Trust Centre

Evidence, boundaries and ownership — in plain language.

This page separates controls implemented in the CareFlow application from deployment responsibilities and certifications CareFlow does not currently claim. It is a product transparency record, not a substitute for a customer-specific security review.

Implemented in the product

Controls the current code can substantiate.

Configuration can still affect a production deployment, so customer due diligence remains important.

Authenticated, scoped workspaces

Signed session cookies protect workspace routes. API requests resolve a tenant and module access is checked against the signed-in role or explicit custom permissions.

Role and module access

Owners and managers can assign roles, narrow a staff member to selected modules and immediately deactivate an account.

Owner-authorised data export

Only the workspace owner can export tenant-scoped operational records, after re-entering the current password. The event is logged; password hashes and authentication tokens are excluded.

Recoverable owner-confirmed erasure

Only the workspace owner can schedule deletion after password and exact-name confirmation. A seven-day grace period allows recovery; operational records are then erased while a pseudonymised, redacted audit minimum is retained for up to 365 days.

Searchable activity evidence

Sensitive actions create tenant-scoped audit records with actor, role, action, target and time. CareFlow does not describe this application-level trail as an external certification.

Verified payment activation

CareFlow verifies Checkout and raw webhook signatures, then fetches Razorpay's payment record and confirms captured status, order, amount and INR currency before activation. Duplicate callbacks are idempotent and pending orders are reconciled server-side.

Shared responsibility

Trust is more than an application feature.

The final assurance level depends on three layers working together.

LAYER 01

CareFlow application

Tenant and module scoping, role controls, application audit records, export and deletion flows, payment verification and human approval boundaries.

LAYER 02

Production deployment

Database and object-storage region, encryption and backup settings, secret management, monitoring, incident response, retention and recovery testing.

LAYER 03

Customer organisation

Authorised users, lawful data collection, least-privilege role assignment, device security, clinical governance and review of AI-assisted output.

Data lifecycle

What ownership means in CareFlow.

  1. 01

    Collect deliberately

    New workspaces start empty. Teams enter or import real master and operational data after access is configured.

  2. 02

    Use within the tenant

    Application requests scope records to the resolved tenant and authorised modules.

  3. 03

    Export with re-authentication

    The owner re-enters the current password before downloading operational, configuration, billing and audit records in structured JSON.

  4. 04

    Erase after a grace period

    The owner confirms password and workspace name, receives seven days to cancel, and then operational records are erased. A redacted security and financial audit minimum expires after its separate retention window.

Not currently claimed

No badge without the evidence behind it.

CareFlow does not present the following as current certifications or universal guarantees:

  • HIPAA certification
  • GDPR certification
  • ABDM certification or empanelment
  • SOC 2
  • ISO 27001
  • A universal data-residency guarantee

A customer requiring one of these frameworks should request a scoped readiness and contractual review before placing regulated data in production.

Authoritative references

These links explain the external frameworks. They do not certify CareFlow.

Need a customer-specific review?

Send the intended deployment, data categories, required framework and contractual controls. We will answer against evidence rather than badges.

Start a trust review