Founder Cohort: 50 UK practices, founder pricing for life, direct line to the founder.
Trust · Security · The honest version

Built by a dentist. Held to dentist standards.

Trust isn't a checkbox you bolt on. It's earned by being clear about what's true today, what's coming, and who's accountable when something breaks. Here's all three.

UK-built

Founder GDC-registered, UK-based

UK-hosted data

Supabase Postgres in AWS London (eu-west-2), encrypted at rest

Tenant-scoped

Every API request filters on tenant

Audit log on every mutation

Who, what, when - searchable

Built by a UK clinical director - not by a tech team guessing.

SmileOS isn't a generic SaaS rebranded for dentistry. It's built by Haroon Ismail, a UK GDC-registered clinical director who runs cosmetic and orthodontic consultations every week. Every workflow has been used in a real chair before it shipped.

  • GDC-registered - verifiable on the General Dental Council register.
  • Clinical director - running consultations, consent and treatment workflows, not just observing them.
  • UK-based - Dr Hi Ltd (t/a SmileOS), founder reachable by contact form or WhatsApp on 07457 427 086.
  • Hands-on, not hands-off - every feature is reviewed by a practising dentist before it ships.

"If a feature wouldn't survive a Monday morning in my own chair, it doesn't ship."

HI
Haroon Ismail
Founder · GDC-registered Clinical Director

What's true today, and what's coming.

Most software companies bury this. We don't, because dentists know the difference between a marketing claim and a clinically defensible one.

In production today

Live UK-hosted data

Patient data lives on Supabase Postgres in AWS London (eu-west-2), UK. Encrypted at rest and in transit over TLS. AI runs on Microsoft Azure OpenAI under our own subscription - audio transcribed in the EU (Sweden); note-drafting is moving to an EU-only data zone, safeguarded under the Microsoft DPA (EU SCCs + UK Addendum).

Live Tenant scoping at API layer

Every read and write filters on your tenant ID before touching the database. One clinician can't query another practice's records.

Live Custom JWT auth

Short-lived signed tokens, no third-party auth vendor in the data path. Password hashing with bcrypt, no plaintext storage.

Live Immutable audit log

Every mutation (case created, consent signed, payment verified) writes to an append-only audit table. Searchable by clinical director.

Live UK company

Dr Hi Ltd (t/a SmileOS), registered in the UK. Founder reachable by contact form or WhatsApp on 07457 427 086 - no support queue.

Live Stripe for payments

We don't touch card data. Payments flow through Stripe (PCI-DSS Level 1). Refunds, disputes, invoices - all via Stripe's regulated path.

Live ICO registered

Dr Hi Ltd is registered with the UK Information Commissioner's Office as a data controller, registration reference ZC221978.

Live Row-level security (RLS) defence-in-depth

Row-level security is enabled on all 36 database tables, behind the API-layer tenant scoping above. A job runs every day that tests the public key against every sensitive table and alerts us if anything is ever readable. Being straight about the shape of it: the application connects with a service role that bypasses RLS by design, so RLS is the second line, not the first.

Live Article 28 DPA, signed in-app

A versioned UK GDPR Article 28 Data Processing Agreement, presented and signed inside SmileOS before you use it. It names Dr Hi Ltd by company number and registered office, lists every sub-processor and where they process, and re-prompts you to sign again whenever the terms change. Not yet solicitor-reviewed - that is on the roadmap below.

On the founder-cohort roadmap

Coming Solicitor review of the DPA

The Article 28 DPA is live and signable in-app today (see above). Independent solicitor review of its wording is still to come, and we will say so plainly until it is done.

Coming DPIA - Data Protection Impact Assessment

We have written our own processor-side data protection assessment of the AI note-taking, and a short DPIA template your practice can complete and sign - ask and we will send both. What is still to come is the formal version reviewed with a UK dental defence union, and independent data-protection review. Until that is done we will not describe either document as reviewed.

Coming Independent penetration test

Third-party pentest scheduled before our first 50 founders go live. Findings shared with the cohort.

Coming SOC 2 / ISO 27001 alignment

Not certified - and we won't claim it until we are. We're aligning internal controls now to be audit-ready by year-end.

We deliberately don't display "ISO 27001 certified" or "HIPAA compliant" badges, because we aren't certified, and dentists know fake badges when they see them. If you need a specific compliance assurance before signing, email the founder and we'll tell you exactly where that line is for us - and when we'll cross it.

Designed around how UK dentists actually work.

Three things most dental software gets wrong - and how SmileOS handles them differently.

01

Consultation as a clinical act, not paperwork

Voice-first capture means notes happen during the consult, not after hours. The patient sees you, not your laptop.

02

Consent isn't an afterthought

Consent and estimate generation are inside the consultation flow - not a separate file the patient never receives.

03

The pipeline is the truth

Every case sits in a stage. Unsigned consents, unverified payments, missing ClinChecks - visible at a glance, not hidden in folders.

Have a compliance question? Ask Haroon directly.

Before you commit. Before you sign anything. Email the founder - you'll get a real answer, not a marketing reply.

Ask the founder →