Skip to content
Security

Your building. Your data. Our discipline.

Chartwright deploys on your practice's own server. Patient information stays inside your walls — Chartwright never stores or possesses it, and support work happens on your system, under your authority and supervision. No dependency on outside servers, no third-party data brokers, no per-seat telemetry. We publish what the software does; how it does it is our trade secret, and we're glad to walk qualified practices through it under NDA.

Found a vulnerability? Tell us: security@chartwright.io — we read every report.

  • Isolation

    Every practice's data lives in its own deployment, on its own server. There is no shared table where one office could see another's work.

  • Rotatable keys

    Encryption keys can be rotated on your schedule, not ours. Old data re-encrypts under the new key; the old key is destroyed.

  • Append-only audit

    Every write is attributed and permanent. You can see who did what, and when. Records can be corrected — never silently overwritten.

  • Snapshots

    Point-in-time snapshots on your retention window. If something looks wrong today, you can see exactly what it looked like last Tuesday.

  • Export anytime

    Your data is exportable in an open format on demand — not as a favor, and not for a fee. If you ever leave Chartwright, you take everything with you.

What lives where, in one list.

On your server
  • Patient identifiers and demographics
  • Clinical notes
  • Radiographs and photos
  • Treatment plans
  • Everything the three products produce
At Chartwright
  • Your account and billing contact
  • Support correspondence you send us
  • Nothing about your patients. Not their name. Not their birthdate. Nothing.

We do not display third-party compliance badges we have not earned. If we ever hold a formal certification, it will appear here with the certificate. Not before.

Questions your IT person will ask? Bring them.

Request a walkthrough →