Skip to main content
Due diligence

A clearer starting point for your review.

Bring your data protection lead, procurement checklist and practical questions. This page brings together the implemented controls and the topics to discuss before you decide.

Your review checklist

Work through the questions that matter.

Use these topics to shape your review. We’ll discuss the current documentation and the requirements specific to your homes.

01

Access and responsibilities

Confirm the roles in your organisation, which homes each person can access and who can act across the group.

02

Hosting and sub-processors

Request the current hosting details, data locations and sub-processor list for your data protection review.

03

Retention and leaving the service

Discuss the applicable retention schedules, export arrangements and how information is handled when your agreement ends.

04

Incident response and continuity

Ask about notification procedures, backup arrangements and the support routes your organisation should use.

05

AI and record approval

Review the tasks AI supports, the source information it uses and where your staff review and confirm the output.

06

The service agreement

Confirm subscription terms, onboarding scope and responsibilities in the written agreement before rollout.

Platform controls

The detail behind the overview.

The same implemented controls described on our security page, ready to review with your technical or data protection lead.

See security in context
01Database-level isolation

Row-Level Security is enabled on every table, denying direct API access by default. Data cannot be read around the application layer.

02Tamper-evident incidents

Each incident is hashed over a canonical payload and chained to the previous hash, with a verification routine, so after-the-fact alteration is detectable.

03Comprehensive audit trail

Material actions are written to an activity log, alongside dedicated child audit logs, authentication event logging, care summary audit events and a separate Child Portal audit log. Older entries are archived over time.

04Home-scoped data access

A global query scope binds personal data to a home and fails closed when no home context is present, rather than returning or saving an unowned record.

05Child Portal isolation

A separate subdomain with no shared web session, hashed opaque tokens, httpOnly and strict same-site cookies, device-bound request validation, PIN step-up for emergencies and dedicated rate limits.

06Safe API retries

Idempotency keys prevent duplicated records when a mobile client retries a request.

07Log hygiene

Email addresses are hashed rather than written in plaintext, so operational logs don't accumulate personal data.

08Standard web protections

CSRF protection, parameterised database access, encrypted sessions and modern password hashing.

How it works

Make the review a conversation.

  1. 01

    Share your requirements

    Tell us about your homes, review process and the documentation your decision-makers need.

  2. 02

    Walk through the controls

    Bring your DPO or technical lead. We’ll demonstrate access and record-history workflows and work through open questions.

  3. 03

    Agree the next steps

    Confirm the service terms, onboarding scope and checks your organisation needs before going live.