged.
No "HIPAA certified" badge
There is no such certificate. HIPAA obligations are met in a signed agreement, not a logo.
No penetration test yet
We have not had a third-party test. This page will say so until we have.
No uptime figure
We do not publish one, because we do not yet measure one.
No promise to answer every call
Closures, an offline practice server and outages can leave a call unanswered or unbooked.
No incident record, yet
We have never had a security incident, because no practice runs on Leady in production yet. That is a fact about our age, not our controls.
Who else touches practice data.
Every supplier we use, what it does for us, what it sees and the agreement we hold with it.
| Supplier | What it does for us | What it sees | Agreement |
|---|---|---|---|
| AWS | Hosting, the voice line, the speech model, the database and storage | Patient dataPractice and patient data | Business Associate Addendum in place |
| Clerk | Staff sign-in to the portal | No patient dataStaff names, work emails and roles | Standard terms |
| Stripe | Billing the practice | No patient dataThe practice's billing details | Standard terms |
| HubSpot | Our sales records | No patient dataProspects who contact us | Standard terms |
| Google Workspace | Company email, calendar and documents | No patient dataNo patient data by design | Business Associate Agreement in place |
A supplier that would handle patient data is added here only after it has signed a Business Associate Agreement with us.
Open Dental is your system, not our supplier: Leady connects to it with your permission, through your own connector.
If this list changes, this page changes with it.
For your practice's IT, in writing.
If someone reviews vendors for your practice, send them here. We share the BAA before you sign anything, and the rest on request.
- Business Associate AgreementOur standard BAA, the same for every licenseBefore you sign
- Security overviewHow we protect practice data, in writing, for your IT consultantOn request
- Subprocessor listEach supplier by name, what it sees, and its agreementOn request
- Privacy noticeWhat we collect, why, and for how longOn request
- Terms of serviceThe customer agreement, readable onlineOnline
Security questions: security@meetleady.com · Privacy questions: privacy@meetleady.com
Available in the United States.
Your practice's data stays in a United States region wherever you are in the country. Calls are answered in English today; other languages are added only once each is tested.
- Available
United States
State by state, once our legal review clears each one. Florida first.
- Waitlist
Canada
Join the waitlist and we will write when it opens.
- Waitlist
United Kingdom
Join the waitlist and we will write when it opens.
- Waitlist
Australia
Join the waitlist and we will write when it opens.
Questions about privacy and safety
See all questionsHow does Leady handle HIPAA?
We sign a Business Associate Agreement with your practice before any call is answered or any practice data is touched, and the obligations in it are ours in writing. We do not use "HIPAA compliant" as a badge, because HIPAA is met in an agreement, not a logo.
Is there a SOC 2 report?
No. We are not certified. We plan the audit after our first practices go live, and we will not publish an audit date until an auditor is engaged.
Where is our data?
On Amazon Web Services (AWS), in a United States region, under our Business Associate Addendum with AWS. The voice line, the speech model and the database run in one AWS account.
Does anyone at Leady listen to our calls?
No. Nobody at Leady listens to call audio, and recording is off in every state. Only your practice's authorized staff can play a recording, once your state is cleared and you switch it on.
Can we get our data back if we leave?
Yes. Anything we hold is yours. On request we send you a copy and delete ours, and at termination there is a 30-day transition for exporting your data.
Who do we contact about a security issue?
Write to security@meetleady.com. Please describe what you found without including any patient information.