PRO

Security & compliance

Protecting dignity, starting with how the data is designed.

CareOS handles sensitive, care-adjacent information. It is designed around privacy-by-design — with consent, least-privilege access, encryption, audit logs, and human approval at the center — and aligned to APPI (Japan), GDPR (EU), and HIPAA-style principles.

01

Data residency

Patient data is processed and stored in-region (Japan, EU, or your jurisdiction), so it never leaves the boundary you require.

02

Privacy by design

Consent, purpose limitation, and the right to erasure are built into the data model — not bolted on afterwards.

03

Human-approved, always

AI only drafts. Every monitoring record and family message is reviewed and approved by a care manager before it becomes final or is sent.

04

Least-privilege access

Role-based access control with per-role scoping. Care managers see only their assigned residents; families see only approved summaries.

05

Encryption everywhere

TLS 1.2+ in transit and AES-256 at rest. Keys and secrets live server-side only — never exposed to the browser or client code.

06

Full audit trail

Every call, draft, edit, approval, and access is logged with who, what, and when — tamper-evident and exportable.

07

No training on your data

Patient data is never used to train third-party foundation models. Prompts and records stay within the processing boundary.

08

Consent & deletion

Recorded consent per patient and family, with self-serve deletion requests honored within a defined SLA.

09

Data minimization

We collect and share only what care requires. Family updates contain only what a care manager has explicitly approved.

10

Secure vendors

Sub-processors are vetted and listed; each is bound by a data-processing agreement (DPA) with the same standards.

11

Backups & recovery

Encrypted, regularly-tested backups with a documented recovery objective, so care records survive failures.

12

Incident response

A written breach-response plan with defined notification timelines to your agency and the relevant authority.

Standards we align to

APPI, GDPR, and HIPAA-style principles — by design.

CareOS is positioned as care coordination and monitoring support, not a medical device. We build to the strictest applicable standard in each market, and can sign a DPA/BAA where required.

You stay in control

Deletion, purpose, and sharing scope — all controlled by your agency.

Consent records, access permissions, and deletion requests stay with your agency. CareOS does not replace judgment — it makes it safer to see.