What protects the records, and who can reach them.

You are handing us health information about people who cannot easily advocate for themselves. This page says what is actually in place and, further down, what is not. We would rather lose a sale here than be found out in month three.

How access works

One provider cannot see another's records

When you use HeraIQ in a browser, and when a carer asks the assistant a question, the database itself checks every read against who is signed in, using row-level security. Hera's work on our servers, and the other requests our backend handles, use a privileged database connection that those rules do not apply to, so the backend limits each one to your organisation with its own checks. The carer's pre-visit briefing is one of those: it runs on our servers, and is limited to the service users that carer is assigned to visit, as well as to your organisation.

Who you are comes from your session, not from the request

Your organisation and identity are read from the verified sign-in token. A request cannot claim to be somebody else by changing what it sends.

A carer's assistant cannot be talked into another person's data

The carer's version of Hera takes no identity as input at all — it only ever knows the carer who is signed in. There is no argument to change, so asking it for a colleague's visits has nowhere to go. That is a structural limit, not a rule we ask it to follow.

Changes to care records wait for a named person

Every change Hera prepares to a clinical, identity, status or rota record is shown first as a confirmation, saying exactly what will change and how many records it touches, and it applies only when a named person presses Apply. Cancelling visits, closing a safeguarding concern, lifting a safeguarding separation between a carer and a client, recording that a visit happened without a check-in, and assigning a carer who has no training record for a skill the visit needs also need a typed reason, which is kept with the record. Three kinds of change save straight away instead: four preference fields on a service user's profile (preferred name, pronouns, preferred language and access notes), which are logged with the value they replaced; Hera's own memories and reminders, which you can ask it to forget; and your organisation's own CQC self-audit, which Hera can run, and set how often it runs, without asking first. An audit run records a reading and a draft report and changes no care record.

Actions Hera applies keep a copy of what was there before

When Hera applies a change, the action log keeps who made it, when, and, for the actions it supports, what the record said beforehand. Twenty-two kinds of action can be undone, and undoing writes a new entry rather than erasing the old one. Edits to visits, medication records and visit notes keep a history however they are made. An edit made directly to a service user's profile in the screens does not yet keep a copy of the previous value.

The voice you speak to holds no write tools

In voice mode, the model you talk to cannot change a record itself. It passes your request to Hera, which follows the same rules as above: a change to a care record comes back as a confirmation, and applies only when you press it or say confirm.

Reading a document makes the rest of the turn more cautious

If Hera reads an uploaded document while answering you, anything that would otherwise save straight away needs confirmation for the rest of that answer, so text hidden inside a document cannot cause a silent change.

Files are private by default

Staff documents, uploaded care plans, photos and generated images live in private storage and are reached only through short-lived links that expire within 30 minutes. A file you upload lands in a separate holding area first, and our server checks the file itself before it is stored.

What HeraIQ staff can see

Our staff console is open only to named HeraIQ staff with an @heraiq.io address, and every page in it needs a second factor. It shows organisation names, how much Hera is used and what it costs, error codes, support tickets and misuse flags, and, for each organisation, the email address and name of everyone who has an account there, with a control that lets us block one of those accounts or the whole organisation. It has no screen for care plans, visits, notes or staff documents, but its list of recent Hera actions shows each action's short label, which can include a person's name. We do not yet keep a log of what staff look at in the console.

Requests Hera declines are kept for review

When Hera declines a request as off-topic, it keeps up to 500 characters of that message, with who sent it, their organisation and which part of HeraIQ it came from. Only HeraIQ staff can read these flags, and they are deleted after 180 days. Staff review flags by hand, and can block a user or a whole organisation from HeraIQ, recording a written reason.

What we collect, and where we do not

The signed-in product loads no third-party analytics, no session recording, no advertising pixels and no third-party scripts of any kind. Nothing records a screen with a service user's name on it. That is enforced by an explicit list of public page addresses rather than by masking rules, so a page nobody has written yet is already excluded.

This public website is different, and you are asked. If you accept the cookie banner, PostHog records which of these pages you read and how you move through them, and stores it on its servers in the European Union, in Frankfurt, Germany. If you refuse, none of that code is downloaded at all. The cookie notice names every cookie either way.

Care data is stored in our database in London, in the United Kingdom. These companies process data for us:

  • Supabase Pte. Ltd — Database, sign-in and file storage.
  • Vercel Inc. — Hosting for the website, the app and its server functions.
  • OpenAI OpCo, LLC — AI processing: chat, realtime voice sent straight from the browser, transcription, reading documents (including identity documents and DBS certificates), speech, image generation and embeddings.
  • LangChain, Inc. (LangSmith) — Monitoring Hera's AI so that we can find and fix problems: a record of each AI request, the steps and tools it used, and its answer.
  • Plus Five Five, Inc. (Resend) — Sending transactional email.
  • 650 Industries, Inc. (Expo) — Delivering push notifications to the HeraIQ Care app, passed on to Apple Push Notification service and Firebase Cloud Messaging.
  • Stripe Payments Europe, Limited — Taking card payments for paid plans.

Where each of them processes data, and the safeguard for anything that leaves the United Kingdom, is on our sub-processors page.

What we do not have

In full, so you can decide now rather than later. If any of these is a requirement for your service, we are not the right choice yet, and it is better that you know.

Certifications
We hold no ISO 27001, SOC 2, Cyber Essentials or DSPT certification.
Clinical safety standards
DCB0129 and DCB0160 have not been undertaken, and no Clinical Safety Officer has been appointed.
Two-factor sign-in
Built, not yet switched on for customers. Every account can set up an authenticator app or take a six-digit code by email. When it is switched on, the database refuses care records to any account that has not completed it, but three areas are not yet covered by that check: staff messaging, downloading a service user's record as a PDF, and carers' document uploads. It is off while we roll it out, so sign-in today is email and password, with a minimum of eight characters and no forced rotation. Our staff console already requires it.
Single sign-on
Not built.
Where AI processing happens
Your records are stored in the United Kingdom, but what you send to Hera is processed by OpenAI: text, voice, and the documents it reads, including identity documents and DBS certificates. OpenAI runs this on its standard infrastructure rather than in a UK or EU region, and keeps abuse-monitoring logs for up to 30 days. We will not claim a UK or EU processing guarantee for AI until one exists. Separately, we keep a record of each AI request in LangSmith's EU region so that we can find and fix problems, and that monitoring switches itself off if it is ever pointed anywhere else.
Whole-service data export
You can export individual generated documents as Word or PDF. There is no self-service export of your whole record set yet. If you ask in writing, we send you an export of your whole organisation's records within 30 days.
Backups of stored files
Our database provider takes a daily backup of the database. Files you store, such as uploaded documents and photos, are not yet included in any backup. We do not publish one figure for how long a backup lasts, because how long a copy is kept depends on where it is held. We will tell you the current periods in writing on request.
Offline working
The mobile app needs a signal. A visit in a notspot is recorded when the carer is back in coverage.
Electronic signatures
Agreements generate and download, and you can mark one as sent, but nothing is delivered or signed inside HeraIQ.
eMAR
Medication is recorded through care planning and visit notes, not as a formal administration chart.
Payroll, invoicing and family portals
Out of scope.
Penetration testing
No third-party penetration test has been commissioned.

Reporting something

If you believe you have found a security problem, email security@heraiq.io with enough detail to reproduce it. We will confirm we have received it, and we will not take action against anyone who reports a genuine issue in good faith.