
Production Readiness
CareVerity ECM & Care Compliance System with CareVerity Training Academy.
DR
Demo Registered Manager
Registered Manager demo role view
UK Launch Readiness
Security, privacy, tenant isolation, UAT and business compliance gates for UK launch. Demo records only until every blocked gate is resolved.
Launch blocked
Reference: CAREVERITY-UK-LAUNCH-READINESS-001. Not ready for full UK launch until production database, authentication, tenant isolation, backup restore, security testing, load testing and full UAT evidence all pass.
Controls passed
1
Controls prepared
21
Blocked gates
15
Runtime mode
Demo
Supabase connected
No
Never query staff, service users, MAR, rota, documents, journal, invoices, reports or audit logs without filtering by company_id/provider_id.
Hard stops before launch
CareVerity must not be marked ready while any hard stop remains open.
Production Supabase/Postgres project, migrations and verified Row Level Security are not yet evidenced.
Secure production authentication, MFA enrolment and admin/super-admin session policies are not yet evidenced.
Real tenant isolation tests with Company A and Company B users must pass against the production-like database.
Backup restore has not been evidenced against production-like database and file storage.
100-company load test cannot be signed off until k6 or equivalent load tooling is installed and executed.
Vulnerability scan, OWASP Top 10 test pass and external penetration test are required before launch.
Full UAT with sandbox admin and carer credentials remains required before go-live.
NEXT_PUBLIC_DEMO_MODE is not false. Production cannot use demo/localStorage persistence.
Database and production status
Demo/localStorage mode is active. Supabase queries are prepared but not used.
Environment
.env.example contains Supabase and multi-tenant placeholders
Schema
supabase/schema.sql contains CareVerity provider, care, rota, MAR, finance, import and audit tables
Service layer
/lib/careverity-db.ts switches between demo/localStorage and Supabase mode and blocks tenant-scoped database calls without companyId/providerId
Storage
provider-documents/company_id folders planned for restricted document areas
Audit
audit_logs schema includes append-only/hash-chain fields, action, module, old/new value, reason, IP/device and tenant identifiers
Middleware
Protected CareVerity routes require auth when demo mode is disabled and security headers are emitted
Demo safety
Current frontend and local demo seed data remain available for UAT only
Security and privacy control register
Each item maps to a launch gate. Prepared means the structure exists; it does not mean production evidence has passed.
Build errors
Local npm run lint and npm run build are required evidence gates.
Build must pass before every release candidate.
Remove demo/localStorage-only production mode
Database mode guard blocks Supabase operations when required environment values are missing; demo mode remains for local testing only.
Set NEXT_PUBLIC_DEMO_MODE=false in production and verify no localStorage persistence path is used for live records.
Real database persistence
Supabase/Postgres schema and service layer are present with tenant-scoped tables.
Run migrations on a production-like Supabase project and execute CRUD/UAT tests against database mode.
Secure authentication
Middleware redirects protected non-demo routes when no Supabase session cookie exists.
Configure Supabase Auth or approved identity provider, test login, reset, lockout and role claims.
MFA for admin and super-admin
MFA control rows and schema placeholders exist.
Require and test MFA for System Owner, Provider Admin, Registered Manager and super-admin roles.
Role-based access control
Role matrix and RLS policy placeholders exist.
Prove each role can only view permitted modules and records with real auth claims.
Strict companyId tenant separation
Core demo fixtures include companyId/providerId and Playwright checks tenant identifiers.
Company A/Company B database tests must pass with RLS enabled and direct API calls attempted.
Cross-company data prevention
Service layer requires tenant scope for tenant-scoped database tables.
Prove Company A cannot read, search, export or infer Company B staff, clients, MAR, rota, invoices or audit logs.
HTTPS in transit
Security headers are set by middleware.
Host only behind HTTPS with HSTS and secure cookies in production.
Sensitive data encryption at rest
Schema enables pgcrypto and restricted document storage planning.
Enable managed database/storage encryption and field-level encryption for key-safe, payroll, MAR and restricted records where required.
Password hashing
The app should use Supabase Auth or an approved auth service; no custom plaintext password storage is present.
Confirm bcrypt/Argon2id hashing through the identity provider or implement Argon2id if self-hosting auth.
Secure password reset
Password reset request schema placeholders are prepared.
Test expiring, single-use reset tokens and audit reset events.
Session timeout
Session timeout environment placeholders are documented.
Enforce idle and absolute timeout in auth middleware/session provider.
Account lockout
Login attempt table and environment placeholders are prepared.
Test lockout after failed attempts and unlock/admin review process.
Rate limiting
Rate limit table and environment placeholders are prepared.
Deploy edge/API rate limiting for login, password reset, export, import and medication actions.
Audit all create/view/edit/delete/login/export/MAR actions
Audit schema includes action, module, record type, old/new values, reason, IP/device placeholders and tenant identifiers.
Verify audit insertion for every sensitive action in UAT.
Tamper-resistant audit logs
Schema adds append-only/hash-chain fields and mutation-blocking trigger.
