Security at CareOS

CareOS holds some of the most sensitive data there is — care records for vulnerable people. This page summarises how Byte River Ltd (the company behind CareOS) protects it. For contractual detail, see our Data Processing Addendum and sub-processor register.

NHS Data Security & Protection Toolkit

Standards Exceeded

Year
2025-26 (version 8)
Published
22 July 2026
ODS code
L8N6V
Organisation
Byte River Ltd

CareOS is operated by Byte River Ltd. This status is published by NHS England and can be verified independently — look up ODS code L8N6V on the DSPT portal. Alongside it: Cyber Essentials Plus (independently assessed, 2026), ICO registration ZB847215, all customer data at rest in the United Kingdom including backups, and a separate database per customer organisation.

Independent assurance

  • Cyber Essentials Plus — independently assessed certification held (2026).
  • NHS Data Security and Protection Toolkit (DSPT) Standards Exceeded for 2025-26 (version 8), published 22 July 2026. Registered under ODS code L8N6V; the assessment is against the National Data Guardian's 10 data security standards and the published record is public on the DSPT portal. If you are completing your own toolkit, our guide to the DSPT for care providers covers what it asks of you and what to ask a supplier.
  • ICO registration— Byte River Ltd is registered with the Information Commissioner's Office, registration ZB847215.

UK data residency

  • All customer data at rest is stored in the United Kingdom (AWS London, eu-west-2) — including every database, uploaded document and backup.
  • Limited, safeguarded transfers apply only to specific sub-processors (for example optional AI features and error monitoring) — see our sub-processor register for exactly what goes where.

Isolation by architecture

  • Every customer organisation gets its own dedicated PostgreSQL database — care records are never co-mingled across customers in shared tables.
  • The organisation claim in every authenticated request is validated against the requesting subdomain, so a user of one organisation cannot reach another's data.

Encryption

  • TLS 1.2+ on all connections in transit.
  • Disk-level encryption at rest across hosting and storage.
  • Additional application-layer field encryption for designated identifiers such as NHS numbers and medical conditions.
  • Passwords are hashed with bcrypt; sessions use httpOnly cookies.

Access control

  • Role-based access control enforced server-side, with granular permission groups for tenant users and a separately scoped permission catalogue for platform administrators.
  • All platform-administrator access to customer data is permission-gated and audit-logged.
  • Optional customer-controlled two-factor authentication for admins, and a mandatory-biometrics policy option for care staff on mobile.

Auditability

  • An append-only audit log records every data mutation with the actor, organisation and changed fields.
  • Request logging, outbound-email logging, and an AI-call audit (token counts and prompt hashes — never prompt content) provide full operational traceability.
  • Care records are soft-deleted only, supporting the 8+ year regulatory retention duties of care providers.

Resilience and continuity

  • Automated backups with 30-day retention and point-in-time recovery.
  • Autoscaled application instances behind a load balancer, with zero-downtime deployment mechanisms.
  • A documented and scenario-tested business continuity and disaster recovery plan.

Incident response

  • A documented incident response procedure covering detection, triage, containment and post-incident review.
  • Customers are notified of any personal data breach affecting their data without undue delay (target: within 24 hours), with the information they need to meet their own 72-hour ICO notification obligations.

Working with your own DSPT and supplier lists

Care providers name their software suppliers in their own DSPT submissions and supplier registers. We support that with data-processing terms in every customer agreement, our published sub-processor register with 30 days' advance notice of changes, breach notification without undue delay, per-tenant audit logs, and full data export at contract end. Security questionnaires and further evidence are available on request — contact us.

Last reviewed: July 2026. This page is a summary; the underlying policies are reviewed annually and available to customers and prospective customers under NDA.