Skip to content
CareKindle

Built to protect the health information you entrust to us.

Inspection recordLast reviewed: June 2026

You’re trusting us with people’s health information. Here, in plain terms, is how we protect it today, and what we’re still working toward. We don’t claim certifications we haven’t earned.

A client chart in CareKindle

Safeguards we have today

What’s protecting your data right now, each one real and in the product today. Anything still in the works is listed further down, clearly labelled.

  1. Each agency’s data stays private

    Every agency’s data is kept private and separate, enforced by the database itself, so one agency can never see another’s.

    See it in the product
  2. Tamper-evident audit trail

    Sensitive actions are recorded to a log that can’t be edited or deleted (by design, not policy), so accountability records cannot be rewritten.

    See it in the product
  3. Chart access is logged

    Every view of a client chart is recorded (who looked, at what, and when), so even just reading a record is accountable.

    See it in the product
  4. Strong password hashing

    Account passwords are hashed and salted, and never stored in plain text.

    See it in the product
  5. Health information kept out of logs

    Health-card numbers, identifiers and clinical details are kept out of our system logs.

    See it in the product
  6. Role-based access control

    Staff access is scoped by role (owner, admin, scheduler, biller, coordinator, viewer), so people see only what their job requires. Caregivers and family members sign in through separate, secure spaces.

    See it in the product
  7. Encrypted in transit

    All traffic between you and CareKindle is encrypted in transit (HTTPS/TLS).

    See it in the product

See it for yourself

Every safeguard above is something you can open and check inside CareKindle. The compliance centre keeps the tamper-evident audit trail and the record of who accessed health information next to incidents, consent, retention schedules and privacy requests, so your privacy officer can verify our claims any ordinary day, not just at audit time.

CareKindle compliance centre showing the tamper-evident audit trail with logged access to health information
The compliance centre’s audit trail: tamper-evident, with logged access to health information.

Certifications & attestations

Items marked "In progress" or "Planned" are not yet certified or audited. We list them for transparency and will update this page when each is complete.

Engagement underwayCommitted, not yet started
  1. SOC 2 Type IIIn progress

    Independent audit of our security, availability, and confidentiality controls over a monitoring period.

    Independent CPA firm · AICPA Trust Services Criteria
  2. PHIPA / PIPEDA alignmentPlanned

    Practices aligned to Ontario's PHIPA and Canada's PIPEDA for the collection, use, and disclosure of personal health information.

    Self-attested · Canadian privacy law
  3. ISO/IEC 27001:2022Planned

    Internationally recognized standard for an information security management system (ISMS).

    Accredited ISO certification body
  4. HIPAA Security & Privacy RulesPlanned

    Administrative, physical, and technical safeguards aligned to the US HIPAA Security Rule for handling protected health information.

    Self-attested + independent readiness assessment
  5. GDPRPlanned

    Data-subject rights, lawful-basis, and processor obligations under the EU General Data Protection Regulation.

    Self-attested · EU Regulation 2016/679

What we’re working toward

Controls we are building or formalizing. None of these is claimed above, because none of these is finished.

  • Mandatory multi-factor authentication for privileged roles
  • Encryption at rest with managed keys
  • Verified Canadian data residency
  • Independent SOC 2 Type II audit, then ISO 27001
  • Automated data-subject access & erasure (DSAR) fulfilment
  • A documented breach-notification runbook with statutory timelines

Sub-processors

The third parties we use in delivering CareKindle. We notify customers before adding a new sub-processor that handles their data.

We publish "Confirming region" rather than guess.

Sub-processor register · rev. June 2026
Sub-processorPurposeData locationStatus
Cloud hosting & databaseApplication compute and the primary database.Confirming regionActive
Email delivery (Amazon SES)Transactional email delivery — invitations, verification codes and schedule/visit notifications. Message content can reference a client.Confirming regionActive
StripeAgency subscription billing only. Never used for client/patient billing.United States / globalActive
MapboxMaps and geocoding for scheduling and visit verification (EVV).United StatesActive
QuickBooks OnlineAccounting sync for client invoicing (export).United StatesComing soon

Procurement or security team?

We’re happy to walk through our safeguards, share sub-processor data-processing agreements, and (once available) our SOC 2 report under NDA.

Read it, then try it: every line on this page is in the product.

14-day trial · full access · no credit card.

Caregiver credential expiry tracking
Security & Trust · CareKindle