Prove update/delete attempts fail and hash-chain verification passes.
Backup and restore process
Backup/restore evidence tables and UI placeholders exist.
Run and record a restore test from encrypted database and file backups.
Data retention and deletion controls
Retention rules and deletion request schema are prepared.
Approve retention schedule, test deletion/anonymisation workflow and audit outcomes.
Export controls
Export approval and backup/export log structures exist.
Prove role-controlled exports, purpose recording, audit logging and tenant filtering.
Breach-reporting workflow
Breach report schema and Article 32 demo register are present.
Run tabletop test for triage, ICO/DSPT/safeguarding notification decision and evidence retention.
Monitoring and security alerts
Security event and alert schema placeholders are prepared.
Connect production logs to alerting for auth abuse, export spikes, failed RLS attempts and medication anomalies.
Vulnerability scanning
Vulnerability scan run table is prepared.
Run dependency, SAST, DAST and container/hosting scans; resolve high and critical findings.
OWASP Top 10 testing
OWASP checklist is prepared for testing.
Pass OWASP Top 10 testing, including broken access control and injection attempts.
Penetration testing checklist
Pen-test checklist and findings table are prepared.
Complete independent penetration test and close high/critical issues.
Cyber Essentials readiness
Cyber Essentials checklist is prepared.
Confirm boundary firewalls, secure configuration, access control, malware protection and patching evidence.
DPIA support
DPIA support checklist and records table are prepared.
Complete DPIA with DPO/IG sign-off before processing real care records.
Privacy notice and DPA templates
Template register tables and document checklist are prepared.
Have UK GDPR privacy notice and processor/controller agreements legally reviewed and approved.
100-company load test
Playwright 100-company data test exists; k6 load script exists.
Install/run k6 or equivalent and pass defined latency/error thresholds.
Final launch readiness report
Launch readiness report document and UI panel are prepared.
Update report only after all blocked gates have passed.
OWASP Top 10 test plan
A01 Broken Access Control: test tenant escape, IDOR, role bypass, export and MAR access.
A02 Cryptographic Failures: verify TLS, secure cookies, encryption at rest and restricted field handling.
A03 Injection: test forms, imports, search, filters, notes and report parameters.
A04 Insecure Design: review tenant model, break-glass access, medication safety and audit immutability.
A05 Security Misconfiguration: review headers, CORS, storage buckets, Supabase RLS and environment secrets.
A06 Vulnerable and Outdated Components: run npm audit/dependency scanning and patch high/critical findings.
A07 Identification and Authentication Failures: test MFA, reset, lockout, session timeout and credential stuffing controls.
A08 Software and Data Integrity Failures: validate import templates, package integrity, CI/CD and audit hash chain.
A09 Security Logging and Monitoring Failures: test alerts for failed logins, exports, restricted views and MAR changes.
A10 Server-Side Request Forgery: review any URL import, hosted video, document fetch or integration endpoint.
Penetration test checklist
Unauthenticated access and forced browsing.
Role bypass between System Owner, Provider Admin, Registered Manager, HR, Care Coordinator and Care Worker.
Company A to Company B tenant isolation attempts through UI, API, exports and predictable IDs.
Medication/MAR tampering, controlled drugs balance manipulation and audit-log bypass.
Import file abuse, formula injection, CSV injection and malicious document upload.
Session fixation, timeout bypass, MFA bypass and account lockout evasion.
Backup/export download authorisation and audit evidence.
Cyber Essentials readiness
Boundary firewalls and internet gateways documented.
Secure configuration baseline for servers, Supabase, storage and admin devices.
Access control and least privilege for staff, admins, providers and support users.
Malware protection and endpoint management evidence.
Security update management and vulnerability remediation timescales.
DPIA support checklist
Describe processing: staff, service user, health, MAR, rota, finance, documents, audit and family portal data.
Assess necessity and proportionality for care delivery, employment, safeguarding, medication and compliance.
Identify risks to rights and freedoms, including unauthorised access, tenant leakage, export misuse and breach impact.
Record mitigations: RLS, RBAC, MFA, encryption, audit logs, retention, backup restore and incident response.
Seek DPO/IG advice and consult ICO if high risk cannot be mitigated.
Backup and restore checklist
Encrypted daily database backup configured.
Encrypted document/storage backup configured.
Audit-log backup and hash-chain verification included.
Restore test completed to isolated environment.
Restore result, data integrity checks, RPO/RTO and sign-off recorded.
Failed restore escalation and corrective action process documented.
Breach-reporting workflow
Detect and classify event.
Contain access, preserve evidence and suspend affected sessions.
Assess personal data, special category data, medication/safeguarding impact and tenant scope.
Decide ICO, DSPT, commissioner, safeguarding and individual notifications.
Record actions, timeline, lessons learned and corrective controls.
Close only after manager/DPO sign-off.
Privacy notice / DPA templates
Provider privacy notice for service users, relatives and staff.
CareVerity SaaS data processing agreement.
Sub-processor register and hosting location schedule.
Data retention and deletion schedule.
Data subject access/export process.
International transfer assessment where applicable.