Patient data security in Synora
and what happens to your data
In Synora each staff member sees only what their role allows, and every view of a patient's dental chart, medical history or images is written to a log that cannot be edited. Sign-in uses strong passwords with optional two-factor codes, each clinic's data is isolated in the database, and nothing is deleted if you stop paying.
The real question: if something happens, do I lose my patients? This page says what the app does today, and what we have not done yet.
Who can see a patient's file?
Every screen and action in Synora has a permission, and without it the data is not served, even if someone opens the link directly: access is closed until a staff member's role allows it.
- Built-in roles: Owner, Branch manager, Dentist, Assistant, Receptionist, Accountant, Inventory manager and Read-only auditor.
- Reception does not see the medical file: the built-in Receptionist role registers patients, books and takes payments, but does not see the medical history, the dental chart or the images.
- Custom roles without loopholes: you can create a role with the permissions you choose, but you cannot grant anyone a permission you do not hold yourself.
- Branches: on Enterprise, a staff member works only in the branches they are assigned to.
More on roles in staff and permissions.
Is every view of a patient's file logged?
Yes. Every time someone opens a patient's dental chart, medical history or images, the user and the time are recorded. Every change to the patient's data is recorded too.
The log is append-only: the database account the app runs as has no permission to edit or delete from it. The clinic owner (and anyone allowed to review the log) sees, in the History card of each patient's file, what was done to the file and when.
How are accounts protected?
- Passwords: at least 10 characters, stored as Argon2id hashes, never as text. A password that appears in known breaches is refused without being sent anywhere: the app asks Have I Been Pwned using only the first 5 characters of its hash.
- Two-factor sign-in: optional for each user from the Security page of their account, with a code from an authenticator app on the phone and 10 recovery codes in case the phone is lost.
- Sign-in attempts: after 10 wrong attempts the account locks for 15 minutes, and sign-in requests are rate-limited per address (IP) and per account.
- Forgotten password: an email link valid for one hour and one use. Setting a new password signs out every open session on every device.
- Encrypted connection: the app is served over HTTPS only, and browsers are told to keep using HTTPS (HSTS). Two-factor secrets and integration keys (such as WhatsApp) are also encrypted inside the database.
Is each clinic's data kept apart?
Yes, at two levels. The app adds the clinic's id to every query, and the database itself (PostgreSQL) enforces the same with Row-Level Security on the clinic data tables: each row is visible only to the clinic it belongs to. The app connects with a database account that cannot bypass those rules, and isolation tests check that one clinic cannot read another's data.
Are the links shared with patients safe?
When you share a treatment plan, an invoice or images with a patient, the link always has an expiry date; you can protect it with a 4–6 digit PIN and revoke it at any time from the patient's file. The PIN is stored as an Argon2id hash, and after 5 wrong tries in 15 minutes the link stops accepting attempts for a while. Every time the link is opened, it is recorded.
If I stop paying, where does my data go?
Nowhere, and nothing is deleted. You get a reminder before the paid period ends, then seven days of grace, and then the clinic moves back to the Free plan: every file, appointment and invoice stays, and the paid modules are hidden until you pay again. The limits are on the free plan page.
Can I get my data out of Synora?
Yes, on every plan, including Free: the clinic's owner can download all of the clinic's data from Settings → Data export as one ZIP file — every table in CSV and JSON, with the images and documents — and the link works for 7 days. You can also export a single patient's file from the file itself, and reports as CSV, Excel or PDF on Pro.
Does Synora follow Egypt's data protection law (151/2020)?
Synora is built with Egypt's Personal Data Protection Law (No. 151 of 2020) in mind: role-based access, a log of every view of the medical file, and patient links that expire and can be revoked. That describes how it is designed; it is not a compliance certificate. No authority has reviewed Synora and certified it.
What have we not done yet?
- An independent penetration test: not done yet.
- Mandatory two-factor sign-in: it is optional for each user; there is no clinic setting that enforces it for all staff.
- Hosting details: encrypting the database on disk is decided at the server level, not in the app, and is not confirmed yet. We will publish it here, with where the servers are and the backup policy, once they are confirmed.
A question about your data? Contact us.
Questions about security
Not with the built-in Receptionist role: it registers patients, books and takes payments, but does not see the medical history, the dental chart or the images. If you create a custom role, you decide what it can do.
Every view of the dental chart, medical history or images is recorded with the user and the time, in a log that cannot be edited. The owner sees what was done to the file and when in the History card of the patient's file; the user's name is stored in the log but is not shown on that card yet.
Use “Forgot password?” on the sign-in page and enter your email or phone. You get an email link valid for one hour and one use. When you set a new password, every open session on every device is signed out.
No. Seven days after the paid period ends, the clinic moves back to the Free plan and all its data stays. The paid modules are hidden, and if you are over Free's limits you cannot add new patients, staff or rooms.