Trust centre · Security & compliance

Security built for
regulated healthcare hiring.

Procurement teams, DPOs, and clinical governance leads need evidence — not buzzwords. Here is how HealthCrew AI approaches data protection, access control, and UK compliance during our Alpha design partner programme.

UK
Privacy focus
Website notice published
Clear
Status labels
Current and roadmap separated
Direct
Security reporting
Dedicated contact route
Review
Procurement evidence
Confirm before reliance

Compliance framework

Status labels distinguish published information, items that require current evidence, work in progress and roadmap plans.

Published

UK GDPR & privacy

Our public website notice explains its stated lawful bases, retention periods, cookie choices and rights contact route.

  • Website Privacy Notice
  • Cookie preference controls
  • Data-subject request contact route
  • Product processing assessed separately
Verify evidence

Assurance and registrations

Registration, toolkit and assurance status should be confirmed from current documentary evidence during procurement.

  • No certification implied by this page
  • Current evidence shared where available
  • Scope and expiry dates checked before reliance
  • Customer requirements assessed during procurement
In progress

ISO 27001

ISO 27001 certification is not claimed. Relevant management-system work remains in progress.

  • Risk-based control framework
  • Documented security policies
  • Vendor & access reviews
  • Continuous improvement cycle
Roadmap

SOC 2

SOC 2 Type II is a roadmap item; no current SOC 2 report or certification is claimed.

  • Security & availability controls
  • Confidentiality & processing integrity
  • Privacy criteria mapping
  • Available on enterprise timeline

Platform security

Architecture you can explain to your board

Use these topics to structure a product-specific security review. Availability and implementation can differ by product, deployment and release stage.

Access control

Confirm role design, privileged-access controls and available authentication options for the product and deployment you are reviewing.

Encryption

Request current evidence for transport, storage, key-management and backup protections before relying on specific algorithms or versions.

Logging and auditability

Confirm which events are logged, who can access them, how they are protected and how long they are retained.

Monitoring & response

Review monitoring, vulnerability-management, incident-response and notification arrangements during procurement.

Healthcare-specific

Credentialing & regulatory evidence

A product review should cover how worker checks, consent records, candidate documents and audit evidence are implemented for the intended workflow.

Identity and DBS checks
Confirm source, scope and timing
Professional registers
Confirm supported registers
Consent records
Review purpose and auditability
Regulatory evidence
Confirm available export formats
Working-time controls
Validate configured rules
Candidate documents
Review access and retention controls

Secure development review

Procurement reviews should confirm the secure-development lifecycle, dependency review, security testing and access practices that apply to the proposed service.

  • Input validation and output encoding
  • Secrets and privileged-access management
  • Dependency and vulnerability review
  • Vulnerability reporting and remediation

Data residency

Confirm hosting and transfers

Hosting locations, subprocessors and transfer mechanisms can vary by service and deployment. Request current product-specific documentation before making a residency or transfer assessment.

  • Hosting region and backup locations
  • Subprocessor locations and roles
  • Applicable UK transfer mechanism
  • Product-specific retention schedule
Hosting
Confirm primary region
Confirm backup region
Transfers
Review subprocessors
Review safeguards
Your review
Request current evidence
Record approved scope

Security FAQ

HealthCrew AI is designed with UK healthcare hiring in mind. Our infrastructure posture prioritises UK/EU hosting with clear data residency documentation available for procurement and DPO review.

Questions for your security review?

Our team can walk through architecture, subprocessors, and compliance evidence during a dedicated security briefing. Evidence availability depends on the product and release stage.

Privacy notice