Security at CareVaultHub
How we protect the care records you trust us with.
In transit and at rest
Every connection to CareVaultHub is HTTPS-only (TLS 1.2+). Every record and uploaded document is stored on encrypted Azure SQL and Azure Blob Storage with server-side encryption enabled by default.
Access control
Records are scoped to the owner and people they explicitly invite. We enforce role-based authorisation on every API endpoint and audit-log every read of sensitive data (insurance, legal, financial).
Authentication
Sign-in is protected by password plus required two-factor authentication (authenticator app). Recovery codes are issued at enrolment.
Reporting a vulnerability
Please email security@carevaulthub.com. We acknowledge reports within two business days.