Revitaco is a trading name of JG Core Ltd (company no. 16218779). Security and compliance are fundamental to everything we do. This page provides transparency into our practices, certifications, and the third parties we work with.
Security Overview
Revitaco implements comprehensive security measures to protect your data. Our approach is based on defence in depth, with multiple layers of protection.
Encryption
All data encrypted in transit and at rest using industry-standard encryption
Access Control
Role-based access controls
Monitoring
Continuous monitoring and alerting
Secure Development
Secure coding practices and regular code reviews
Incident Response
Documented procedures with 48-hour breach notification
Business Continuity
Backup and disaster recovery procedures to be in place before any customer data is onboarded
Technical Security Measures
- Network Security: DDoS protection and network segmentation
- Application Security: Input validation and secure coding practices
- Data Security: Encryption at rest and in transit, data minimisation
- Identity Security: Password policies and session management
- Operational Security: Least privilege access and security training
Data Hosting
Our database is hosted in the United Kingdom on Supabase (PostgreSQL), in the London region, ensuring compliance with UK data residency requirements and minimising latency for UK-based users. We hold no customer data today; the platform currently contains demonstration data only.
Data Centre Location
- Location: London, United Kingdom (eu-west-2)
- Database Platform: Supabase (PostgreSQL)
- Infrastructure Provider Certifications: ISO 27001, SOC 2
Data Residency
All primary data (resident records, care notes, user data) will be stored exclusively in our UK (London) database. No customer data will be transferred outside the UK without explicit consent and appropriate safeguards.
Backup and Recovery
No customer data is held yet. Before any customer data is onboarded, we will ensure our database platform provides:
- Automated daily backups
- Point-in-time recovery capability
- Backups encrypted and stored securely
- Regular backup restoration testing
Sub-Processors
We use carefully selected third-party service providers (sub-processors) to deliver our platform. Each provider is vetted for security and compliance.
| Provider | Purpose | Location | Privacy |
|---|---|---|---|
| Vercel | Application hosting and content delivery (CDN) | Global (edge network) | View |
| Supabase Inc. | PostgreSQL database hosting | London, UK (eu-west-2) | View |
This list reflects the services in use today. Additional providers will be added here before they process any customer data. We maintain contracts with all sub-processors that include appropriate data protection obligations. Customers are notified of new sub-processors with at least 30 days notice.
Audit Logging
Comprehensive audit logging is essential for care sector compliance and demonstrating accountability. Revitaco maintains detailed, immutable audit trails.
What We Log
We maintain audit trails covering administrative and configuration changes, billing events, compliance document uploads, and incident records. This supports CQC compliance and enables accountability.
Retention and Access
- Audit logs retained in line with NHS records guidance
- Logs are append-only and immutable by design
- Accessible to authorised administrators via the platform
- Viewable and filterable in-platform for inspections
Certifications & Compliance
We are committed to achieving and maintaining recognised security and compliance certifications relevant to the UK care sector.
ISO 27001
PlannedInformation Security Management System certification
Cyber Essentials Plus
PlannedUK Government-backed cybersecurity certification
NHS DSPT
PlannedNHS Data Security and Protection Toolkit alignment
Regulatory Alignment
- ICO Registration: JG Core Ltd, trading as Revitaco, is registered with the Information Commissioner's Office (registration ZC079115)
- CQC: Platform designed to support CQC compliance requirements
- UK GDPR: Full compliance with UK data protection legislation
- Data Protection Act 2018: Adherence to UK-specific requirements
- PECR: Compliance with electronic communication regulations
Security Questions or Concerns?
If you have security questions, require additional documentation, or want to report a security concern, please contact our security team.
- Security Enquiries: security@revitaco.io
- Responsible Disclosure: security@revitaco.io
- Compliance Documentation: legal@revitaco.io