Privileged MFA
Require MFA for owners, administrators, managers, finance, support and export-capable roles, or document an approved compensating control.
Security at CoreCare
This statement separates controls found in the current product source from assurance work that is still required. A guided evaluation is not approval to introduce sensitive production data.
Source review updated 5 August 2026
Control verification
| Control | Current position | Evidence and qualification |
|---|---|---|
| Password storage | Verified with qualification | Care, Campsites, Finance and POS use salted PBKDF2-SHA-256 password hashing. Garage delegates credential validation to its configured upstream authentication service. |
| Website login and public forms | Verified | The public login, trial, contact, checkout, password-activation and privacy-request routes use server-side rate limiting and same-origin checks where applicable. |
| Session cookies | Verified in product source/tests | Product session cookies are HttpOnly, Secure and SameSite. Each product creates and validates its own session. |
| Organisation separation | Verified in source; independent test pending | Product data access is scoped by organisation, tenant, property, site or workshop identifiers on the server. Independent adversarial tenant-isolation testing has not yet been completed. |
| Support access | Verified in source/tests | Configured cross-product support sessions are time-limited, record purpose and access mode, and support read-only restrictions where provided. |
| Audit records | Verified in source | Products contain durable database audit/compliance tables for authentication, support access and significant mutations. Coverage continues to be reviewed per route. |
| Sensitive logging | Partially verified | The public site’s analytics table stores event, product, route and outcome rather than form payloads. A full independent log-content review across every provider has not yet been completed. |
| Product data separation | Verified by configuration | The five customer products are deployed as separate Workers with separate product database bindings and product-owned sessions. |
| Backup restoration | Recovery facility available; restore evidence pending | Cloudflare D1 recovery facilities are available, but CoreCare does not yet claim a completed product-by-product restore exercise or universal RPO/RTO. |
| Multi-factor authentication | Not universal | MFA is not yet available to every customer-product privileged account and remains a production-readiness requirement for higher-risk deployments. |
| Independent security testing | Not yet claimed | The complete suite has not yet received an independent penetration test or CoreCare-level ISO 27001, Cyber Essentials or SOC 2 certification. |
Production security gates
The order and readiness record must identify who approved each applicable control. A marketing page cannot replace implementation evidence.
Require MFA for owners, administrators, managers, finance, support and export-capable roles, or document an approved compensating control.
Complete negative tests for tenant, organisation, branch, site and support access against the deployed release.
Restore each production data store to an isolated target and record recovery point, time, validation and responsibility.
Run dependency, secret, static, authentication, access-control, session, upload and API-abuse testing, followed by an external penetration test for higher-risk products.
Production access uses HTTPS/TLS. Cloudflare documents encryption at rest for D1 databases and R2 objects. CoreCare does not claim customer-managed keys or UK-only storage unless a customer order expressly confirms them.
Backup frequency, recovery-point objective, recovery-time objective, retention, restore-test frequency and customer communication are product/order-specific until restore exercises support a common published baseline.
This is intentionally more limited than saying “backups are tested”.
Customers should keep accounts individual, choose unique passwords, review roles, remove leavers promptly, secure their own devices and keep regulated information out of representative trials unless expressly approved.
Cloudflare provider certifications do not certify CoreCare itself. CoreCare will publish a certification or independent test only after the scope, date and unresolved findings can be stated accurately.
Personal data breach response
Every suspected breach receives a central record, including events that do not meet a notification threshold.
Start a timestamped case, preserve evidence, restrict affected access and stop further loss where proportionate.
Identify data, people, systems, scale, likely consequences, customer roles and available mitigation.
Support the controller’s decision. Where CoreCare is controller, report qualifying risk to the ICO within 72 hours of awareness and inform people without undue delay where high risk applies.
Validate recovery, document the decision, communicate in phases where needed and track corrective actions to completion.
Data lifecycle
Product retention follows customer instructions, legal holds and the agreed service. Data return and deletion are handled under the DPA and customer terms.
Read the retention policyResponsible disclosure
Email the product, affected URL, time observed and a safe description. Do not send passwords, health data, payment information or harmful exploit data by ordinary email.
security@corecaresystems.co.uk