The short version. Willow is built on a serverless, encryption-by-default architecture and stores the minimum data needed to deliver the service. Most resident data lives on the resident's own device, not on our servers. We use industry-standard hosting (Cloudflare) and treat security as continuous work — not a one-off certification.

1. Architecture at a glance

2. Encryption

3. Authentication and access

4. Data minimisation

We collect the minimum needed to deliver the Service. As a result of this principle, our backend KV holds only:

We do not collect resident health information, GP details, medication, or any other sensitive medical data through the Willow service.

5. Code and supply chain

6. Logging and monitoring

7. Incident response

If we discover a security incident affecting personal data, we follow a documented response plan:

  1. Contain — isolate the affected service or credential.
  2. Assess — what was accessed, by whom, what's the impact.
  3. Notify — affected care-home customers within 48 hours (per our DPA); the ICO within 72 hours where the UK GDPR notification threshold is met.
  4. Remediate — patch the cause; rotate credentials; verify.
  5. Review — post-incident review and update controls.

8. Reporting a vulnerability

If you believe you've found a security vulnerability in any part of the Willow service, please tell us before disclosing it publicly.

We commit to:

9. Certifications and frameworks

Our roadmap on certifications:

We will update this page as certifications are obtained.

10. Contact

Security and trust enquiries:
info@nemorahealthcaresolutions.com
Vulnerability disclosures: subject "Security disclosure"