Babiha is built for UK domiciliary care agencies handling sensitive health data. Security is embedded in every layer of our platform. For most care data we act as a data processor on the agency's behalf, under our Data Processing Agreement.
Data Encryption
- At rest: data is encrypted by our hosting provider under the terms they publish for their platform
- In transit: all connections use TLS encryption
- Sensitive fields: NHS numbers, key safe codes and bank details are additionally encrypted at the application layer (AES-256-GCM) before storage
Data Hosting
Our primary database and file storage are hosted in the United Kingdom (London region), so the core of the personal data we handle does not leave the UK:
- Primary database and storage hosted in the UK (London) via Supabase
- A small number of sub-processors are located outside the UK; where they are, we apply an approved transfer safeguard (see our Sub-processors page)
- Our infrastructure providers maintain SOC 2 Type II compliant data centres
Access Controls
- Role-based access control (RBAC): granular permissions across care staff, management and external users
- Row Level Security (RLS): database-level policies ensure complete agency isolation — each agency can only access its own data
- Multi-tenancy: every database query is filtered by agency, enforced at the database level
- Two-factor authentication: available for all user accounts
- Session management: automatic session expiry and refresh handling
Audit Logging
- All data modifications are recorded with user, timestamp and context
- Sensitive data access is logged for compliance purposes
- Audit logs are retained for 7 years in line with UK care-sector requirements
- Automatic redaction of personal data in logs and error reports
Application Security
- Rate limiting: hourly and burst limits on API endpoints to prevent abuse
- Input validation: all inputs validated using strict schemas on both client and server
- Content Security Policy: nonce-based CSP headers to help prevent cross-site scripting (XSS)
- Security headers: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy on responses
- Webhook signatures: HMAC-SHA256 verification for webhook integrations
- Ongoing assurance: regular internal security reviews, automated dependency and secret scanning, and code review on every change
Cookie Consent and Analytics
We respect your privacy choices. How our analytics and monitoring apply depends on where they run:
- In your browser: analytics, performance tracing and session replay (Vercel Analytics, Sentry) are disabled by default and only load after you grant analytics consent; nothing is stored on your device for these purposes beforehand
- On our servers: server-side error monitoring (Sentry) runs under our legitimate interest in a reliable, secure service, with personal data minimised and scrubbed before any report is sent. It uses no cookies or device storage, so it is not controlled by the cookie banner
- You can change your cookie preferences at any time via the Cookie Settings link in the footer
- See our Cookie Policy for full details
Compliance
- CQC-ready: built to support compliance with all 12 CQC Fundamental Standards (Regulations 9–20)
- UK GDPR: designed for compliance with UK GDPR and the Data Protection Act 2018, with a Data Processing Agreement available to every agency customer
- NHS DSPT: designed to align with the NHS Data Security and Protection Toolkit
- Cyber Essentials: working towards certification, including independent penetration testing as part of that programme
Incident Response
In the event of a personal data breach, we follow a structured process:
- Affected agencies are notified without undue delay so they can meet their own obligations
- Where Babiha is the controller, the Information Commissioner's Office (ICO) is notified within 72 hours where required under UK GDPR Article 33
- A full investigation is conducted and documented
- Remediation measures are implemented and verified
Responsible Disclosure
If you discover a security vulnerability in Babiha, we encourage responsible disclosure. Please report it to security@babiha.care. We will acknowledge receipt within 48 hours and aim to resolve confirmed vulnerabilities promptly.
Questions
For security questions, contact security@babiha.care. For data protection enquiries, contact our Data Protection Lead at dpo@babiha.care.