Kythro

Patient data is non-negotiable.

A clinic management system holds the most sensitive data your practice owns. We treat it that way. Kythro is built on Google Cloud, with encryption at rest and in transit, region-locked storage in India, and per clinic isolation enforced at the database layer.

Where data lives

  • Patient records, appointments, treatment plans, payments: Google Cloud Firestore, asia-south1 region (Mumbai)
  • Photos and radiographs: Google Cloud Storage, asia-south1 region
  • Authentication: Firebase Auth, Google Identity Platform

How data is protected

  • Encrypted at rest by default (Google managed keys)
  • TLS for all client and server traffic
  • Per clinic Firestore security rules enforce isolation at the database
  • Role-based access control for team members within a clinic
  • Server-side admin access is audited and requires written customer approval

Backups and recovery

Firestore is automatically backed up by Google Cloud, with point in time recovery available for 7 days. In a disaster scenario we can restore an entire clinic to any point within that window.

Compliance

Kythro follows industry standard practices for healthcare-adjacent software. India does not currently have a HIPAA equivalent specifically for dental software, but our security posture is built to meet the DPDP Act 2023 obligations for healthcare data. We will publish formal compliance certifications as they become applicable.

Security FAQ

Where is my clinic's data stored?

Kythro stores all patient data in Google Cloud Firestore in the asia-south1 region (Mumbai). Files like photos and radiographs are stored in Google Cloud Storage in the same region. Data does not leave India.

Is data encrypted?

Yes. All data is encrypted at rest using Google's default Firestore and Cloud Storage encryption, and encrypted in transit over TLS. Authentication uses Firebase Auth with Google or password sign in.

How is data isolated between clinics?

Kythro uses Firestore security rules that enforce per clinic isolation at the database layer. A team member cannot read or write data for a clinic they have not been granted access to, even if they bypass the user interface and call the database directly.

Who can access my clinic's data?

Only team members you have explicitly invited and assigned to your clinic. Kythro's own staff do not access clinic data without an explicit support request from you, captured in writing.

What happens if I cancel?

Your data remains exportable for 30 days after cancellation. Patient and treatment records can be exported as CSV at any time. After 30 days, data is permanently deleted from active storage.

Are there backups?

Firestore is automatically backed up daily by Google Cloud, with point in time recovery available for 7 days. We can restore an entire clinic to any point within that window.

Run your clinic on Kythro.

Start a free 30 day trial. No credit card required.