Data security

Keep access limited and client-controlled

The baseline starts with dated AI answers and public web pages. When approved platform data improves the analysis, we use restricted read-only access.

01

Least access

When data is needed, we ask for the lowest practical permission: read-only aggregate analytics or Search Console access.

02

Revoke anytime

The client controls platform access and can remove it. Access needs are reviewed when scope changes.

03

Contract before sensitive scope

If a project could require regulated data, work pauses for security, legal and contracting review.

Default data

What the baseline uses

  • Dated Google AI Overviews and ChatGPT + Gemini captures
  • Public clinic, competitor and source pages
  • Read-only aggregate search and analytics data, when approved
  • Service, market and location information supplied by the client

AI audit data flow

What enters a platform and what we retain

The baseline records only the business context and evidence needed for the agreed search questions.

01

Client input

Clinic domain, priority treatment, market, patient language, locations and selected competitors.

02

Platform input

Only approved patient questions plus clinic, service and location context enter search and AI platforms.

03

Evidence retained

Dated answer captures, visible sources, public pages, metrics and prioritized improvements.

04

Account state

Platform, visible model label, market, language and signed-in or signed-out state are logged where observable.

05

Optional access

Read-only aggregate Search Console or analytics access only after client approval.

06

Offboarding

Revoke platform access, close shared accounts and complete the deletion schedule agreed in scope.

Procurement summary

Confirm controls before client-system access

The public-data audit does not require client-system access. Work that uses client systems starts only after the required facts and controls are accepted.

Required in the scope or security pack

Contracting entity and incident contact

Data classes, approved accounts and processors

Processing locations and applicable transfer terms

Retention and deletion schedule

MFA, least-access and credential rules

Offboarding and access-revocation checklist

Contracting

Confirm requirements before access

NDA or DPA terms can be reviewed as part of the agreement. We do not claim a healthcare, GDPR or HIPAA certification on this site.

Security questions

Email evgeniy.yudin@rotgar.com to request the procurement checklist before sharing credentials or data.

Read the current site privacy notice

AI Visibility Audit

AI Visibility Audit

The AI visibility audit starts with one clinic or selected location, one priority market and one patient language.

Best fitClinics, hospitals and medical groups in:
  • Dental
  • Aesthetic medicine
  • Physiotherapy
  • Fertility & IVF
  • Dermatology
  • Hair transplant
  • Plastic surgery
  • Mental health
  • Multi-specialty groups
  • Your current visibility and named competitors
  • The sources AI answers cite
  • A prioritized list of improvements to implement

Need to cover several clinics, locations, countries, markets or patient languages? Book a 30-minute call We’ll discuss the scope for your organization.

AI Visibility Audit

Google AI Overviews, ChatGPT + Gemini.

  1. 1Contact
  2. 2Priorities
  3. 3Focus

Step 1 of 3: Contact

Step 1 of 3

Contact details

Enter at least one contact: email or WhatsApp.

Step 2 of 3

Audit priorities

Step 3 of 3

Search focus

What are you most interested in?

Do not include patient records or confidential health information.

Your request is sent securely to Rotgar.

The audit uses public data. Account access is not required.

We will confirm the scope and that the audit is in progress within 2 business days. The initial report will be delivered within 6 business days.