Built to protect the health information you entrust to us.
You’re trusting us with people’s health information. Here, in plain terms, is how we protect it today, and what we’re still working toward. We don’t claim certifications we haven’t earned.

Safeguards we have today
What’s protecting your data right now, each one real and in the product today. Anything still in the works is listed further down, clearly labelled.
Each agency’s data stays private
Every agency’s data is kept private and separate, enforced by the database itself, so one agency can never see another’s.
See it in the productTamper-evident audit trail
Sensitive actions are recorded to a log that can’t be edited or deleted (by design, not policy), so accountability records cannot be rewritten.
See it in the productChart access is logged
Every view of a client chart is recorded (who looked, at what, and when), so even just reading a record is accountable.
See it in the productStrong password hashing
Account passwords are hashed and salted, and never stored in plain text.
See it in the productHealth information kept out of logs
Health-card numbers, identifiers and clinical details are kept out of our system logs.
See it in the productRole-based access control
Staff access is scoped by role (owner, admin, scheduler, biller, coordinator, viewer), so people see only what their job requires. Caregivers and family members sign in through separate, secure spaces.
See it in the productEncrypted in transit
All traffic between you and CareKindle is encrypted in transit (HTTPS/TLS).
See it in the product
See it for yourself
Every safeguard above is something you can open and check inside CareKindle. The compliance centre keeps the tamper-evident audit trail and the record of who accessed health information next to incidents, consent, retention schedules and privacy requests, so your privacy officer can verify our claims any ordinary day, not just at audit time.

Certifications & attestations
Items marked "In progress" or "Planned" are not yet certified or audited. We list them for transparency and will update this page when each is complete.
- SOC 2 Type IIIn progress
Independent audit of our security, availability, and confidentiality controls over a monitoring period.
Independent CPA firm · AICPA Trust Services Criteria - PHIPA / PIPEDA alignmentPlanned
Practices aligned to Ontario's PHIPA and Canada's PIPEDA for the collection, use, and disclosure of personal health information.
Self-attested · Canadian privacy law - ISO/IEC 27001:2022Planned
Internationally recognized standard for an information security management system (ISMS).
Accredited ISO certification body - HIPAA Security & Privacy RulesPlanned
Administrative, physical, and technical safeguards aligned to the US HIPAA Security Rule for handling protected health information.
Self-attested + independent readiness assessment - GDPRPlanned
Data-subject rights, lawful-basis, and processor obligations under the EU General Data Protection Regulation.
Self-attested · EU Regulation 2016/679
What we’re working toward
Controls we are building or formalizing. None of these is claimed above, because none of these is finished.
- Mandatory multi-factor authentication for privileged roles
- Encryption at rest with managed keys
- Verified Canadian data residency
- Independent SOC 2 Type II audit, then ISO 27001
- Automated data-subject access & erasure (DSAR) fulfilment
- A documented breach-notification runbook with statutory timelines
Sub-processors
The third parties we use in delivering CareKindle. We notify customers before adding a new sub-processor that handles their data.
We publish "Confirming region" rather than guess.
| Sub-processor | Purpose | Data location | Status |
|---|---|---|---|
| Cloud hosting & database | Application compute and the primary database. | Confirming region | Active |
| Email delivery (Amazon SES) | Transactional email delivery — invitations, verification codes and schedule/visit notifications. Message content can reference a client. | Confirming region | Active |
| Stripe | Agency subscription billing only. Never used for client/patient billing. | United States / global | Active |
| Mapbox | Maps and geocoding for scheduling and visit verification (EVV). | United States | Active |
| QuickBooks Online | Accounting sync for client invoicing (export). | United States | Coming soon |
Procurement or security team?
We’re happy to walk through our safeguards, share sub-processor data-processing agreements, and (once available) our SOC 2 report under NDA.
Read it, then try it: every line on this page is in the product.
14-day trial · full access · no credit card.
