Trust & security
Security built for healthcare data
Care providers handle some of the most sensitive personal data in existence. We treat it that way — with controls equivalent to a modern bank, not a typical SaaS app.
Built to protect vulnerable people’s data
Encryption, UK data residency, least-privilege access and a full audit trail — a quick look at how CareLoop keeps your data safe.
Defence in depth
Twelve controls, working together
Reporting a vulnerability
We welcome responsible disclosure. Email careloop@ashdub.com with full details. We acknowledge within 24 hours, fix high-severity findings within 7 days, and credit you (with your consent) on our security hall-of-fame at /security/credits.
Our PGP key is available at /.well-known/security.txt.
Security you can hand to your DPO
See the controls on your own data
Bring your IG lead. We'll walk you through RLS isolation, audit logging and data residency live — then import your data so you can see it for real.
UK-hosted · ICO-registered · GDPR-compliant