CareGeo Trust Center

“HIPAA compliant” is the floor. Here's the rest.

A serious agency evaluation shouldn't stop at a compliance badge — it should ask about backups, breach response, data export, and who touches the data. Here are those answers in writing, including the ones still maturing.

Business Associate Agreement (BAA)

Included on every plan, not an enterprise upsell. Signing it is a built-in onboarding step, and your executed BAA is downloadable from your dashboard whenever a payer or auditor asks.

Encryption

PHI is encrypted at rest (AES-256) and in transit (TLS 1.3). The caregiver mobile app encrypts locally stored offline data before sync.

Infrastructure & architecture

CareGeo runs on Google Cloud in the United States under Google's HIPAA-eligible services with our BAA chain in place: Cloud Run services, Cloud SQL (PostgreSQL), and Secret Manager for credentials. Access to production is restricted and role-based.

Backups & recovery

Automated daily database backups plus continuous point-in-time recovery with a 7-day transaction-log window — the database can be restored to any minute within the past week. Recovery procedures are tested against real Cloud SQL clones.

Access control & audit logs

Role-based access throughout (admin, coordinator, caregiver, family view). Administrative and care actions are logged with actor and timestamp; visit records are immutable once verified.

Data export — no lock-in

Your data is always exportable: payroll, mileage, EVV records, reports, and audit packets export to standard files at any time, including after cancellation on request.

Data retention

Agency records are retained for the life of the subscription and exported or deleted on termination per your instruction — with the caveat that Medicaid documentation retention rules (typically 5–7 years, state-specific) may require you to retain exports. Account-deletion requests scrub personal data while retaining legally required records.

Subprocessors

Google Cloud Platform & Firebase (hosting, database, authentication), Stripe (payments — card data never touches CareGeo servers), Resend (transactional email), Anthropic (AI visit summaries; no data used for model training under our agreement). We'll notify customers before adding subprocessors that touch PHI.

Breach response

HIPAA Breach Notification Rule timelines drive our commitment: affected agencies are notified without unreasonable delay upon discovery of a reportable incident, with the facts needed for your own notification obligations.

Uptime & continuity

CareGeo runs on auto-scaling, managed Google Cloud infrastructure with health-checked deploys. The caregiver app is offline-first by design — visits, medications, and mileage keep recording through outages and sync afterward, which is the continuity property that matters most in the field. Formal uptime SLAs are available on Enterprise agreements.

Security testing

Continuous dependency and code review are part of our development process. An independent third-party penetration test is on our security roadmap; agencies with a pentest requirement should contact us to discuss timing. We publish this honestly rather than implying an audit that hasn't happened.

Cyber insurance

Documentation available to serious evaluators on request — ask us at Caregeo@gorevamp.ai and we'll respond with current specifics in writing.

Send us your security questionnaire.

1-month free trial · no credit card · every feature unlocked · free caregiver app

Related: HIPAA compliance · Integration matrix · Video demos