Trust centre

Security posture

Last updated: August 20, 2026

SeniorGuardCare handles medication and health information. This page summarises how we protect that data for families and care facilities. It is not a substitute for a signed DPA — facility customers can request our DPA template at support@seniorguard.care.

Controls in place

  • Encrypted transport (TLS) for all web and API traffic.
  • Supabase Auth with session cookies; mobile apps use bearer tokens over HTTPS.
  • Row Level Security (RLS) on care data so users only see circles they belong to.
  • Document vault stored in Supabase Storage with access scoped to the care circle.
  • Stripe processes card payments; we store Stripe customer IDs, not full card numbers.
  • Account deletion available in-app and on the web (Apple/Google store requirement).
  • Audit-oriented activity feed and compliance CSV / inspection pack for facility plans.

AI privacy stance

AI features (label scan, doctor visit summary, and similar) are optional and gated behind explicit consent in-product. Prompts are sent to the model provider to generate the requested output. We do not sell care data. We instruct providers not to use customer content to train their foundation models where the provider contract allows that setting. Prefer generating a doctor PDF only with data you are comfortable sharing with a clinician.

Full privacy details: Privacy Policy — AI section.

Subprocessors

We use the following processors to run the Service. Regions depend on your project configuration and the vendor's infrastructure.

VendorRoleTypical region
SupabaseDatabase, auth, file storageEU / configured project region
VercelApplication hostingGlobal edge
StripePayments and billing portalUS / EU as configured
ResendTransactional emailUS / EU as configured
TwilioSMS alerts (when enabled)US / EU as configured
OpenAIOptional AI features (label scan, doctor summary)US
PostHogProduct analytics (feature events)EU cloud preferred
SentryError monitoringUS / EU as configured

Certifications roadmap

We do not claim DSPT, Cyber Essentials Plus, ISO 27001, or NHS Assured status unless a specific customer deal requires that programme. Basic Cyber Essentials and a DPIA for medication/health data are on the month-1 legal track. Ask us if a procurement checklist blocks your purchase.

Questions or incidents

Security reports and DPA requests: support@seniorguard.care. Related: Privacy · Terms.