CareGeo Trust Center
“HIPAA compliant” is the floor. Here's the rest.
A serious agency evaluation shouldn't stop at a compliance badge — it should ask about backups, breach response, data export, and who touches the data. Here are those answers in writing, including the ones still maturing.
Business Associate Agreement (BAA)
Included on every plan, not an enterprise upsell. Signing it is a built-in onboarding step, and your executed BAA is downloadable from your dashboard whenever a payer or auditor asks.
Encryption
PHI is encrypted at rest (AES-256) and in transit (TLS 1.3). The caregiver mobile app encrypts locally stored offline data before sync.
Infrastructure & architecture
CareGeo runs on Google Cloud in the United States under Google's HIPAA-eligible services with our BAA chain in place: Cloud Run services, Cloud SQL (PostgreSQL), and Secret Manager for credentials. Access to production is restricted and role-based.
Backups & recovery
Automated daily database backups plus continuous point-in-time recovery with a 7-day transaction-log window — the database can be restored to any minute within the past week. Recovery procedures are tested against real Cloud SQL clones.
Access control & audit logs
Role-based access throughout (admin, coordinator, caregiver, family view). Administrative and care actions are logged with actor and timestamp; visit records are immutable once verified.
Data export — no lock-in
Your data is always exportable: payroll, mileage, EVV records, reports, and audit packets export to standard files at any time, including after cancellation on request.
Data retention
Agency records are retained for the life of the subscription and exported or deleted on termination per your instruction — with the caveat that Medicaid documentation retention rules (typically 5–7 years, state-specific) may require you to retain exports. Account-deletion requests scrub personal data while retaining legally required records.
Subprocessors
Google Cloud Platform & Firebase (hosting, database, authentication), Stripe (payments — card data never touches CareGeo servers), Resend (transactional email), Anthropic (AI visit summaries; no data used for model training under our agreement). We'll notify customers before adding subprocessors that touch PHI.
Breach response
HIPAA Breach Notification Rule timelines drive our commitment: affected agencies are notified without unreasonable delay upon discovery of a reportable incident, with the facts needed for your own notification obligations.
Uptime & continuity
CareGeo runs on auto-scaling, managed Google Cloud infrastructure with health-checked deploys. The caregiver app is offline-first by design — visits, medications, and mileage keep recording through outages and sync afterward, which is the continuity property that matters most in the field. Formal uptime SLAs are available on Enterprise agreements.
Security testing
Continuous dependency and code review are part of our development process. An independent third-party penetration test is on our security roadmap; agencies with a pentest requirement should contact us to discuss timing. We publish this honestly rather than implying an audit that hasn't happened.
Cyber insurance
Documentation available to serious evaluators on request — ask us at Caregeo@gorevamp.ai and we'll respond with current specifics in writing.
Send us your security questionnaire.
1-month free trial · no credit card · every feature unlocked · free caregiver app
Related: HIPAA compliance · Integration matrix · Video demos