Trust

    Security and compliance

    Care data is sensitive. We treat it that way.

    Data residency

    All customer data stored in AWS Sydney (ap, southeast, 2). Backups encrypted, region pinned.

    Encryption

    AES, 256 at rest. TLS 1.3 in transit. Application secrets stored in Supabase Vault, never in source.

    Access control

    Row Level Security on every table. Server side admin proxy. SECURITY DEFINER for elevated reads. Three role centre model.

    Compliance

    SOC2 Type I underway. Aligned to Australian Aged Care Act, NDIS Code of Conduct, Childcare quality standards.

    Multi region trust

    Per country compliance frames: NDIS, DBS (UK), Police Vetting (NZ), CRB (US), CQC (UK).

    Monitoring

    Continuous uptime monitoring. Edge function audit logs. Anomaly detection on auth and admin actions.

    Frequently asked

    Where is data stored?

    AWS Sydney only. We do not replicate to other regions.

    Do you sell or share data?

    Never. Customer data is yours. We never sell, rent or share without explicit consent.

    Can we sign a DPA?

    Yes. Email security@suggicare.io and we send within one business day.

    Is Care Alerts a medical device?

    No. Care Alerts is a wellbeing signal layer, not a medical device. We do not provide triage or medical advice.

    How do you handle breaches?

    24 hour notification policy with full incident report within 7 days. Run, books rehearsed quarterly.

    Penetration testing?

    Annual third party penetration test. Findings remediated and re tested before close.

    Need our security pack?

    DPA, SOC2 progress letter, network diagram and penetration test summary.

    You are offline. We will retry when you reconnect.