Security at CareVaultHub

How we protect the care records you trust us with.

In transit and at rest

Every connection to CareVaultHub is HTTPS-only (TLS 1.2+). Every record and uploaded document is stored on encrypted Azure SQL and Azure Blob Storage with server-side encryption enabled by default.

Access control

Records are scoped to the owner and people they explicitly invite. We enforce role-based authorisation on every API endpoint and audit-log every read of sensitive data (insurance, legal, financial).

Authentication

Sign-in is protected by password plus required two-factor authentication (authenticator app). Recovery codes are issued at enrolment.

Reporting a vulnerability

Please email security@carevaulthub.com. We acknowledge reports within two business days.