Demonstration only — do not enter real patient information.

Taking a small number of design partners for paid pilots this quarter. Talk to us

Controls

Enforced in the database, not just the screens.

Row-level security on every table

Access is decided in the database by membership of the client's circle or care team — not only in the application. A bug in a screen cannot return a record the viewer has no right to.

Per-category visibility

Legal, insurance, identity and financial documents are restricted by default to the family and senior staff. Coordinators and hired carers see the care record, not the paperwork around it.

Private document storage

Uploaded documents sit in a private bucket and are only ever served through links that expire within minutes. Nothing is public, and there is no guessable address.

A human confirms every read

Nothing the model extracts becomes part of a record until a named person approves it, and their name is stored against it.

Full audit trail

Extractions, confirmations, deletions and joins are recorded with who and when. Owners and managers can read it inside the product.

Export and deletion

Anyone who can see a record can export everything they can see, as a file, without asking us. Deletion requests are recorded and confirmed before anything is erased.

AI

It reads. A person decides.

The model is a transcriber. It does not practise medicine and it does not write to the record.

  • Documents are sent to Anthropic's API to be read. The model transcribes; it is instructed never to infer a dose, strength or date that is not printed.
  • Every proposal is shown beside the exact line it was read from, with uncertain reads flagged for a person to check.
  • Nothing is written to a medication list or calendar automatically.
  • The raw model output is kept alongside the extraction so a bad read can be investigated without asking for the document again.

Subprocessors

Everyone else who touches your data.

ServiceWhat it doesWhere
SupabaseDatabase, authentication, document storageUnited States (East)
VercelWeb application hostingUnited States
RailwayApplication APIUnited States
AnthropicReading uploaded documentsUnited States

Compliance status

Where the paperwork stands.

OurCareBook is built for a HIPAA business associate agreement: the controls above, consent capture, and a breach-notification record exist today.

The agreements with every subprocessor that would touch real client records are not all signed yet. Until they are, pilots run on de-identified or synthetic documents, and the product itself says so on every screen.

Ask us on the first call and we will tell you exactly which are signed and which are not. If a vendor ever tells you they are “fully compliant” without being able to show you the same list, ask them for it.

Ask us directly

Found a security issue?

Tell us before anyone else. We will acknowledge within two working days and keep you informed while we fix it.

Report a security issue