Testing Schedule
Last updated: 15 July 2026
CareLedgerPro carries out layered, continuous testing to help protect Controllers' data and demonstrate ongoing assurance. A customer-specific summary can be provided for audit packs.
Testing Activities
Automated code security scan
Frequency: Every deploy
Scope: Dependency vulnerabilities, secret leaks, static analysis
Owner: Engineering
Automated functional test suite
Frequency: Every commit and every deploy
Scope: Billing mapping, authentication flows, RLS-protected routes, end-to-end user journeys
Owner: Engineering
Row-level security review
Frequency: Quarterly and on every schema change
Scope: All Data API tables, policies, grants, SECURITY DEFINER functions
Owner: Engineering + DPO
Access review
Frequency: Quarterly
Scope: Internal staff access to production systems and Controller data
Owner: DPO
Backup restore test
Frequency: Quarterly
Scope: Restore latest snapshot to isolated environment and validate integrity
Owner: Engineering
Disaster-recovery drill
Frequency: Annually
Scope: End-to-end failover, RTO/RPO validation, incident-response rehearsal
Owner: Engineering + Incident Lead
Third-party penetration test
Frequency: Annually
Scope: Application, authentication, API surface, OWASP Top 10
Owner: External vendor
Incident Response Plan review
Frequency: Annually and after every SEV-1 incident
Scope: Roles, response times, notification workflow, evidence handling
Owner: DPO
Remediation Workflow
Triage
Every finding is triaged within 2 working days and assigned a severity level: Critical, High, Medium, or Low.
Fix targets
- Critical — within 24 hours
- High — within 7 days
- Medium — within 30 days
- Low — in the next planned release
Verification
A fix is only closed once automated tests or a repeat scan confirm remediation.
Reporting
Trends and outstanding findings are reviewed at the quarterly access review.
Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.