A clearer starting point for your review.
Bring your data protection lead, procurement checklist and practical questions. This page brings together the implemented controls and the topics to discuss before you decide.
Work through the questions that matter.
Use these topics to shape your review. We’ll discuss the current documentation and the requirements specific to your homes.
Access and responsibilities
Confirm the roles in your organisation, which homes each person can access and who can act across the group.
Hosting and sub-processors
Request the current hosting details, data locations and sub-processor list for your data protection review.
Retention and leaving the service
Discuss the applicable retention schedules, export arrangements and how information is handled when your agreement ends.
Incident response and continuity
Ask about notification procedures, backup arrangements and the support routes your organisation should use.
AI and record approval
Review the tasks AI supports, the source information it uses and where your staff review and confirm the output.
The service agreement
Confirm subscription terms, onboarding scope and responsibilities in the written agreement before rollout.
The detail behind the overview.
The same implemented controls described on our security page, ready to review with your technical or data protection lead.
See security in context01Database-level isolation
Row-Level Security is enabled on every table, denying direct API access by default. Data cannot be read around the application layer.
02Tamper-evident incidents
Each incident is hashed over a canonical payload and chained to the previous hash, with a verification routine, so after-the-fact alteration is detectable.
03Comprehensive audit trail
Material actions are written to an activity log, alongside dedicated child audit logs, authentication event logging, care summary audit events and a separate Child Portal audit log. Older entries are archived over time.
04Home-scoped data access
A global query scope binds personal data to a home and fails closed when no home context is present, rather than returning or saving an unowned record.
05Child Portal isolation
A separate subdomain with no shared web session, hashed opaque tokens, httpOnly and strict same-site cookies, device-bound request validation, PIN step-up for emergencies and dedicated rate limits.
06Safe API retries
Idempotency keys prevent duplicated records when a mobile client retries a request.
07Log hygiene
Email addresses are hashed rather than written in plaintext, so operational logs don't accumulate personal data.
08Standard web protections
CSRF protection, parameterised database access, encrypted sessions and modern password hashing.
Make the review a conversation.
- 01
Share your requirements
Tell us about your homes, review process and the documentation your decision-makers need.
- 02
Walk through the controls
Bring your DPO or technical lead. We’ll demonstrate access and record-history workflows and work through open questions.
- 03
Agree the next steps
Confirm the service terms, onboarding scope and checks your organisation needs before going live.
