Security at CoreCare

Verified controls, known gaps and clear gates.

This statement separates controls found in the current product source from assurance work that is still required. A guided evaluation is not approval to introduce sensitive production data.

Source review updated 5 August 2026

Production security gates

Required before sensitive or high-risk use.

The order and readiness record must identify who approved each applicable control. A marketing page cannot replace implementation evidence.

01

Privileged MFA

Require MFA for owners, administrators, managers, finance, support and export-capable roles, or document an approved compensating control.

02

Isolation tests

Complete negative tests for tenant, organisation, branch, site and support access against the deployed release.

03

Restore exercise

Restore each production data store to an isolated target and record recovery point, time, validation and responsibility.

04

Independent review

Run dependency, secret, static, authentication, access-control, session, upload and API-abuse testing, followed by an external penetration test for higher-risk products.

Encryption and transport

Production access uses HTTPS/TLS. Cloudflare documents encryption at rest for D1 databases and R2 objects. CoreCare does not claim customer-managed keys or UK-only storage unless a customer order expressly confirms them.

Recovery commitments

Backup frequency, recovery-point objective, recovery-time objective, retention, restore-test frequency and customer communication are product/order-specific until restore exercises support a common published baseline.

This is intentionally more limited than saying “backups are tested”.

Customer operation

Customers should keep accounts individual, choose unique passwords, review roles, remove leavers promptly, secure their own devices and keep regulated information out of representative trials unless expressly approved.

Assurance boundary

Cloudflare provider certifications do not certify CoreCare itself. CoreCare will publish a certification or independent test only after the scope, date and unresolved findings can be stated accurately.

Personal data breach response

Contain, assess, notify and learn.

Every suspected breach receives a central record, including events that do not meet a notification threshold.

01

Record and contain

Start a timestamped case, preserve evidence, restrict affected access and stop further loss where proportionate.

02

Assess risk

Identify data, people, systems, scale, likely consequences, customer roles and available mitigation.

03

Notify

Support the controller’s decision. Where CoreCare is controller, report qualifying risk to the ICO within 72 hours of awareness and inform people without undue delay where high risk applies.

04

Recover and learn

Validate recovery, document the decision, communicate in phases where needed and track corrective actions to completion.

Data lifecycle

Retention, export and deletion.

Product retention follows customer instructions, legal holds and the agreed service. Data return and deletion are handled under the DPA and customer terms.

Read the retention policy

Responsible disclosure

Report a security concern.

Email the product, affected URL, time observed and a safe description. Do not send passwords, health data, payment information or harmful exploit data by ordinary email.

security@corecaresystems.co.uk