Now onboarding Open Dental practices. Apply for the betaApply
Trust center

Privacy & SafetyStated plainly.

For the owner dentist who signs, and the person they ask first. What is in place, what we are still building, and what we do not claim.

Last reviewed 27 September 2026 · Questions go to security@meetleady.com
Where your data lives

One cloud account, in the United States, under a BAA.

Every part of a call that touches patient data runs in one place, and we can name it.

The path of a call
  • In place

    On AWS, in a United States region

    All practice data lives on Amazon Web Services (AWS), in a United States region, under our Business Associate Addendum with AWS.

  • In place

    One account, not a chain of vendors

    The voice line, the speech model and the database run inside one AWS account, and file storage will be added to the same account. The speech model runs through AWS’s managed model service in that account. Our AWS organization has the AI-services opt-out policy set.

  • In place

    The improvement clause is off

    An optional supplier clause that would allow our content to be used to improve their services is off, and it stays off.

  • In place

    The BAA comes before the first call

    No call is answered before the practice signs a BAA with Leady.

  • In place

    Nobody at Leady listens

    Nobody at Leady listens to call audio. Audio recording is off in every state until counsel clears that state.

Where we stand today

Where we stand today.

Ten things a security reviewer asks first, with the honest status of each.

In place
Runs today, with evidence we can show you.
Being built
Designed and written down, not yet running for a practice.
Not claimed
We do not have it, and we do not imply it.
Status as of 27 September 2026
  • Being built

    Business Associate Agreement

    Our standard BAA is drafted and being finalized with counsel. No call is answered and no practice data is touched before yours is signed. One BAA covers every license.

  • In place

    United States data residency

    All practice data lives on AWS, in a United States region, under our Business Associate Addendum with AWS.

  • In place

    Call recording off

    Off in every state. A state is switched on only after counsel clears its consent rules. No state is cleared today.

  • In place

    No voice prints

    No voice-print or speaker-identification feature, on any license, now or later.

  • Being built

    Minimum-necessary reads

    Your PMS is read only for what booking needs. Clinical notes, imaging, ledgers, payments and payroll are not read.

  • Being built

    Access logging

    A record of every read of patient data: who, what, when and why. Nobody at Leady reads patient data before it exists.

  • Being built

    Role-based permissions

    Separate permissions for the owner dentist, office manager, front desk and hygienist, set by your practice.

  • Not claimed

    SOC 2

    Not certified.

  • Not claimed

    Penetration test

    No third-party penetration test yet. We will say so here until we have had one.

  • Not claimed

    Uptime figure

    Not published. We will not publish one until we measure one.

"Being built" means designed and written down, not yet running for a practice. We mark it that way everywhere on this site until it is live.

Five pillars

How we protect a practice, in five parts.

Each part has its own page, written for the person who reviews vendors for your practice. Start with the one they will ask about first.

Before the first call

Agreements first. Calls last.

Going live happens in a fixed order, the same for every license. The agreement always comes first.

  1. STEP 01

    BAA signed

    Before anything else. No call is answered and no practice data is touched until it is.

  2. STEP 02

    Your PMS connected

    With a key your practice enables. We read only what booking needs.

  3. STEP 03

    Digital Twin and test calls

    Your rules written down with you, then tested on staged calls. You hear it before a patient does.

  4. STEP 04

    First patient call

    Only after the first three steps, and only in a state our legal review has cleared.

  • One BAA for every license
  • Audio off until your state is cleared
  • Test calls before go-live
What we do not claim

The sentences you will not find here.

A trust page is only useful if it is honest about its gaps. These are ours.

Not claimed
  • No SOC 2 certification

    Not certified. We plan the audit after our first practices go live. No audit date is published until an auditor is engaged.

  • No "HIPAA certified" badge

    There is no such certificate. HIPAA obligations are met in a signed agreement, not a logo.

  • No penetration test yet

    We have not had a third-party test. This page will say so until we have.

  • No uptime figure

    We do not publish one, because we do not yet measure one.

  • No promise to answer every call

    Closures, an offline practice server and outages can leave a call unanswered or unbooked.

  • No incident record, yet

    We have never had a security incident, because no practice runs on Leady in production yet. That is a fact about our age, not our controls.

Subprocessors

Who else touches practice data.

Every supplier we use, what it does for us, what it sees and the agreement we hold with it.

Request the subprocessor list
Suppliers, what each does for Leady, what each sees, and the agreement in place
SupplierWhat it does for usWhat it seesAgreement
AWSHosting, the voice line, the speech model, the database and storagePatient dataPractice and patient dataBusiness Associate Addendum in place
ClerkStaff sign-in to the portalNo patient dataStaff names, work emails and rolesStandard terms
StripeBilling the practiceNo patient dataThe practice's billing detailsStandard terms
HubSpotOur sales recordsNo patient dataProspects who contact usStandard terms
Google WorkspaceCompany email, calendar and documentsNo patient dataNo patient data by designBusiness Associate Agreement in place

A supplier that would handle patient data is added here only after it has signed a Business Associate Agreement with us.

Open Dental is your system, not our supplier: Leady connects to it with your permission, through your own connector.

If this list changes, this page changes with it.

Documents

For your practice's IT, in writing.

If someone reviews vendors for your practice, send them here. We share the BAA before you sign anything, and the rest on request.

  • Business Associate AgreementOur standard BAA, the same for every license
    Before you sign
  • Security overviewHow we protect practice data, in writing, for your IT consultant
    On request
  • Subprocessor listEach supplier by name, what it sees, and its agreement
    On request
  • Privacy noticeWhat we collect, why, and for how long
    On request
  • Terms of serviceThe customer agreement, readable online
    Online

Security questions: security@meetleady.com · Privacy questions: privacy@meetleady.com

Request our security documents

Tell us who is asking. We reply by email within one business day. Please don't include patient information.

Documents

We use your details only to reply to this request.

Availability

Available in the United States.

Your practice's data stays in a United States region wherever you are in the country. Calls are answered in English today; other languages are added only once each is tested.

  • Available

    United States

    State by state, once our legal review clears each one. Florida first.

  • Waitlist

    Canada

    Join the waitlist and we will write when it opens.

  • Waitlist

    United Kingdom

    Join the waitlist and we will write when it opens.

  • Waitlist

    Australia

    Join the waitlist and we will write when it opens.

See all questions

How does Leady handle HIPAA?

We sign a Business Associate Agreement with your practice before any call is answered or any practice data is touched, and the obligations in it are ours in writing. We do not use "HIPAA compliant" as a badge, because HIPAA is met in an agreement, not a logo.

Is there a SOC 2 report?

No. We are not certified. We plan the audit after our first practices go live, and we will not publish an audit date until an auditor is engaged.

Where is our data?

On Amazon Web Services (AWS), in a United States region, under our Business Associate Addendum with AWS. The voice line, the speech model and the database run in one AWS account.

Does anyone at Leady listen to our calls?

No. Nobody at Leady listens to call audio, and recording is off in every state. Only your practice's authorized staff can play a recording, once your state is cleared and you switch it on.

Can we get our data back if we leave?

Yes. Anything we hold is yours. On request we send you a copy and delete ours, and at termination there is a 30-day transition for exporting your data.

Who do we contact about a security issue?

Write to security@meetleady.com. Please describe what you found without including any patient information.

Keep exploring