All articles
Buying guide3 August 2026 9 min read

Six questions to ask any AI dental software vendor — and how to check the answers

Every vendor now says their AI is secure and Canadian. These are the questions that separate the ones telling the truth from the ones saying the words, and how a denturist can verify each answer without taking anyone's word for it.

By Damien John Hiorth, DD

There is a version of this conversation going around the profession at the moment, and it is a good conversation to have. Every practice-management vendor has added AI in the last two years, every one of them describes it as secure and Canadian, and a denturist evaluating them has no obvious way to tell which claims are load-bearing.

The questions below are the right ones. What follows is how to ask each one so that a vague answer becomes obvious, what a good answer sounds like, and — since we are a vendor and you should discount us accordingly — ours, with a link to where you can check it. Every claim we make here is set out in more detail, in plain language, on our privacy and PHIPA page.

Is my patient data stored in Canada?

Ask for the region, not the country. "Stored in Canada" is a claim that survives a lot of arrangements you would not accept if they were described plainly — a database in Toronto whose backups replicate to Virginia, or an application hosted in Canada that sends every clinical note to an AI service in Iowa for processing. The follow-up question that does the work is: which components run where? The application, the database, the file storage for radiographs and scanned documents, the backups, and the AI processing are five separate answers, and a vendor who has genuinely done this will give you five.

Our answer: everything runs in Google Cloud's Montréal region, northamerica-northeast1 — the application on Cloud Run, the database, patient documents and radiographs in regional storage, and the AI processing in the same region as the rest of it.

Is my data used to train public AI models?

This one turns entirely on which AI service the vendor calls, so ask that instead. There is a real difference between a consumer AI product and an enterprise cloud AI service under a signed agreement, and it is precisely the difference this question is getting at. A vendor who answers "no, of course not" without naming the provider and the agreement has told you their intention, not their architecture.

Ours: Gemini through Google Cloud Vertex AI, under our signed Google Cloud agreement, in the same Montréal region as everything else — not a consumer AI service. Patient information is not used to train models, ours or anyone else's.

A useful tell: ask whether the AI provider is named in the privacy documentation you would sign. If a vendor will not put the provider in writing, the assurance is not one you can hold them to.

Who owns the recordings and chart notes?

The practice does — but ownership is the wrong test, because everyone says yes. The question that actually protects you is: can you get the record out, in a form something else can read, without asking? Ownership you cannot exercise is a sentence in a contract. Two different needs sit behind it, and they need two different formats:

  • A patient asking for their own record — their right of access under PHIPA. That copy has to be readable by a person, so it goes out as a PDF.
  • A patient moving to another practice — a chart transfer. That copy has to be readable by a system, so it goes out as structured JSON, or a ZIP when the radiographs and scanned documents need to travel with it. A transfer without the images is not a transfer.

Ask any vendor to show you a sample export before you sign. Not a description of one — the actual file.

Can data be permanently deleted?

In a denture practice, usually it should not be — and a vendor promising instant permanent deletion may be offering you a way to breach your own retention obligations. This is the question on the list where the intuitive answer is the wrong one, so it is worth being precise.

Denturists in Canada are subject to College record-retention periods measured in years after the last entry, and longer for minors. A clinical record is also, by design, an append-only document: notes lock, corrections append, and nothing is backdated — because a record that can be quietly revised is not evidence of anything. "Send us the chart and delete it" is two requests, and only the first can be honoured on the spot.

So DentureFlowPro has no facility to delete a patient chart from the interface. That is a deliberate position, not a missing feature, and it is stated as such on our compliance page. If a genuine erasure obligation ever arises, it should be a deliberate, audited operation with a documented legal basis recorded against it — not a button on the chart that anyone can press on a Tuesday afternoon.

Worth asking your own College before you accept any vendor's answer here, including ours. The retention rule is your obligation, not your software's.

Does the company understand Canadian health privacy law?

Ask them to name an obligation and show you where the software meets it. "PHIPA compliant" is not a certification anyone issues; there is no badge. It is a description of how a system behaves, so it can only be demonstrated. Three requests that are hard to fake:

  • Show me the audit trail. Who viewed this chart, when, from where. Under PHIPA, knowing who looked at a record is much of the point — and a download otherwise leaves no trace at all, so ask whether exports are logged separately.
  • Produce a patient's record for a right-of-access request, live. If it takes an email to support and three days, that is your answer.
  • State the retention position in writing. A vendor who has not thought about retention has not thought about records.

We will do all three on a call, against a demo chart, without preparation.

Will I still have support five years from now?

Nobody can answer this honestly — including vendors who have been around for decades — so replace the question with one that can be answered. Longevity is a reasonable thing to want and a poor thing to rely on. Long-established software companies are acquired, sunset products, and change their pricing; newer ones are bought or fold. Age is evidence, not a guarantee, and the guarantee is what you actually need.

The question with a checkable answer is: if this vendor disappeared tomorrow, what happens to my records? If you can export every chart, with its radiographs and documents, in an open and documented format, at any time, without asking permission and without a fee, then a vendor's survival stops being your risk. If you cannot, then no amount of corporate history protects you — it only delays the problem.

We are newer than the alternatives, and pretending otherwise would be silly. What we can offer instead of history is the exit: your complete record, in a form another system can read, on demand. Ask every vendor you are considering for the same thing, and notice who hesitates.

The short version

Most of these questions have a weak form that any vendor passes and a strong form that separates them. The strong forms are: which components run in which region; which AI provider, under which agreement; show me an export; what is your retention position; show me the audit trail; and what happens to my records if you disappear.

Ask them of us too. Our answers are on the compliance page, written to be checked, because a privacy officer will check them.

Quick answers

Is my patient data stored in Canada?

Ask for the specific region, not the country. DentureFlowPro runs entirely in Google Cloud's Montréal region (northamerica-northeast1) — the application, the database, patient documents and radiographs, and the AI processing, all in the same region.

Is my patient data used to train public AI models?

It should not be, and the answer depends on which AI service the vendor calls. DentureFlowPro uses Google Cloud Vertex AI under a signed enterprise agreement, not a consumer AI service, and patient information is not used to train models — ours or anyone else's.

Who owns the chart notes and recordings in dental software?

The practice does. The test is not what the contract says about ownership but whether you can get the record out: DentureFlowPro exports any patient chart as a PDF for a patient's right of access, or as structured JSON or ZIP — including radiographs — for a transfer to another practice.

Can patient data be permanently deleted from dental software?

Usually it should not be. Denturists in Canada are subject to College record-retention obligations measured in years after the last entry, and longer for minors. DentureFlowPro deliberately has no delete-a-chart button; a vendor offering instant permanent deletion may be offering you a way to breach your own retention rules.

How do I check whether a software vendor actually understands PHIPA?

Ask them to name the obligation, not the acronym. Concretely: can they show an audit trail of who viewed a chart, produce a record export in a form a patient can read, and explain their retention position? Vague assurances of compliance are not compliance.

How do I know a software company will still support me in five years?

You cannot know, from any vendor, of any age. What you can do is remove the consequences: confirm you can export the complete record in an open, documented format at any time, without asking permission or paying a fee.

See how it actually works

Every claim on this page is set out in detail on our compliance page — or watch the software do the work in the demo videos.