Production Readiness

CareVerity ECM & Care Compliance System with CareVerity Training Academy.

UK Launch Readiness

Security, privacy, tenant isolation, UAT and business compliance gates for UK launch. Demo records only until every blocked gate is resolved.

Launch blocked
Reference: CAREVERITY-UK-LAUNCH-READINESS-001. Not ready for full UK launch until production database, authentication, tenant isolation, backup restore, security testing, load testing and full UAT evidence all pass.
Controls passed
1
Controls prepared
21
Blocked gates
15
Runtime mode
Demo
Supabase connected
No
Never query staff, service users, MAR, rota, documents, journal, invoices, reports or audit logs without filtering by company_id/provider_id.

Hard stops before launch

CareVerity must not be marked ready while any hard stop remains open.

Production Supabase/Postgres project, migrations and verified Row Level Security are not yet evidenced.
Secure production authentication, MFA enrolment and admin/super-admin session policies are not yet evidenced.
Real tenant isolation tests with Company A and Company B users must pass against the production-like database.
Backup restore has not been evidenced against production-like database and file storage.
100-company load test cannot be signed off until k6 or equivalent load tooling is installed and executed.
Vulnerability scan, OWASP Top 10 test pass and external penetration test are required before launch.
Full UAT with sandbox admin and carer credentials remains required before go-live.
NEXT_PUBLIC_DEMO_MODE is not false. Production cannot use demo/localStorage persistence.

Database and production status

Demo/localStorage mode is active. Supabase queries are prepared but not used.

Environment
.env.example contains Supabase and multi-tenant placeholders
Schema
supabase/schema.sql contains CareVerity provider, care, rota, MAR, finance, import and audit tables
Service layer
/lib/careverity-db.ts switches between demo/localStorage and Supabase mode and blocks tenant-scoped database calls without companyId/providerId
Storage
provider-documents/company_id folders planned for restricted document areas
Audit
audit_logs schema includes append-only/hash-chain fields, action, module, old/new value, reason, IP/device and tenant identifiers
Middleware
Protected CareVerity routes require auth when demo mode is disabled and security headers are emitted
Demo safety
Current frontend and local demo seed data remain available for UAT only

Security and privacy control register

Each item maps to a launch gate. Prepared means the structure exists; it does not mean production evidence has passed.

Build errors
Local npm run lint and npm run build are required evidence gates.
Pass
Build must pass before every release candidate.
Remove demo/localStorage-only production mode
Database mode guard blocks Supabase operations when required environment values are missing; demo mode remains for local testing only.
Prepared
Set NEXT_PUBLIC_DEMO_MODE=false in production and verify no localStorage persistence path is used for live records.
Real database persistence
Supabase/Postgres schema and service layer are present with tenant-scoped tables.
Prepared
Run migrations on a production-like Supabase project and execute CRUD/UAT tests against database mode.
Secure authentication
Middleware redirects protected non-demo routes when no Supabase session cookie exists.
Blocked
Configure Supabase Auth or approved identity provider, test login, reset, lockout and role claims.
MFA for admin and super-admin
MFA control rows and schema placeholders exist.
Blocked
Require and test MFA for System Owner, Provider Admin, Registered Manager and super-admin roles.
Role-based access control
Role matrix and RLS policy placeholders exist.
Prepared
Prove each role can only view permitted modules and records with real auth claims.
Strict companyId tenant separation
Core demo fixtures include companyId/providerId and Playwright checks tenant identifiers.
Prepared
Company A/Company B database tests must pass with RLS enabled and direct API calls attempted.
Cross-company data prevention
Service layer requires tenant scope for tenant-scoped database tables.
Prepared
Prove Company A cannot read, search, export or infer Company B staff, clients, MAR, rota, invoices or audit logs.
HTTPS in transit
Security headers are set by middleware.
Action required
Host only behind HTTPS with HSTS and secure cookies in production.
Sensitive data encryption at rest
Schema enables pgcrypto and restricted document storage planning.
Prepared
Enable managed database/storage encryption and field-level encryption for key-safe, payroll, MAR and restricted records where required.
Password hashing
The app should use Supabase Auth or an approved auth service; no custom plaintext password storage is present.
Blocked
Confirm bcrypt/Argon2id hashing through the identity provider or implement Argon2id if self-hosting auth.
Secure password reset
Password reset request schema placeholders are prepared.
Blocked
Test expiring, single-use reset tokens and audit reset events.
Session timeout
Session timeout environment placeholders are documented.
Prepared
Enforce idle and absolute timeout in auth middleware/session provider.
Account lockout
Login attempt table and environment placeholders are prepared.
Prepared
Test lockout after failed attempts and unlock/admin review process.
Rate limiting
Rate limit table and environment placeholders are prepared.
Prepared
Deploy edge/API rate limiting for login, password reset, export, import and medication actions.
Audit all create/view/edit/delete/login/export/MAR actions
Audit schema includes action, module, record type, old/new values, reason, IP/device placeholders and tenant identifiers.
Prepared
Verify audit insertion for every sensitive action in UAT.
Tamper-resistant audit logs
Schema adds append-only/hash-chain fields and mutation-blocking trigger.
Prepared
Prove update/delete attempts fail and hash-chain verification passes.
Backup and restore process
Backup/restore evidence tables and UI placeholders exist.
Prepared
Run and record a restore test from encrypted database and file backups.
Data retention and deletion controls
Retention rules and deletion request schema are prepared.
Prepared
Approve retention schedule, test deletion/anonymisation workflow and audit outcomes.
Export controls
Export approval and backup/export log structures exist.
Prepared
Prove role-controlled exports, purpose recording, audit logging and tenant filtering.
Breach-reporting workflow
Breach report schema and Article 32 demo register are present.
Prepared
Run tabletop test for triage, ICO/DSPT/safeguarding notification decision and evidence retention.
Monitoring and security alerts
Security event and alert schema placeholders are prepared.
Prepared
Connect production logs to alerting for auth abuse, export spikes, failed RLS attempts and medication anomalies.
Vulnerability scanning
Vulnerability scan run table is prepared.
Blocked
Run dependency, SAST, DAST and container/hosting scans; resolve high and critical findings.
OWASP Top 10 testing
OWASP checklist is prepared for testing.
Blocked
Pass OWASP Top 10 testing, including broken access control and injection attempts.
Penetration testing checklist
Pen-test checklist and findings table are prepared.
Prepared
Complete independent penetration test and close high/critical issues.
Cyber Essentials readiness
Cyber Essentials checklist is prepared.
Prepared
Confirm boundary firewalls, secure configuration, access control, malware protection and patching evidence.
DPIA support
DPIA support checklist and records table are prepared.
Prepared
Complete DPIA with DPO/IG sign-off before processing real care records.
Privacy notice and DPA templates
Template register tables and document checklist are prepared.
Prepared
Have UK GDPR privacy notice and processor/controller agreements legally reviewed and approved.
100-company load test
Playwright 100-company data test exists; k6 load script exists.
Blocked
Install/run k6 or equivalent and pass defined latency/error thresholds.
Final launch readiness report
Launch readiness report document and UI panel are prepared.
Prepared
Update report only after all blocked gates have passed.

