Security Overview

A public-safe summary of the security controls CareLedgerPro operates as a staff-facing client-money ledger. For the plain-language version, see the Security page. This page is provided for transparency and does not constitute an independent security assessment.

Application-level controls

  • Role-based access with row-level security on every client-facing table.
  • Append-only audit log covering transactions, corrections and sign-offs.
  • Capacity-aware signature workflow with authoriser and reason recorded.
  • Staff-only authentication; no public sign-up and no family-facing routes.
  • Server-side validation on inputs and typed RPC boundaries between client and server.

Authentication

  • Email + password sign-in with leaked-password protection enabled at the identity provider.
  • Session management provided by our authentication sub-processor.
  • Optional Google OAuth for staff sign-in.

Infrastructure (via sub-processors)

  • Encryption in transit (TLS) and at rest, provided by our hosting sub-processor.
  • Database backups managed by the hosting sub-processor.
  • Payment card data handled entirely by our payments sub-processor; card details never touch CareLedgerPro servers.
  • UK/EU-aligned regions used where available.

Audit trail

  • Transactions and ledger entries are append-only.
  • Corrections are recorded with the original entry preserved and a reason captured.
  • Voids record who voided, when and why; original rows are preserved.
  • Audit records can be exported as CSV for internal review.

Breach register

CareLedgerPro includes an in-app breach register so staff can record incidents they have assessed, with timeline notes and links to supporting evidence. It is a record-keeping aid; the Controller remains responsible for assessment, ICO notification and communications with affected individuals. See Incident Response.

What we don't claim

CareLedgerPro is not independently certified against ISO 27001, SOC 2, Cyber Essentials, or DSPT. The provider remains the data controller and is responsible for user provisioning, offboarding, device security, and their own incident-response process.

Reporting a vulnerability

If you believe you have found a security issue, please email support@careledgerpro.co.uk with reproduction steps. We aim to acknowledge reports within one working day.

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.