Trust Center
Security, privacy and enterprise readiness.
CareSync is built for healthcare organizations that carry regulatory responsibility. This page describes the platform's architecture and controls, and the shared responsibilities that apply to every deployment.
Access and identity
- Role-based access control by role, branch and service
- Configurable administrative permissions
- Identity and SSO integration where supported by your provider
- Session and account controls
Data protection
- Encryption in transit
- Encryption at rest on managed infrastructure
- Environment separation between configuration and production data
- Data retention controls agreed during deployment
Hosting and residency
- Configurable data residency options
- In-Kingdom hosting options for Saudi deployments
- Dedicated entity server deployment option
- Backup and recovery approach documented per deployment
Platform operations
- Activity logging for administrative actions
- Change management through release processes
- Monitoring of platform availability
- Incident response process agreed with the customer
Integration security
- API-based integration with approved enterprise systems
- Scoped credentials per integration
- Integration scope confirmed during discovery
- No integration enabled without customer approval
Regulatory support model
- Architecture built to support PDPL requirements
- Architecture built to support HIPAA-aligned controls where contracted
- Customer retains responsibility for clinical and regulatory obligations
- Deployment documentation provided for internal review
CareSync is designed to support healthcare organizations' compliance programs, subject to deployment configuration, customer policies, third-party services and shared responsibilities. CareSync does not claim certification under any standard or regulation.
Need the technical detail?
Our team can walk your security, IT and compliance stakeholders through architecture, deployment models and integration requirements.
Book a Tailored Demo