Compliance

What's actually in place, and what isn't.

A lot of care-tech products list badges they don't hold. We won't. This page is the honest picture of where Vicarity stands on compliance — updated as things land.

In placeIn progressOn roadmap

CQC Single Assessment Framework

In place

The platform is modelled around the CQC framework.

Care logs, incidents, risk assessments and staff training link to CQC quality statements. Evidence is structured so it's available when inspectors ask for it.

UK GDPR + Data Protection Act 2018

In place

Special Category Data handled appropriately.

Role-based access control, scoped data visibility (care home isolation), audit logs on sensitive actions, encrypted at rest and in transit (TLS 1.3).

UK hosting

In place

No data leaves the UK.

Application hosted on UK infrastructure. Database on Supabase EU region. No US cloud dependencies in the production path.

DBS handling

In place

Care workers upload DBS; care homes verify before booking.

Worker credentials including DBS certificate, expiry and update-service subscription are stored against the worker's profile. Care homes can set DBS requirements per shift and passporting enforces them automatically.

Audit trail

In place

Structured logs of sensitive actions.

Mutations on resident records, care plans, medication-related actions, and staff credentials are logged with user, timestamp, and before/after state.

Subject access requests (SARs)

In progress

Tools for data export and deletion.

Backend audit trail exists. Self-service SAR tooling for care workers, families and residents is being built.

ICO registration

In progress

Application in progress.

As a data controller, Vicarity will be registered with the Information Commissioner's Office. We'll publish the registration number here once granted.

NHS Data Security and Protection Toolkit (DSPT)

On roadmap

Target: before general availability.

DSPT is required to process NHS patient data at scale. We're preparing the assessment alongside ISO 27001 groundwork.

ISO 27001 certification

On roadmap

Target: 12–18 months post-launch.

Information security management. We'll undertake a formal audit once we have production scale to warrant certification.

Cyber Essentials Plus

On roadmap

Target: pre-DSPT.

UK baseline cyber security certification. Simpler and faster than ISO 27001 — a natural first step.

Questions about a specific requirement?

We'll answer directly — no PDFs, no gatekeeping.

Ask us anything