Controls
Last reviewed September 29, 2026Infrastructure security
| Control | Status |
|---|---|
|
Remote access MFA enforced Carebility staff reach production systems only with a Google Workspace account that requires 2-step verification. |
In place |
|
Remote access encrypted enforced Staff reach production systems only over encrypted connections. |
In place |
|
Network segmentation implemented Production, staging, testing, development and demo run in separate cloud projects and networks, with separate credentials and encryption keys. |
In place |
|
Configuration management system established Carebility's infrastructure is defined in code and deployed the same way in every environment. |
In place |
|
Hosted on SOC 2 audited infrastructure Carebility runs in production on Google Cloud, which is SOC 2 audited. |
In place |
|
Data encrypted in transit Connections to Carebility require HTTPS with TLS 1.2 or later. |
In place |
|
Resident data encrypted at rest Resident fields in Coworker are encrypted in the database with keys held in Google Cloud KMS and rotated every 90 days. |
In place |
|
Document storage encrypted and private Coworker document storage is encrypted with Carebility-managed keys, and public access to it is blocked. |
In place |
|
Database backups with point-in-time recovery Carebility's databases are backed up continuously and can be restored to a point in time. |
In place |
Organizational security
| Control | Status |
|---|---|
|
Security awareness training implemented Carebility employees complete security awareness training when they are hired and every year after. |
In place |
|
Code of Conduct acknowledged by employees and enforced Employees acknowledge Carebility's code of conduct when they are hired. Violations are handled under a disciplinary policy. |
In place |
|
Confidentiality Agreement acknowledged by employees Employees sign a confidentiality agreement during onboarding. |
In place |
|
Confidentiality Agreement acknowledged by contractors Contractors sign a confidentiality agreement when they are engaged. |
In place |
|
Performance evaluations conducted Managers complete performance evaluations for their direct reports at least once a year. |
In place |
Product security
| Control | Status |
|---|---|
|
Penetration testing performed Carebility's application is penetration tested, and findings are fixed. The report is available on request. |
In place |
|
Vulnerability and system monitoring procedures established Security scans run on every code change, container images are scanned, dependency alerts are on, and application errors are monitored. |
In place |
|
Control self-assessments conducted At least once a year, Carebility checks that each of its controls is in place and working, records the result, and fixes what it finds. |
In place |
|
Single sign-on Users can sign in with their Google or Microsoft account. Passwords must be at least 8 characters, and accounts lock after repeated failed sign-in attempts. |
In place |
|
Access denied by default Carebility's authorization rules deny access unless a policy explicitly allows it. |
In place |
|
Organization data isolation Each organization's data is scoped to that organization. Every Coworker record carries its organization, and every read filters by it. |
In place |
|
Resident information access logged Opening resident-level information in Coworker writes an access log entry that names who opened it. |
In place |
|
Health information kept out of error reports Error reports are scrubbed of health information before they reach our error monitoring service. |
In place |
Internal security procedures
| Control | Status |
|---|---|
|
Continuity and Disaster Recovery plans established Carebility has business continuity and disaster recovery plans, including how the team communicates if key people are unavailable. |
In place |
|
Continuity and Disaster Recovery plans tested Carebility tests its business continuity and disaster recovery plans. |
In place |
|
Incident response policies established Carebility has written policies for responding to security incidents. |
In place |
|
Incident response plan tested Carebility tests its incident response plan. |
In place |
|
Backup processes established Carebility has documented backup processes for its production data. |
In place |
|
Cybersecurity insurance maintained Carebility carries cybersecurity insurance. |
In place |
|
Security policies established and reviewed Carebility's security policies are written down and reviewed on a schedule. |
In place |
|
Risk management program established Carebility runs a risk management program to identify and reduce risks to the service and to customer data. |
In place |
|
Risks assessments performed Carebility performs risk assessments and acts on what they find. |
In place |
|
Risk assessment objectives specified Carebility's risk assessments have written objectives. |
In place |
|
Vendor management program established Carebility reviews the vendors it relies on under a written vendor management policy. |
In place |
|
Third-party agreements established Every company that processes data for Carebility works under a written agreement. Every company that handles protected health information also works under a business associate agreement. |
In place |
|
Access requests required Staff access to Carebility systems is requested and approved before it is granted, reviewed on a schedule, and removed when someone leaves. |
In place |
|
Organization structure documented Carebility documents its organization structure. |
In place |
|
Roles and responsibilities specified Roles and responsibilities for security are written down. |
In place |
|
Management roles and responsibilities defined Management's responsibilities for security and compliance are defined. |
In place |
|
Board oversight briefings conducted Carebility's board is briefed on the state of security and privacy risk. |
In place |
|
Board charter documented Carebility's board has a documented charter. |
In place |
|
Board expertise developed Carebility's board has the expertise to oversee security and privacy risk. |
In place |
|
Board meetings conducted Carebility's board meets regularly. |
In place |
|
Whistleblower policy established Carebility has a whistleblower policy and a way to report concerns anonymously. |
In place |
|
Company commitments externally communicated Carebility publishes its terms of use, privacy policy, master services agreement and business associate agreement. |
In place |
|
Service description communicated Carebility describes its products and services publicly. |
In place |
|
Support system available Customers can reach Carebility support. |
In place |
|
External support resources available Carebility publishes help resources for its products. |
In place |
Data and privacy
| Control | Status |
|---|---|
|
Data retention procedures established Carebility has written procedures for how long data is kept and how it is disposed of. |
In place |
|
Data classification policy established Carebility classifies the data it handles. Protected health information is handled separately, and that handling is recorded. |
In place |
|
Organization data deleted upon leaving When an organization leaves Carebility, its data is deleted under a documented process. |
In place |
|
Business associate agreement with every organization Carebility signs a business associate agreement with each organization it serves. |
In place |
|
AI conversations stored in Carebility's databases AI conversations are stored in Carebility's own databases. |
In place |
|
AI providers under business associate agreements Every AI provider Carebility uses works under a business associate agreement with Carebility. |
In place |
No results