Trust & Security

Care data deserves care-grade security.

How FlexiEle protects your residents' and staff data — certifications, UK data residency, encryption, access controls, clinical safety and incident response.

Last updated:

Certifications & assurance

ISO/IEC 27001

Information security management, certified.

SOC 2 Type 2

Independently audited operating effectiveness.

UK & EU GDPR

UK-resident, lawful-basis processing.

Alongside these, FlexiEle is DSCR-aligned, NHS Digital ODS-registered, aligned to Skills for Care (ASC-WDS) reporting, and maintains a full CQC Reg 17 audit trail. Our NEWS2 implementation is version-tagged for clinical-safety assurance under DCB0129.

UK data residency by default

Your data never leaves the UK.

All FlexiEle production data — resident care records and staff data — is stored in AWS eu-west-2 (London). It does not cross regions in the normal course of operation. Voice notes captured at the point of care are transcribed on our own UK infrastructure; audio is never sent to a third-party service and is retained as evidence alongside the note.

Website data (contact-form and demo bookings) is likewise held in the UK (London, AWS eu-west-2). See our privacy policy for the full breakdown.

Encryption

In transit

  • TLS 1.2+ on all customer-facing endpoints
  • HSTS enforced on the marketing site
  • Certificate transparency monitored

At rest

  • AES-256 on all database storage volumes
  • AWS-managed KMS keys with rotation
  • Encrypted backups in the same region

Access controls

  • Role-based access controls in the application; permissions follow least-privilege, so carers, nurses and managers see only what their role requires.
  • Multi-factor authentication available for all administrative users, and required for FlexiEle staff.
  • Production access for FlexiEle engineers is scoped, logged and reviewed quarterly.
  • Single sign-on (SAML/OIDC) supported for larger groups.
  • Every action is captured in a per-user audit log, supporting CQC Reg 17 governance.

Backups & disaster recovery

  • Automated daily snapshots of all customer databases, retained for 35 days.
  • Point-in-time recovery available within the retention window.
  • Backups remain in the UK region as the source database — they do not cross borders.
  • A documented disaster-recovery runbook with RPO and RTO targets, shared with customers under NDA.

Testing & assessments

  • Annual third-party penetration tests, with remediation tracked to closure.
  • Continuous vulnerability scanning of dependencies and infrastructure.
  • Static and dynamic application security testing in our CI pipeline.
  • Summary reports available to customers under NDA.

Clinical safety

Because FlexiEle handles clinical information, we treat clinical safety as part of security. NEWS2 scores are computed on the server, version-tagged for DCB0129 clinical-safety assurance, role-gated, and reviewed against the published NHS chart. In V1 there is no automatic escalation — the score is shown with guidance, and a clinician decides. This keeps a human in the loop for every clinical judgement.

Sub-processors

We engage a small number of trusted sub-processors for infrastructure and email. The full list, with each supplier’s purpose and processing region, is published at /sub-processors. Notably, voice transcription is self-hosted on UK infrastructure — it is not outsourced to a third party.

Customers receive 30 days’ notice before any new sub-processor is added to that list.

Incident response

FlexiEle runs a defined incident-response process: detection → containment → eradication → recovery → post-mortem. Critical incidents trigger customer notification within 72 hours of confirmation, in line with UK/EU GDPR Article 33 where applicable.

To report a vulnerability or suspected security issue, email security@flexiele.com — we acknowledge reports within one business day.

Talk to our security team

Customers and prospects can request our security questionnaire responses, penetration-test summaries, sub-processor list and Data Processing Agreement (DPA).

Security & trust: security@flexiele.com
Data Protection Officer: dpo@flexiele.com