OWASP Top 10 test plan

A01 Broken Access Control: test tenant escape, IDOR, role bypass, export and MAR access.
A02 Cryptographic Failures: verify TLS, secure cookies, encryption at rest and restricted field handling.
A03 Injection: test forms, imports, search, filters, notes and report parameters.
A04 Insecure Design: review tenant model, break-glass access, medication safety and audit immutability.
A05 Security Misconfiguration: review headers, CORS, storage buckets, Supabase RLS and environment secrets.
A06 Vulnerable and Outdated Components: run npm audit/dependency scanning and patch high/critical findings.
A07 Identification and Authentication Failures: test MFA, reset, lockout, session timeout and credential stuffing controls.
A08 Software and Data Integrity Failures: validate import templates, package integrity, CI/CD and audit hash chain.
A09 Security Logging and Monitoring Failures: test alerts for failed logins, exports, restricted views and MAR changes.
A10 Server-Side Request Forgery: review any URL import, hosted video, document fetch or integration endpoint.

Penetration test checklist

Unauthenticated access and forced browsing.
Role bypass between System Owner, Provider Admin, Registered Manager, HR, Care Coordinator and Care Worker.
Company A to Company B tenant isolation attempts through UI, API, exports and predictable IDs.
Medication/MAR tampering, controlled drugs balance manipulation and audit-log bypass.
Import file abuse, formula injection, CSV injection and malicious document upload.
Session fixation, timeout bypass, MFA bypass and account lockout evasion.
Backup/export download authorisation and audit evidence.

Cyber Essentials readiness

Boundary firewalls and internet gateways documented.
Secure configuration baseline for servers, Supabase, storage and admin devices.
Access control and least privilege for staff, admins, providers and support users.
Malware protection and endpoint management evidence.
Security update management and vulnerability remediation timescales.

DPIA support checklist

Describe processing: staff, service user, health, MAR, rota, finance, documents, audit and family portal data.
Assess necessity and proportionality for care delivery, employment, safeguarding, medication and compliance.
Identify risks to rights and freedoms, including unauthorised access, tenant leakage, export misuse and breach impact.
Record mitigations: RLS, RBAC, MFA, encryption, audit logs, retention, backup restore and incident response.
Seek DPO/IG advice and consult ICO if high risk cannot be mitigated.

Backup and restore checklist

Encrypted daily database backup configured.
Encrypted document/storage backup configured.
Audit-log backup and hash-chain verification included.
Restore test completed to isolated environment.
Restore result, data integrity checks, RPO/RTO and sign-off recorded.
Failed restore escalation and corrective action process documented.

Breach-reporting workflow

Detect and classify event.
Contain access, preserve evidence and suspend affected sessions.
Assess personal data, special category data, medication/safeguarding impact and tenant scope.
Decide ICO, DSPT, commissioner, safeguarding and individual notifications.
Record actions, timeline, lessons learned and corrective controls.
Close only after manager/DPO sign-off.

Privacy notice / DPA templates

Provider privacy notice for service users, relatives and staff.
CareVerity SaaS data processing agreement.
Sub-processor register and hosting location schedule.
Data retention and deletion schedule.
Data subject access/export process.
International transfer assessment where applicable.