Trust & Security
Last updated: 20 August 2026
Cyber Essentials certified — SoftCare Technologies Ltd was certified under the NCSC's Cyber Essentials scheme (IASME) in August 2026. Certificate available on request; verify via the NCSC certificate search.
SoftCare is built by a CISSP-certified former Principal Security Engineer. We don't outsource your residents' records to someone else's default configuration: your data lives in the UK, encrypted, behind row-level security policies we wrote ourselves — and everything on this page is verifiable.
Where your data lives
All service data is hosted in the United Kingdom (London region) on fully managed cloud infrastructure, encrypted in transit and at rest. Every care provider's records are isolated by security policies enforced inside the database itself, not just in application code. We operate no servers of our own — there is no remote-login surface to attack.
Certifications and assurance
| Scheme | Status |
| Cyber Essentials (NCSC / IASME) | Certified — August 2026 |
| Cyber Essentials Plus | In progress |
| NHS DSPT (Standards Met) | Planned |
| DCB0129 clinical safety case | In progress with our Clinical Safety Officer |
| ICO registration | ZC204698 — verify on the ICO register |
| UK GDPR Data Processing Agreement | Available on request — we send it before you ask |
What we publish that most vendors don't
- Our full sub-processor register — every service that touches data, what for, where, and under what safeguard
- Our Data Processing Agreement — read it before you ever talk to us
- Redacted Data Protection Impact Assessments for high-risk processing (medication records, safeguarding) — on request while we prepare them for publication
Security practices, in plain English
- Multi-factor authentication on every administrative system — checked automatically every week
- Every code change passes automated security scanning before it can ship: secret detection, static analysis, dependency and container image checks
- Critical security fixes reach production within 14 days, usually within the week
- Daily database backups with point-in-time recovery
- Company devices are centrally managed: encrypted disks, enforced screen locks, automatic updates, standard (non-administrator) accounts
- A written incident-response plan: if something affects your data, you hear from us within 48 hours
Ask us anything
Security questionnaire? Send it: [email protected]. DPA requests to the same address. We answer within one business day.