Care records deserve clear boundaries.
Keep access connected to the right home, make changes traceable and give your reviewers the information they need. Here are the controls behind Welma’s everyday workflows.
For children’s residential homes. Built around your team.
- Home-scoped access
- Traceable changes
- Human review of AI
Give people the access their role needs.
Care records belong to a home. Access is tied to that context and the responsibilities of the person using the platform.
Home-scoped queries and database-level isolation support the boundary. Organisation-level access is explicit, so a group view does not mean every staff member can open every home.
- Personal data bound to a home
- Access reviewed against your team structure
- A separate session boundary for the Child Portal
Make the history part of the record.
Keep authorship, important actions and changes available for review.
Welma maintains audit events across key workflows. Incident records use a tamper-evident history so a later alteration can be detected, supporting the conversations and checks your reviewers need.
- Named activity and audit events
- Dedicated child and care-summary histories
- Tamper-evident incident records
Look closer at the controls.
Open a topic for the technical detail. Your data protection lead can use these as a starting point for review.
01Database-level isolation
Row-Level Security is enabled on every table, denying direct API access by default. Data cannot be read around the application layer.
02Tamper-evident incidents
Each incident is hashed over a canonical payload and chained to the previous hash, with a verification routine, so after-the-fact alteration is detectable.
03Comprehensive audit trail
Material actions are written to an activity log, alongside dedicated child audit logs, authentication event logging, care summary audit events and a separate Child Portal audit log. Older entries are archived over time.
04Home-scoped data access
A global query scope binds personal data to a home and fails closed when no home context is present, rather than returning or saving an unowned record.
05Child Portal isolation
A separate subdomain with no shared web session, hashed opaque tokens, httpOnly and strict same-site cookies, device-bound request validation, PIN step-up for emergencies and dedicated rate limits.
06Safe API retries
Idempotency keys prevent duplicated records when a mobile client retries a request.
07Log hygiene
Email addresses are hashed rather than written in plaintext, so operational logs don't accumulate personal data.
08Standard web protections
CSRF protection, parameterised database access, encrypted sessions and modern password hashing.
Security questions, answered.
Specific controls, with room for your reviewer’s questions.
Can staff access another home’s records?
Access depends on the user’s role and home or organisation context. Personal records are home-scoped, and wider access is explicit. We can demonstrate the permission model against your team structure.
Does this page claim a security certification?
No. This page describes the controls implemented in the platform. Ask our team for the documentation and assurance information your review requires.
Who approves AI-assisted records?
Your team reviews drafts and source references and remains responsible for the final record. AI assistance does not replace professional judgement or safeguarding procedures.
Can our DPO review the platform before we decide?
Yes. Bring your questions about access, hosting, sub-processors, retention and incident response. The due-diligence page sets out a practical starting point for the discussion.
Bring your questions. We’ll work through them.
Invite your manager, provider or data protection lead to a walkthrough of the controls that matter to your homes.
£400/month for your organisation, including two homes.