Security

CareLedgerPro applies technical and organisational measures designed to protect client-money records. Some measures are delivered by our sub-processors (hosting, authentication, email, payments) and some are implemented in the application itself. CareLedgerPro is not independently certified against ISO 27001, SOC 2, Cyber Essentials, or DSPT.

Encryption in transit and at rest

All data is encrypted in transit using TLS and at rest by our managed hosting sub-processor. Card details are handled entirely by our payments sub-processor and never touch CareLedgerPro servers.

Role-based access with row-level security

Access is scoped by role and enforced with row-level security on every client-facing table. Staff only see the records their role permits, and permissions can be updated or revoked by an administrator.

Append-only audit log

Transactions, corrections and sign-offs are recorded in an append-only audit log with the actor, timestamp and reason. Records are not silently edited; corrections keep the original entry visible.

Staff-only authentication

CareLedgerPro uses staff-only sign-in with strong password hashing and leaked-password protection enabled at the identity provider. There is no public sign-up, and no family or resident-facing login.

Managed hosting (via sub-processor)

CareLedgerPro runs on managed cloud infrastructure provided by our hosting sub-processor. UK/EU-aligned regions are used where available. Full details are on the Sub-processors page.

Backups (via sub-processor)

Database backups are managed by our hosting sub-processor. Restore is available in the event of an incident, in line with their published backup policy.

Least-privilege by design

Application and database access rules are written to grant the minimum access required. Row-level security policies are the primary boundary between tenants.

Incident handling

If a security incident affecting a Controller's data occurs, we notify the Controller without undue delay. The Controller remains responsible for assessing the breach and notifying the ICO where required.

Reporting a Vulnerability

If you believe you have discovered a security issue, please contact us so we can investigate promptly. See also our Compliance and Data Processing pages.

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.