Care Governance Solutions is built for UK care providers who handle sensitive personal data. This page explains the technical and organisational measures we have in place.
All data is stored within the European Economic Area on Supabase infrastructure hosted in the West Europe region. No personal or organisational data is transferred to or processed in countries outside the EEA without appropriate safeguards.
The platform enforces row-level security (RLS) at the database layer. Every query is automatically scoped to the authenticated organisation — it is not possible for one organisation to read, write, or enumerate another organisation's records, even in the event of an application-layer error.
Access within an organisation is governed by twelve defined roles, each with a distinct permission set. Roles are assigned by the organisation administrator and can be adjusted at any time. Users see only the modules and records their role permits.
Multi-factor authentication (MFA) is available to all users via an authenticator app (TOTP). Organisations can require MFA for all staff. Recovery codes are provided at enrolment; administrators can reset MFA for users who lose access to their device.
All connections to the platform are encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Encryption is managed by the underlying infrastructure provider and applies to all stored data including backups.
The platform maintains an audit trail of access to records. Significant actions — including record creation, amendment, and deletion — are logged with a timestamp and the identity of the user who performed the action. Audit logs support governance oversight and can assist with regulatory enquiries.
Care Governance Solutions is registered with the Information Commissioner's Office (ICO) under registration number ZC147699. Our registration can be verified on the ICO register.
A Data Processing Agreement (DPA) is available to all subscribing organisations. The DPA sets out the obligations of Care Governance Solutions as a data processor and the rights of the organisation as a data controller. To request a copy, contact support@caregovernance.solutions.
Retention periods are aligned to the Records Management Code of Practice published by NHS England. Data is retained for the minimum period necessary for the purpose for which it was collected. Organisations can request deletion of their data on termination of their subscription, subject to any statutory retention obligations.
Questions about our security or data practices? Contact us at support@caregovernance.solutions or visit our Data Processing Agreement page.