Our Security Focus

For over three decades, more than 25,000 dental professionals across Australia have trusted Centaur Software with their most sensitive practice data. As Australia’s leading practice management solution provider, we understand that security isn’t just a feature: it’s the foundation of everything we do. 

Security Certifications, Standards and Documentation

Our Trust Portal is an online hub where you can download up-to-date information about our security, privacy and compliance posture, including our ISO 27001:2022 certification, Data Processing Addendum and key security and data protection documents. 

It is designed for practice owners, managers and IT teams who want clear, practical evidence of how we protect patient and practice data when choosing or reviewing a dental practice management system. 

The Trust Portal provides your organisation with transparent, ready-to-use material to support internal governance, risk assessment, and accreditation requirements. 

We hold ISO 27001:2022 certification, demonstrating our commitment to the highest international standards for information security management. Our systems and processes undergo rigorous annual audits to maintain this certification. 

We maintain comprehensive compliance with the Australian Privacy Principles, GDPR, the Australian Cyber Security Centre’s Essential 8, the OAIC Data Breach Notification Scheme, and all relevant state and territory regulations across Australia. 

Yes, we comply with the Privacy Act and other health-related data regulations in Australia, safeguarding personal health information in accordance with national standards. 

We conduct annual security risk assessments as part of our ISO 27001 compliance and regular monitoring to identify potential risks. We also perform annual penetration testing against recognised standards, including PTES, OSSTM, and OWASP. Our systems undergo regular independent security audits and continuous monitoring to identify and address potential vulnerabilities. 

We conduct regular compliance reviews, maintain ISO certification, and update our policies and procedures to stay aligned with evolving standards. 

Data Protection and Sovereignty

All hosted customer data is stored in data centres in Australia, across multiple facilities to ensure availability, and remains under Australian jurisdiction and in compliance with local data sovereignty requirements. We prioritise keeping your data within Australia’s borders. 

We prioritise data residency in Australia. Any cross-border data transfers would comply with relevant Australian regulations and require appropriate safeguards. 

All data is encrypted both in transit and at rest using industry-standard encryption. Encryption keys are managed through enterprise-grade key management systems, ensuring robust security and protection against unauthorised access. 

We maintain strict data retention policies that comply with regulatory guidelines, including a standard 90-day retention period for deleted data versions and modifications. When data is no longer required, it is securely disposed of in accordance with ISO 27001:2022 A.8.3 Annex Control standards, ensuring complete and secure deletion. 

We adhere to Privacy by Design principles, embedding privacy into our systems, policies, and procedures to meet stringent regulatory standards. 

Partner and Third-Party Security

All our partners undergo rigorous third-party risk assessments before integration. We maintain ongoing security monitoring and regular reviews to ensure all partner relationships meet our stringent security standards. 

Every third-party vendor and partner must pass comprehensive security assessments covering their certifications, data-handling practices, and security controls before being approved to work with customer data. 

Access Controls and Authentication

We implement role-based access controls with multi-factor authentication (MFA) and single sign-on (SSO) across all our key systems. Staff access is granted on a need-to-know basis and is regularly reviewed. 

We maintain extensive audit trails for all system access and user activities by our staff. All access to customer data is logged and monitored for security and compliance purposes. 

Staff roles and permissions are configured based on specific job requirements and regularly audited. We enforce strict access controls, including IP restrictions and continuous monitoring of all staff activities involving customer data. 

Comprehensive logging and auditing are available within the application, enabling customers to review user activity and application access logs. 

Staff Security and Training

All Centaur Software staff undergo comprehensive background checks before accessing customer systems. We maintain ongoing security awareness training programs to ensure our team stays current with the latest security threats and best practices. 

Our staff receive regular security awareness training and must comply with our ISO 27001:2022-certified security policies and procedures. Access to customer data is strictly controlled and monitored. 

Cloud Product Security

Our cloud products benefit from enterprise-grade infrastructure security, automated backup and recovery systems, and continuous security monitoring. All cloud deployments follow our ISO 27001:2022-certified security framework with additional cloud-specific protections. 

We operate under a shared responsibility model, where we secure the cloud infrastructure while customers manage security within the cloud, including data access permissions and configurations. 

We utilise multi-zone redundancy and real-time data replication to ensure high availability, backed by a 99.99% uptime guarantee. Our infrastructure is designed to provide maximum uptime with comprehensive disaster recovery capabilities. 

We implement tenant isolation measures to protect data across our cloud platform. 

We adhere to standards such as ISO 27001 and conduct regular risk assessments to align with global cloud security standards. 

Incident Response and Management

We maintain well-established incident response processes in accordance with the ISO 27001:2022 guidelines. Our comprehensive incident response plan includes immediate detection, containment, investigation, and remediation procedures. 

We provide immediate notification of confirmed security incidents as part of our commitment to transparency and compliance with the Data Breach Notification Scheme administered by the Office of the Australian Information Commissioner (OAIC), as well as other regulatory requirements. 

We employ multiple layers of security, including continuous monitoring, regular security updates, penetration testing, staff training, and strict access controls to prevent unauthorised access and security incidents. 

Business Continuity and Reliability

Our infrastructure is designed for maximum reliability with redundant systems, regular backups, and comprehensive business continuity planning to ensure uninterrupted service delivery. 

We maintain detailed disaster recovery plans, including automated backup systems, redundant infrastructure, and regular testing to ensure rapid recovery from any potential disruption. 

Customer Data Rights and Ownership

Customers retain full ownership and control of their data at all times. We act solely as a custodian of your information, with established data management protocols that respect your ownership rights. 

For our cloud-hosted systems, we fully support customer requests for data export, migration, or secure deletion. Our processes ensure compliance with regulatory requirements and maintain data integrity throughout any transition. 

We maintain complete transparency about our data-handling practices and provide detailed documentation of our security controls, compliance measures, and data protection procedures. 

Additional Costs and Transparency

Any data storage that exceeds the initial agreements incurs a small fee, billed monthly per GB. 

Billing is managed transparently, with notifications about storage capacity and monthly charges when usage exceeds the agreed limits. 

Simplify Every Aspect of Your Business With Us

Centaur Software has been Australia’s most trusted practice management solution provider for over 30 years. Our commitment to security and compliance ensures that the 25,000+ dental professionals who rely on our solutions can focus on patient care with complete confidence in the protection of their data.