Security
Babiha is built for UK domiciliary care agencies handling sensitive health data. We use the controls described below to help protect that data. For most care data we act as a data processor on the agency's behalf, under our Data Processing Agreement.
Data Encryption
- At rest: data is encrypted by our hosting provider under the terms they publish for their platform
- In transit: deployed website and API connections use TLS encryption
- Sensitive fields: NHS numbers, key safe codes and bank details are additionally encrypted at the application layer (AES-256-GCM) before storage
Data Hosting
Our primary database and file storage are hosted in the United Kingdom (London region). Hosting location does not exclude overseas processing or support access by our providers:
- Primary database and storage hosted in the UK (London) via Supabase
- A small number of sub-processors are located outside the UK; the required transfer safeguards and their recorded verification status are described (see our Sub-processors page)
Access Controls
- Role-based access control (RBAC): granular permissions across care staff, management and external users
- Row Level Security (RLS): database-level policies restrict access to agency data according to the authenticated user and their permissions
- Multi-tenancy: agency-scoped application access and database policies support separation of customer records
- Two-factor authentication: available for supported account types, with agency policy controls
- Session management: automatic session expiry and refresh handling
Audit Logging
- Audited actions record the actor, timestamp and relevant context
- Sensitive data access is logged for compliance purposes
- Our audit retention policy uses a 7-year review threshold; logs are not routinely deleted automatically
- Redaction controls reduce personal data in logs and error reports
Application Security
- Rate limiting: limits on protected API routes to help prevent abuse
- Input validation: structured validation in forms and server request handlers
- Content Security Policy: nonce-based CSP headers to help prevent cross-site scripting (XSS)
- Security headers: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy on responses
- Webhook signatures: signature verification for supported webhook integrations
- Ongoing assurance: regular internal security reviews, automated dependency and secret scanning, and code review
Cookie Consent and Analytics
We respect your privacy choices. How our analytics and monitoring apply depends on where they run:
- In your browser: analytics, performance tracing and session replay (Vercel Analytics, Sentry) are disabled by default and only load after you grant analytics consent; optional monitoring is not initialised before that choice
- On our servers: server-side error monitoring (Sentry) runs under our legitimate interest in a reliable, secure service, with redaction controls to reduce personal data in diagnostic reports. It uses no cookies or device storage, so it is not controlled by the cookie banner
- You can change your cookie preferences at any time via the Cookie Settings link in the footer
- See our Cookie Policy for full details
Compliance
- Care regulation: tools support care planning, record keeping and oversight. Agencies remain responsible for meeting the requirements of their regulator
- UK GDPR: designed for compliance with UK GDPR and the Data Protection Act 2018, with a Data Processing Agreement available to every agency customer
- Assurance: this page is a description of controls, not a certification, independent audit report or NHS approval
- Due diligence: contact us for the current evidence available for your procurement and data protection assessments
Incident Response
In the event of a personal data breach, we follow a structured process:
- Affected agencies are notified without undue delay so they can meet their own obligations
- Where Babiha is the controller, the Information Commissioner's Office (ICO) is notified within 72 hours where required under UK GDPR Article 33
- A full investigation is conducted and documented
- Remediation measures are implemented and verified
Responsible Disclosure
If you discover a security vulnerability in Babiha, we encourage responsible disclosure. Please report it to security@babiha.care. We aim to acknowledge receipt within two working days and resolve confirmed vulnerabilities promptly.
Questions
For security questions, contact security@babiha.care. For data protection enquiries, contact our Data Protection Lead at dpo@babiha.care.