AttestaCare

Security & Trust

Social care data is sensitive by nature. Here’s what we actually do to protect it -- described plainly, without claiming certifications we haven’t obtained.

Passkey-based staff authentication

Staff and privileged accounts require WebAuthn passkey multi-factor authentication in addition to a password -- not an optional add-on, a requirement for any role with access to operational or client data.

Role- and scope-based access control

Every account is scoped to a role, organisation, branch, and team. A coordinator sees their team’s data; a care worker sees their own assignments. Access is enforced on every request, server-side.

Malware scanning on every upload

Documents uploaded to the platform are scanned before they can be opened by anyone. A file that fails scanning is quarantined automatically and never served.

Audit logging

Security-relevant actions -- sign-ins, approvals, access changes, account suspensions -- are recorded to an audit trail, not just application logs.

Encryption in transit & at rest

All traffic to and from AttestaCare AI is served over HTTPS. Data at rest is encrypted using our cloud provider’s managed encryption, and credentials are never stored in plain text.

Cloud infrastructure

AttestaCare AI runs on Microsoft Azure, using managed database, storage, and identity services rather than self-hosted infrastructure.

On responsible AI

Where AttestaCare AI uses AI features -- like drafting suggestions or surfacing patterns -- those features assist the people using the platform. They do not make care decisions, and every AI-assisted action remains attributable to the person who reviewed and confirmed it.

Our approach, in more detail

We haven’t pursued formal certifications yet. Here’s what we can say honestly about how we handle security, privacy, and data today.

Security by design

Access control, input validation, and audit logging are built into how a feature works from the start, not added afterward. Every new capability is designed to support this from day one.

Privacy by design

Sensitive information -- like a care worker’s location during a visit -- is only ever visible for the purpose it was collected for, and only while that purpose applies. Location visibility starts when a visit begins and ends automatically when it’s complete.

Data minimisation

We collect what’s needed to deliver and coordinate care, and design new features to ask the same question before adding a new data point: does this need to exist, and for how long?

Data ownership

Care organisations own the data they put into AttestaCare. We act as the processor of that data, not its owner, and don’t use it for purposes outside delivering and improving the platform.

Our approach to GDPR

AttestaCare is built with GDPR principles in mind -- lawful basis for processing, data minimisation, and the ability to access, correct, or delete personal data on request. We are not presenting this as a certified compliance status, and we welcome specific questions from organisations conducting their own due diligence.

Vendor management

We run on established cloud infrastructure (Microsoft Azure) rather than self-hosting, and we’re deliberate about which third-party services we bring into the platform and what data they can see.

Business continuity

Our production database runs on managed infrastructure with automated backups. As an actively developing platform, formal business continuity and disaster recovery documentation is an area we are still building out -- we’re straightforward about that rather than overstating it.

Vulnerability management

Automated dependency, static-analysis, and secret-scanning checks run as part of our deployment pipeline on every change, so known vulnerabilities and accidental secret exposure are caught before code reaches production.

Incident management

We maintain an internal process for identifying, escalating, and resolving security and operational incidents. If you believe you’ve found a security issue, we want to hear about it -- see contact details below.

Have a specific security or privacy question? Reach us at support@attestacare.com.