Skip to main content

Carebility

Carebility builds software and AI for senior care operators, and works with resident and staff information every day. Protecting that information is part of the product.

This trust center shows how we protect it: the controls we run, the documents we can share, and the companies that process data for us.

If you need something that is not here, request access and our security team will follow up.

Request access

Controls

Last reviewed September 29, 2026

Infrastructure security

Control Status

Remote access MFA enforced

Carebility staff reach production systems only with a Google Workspace account that requires 2-step verification.

In place

Remote access encrypted enforced

Staff reach production systems only over encrypted connections.

In place

Network segmentation implemented

Production, staging, testing, development and demo run in separate cloud projects and networks, with separate credentials and encryption keys.

In place

Configuration management system established

Carebility's infrastructure is defined in code and deployed the same way in every environment.

In place

Hosted on SOC 2 audited infrastructure

Carebility runs in production on Google Cloud, which is SOC 2 audited.

In place

Data encrypted in transit

Connections to Carebility require HTTPS with TLS 1.2 or later.

In place

Resident data encrypted at rest

Resident fields in Coworker are encrypted in the database with keys held in Google Cloud KMS and rotated every 90 days.

In place

Document storage encrypted and private

Coworker document storage is encrypted with Carebility-managed keys, and public access to it is blocked.

In place

Database backups with point-in-time recovery

Carebility's databases are backed up continuously and can be restored to a point in time.

In place

Organizational security

Control Status

Security awareness training implemented

Carebility employees complete security awareness training when they are hired and every year after.

In place

Code of Conduct acknowledged by employees and enforced

Employees acknowledge Carebility's code of conduct when they are hired. Violations are handled under a disciplinary policy.

In place

Confidentiality Agreement acknowledged by employees

Employees sign a confidentiality agreement during onboarding.

In place

Confidentiality Agreement acknowledged by contractors

Contractors sign a confidentiality agreement when they are engaged.

In place

Performance evaluations conducted

Managers complete performance evaluations for their direct reports at least once a year.

In place

Product security

Control Status

Penetration testing performed

Carebility's application is penetration tested, and findings are fixed. The report is available on request.

In place

Vulnerability and system monitoring procedures established

Security scans run on every code change, container images are scanned, dependency alerts are on, and application errors are monitored.

In place

Control self-assessments conducted

At least once a year, Carebility checks that each of its controls is in place and working, records the result, and fixes what it finds.

In place

Single sign-on

Users can sign in with their Google or Microsoft account. Passwords must be at least 8 characters, and accounts lock after repeated failed sign-in attempts.

In place

Access denied by default

Carebility's authorization rules deny access unless a policy explicitly allows it.

In place

Organization data isolation

Each organization's data is scoped to that organization. Every Coworker record carries its organization, and every read filters by it.

In place

Resident information access logged

Opening resident-level information in Coworker writes an access log entry that names who opened it.

In place

Health information kept out of error reports

Error reports are scrubbed of health information before they reach our error monitoring service.

In place

Internal security procedures

Control Status

Continuity and Disaster Recovery plans established

Carebility has business continuity and disaster recovery plans, including how the team communicates if key people are unavailable.

In place

Continuity and Disaster Recovery plans tested

Carebility tests its business continuity and disaster recovery plans.

In place

Incident response policies established

Carebility has written policies for responding to security incidents.

In place

Incident response plan tested

Carebility tests its incident response plan.

In place

Backup processes established

Carebility has documented backup processes for its production data.

In place

Cybersecurity insurance maintained

Carebility carries cybersecurity insurance.

In place

Security policies established and reviewed

Carebility's security policies are written down and reviewed on a schedule.

In place

Risk management program established

Carebility runs a risk management program to identify and reduce risks to the service and to customer data.

In place

Risks assessments performed

Carebility performs risk assessments and acts on what they find.

In place

Risk assessment objectives specified

Carebility's risk assessments have written objectives.

In place

Vendor management program established

Carebility reviews the vendors it relies on under a written vendor management policy.

In place

Third-party agreements established

Every company that processes data for Carebility works under a written agreement. Every company that handles protected health information also works under a business associate agreement.

In place

Access requests required

Staff access to Carebility systems is requested and approved before it is granted, reviewed on a schedule, and removed when someone leaves.

In place

Organization structure documented

Carebility documents its organization structure.

In place

Roles and responsibilities specified

Roles and responsibilities for security are written down.

In place

Management roles and responsibilities defined

Management's responsibilities for security and compliance are defined.

In place

Board oversight briefings conducted

Carebility's board is briefed on the state of security and privacy risk.

In place

Board charter documented

Carebility's board has a documented charter.

In place

Board expertise developed

Carebility's board has the expertise to oversee security and privacy risk.

In place

Board meetings conducted

Carebility's board meets regularly.

In place

Whistleblower policy established

Carebility has a whistleblower policy and a way to report concerns anonymously.

In place

Company commitments externally communicated

Carebility publishes its terms of use, privacy policy, master services agreement and business associate agreement.

In place

Service description communicated

Carebility describes its products and services publicly.

In place

Support system available

Customers can reach Carebility support.

In place

External support resources available

Carebility publishes help resources for its products.

In place

Data and privacy

Control Status

Data retention procedures established

Carebility has written procedures for how long data is kept and how it is disposed of.

In place

Data classification policy established

Carebility classifies the data it handles. Protected health information is handled separately, and that handling is recorded.

In place

Organization data deleted upon leaving

When an organization leaves Carebility, its data is deleted under a documented process.

In place

Business associate agreement with every organization

Carebility signs a business associate agreement with each organization it serves.

In place

AI conversations stored in Carebility's databases

AI conversations are stored in Carebility's own databases.

In place

AI providers under business associate agreements

Every AI provider Carebility uses works under a business associate agreement with Carebility.

In place