Security & compliance
The measures that protect the data we hold — and an honest account of where our formal compliance stands.
DRAFT — pending legal review. This document is a working draft published for transparency. It has not yet been reviewed by legal counsel, is not legal advice, and is not yet contractually binding. Last reviewed: Not yet reviewed.
We hold no third-party security certifications yet. The standards below are the compliance pathway we are building toward — not accreditations we currently hold. We would rather tell you this plainly than imply assurances we cannot back.
1. How we protect data
- Encryption in transit (TLS) and at rest.
- Mandatory multi-factor authentication for every account, every role.
- Least-privilege access — role- and child-scoped permissions; users see only the children they are authorised to support.
- Audit logging of access and changes to support accountability.
- EU-hosted infrastructure with managed, access- controlled databases.
- Invite-only onboarding, email verification, rotating sessions, and brute-force lockout.
2. Compliance pathway — honest status
- UK GDPR & DPA 2018 — In progress. UK company incorporation (London) and ICO registration in progress; draft DPIA and records of processing under way; no DPO appointed yet.
- NHS Data Security & Protection Toolkit (DSPT) — Not yet submitted.
- DCB0129 / DCB0160 (clinical risk management) — In progress; draft safety case and hazard log started, no Clinical Safety Officer appointed yet.
- Caldicott principles — Pending; no Caldicott Guardian appointed yet.
- ISO/IEC 27001 · Cyber Essentials Plus — Not certified.
Draft governance artifacts (DPIA, records of processing, clinical safety case, retention schedule) are being prepared and will be completed by appointed officers before any production NHS deployment.
3. Reporting a vulnerability
We welcome responsible disclosure. If you believe you have found a security issue, please email security@rconnected.health [mailbox being provisioned] with the details and steps to reproduce, and give us reasonable time to respond before any public disclosure. Please do not access or modify data that is not yours while testing.
Related: Privacy Notice · Terms of Service · Cookie Policy · Accessibility