Blog · Security
Red Team agents hunt for holes before the bad guys do
We run offensive agents against our own platform and network — trying to steal PII the way a real attacker would — so we find the crack first. The rest of the defense is a tiny footprint on Cloudflare Workers and the specialists that already won payments, payroll, and payers.
Dental offices already trust too many systems with patient and staff identity: a PMS on a closet PC, a recall vendor, a card reader, a payroll file emailed “just this once.” When practices ask whether an agent platform is safe, the honest answer is not a sticker. It is whether someone is paid to break in before a stranger is.
HeyDental’s answer is a Red Team of agents — an offensive program that treats our own product, APIs, edge, and office portals as the target. Their job is to steal PII, escalate, and wander the network the way a patient-data thief would. Ours is to close every door they open.
Red Team is not a brochure paragraph. It is an attack strategy we run on ourselves so the bad guys are not the first ones to try the lock.
Why we attack ourselves
Defensive checklists matter. So do BAAs, encryption, and least privilege. But checklists do not click the funny edge case at 2am. Offensive work does.
Our Red Team agents are instructed to behave like motivated outsiders and compromised insiders:
- Phish or guess an owner session and walk the office admin.
- Probe public office URLs, waiting-list forms, and share links for data that should stay staff-only.
- Abuse APIs for IDOR-style leaks — “can I see another practice’s staff email by changing a slug?”
- Hunt for secrets in Workers, logs, drafts, and markdown bundles.
- Try to pull payment tokens, payroll identifiers, eligibility payloads, or charts that we should never warehouse in the first place.
When they succeed, that is a win for the defense. The hole is ours to patch before a real attacker finds it. When they fail, we keep score and try a nastier path next week. The product copy still says robot / agent — never a model brand — because the point is the job, not the vendor of the week.
What Red Team agents try
The goal is not theatrical hacking. It is PII and practice trust — names, emails, phones, card tokens, payroll identifiers, insurance responses, anything that would embarrass an owner if it left the building.
Target
Steal the dossier
Agents try to exfiltrate owner, staff, and patient identifiers from portals, forms, media libraries, and logs. If a screen shows more than the role needs, Red Team files it.
Target
Cross the tenant wall
Office A must never read Office B. Red Team hammers path params, cookies, and “preview from markdown” paths until a leak shows up — or doesn’t.
Target
Abuse the tools
Agents try to coerce Stripe, Gusto, Stedi, Twilio, or Resend calls with the wrong office context. Tooling must fail closed, not “helpfully” retry with someone else’s token.
Outcome
Patch before launch day
Every finding becomes a regression test or a Worker guard. The floor should feel boringly locked — not “we’ll fix it after the waitlist.”
This is continuous, not a one-time pen-test PDF. As we ship Media walls, share links, insurance embeds, and new agent tools, Red Team gets the same diff. New surface, new attack.
A tiny footprint on ephemeral Workers
Offensive work only works if the house is small enough to defend. HeyDental.app is not a rack of long-lived VMs in a closet. The public site, office runtime, and edge logic lean hard on Cloudflare Workers — short-lived, isolated compute that starts for a request and goes away.
- Ephemeral by default. There is no always-on box with a month of shell history waiting for someone to land on it.
- Minimal blast radius. A Worker holds the code for that path, not a shared monolith with every practice’s disk mounted.
- Edge close to the practice. TLS, DDoS, and routing sit on Cloudflare’s network instead of a clinic firewall someone last touched in 2019.
- Less to steal on-disk. We orchestrate. Specialists hold cards, payroll, and EDI. Our job is the graph of permissions — not a second vault.
That is the “minimal footprint” in plain language: fewer long-lived machines, fewer copies of sensitive payloads, more compute that evaporates when the request ends. Red Team still tries to break it. The architecture just gives them less furniture to hide behind.
Standing on the shoulders of giants
We do not pretend a dental startup out-secures Stripe’s PCI program or Cloudflare’s Trust Hub. We compose specialists that already carry mountains of audits, then refuse to re-implement a worse copy in our database. Agents call them. Red Team tries to abuse the calls. The payload stays with the specialist.
There is no “HIPAA certified” badge from HHS. What exists are BAAs, SOC reports, PCI assessments, and attested controls. We point at those — and we keep our own house small.
Payments
Stripe
Stripe takes cards. We keep tokens, not PANs. PCI DSS Level 1 is their mountain; we refuse to climb a DIY hill next to it.
Payroll / HR
Gusto
Gusto holds payroll and HR identity. We do not keep a parallel file of SSNs and deposit accounts “for the agent.”
Insurance
Stedi
Stedi is the EDI pipe. Eligibility and claims transit a SOC 2 Type II, HIPAA-eligible platform — not a spreadsheet we host.
Voice and SMS
Twilio
Twilio carries calls and texts under SOC 2 and HIPAA-eligible products with a BAA where PHI rides the wire.
Resend
Resend sends transactional mail. Charts stay out of the body. SOC 2 Type II and encryption in transit / at rest are table stakes we inherit.
Edge & Workers
Cloudflare
Cloudflare is the platform under heydental.app: DNS, TLS, Workers, DDoS, access. SOC 2 Type II and an independently audited HIPAA/HITECH Attestation of Compliance cover in-scope services, with BAAs where PHI transits. Ephemeral Workers are how we keep the footprint small while Red Team keeps kicking the door.
Deeper architecture — why we refuse to bolt AI onto a legacy PMS and warehouse a shadow copy of the practice — lives in Why Open Dental and Dentrix cannot bolt on AI.
What we will not claim
We will not say we are “HIPAA certified.” That phrase is marketing fiction. We will not name a model as if the brand were a control. We will not promise that Red Team finds every bug — only that we keep sending agents to try, on a stack designed so there is less to steal when something goes wrong.
Security for a dental agent platform is two moves at once: stand on giants, and attack yourself like an enemy. Stripe, Gusto, Stedi, Twilio, Resend, and Cloudflare carry the certifications. Cloudflare Workers keep the house small. Red Team agents make sure the door still holds.