Security, Regulatory & Compliance

Rock-solid security. Built for compliance.

An FDA-regulated device company, with software developed under a design-controlled SDLC, an active SOC 2 Type II program, and HIPAA-compliant design. The reference for security and compliance across the platform.

See Sirona in Action

How Sirona is Different

FDA-regulated, by design

Sirona is an FDA Class II device company, and the reporter is part of a Class I device product. Sirona Medical is an FDA-registered medical device establishment, and its Advanced Imaging Suite received FDA 510(k) clearance in October 2025. That regulatory posture is built into how the platform is engineered — it cannot be retrofitted onto software that was never developed under design controls.

The security & compliance stack

The programs, controls, and safeguards behind Sirona's security posture.

FDA-Regulated Device Company

Built and documented under a regulated, design-controlled SDLC. The Sirona Advanced Imaging Suite holds FDA 510(k) clearance.

SOC 2 Type II

An active SOC 2 Type II program, independently audited. The attestation is available under NDA.

HIPAA Compliance

HIPAA-compliant by design: encryption at rest and in transit, audit logging of changes to clinical information, and role-based access controls. One BAA, signed with Sirona.

Security Testing

Routine third-party security testing, vulnerability management, incident response, and continuous security monitoring.

Encryption Standards

AES-256 encryption at rest. TLS 1.2+ with strong ciphers for browser and API traffic; site integrations connect over encrypted VPN tunnels. Keys are managed in AWS KMS.

International Expansion

International expansion in progress — pursuing EU MDR certification and ISO 13485 medical device standards as the foundational pathway for our international deployment across the UK, EU, South Africa, and UAE.

Regulatory posture, security architecture, compliance framework

Documented, independently audited, and ready for your security review.

Regulatory Posture

Developed under design controls

Sirona develops under a regulated, design-controlled SDLC: documented design controls, verification, and a formal change-control process for every release. The design history goes back to the first line of code, which is why this posture cannot be added to a product later.

Regulated, design-controlled software lifecycle

Formal change control with documented verification

Quality system spanning development and deployment

FDA 510(k) clearance for the Advanced Imaging Suite (October 2025)

Security Architecture

Security built into every layer

Encryption by default (AES-256 at rest, TLS 1.2+ in transit), audit logging of changes to clinical information, role-based access controls, and routine security testing. Monitoring and incident response are continuous, not reactive.

AES-256 at rest, TLS 1.2+ in transit

Audit logging of changes to clinical information

Role-based access controls across all systems

Continuous monitoring and incident response

Compliance Framework

Independently audited.

An active SOC 2 Type II audit program, with the attestation available under NDA. HIPAA controls are assessed as part of it, and additional international certifications are in progress. Your security team reviews evidence, not adjectives.

SOC 2 Type II — active audit program

Attestation available under NDA

EU MDR and ISO 13485 in progress

Independent third-party auditors

International Expansion

International expansion, in progress

Sirona operates in the United States today, on multi-AZ, highly available AWS infrastructure. Regional data residency for markets such as the EU, the UK, and Asia-Pacific is on our roadmap, and the platform is designed so that regional deployment does not mean re-platforming. If your contracts require a specific certification or control, raise it with your Sirona representative and we scope it as part of onboarding.

United States: live today

Regional data residency (Roadmap)

EU MDR + ISO 13485 pathway for medical device access, in progress

The same unified platform in every market

A security posture you can prove

SOC 2

Type II, an active program — attestation available under NDA

AES-256

encryption at rest, TLS 1.2+ in transit

Keys managed in AWS KMS

510(k)

clearance for the Sirona Advanced Imaging Suite — October 2025

HIPAA

compliant by design

One BAA, signed with Sirona

Built for security and compliance leaders

The RadOS architecture fireside — how Sirona is built.

FAQs