
Security, Regulatory & Compliance
Rock-solid security. Built for compliance.
An FDA-regulated device company, with software developed under a design-controlled SDLC, an active SOC 2 Type II program, and HIPAA-compliant design. The reference for security and compliance across the platform.
How Sirona is Different
FDA-regulated, by design
Sirona is an FDA Class II device company, and the reporter is part of a Class I device product. Sirona Medical is an FDA-registered medical device establishment, and its Advanced Imaging Suite received FDA 510(k) clearance in October 2025. That regulatory posture is built into how the platform is engineered — it cannot be retrofitted onto software that was never developed under design controls.
The security & compliance stack
The programs, controls, and safeguards behind Sirona's security posture.
FDA-Regulated Device Company
Built and documented under a regulated, design-controlled SDLC. The Sirona Advanced Imaging Suite holds FDA 510(k) clearance.
SOC 2 Type II
An active SOC 2 Type II program, independently audited. The attestation is available under NDA.
HIPAA Compliance
HIPAA-compliant by design: encryption at rest and in transit, audit logging of changes to clinical information, and role-based access controls. One BAA, signed with Sirona.
Security Testing
Routine third-party security testing, vulnerability management, incident response, and continuous security monitoring.
Encryption Standards
AES-256 encryption at rest. TLS 1.2+ with strong ciphers for browser and API traffic; site integrations connect over encrypted VPN tunnels. Keys are managed in AWS KMS.
International Expansion
International expansion in progress — pursuing EU MDR certification and ISO 13485 medical device standards as the foundational pathway for our international deployment across the UK, EU, South Africa, and UAE.
Regulatory posture, security architecture, compliance framework
Documented, independently audited, and ready for your security review.
Regulatory Posture
Developed under design controls
Sirona develops under a regulated, design-controlled SDLC: documented design controls, verification, and a formal change-control process for every release. The design history goes back to the first line of code, which is why this posture cannot be added to a product later.
Regulated, design-controlled software lifecycle
Formal change control with documented verification
Quality system spanning development and deployment
FDA 510(k) clearance for the Advanced Imaging Suite (October 2025)
Security Architecture
Security built into every layer
Encryption by default (AES-256 at rest, TLS 1.2+ in transit), audit logging of changes to clinical information, role-based access controls, and routine security testing. Monitoring and incident response are continuous, not reactive.
AES-256 at rest, TLS 1.2+ in transit
Audit logging of changes to clinical information
Role-based access controls across all systems
Continuous monitoring and incident response
Compliance Framework
Independently audited.
An active SOC 2 Type II audit program, with the attestation available under NDA. HIPAA controls are assessed as part of it, and additional international certifications are in progress. Your security team reviews evidence, not adjectives.
SOC 2 Type II — active audit program
Attestation available under NDA
EU MDR and ISO 13485 in progress
Independent third-party auditors
International Expansion
International expansion, in progress
Sirona operates in the United States today, on multi-AZ, highly available AWS infrastructure. Regional data residency for markets such as the EU, the UK, and Asia-Pacific is on our roadmap, and the platform is designed so that regional deployment does not mean re-platforming. If your contracts require a specific certification or control, raise it with your Sirona representative and we scope it as part of onboarding.
United States: live today
Regional data residency (Roadmap)
EU MDR + ISO 13485 pathway for medical device access, in progress
The same unified platform in every market
A security posture you can prove
SOC 2
Type II, an active program — attestation available under NDA
AES-256
encryption at rest, TLS 1.2+ in transit
Keys managed in AWS KMS
510(k)
clearance for the Sirona Advanced Imaging Suite — October 2025
HIPAA
compliant by design
One BAA, signed with Sirona
Built for security and compliance leaders
The RadOS architecture fireside — how Sirona is built.
FAQs
What does SOC 2 Type II mean?
Is Sirona FDA-regulated?
What encryption does Sirona use?
How does Sirona handle HIPAA compliance?
What is the security testing process?
What regulatory certifications is Sirona pursuing for international markets?