How access, records and disclosure are handled, last reviewed on 8 September 2026.
The clinical schema in our database is reachable only by a service role, never by a browser and never by a public key. Every table in the clinical, billing, payments, growth, care and audit schemas runs with row level security on, so a row is readable only by a caller the policy allows.
A check exists in the database that lists any table added without that protection, so a missing policy is a query away rather than an audit away. That check is run as part of the build.
The build refuses to complete if an environment file or a live credential is committed. No password, key or token is written into a document, a note or a page, and where one is needed the reference is to where it is stored.
Multi factor authentication is enforced on the administrative surfaces. Extending it to every remote account, which the second version of the digital technology assessment criteria requires, is in progress and dated in the Trust Centre.
No Cyber Essentials certificate, no ISO 27001 certificate and no independent penetration test report. All three are in the Trust Centre with the month against them. A page that lists its certificates and stops there is telling you only the half that flatters it.
Write to team@thewellnesslondon.com with what you found, how to reproduce it and what you were able to reach. Do not open a public issue. We acknowledge a report within 24 hours.
We will not pursue anyone who reports a fault in good faith, who does not access, change or keep another person’s data while finding it, and who gives us a reasonable time to fix it before saying anything publicly.
Anything that reaches patient data without an authenticated and authorised caller. An unguarded route, a table readable with a public key, a forged session, or personal data in a log or a web address.
Last reviewed 8 September 2026.