Trust & Security
Care data deserves care-grade security.
How FlexiEle protects your residents' and staff data — certifications, UK data residency, encryption, access controls, clinical safety and incident response.
Last updated:
Certifications & assurance
ISO/IEC 27001
Information security management, certified.
SOC 2 Type 2
Independently audited operating effectiveness.
UK & EU GDPR
UK-resident, lawful-basis processing.
Alongside these, FlexiEle is DSCR-aligned, NHS Digital ODS-registered, aligned to Skills for Care (ASC-WDS) reporting, and maintains a full CQC Reg 17 audit trail. Our NEWS2 implementation is version-tagged for clinical-safety assurance under DCB0129.
UK data residency by default
Your data never leaves the UK.
All FlexiEle production data — resident care records and staff data — is stored in AWS eu-west-2 (London). It does not cross regions in the normal course of operation. Voice notes captured at the point of care are transcribed on our own UK infrastructure; audio is never sent to a third-party service and is retained as evidence alongside the note.
Website data (contact-form and demo bookings) is likewise held in the UK (London, AWS eu-west-2). See our privacy policy for the full breakdown.
Encryption
In transit
- TLS 1.2+ on all customer-facing endpoints
- HSTS enforced on the marketing site
- Certificate transparency monitored
At rest
- AES-256 on all database storage volumes
- AWS-managed KMS keys with rotation
- Encrypted backups in the same region
Access controls
- Role-based access controls in the application; permissions follow least-privilege, so carers, nurses and managers see only what their role requires.
- Multi-factor authentication available for all administrative users, and required for FlexiEle staff.
- Production access for FlexiEle engineers is scoped, logged and reviewed quarterly.
- Single sign-on (SAML/OIDC) supported for larger groups.
- Every action is captured in a per-user audit log, supporting CQC Reg 17 governance.
Backups & disaster recovery
- Automated daily snapshots of all customer databases, retained for 35 days.
- Point-in-time recovery available within the retention window.
- Backups remain in the UK region as the source database — they do not cross borders.
- A documented disaster-recovery runbook with RPO and RTO targets, shared with customers under NDA.
Testing & assessments
- Annual third-party penetration tests, with remediation tracked to closure.
- Continuous vulnerability scanning of dependencies and infrastructure.
- Static and dynamic application security testing in our CI pipeline.
- Summary reports available to customers under NDA.
Clinical safety
Because FlexiEle handles clinical information, we treat clinical safety as part of security. NEWS2 scores are computed on the server, version-tagged for DCB0129 clinical-safety assurance, role-gated, and reviewed against the published NHS chart. In V1 there is no automatic escalation — the score is shown with guidance, and a clinician decides. This keeps a human in the loop for every clinical judgement.
Sub-processors
We engage a small number of trusted sub-processors for infrastructure and email. The full list, with each supplier’s purpose and processing region, is published at /sub-processors. Notably, voice transcription is self-hosted on UK infrastructure — it is not outsourced to a third party.
Customers receive 30 days’ notice before any new sub-processor is added to that list.
Incident response
FlexiEle runs a defined incident-response process: detection → containment → eradication → recovery → post-mortem. Critical incidents trigger customer notification within 72 hours of confirmation, in line with UK/EU GDPR Article 33 where applicable.
To report a vulnerability or suspected security issue, email security@flexiele.com — we acknowledge reports within one business day.
Talk to our security team
Customers and prospects can request our security questionnaire responses, penetration-test summaries, sub-processor list and Data Processing Agreement (DPA).
Security & trust: security@flexiele.com
Data Protection Officer: dpo@flexiele.com