Testing Schedule

Last updated: 15 July 2026

CareLedgerPro carries out layered, continuous testing to help protect Controllers' data and demonstrate ongoing assurance. A customer-specific summary can be provided for audit packs.

Testing Activities

Automated code security scan

Frequency: Every deploy

Scope: Dependency vulnerabilities, secret leaks, static analysis

Owner: Engineering

Automated functional test suite

Frequency: Every commit and every deploy

Scope: Billing mapping, authentication flows, RLS-protected routes, end-to-end user journeys

Owner: Engineering

Row-level security review

Frequency: Quarterly and on every schema change

Scope: All Data API tables, policies, grants, SECURITY DEFINER functions

Owner: Engineering + DPO

Access review

Frequency: Quarterly

Scope: Internal staff access to production systems and Controller data

Owner: DPO

Backup restore test

Frequency: Quarterly

Scope: Restore latest snapshot to isolated environment and validate integrity

Owner: Engineering

Disaster-recovery drill

Frequency: Annually

Scope: End-to-end failover, RTO/RPO validation, incident-response rehearsal

Owner: Engineering + Incident Lead

Third-party penetration test

Frequency: Annually

Scope: Application, authentication, API surface, OWASP Top 10

Owner: External vendor

Incident Response Plan review

Frequency: Annually and after every SEV-1 incident

Scope: Roles, response times, notification workflow, evidence handling

Owner: DPO

Remediation Workflow

Triage

Every finding is triaged within 2 working days and assigned a severity level: Critical, High, Medium, or Low.

Fix targets

  • Critical — within 24 hours
  • High — within 7 days
  • Medium — within 30 days
  • Low — in the next planned release

Verification

A fix is only closed once automated tests or a repeat scan confirm remediation.

Reporting

Trends and outstanding findings are reviewed at the quarterly access review.

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.