Technical Architecture

Built for Trust, Scaled for Growth

CareLedger AI is a vertically-integrated FinTech platform engineered for the regulatory requirements of UK social care financial operations.

Three-Layer Architecture

LAYER 1

Client Layer

React + TypeScript SPA with PapaParse for client-side CSV parsing. No raw data leaves the browser until sanitised.

React 18TypeScriptTanStack TablePapaParseTailwind CSS
LAYER 2

Edge Compute Layer

Supabase Edge Functions running Deno isolates. The reconciliation engine processes logs with sub-second latency.

Deno RuntimeEdge FunctionsService Role AuthJSON API
LAYER 3

Data Layer

PostgreSQL with Row Level Security ensuring complete tenant isolation. Agency A can never access Agency B's data.

PostgreSQL 15Row Level SecurityRealtime SubscriptionsACID Compliance

Key Innovations

Novel approaches to financial reconciliation in regulated care environments.

Privacy Shield Architecture

Clinical data is stripped at the browser level before transmission. The system is GDPR-compliant by architecture, not just policy. PII columns are programmatically excluded from CSV parsing.

Algorithmic Auditing Engine

A deterministic reconciliation algorithm that applies council-specific funding bands, weekend multipliers, and configurable tolerance thresholds to every care visit. No ML black boxes — fully auditable logic.

Multi-Tenant Isolation

PostgreSQL Row Level Security functions ensure cryptographic-strength tenant isolation. Each query is scoped to the authenticated user's agency via security-definer functions.

Universal CSV Ingest

Works with exports from any care rostering system — Birdie, CareLineLive, Access, Careplanner. No integrations to maintain; just CSV in, reconciled data out.

Security & Compliance

GDPR Article 25

Data protection by design and by default. Clinical data never enters the system.

Tenant Isolation

Row Level Security with security-definer functions. No cross-tenant data access is architecturally possible.

Audit Trail

Every reconciliation decision is timestamped and locked. Full traceability for CQC inspections.

Encryption

TLS 1.3 in transit, AES-256 at rest. All database connections enforced via SSL.

Verified Domain

Domain & Identity Verification

Transparent proof of ownership, security posture, and regulatory compliance for careledgerai.tech.

DNS Ownership Proof

TXT Record Verified

_lovable.careledgerai.tech → lovable_verify=…

A Record Active

careledgerai.tech → 185.158.133.1

CNAME www

www.careledgerai.tech → careledgerai.tech

Security Certifications

SSL / TLS 1.3

Let's Encrypt certificate, auto-renewed. All traffic encrypted in transit.

GDPR Article 25 Compliant

Data protection by design. PII excluded at browser level before any transmission.

AES-256 at Rest

All database connections enforced via SSL. Data encrypted at rest.

SOC 2 Type II Infrastructure

Hosted on SOC 2 compliant cloud infrastructure with audit logging.

Brand & Entity Verification

Registered Entity

CareLedger AI Ltd — Registered in England & Wales.

Verified Contact Addresses

General: hello@careledgerai.tech

DPO: dpo@careledgerai.tech

Legal: legal@careledgerai.tech

careledgerai.tech
Verified & Secured

Want to Learn More?

Book a technical deep-dive with our engineering team.