Security at CoreCare

Practical protection across the product suite.

CoreCare uses layered controls so that identity, product access and operational oversight remain clear and contained.

Account protection

Each CoreCare product validates its own registered accounts and creates its own short-lived, secure session. The central login page does not turn one product’s cookie into a master key for another product.

Failed sign-in attempts are limited, passwords are stored as one-way hashes, and session cookies are restricted from browser scripts.

Access and separation

Role and entitlement checks are made on the server. Product databases remain separate, and operational tools use defined service connections instead of sharing unrestricted data stores.

The Owner Platform is restricted to authorised CoreCare operators and is not presented as a customer product.

Infrastructure and monitoring

CoreCare applications use encrypted HTTPS connections and Cloudflare’s network and serverless platform. Production services record operational errors and health signals so problems can be investigated without exposing passwords.

Your responsibility

Use a unique password, do not share accounts, remove access when a colleague leaves and contact us promptly if you believe an account is at risk.

Report a security concern

Please avoid sending passwords, health data, payment information or other sensitive records by email. Describe the issue and we will arrange a safe way to continue.

Email security@corecaresystems.co.uk