
Independently audited information security you can rely on.
VCare operates under a certified ISO/IEC 27001:2022 information security management system (ISMS), ensuring structured controls are in place to manage risk and protect sensitive clinical and operational data.
Our Approach To Security
At VCare, information security is more than a certification — it is a core part of how we develop our software, manage risk and protect the information entrusted to us. Our approach is guided by three principles that underpin everything we do.
01
Security by Design
Built securely from the ground up.
02
Certification & Accountability
Certified to international standards.
03
Continuous Improvement
Continuously improving security measures.
These principles work together to create a proactive and resilient approach to information security. By embedding security throughout the development of our platform, maintaining an ISO/IEC 27001:2022 certified Information Security Management System and continually strengthening our security practices, we help protect the sensitive information entrusted to us while giving our clients confidence in the security of the VCare platform.
VCare Security Capabilities
Our proactive approach to information security is supported by security measures built into every aspect of VCare. From secure access and data protection to business continuity and ongoing platform maintenance, these measures help protect sensitive information while ensuring the platform remains secure, reliable and resilient.
👤 Identity & Access
Secure access is fundamental to protecting sensitive information. VCare supports Multi-Factor Authentication (MFA), Single Sign-On (SSO) and role-based user permissions to help ensure only authorised users can access the information relevant to their role.
🔐 Data Protection
Sensitive information is protected through secure cloud hosting in New Zealand, secure data storage and industry best practices. These measures help safeguard information while supporting the confidentiality, integrity and availability of data.
🔄 Business Continuity
Business continuity is supported through regular backups and disaster recovery planning designed to minimise disruption in the event of an incident. These measures help ensure critical data can be recovered and the platform can continue to support our clients when it matters most.
📊 Monitoring & Governance
Comprehensive audit trails and document activity logs provide greater visibility into user actions and system activity. This supports governance, strengthens accountability and assists organisations with internal auditing and compliance requirements.
⚙️ Platform Resilience
The VCare platform is proactively maintained through regular updates and ongoing security monitoring. These measures help maintain a secure, reliable and resilient environment while supporting the protection and availability of the information entrusted to us.
Why ISO 27001 Matters in Aged Care
Organisations delivering aged care manage highly sensitive clinical, personal and operational information every day. Protecting this information is essential to maintaining trust, safeguarding privacy and supporting high-quality care.
As an ISO 27001 certified organisation, VCare has implemented an independently assessed Information Security Management System (ISMS) that supports the secure development, operation and continual improvement of our platform. This provides our clients with confidence that information security is embedded throughout our organisation.
What is ISO 27001?
ISO/IEC 27001:2022 is the international standard for information security management systems (ISMS). It defines how organisations identify risks, implement controls, and continuously improve their approach to protecting information.
Certification requires independent third-party audit and ongoing compliance review.
What ISO 27001 Means for VCare Customers
ISO/IEC 27001 certification provides assurance that your data is protected through defined controls, governance, and risk management practices.
This includes structured policies, access controls, monitoring processes, and ongoing risk assessment, supporting stringent standards for personally identifiable information, strong security awareness, and a focus on minimising risk across clinical, resident, and organisational data.
Independent Certification
Certification is issued by an accredited certification body and maintained through regular surveillance audits and periodic recertification.
This ensures that security controls are independently verified and remain effective over time.
Maintaining Certification
Maintaining ISO/IEC 27001 certification requires regular risk assessments, internal audits, surveillance audits and management review. These ongoing activities help ensure our Information Security Management System remains effective and continues to evolve alongside changing risks.
Security Resources
Information security is continually evolving, and staying informed is an important part of protecting sensitive information. We regularly publish practical security insights, industry updates and educational resources to help aged care and retirement living providers understand emerging cyber risks, strengthen their security practices and make informed decisions about protecting sensitive information. Explore our latest security insights below.
Featured Articles
ISO 27001:2022 Control List
All 93 ISO/IEC 27001:2022 Annex A controls are implemented and independently verified as part of our certified information security management system. If you would like to view the entire list of implemented controls, you can view our control summary page below.
View the JASANZ Register to search for our certification. VCare is registered under Concept Engineering.
You can find the register here:
Request Compliance Documents
Security Documentation
Get in contact with us to get a copy of our security documents.
Available on request:
ISO/IEC 27001 Certificate
Privacy Policy
Summary of Information Security Policy
Risk Management Approach
Data Protection and Privacy Overview
Statement of Applicability


