Security at AxonTron
AxonTron finishes what it starts — but never behind your back. For every dental and medical customer we operate as a Business Associate under HIPAA, and security here is architecture, not policy documents: the safe path is the only path the software offers.
Tenant isolation
Every clinical row carries its tenant. Cross-tenant access is rejected at the data layer, not by convention — one practice can never see another's data.
Plane separation
Vendor, practice, and patient run on separate portals with separate logins. AxonTron staff cannot browse client PHI — there is no impersonation path, by design (HIPAA minimum-necessary).
Human gates
No AI output leaves the building on its own. External submissions and record commits require an authorized human approval, and the gate cannot be bypassed.
Encryption everywhere
TLS in transit on every endpoint; encryption at rest for the database and backups. Secrets live in a managed vault, never in code or images.
Append-only audit trail
Every action — human or agent — is recorded with who, what, and when. Audit history cannot be edited or deleted, including by us.
Least-privilege access
Role-based access control (admin, clinician, reviewer, biller, patient) governs every route and every approval. Service credentials are scoped to exactly what each component needs.
HIPAA & Business Associate Agreements
AxonTron, Inc. signs a Business Associate Agreement (BAA) with every covered-entity customer before any PHI is processed. Our AI providers are used under agreements that prohibit training on your data.
AI safety posture
Supervised autonomy is a security control, not just a product feature: confidence gating decides what needs human eyes, hard gates stand before all external actions, safety checks on orders cannot be silently disabled, and every agent step is audited. Voice assistants answer administrative questions only and never give medical advice.
Data portability & deletion
One-click, no-fee export of your complete record set, any time. When you leave, data is returned and then deleted on the schedule in our data deletion policy — leaving is as easy as joining.
Reporting a vulnerability
Found something? Email support@axontron.com with the subject SECURITY. We acknowledge within one business day and keep you informed through the fix. Good-faith research is welcome; we don't pursue researchers who respect patient privacy and the law.