Back to Legal Hub

Trust & Compliance

Last updated: 17 July 2026|Version 1.1

Revitaco is a trading name of JG Core Ltd (company no. 16218779). Security and compliance are fundamental to everything we do. This page provides transparency into our practices, certifications, and the third parties we work with.

Security Overview

Revitaco implements comprehensive security measures to protect your data. Our approach is based on defence in depth, with multiple layers of protection.

Encryption

All data encrypted in transit and at rest using industry-standard encryption

Access Control

Role-based access controls

Monitoring

Continuous monitoring and alerting

Secure Development

Secure coding practices and regular code reviews

Incident Response

Documented procedures with 48-hour breach notification

Business Continuity

Backup and disaster recovery procedures to be in place before any customer data is onboarded

Technical Security Measures

  • Network Security: DDoS protection and network segmentation
  • Application Security: Input validation and secure coding practices
  • Data Security: Encryption at rest and in transit, data minimisation
  • Identity Security: Password policies and session management
  • Operational Security: Least privilege access and security training

Data Hosting

Our database is hosted in the United Kingdom on Supabase (PostgreSQL), in the London region, ensuring compliance with UK data residency requirements and minimising latency for UK-based users. We hold no customer data today; the platform currently contains demonstration data only.

Data Centre Location

  • Location: London, United Kingdom (eu-west-2)
  • Database Platform: Supabase (PostgreSQL)
  • Infrastructure Provider Certifications: ISO 27001, SOC 2

Data Residency

All primary data (resident records, care notes, user data) will be stored exclusively in our UK (London) database. No customer data will be transferred outside the UK without explicit consent and appropriate safeguards.

Backup and Recovery

No customer data is held yet. Before any customer data is onboarded, we will ensure our database platform provides:

  • Automated daily backups
  • Point-in-time recovery capability
  • Backups encrypted and stored securely
  • Regular backup restoration testing

Sub-Processors

We use carefully selected third-party service providers (sub-processors) to deliver our platform. Each provider is vetted for security and compliance.

ProviderPurposeLocationPrivacy
VercelApplication hosting and content delivery (CDN)Global (edge network)View
Supabase Inc.PostgreSQL database hostingLondon, UK (eu-west-2)View

This list reflects the services in use today. Additional providers will be added here before they process any customer data. We maintain contracts with all sub-processors that include appropriate data protection obligations. Customers are notified of new sub-processors with at least 30 days notice.

Audit Logging

Comprehensive audit logging is essential for care sector compliance and demonstrating accountability. Revitaco maintains detailed, immutable audit trails.

What We Log

We maintain audit trails covering administrative and configuration changes, billing events, compliance document uploads, and incident records. This supports CQC compliance and enables accountability.

Retention and Access

  • Audit logs retained in line with NHS records guidance
  • Logs are append-only and immutable by design
  • Accessible to authorised administrators via the platform
  • Viewable and filterable in-platform for inspections

Certifications & Compliance

We are committed to achieving and maintaining recognised security and compliance certifications relevant to the UK care sector.

ISO 27001

Planned

Information Security Management System certification

Cyber Essentials Plus

Planned

UK Government-backed cybersecurity certification

NHS DSPT

Planned

NHS Data Security and Protection Toolkit alignment

Regulatory Alignment

  • ICO Registration: JG Core Ltd, trading as Revitaco, is registered with the Information Commissioner's Office (registration ZC079115)
  • CQC: Platform designed to support CQC compliance requirements
  • UK GDPR: Full compliance with UK data protection legislation
  • Data Protection Act 2018: Adherence to UK-specific requirements
  • PECR: Compliance with electronic communication regulations

Security Questions or Concerns?

If you have security questions, require additional documentation, or want to report a security concern, please contact our security team.

If you have questions about this document, please contact us at legal@revitaco.io