Founder Cohort: 50 UK practices, founder pricing for life, direct line to the founder.
Trust · Security · The honest version

Built by a dentist. Held to dentist standards.

Trust isn't a checkbox you bolt on. It's earned by being clear about what's true today, what's coming, and who's accountable when something breaks. Here's all three.

UK-built

Founder GDC-registered, UK-based

EU-hosted data

Supabase (Frankfurt), encrypted at rest

Tenant-scoped

Every API request filters on tenant

Audit log on every mutation

Who, what, when — searchable

Built by a UK clinical director — not by a tech team guessing.

SmileOS isn't a generic SaaS rebranded for dentistry. It's built by Haroon Ismail, a UK GDC-registered clinical director who runs cosmetic and orthodontic consultations every week. Every workflow has been used in a real chair before it shipped.

  • GDC-registered — verifiable on the General Dental Council register.
  • Clinical director — running consultations, consent and treatment workflows, not just observing them.
  • UK-based — SmileOS Ltd, founder reachable by email or WhatsApp.
  • Hands-on, not hands-off — every feature is reviewed by a practising dentist before it ships.
"If a feature wouldn't survive a Monday morning in my own chair, it doesn't ship."
HI
Haroon Ismail
Founder · GDC-registered Clinical Director

What's true today, and what's coming.

Most software companies bury this. We don't, because dentists know the difference between a marketing claim and a clinically defensible one.

In production today

Live EU/UK-hosted data

Patient data lives on Supabase Postgres in Frankfurt (eu-central-1). Encrypted at rest, in transit over TLS, and never leaves European infrastructure.

Live Tenant scoping at API layer

Every read and write filters on your tenant ID before touching the database. One clinician can't query another practice's records.

Live Custom JWT auth

Short-lived signed tokens, no third-party auth vendor in the data path. Password hashing with bcrypt, no plaintext storage.

Live Immutable audit log

Every mutation (case created, consent signed, payment verified) writes to an append-only audit table. Searchable by clinical director.

Live UK company

SmileOS Ltd, registered in the UK. Founder reachable by email or WhatsApp directly — no support queue.

Live Stripe for payments

We don't touch card data. Payments flow through Stripe (PCI-DSS Level 1). Refunds, disputes, invoices — all via Stripe's regulated path.

On the founder-cohort roadmap

Coming Row-level security (RLS) defence-in-depth

Tenant scoping at the API layer is enforced today. We're adding database-level row-level security as a second layer before public launch.

Coming Formal DPA template

A Data Processing Agreement reviewed by our solicitor, ready to sign per practice. Currently bespoke — happy to talk through what we'll commit to before you sign.

Coming DPIA — Data Protection Impact Assessment

Formal DPIA covering AI-assisted clinical notes, in collaboration with a UK dental defence union. Shared with founder cohort once complete.

Coming ICO data controller registration

Registration with the UK Information Commissioner's Office as a data controller. We're a processor today; controller registration is on the immediate roadmap.

Coming Independent penetration test

Third-party pentest scheduled before our first 50 founders go live. Findings shared with the cohort.

Coming SOC 2 / ISO 27001 alignment

Not certified — and we won't claim it until we are. We're aligning internal controls now to be audit-ready by year-end.

We deliberately don't display "ISO 27001 certified" or "HIPAA compliant" badges, because we aren't certified, and dentists know fake badges when they see them. If you need a specific compliance assurance before signing, email the founder and we'll tell you exactly where that line is for us — and when we'll cross it.

Designed around how UK dentists actually work.

Three things most dental software gets wrong — and how SmileOS handles them differently.

Consultation as a clinical act, not paperwork

Voice-first capture means notes happen during the consult, not after hours. The patient sees you, not your laptop.

Consent isn't an afterthought

Consent and estimate generation are inside the consultation flow — not a separate file the patient never receives.

The pipeline is the truth

Every case sits in a stage. Unsigned consents, unverified payments, missing ClinChecks — visible at a glance, not hidden in folders.

Have a compliance question? Ask Haroon directly.

Before you commit. Before you sign anything. Email the founder — you'll get a real answer, not a marketing reply.

Email the founder