AI Powered Remote Monitoring Circadian Smart Bulb
The Circadacare AI powered device is transferable to any care setting or eco-system, supporting healthier sleep/wake cycles, reducing falls, and alleviating challenging sun downing behaviours in care homes or in the community. This system provides live environment & behavioural insights & reporting via integrated sensors paired with an accessible dashboard.
Features
- "Circadian Lighting"
- "falls prevention"
- "remote monitoring"
- "reporting"
- "data insights"
- "integration"
Benefits
- "sundowning"
- "falls prevention"
- "healthier outcomes"
- "improved sleep patterns"
- "care interventions"
- "care insights"
- "healthy circadian rythms"
- "improved care planning"
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 8 9 6 6 2 3 5 6 5 4 2 8 9 6
Contact
CIRCADIAN LIGHTING LIMITED
Dan Waller
Telephone: 07595601398
Email: hello@circadacare.com
About your service
- Service categories
-
Application Development and Deployment
AI platforms
- Search and knowledge discovery
AI software services
- Anomaly Detection AI Software Services
- Forecast AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- This system has an API, so interoperability with other digital platforms, although not required, is encouraged. We have active partnerships in place with care management platforms (PCS) alarm receiving centres, (UMO) and digital care hubs (2iC-Care).
- Cloud deployment model
- Public cloud
- Service constraints
- None.
- System requirements
-
- "Digital inclusion"
- "WIFI"
User support
- Email or online ticketing support
- Yes
- Support response times
- Our SLA for responding to email tickets is 24 hours from 09:00 - 17:30, Monday to Friday
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
- Circadacare offers onsite support for full or partial installations and can also manage the replacement of existing equipment. All costs are scoped and tailored to the needs of each customer.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide user documentation on installation best practice, onsite installation training, remote/onsite training on accessing the care platform, and ongoing support on data insights reports.
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- "digital videos"
- "best practice guides"
- "FAQs"
- End-of-contract data extraction
- Users can request an export of the data.
- End-of-contract process
- Access the the platform is revoked and the bulb's circadian output is fixed at a standard colour temperature. There is no additional cost for this.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Ultimately accessing the dashboard from either device is the same, but the mobile app was designed for non fixed locations, or to provide access to remote family members, carers or community support.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- Yes. The service includes a secure, browser-based web interface for authorised users to access data, review alerts and manage system settings. No local installation is required.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- Users of our interface are care professionals - service users do not need to access the platform at all.
- API
- Yes
- What users can and can't do using the API
- Integrations managed case by case via technical team.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Pulling data into desired platforms, adding integrations to our platform and configuring alerts.
Scaling
- Independence of resources
- The service is highly predictable due to it being an IoT-based solution that regularly communicates with the cloud. We can accurately predict the load on our system. However, we also have auto-scale capabilities built into our system to handle increase in device number & therefore demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide metrics regarding anomaly alerts, dashboard reports, or requested bespoke insights reports regarding specific trends that are identified via internal data analysts. We can also provide reports regarding WiFi health on the premises, and whether hardware is currently communicating with the platform.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Carers with relevant permissions accessing the platform can export data on service users via pdf reporting.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Circadacare operates on Google Cloud Platform infrastructure, which provides enterprise-grade availability SLAs ranging from 99.5% to 99.95% depending on service configuration. Full GCP SLA details are available at https://cloud.google.com/terms/sla.
We maintain automated monitoring with alerting for service disruptions during business hours (9:00-17:30, Monday to Friday). Incident response protocols ensure rapid resolution of critical issues during operating hours, with escalation procedures for urgent matters. Scheduled maintenance is performed during low-usage periods with advance customer notification, and we conduct post-incident reviews to prevent recurrence.
Service level agreements, including specific availability targets, monitoring coverage, incident response times, and service commitments, are defined individually within each customer contract. This approach allows us to tailor availability guarantees to the specific operational requirements and risk profiles of different care environments. As a healthcare technology provider supporting vulnerable populations, our contractual approach emphasizes operational accountability, service reliability, and continuous improvement rather than financial compensation mechanisms.
Availability commitments exclude downtime caused by customer infrastructure issues, third-party service failures beyond our control, scheduled maintenance performed with appropriate notice, or force majeure events. - Approach to resilience
- Available on request.
- Outage reporting
- Email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is restricted using Google Cloud Platform's identity and access management with role-based permissions following least privilege principles. Multi-factor authentication is enforced for all administrative access to cloud infrastructure and production systems. Access is granted only to authorized personnel based on job function, with the CTO approving elevated privileges.
Production system access is logged and auditable through GCP's monitoring. User account policies document access control procedures. Support channels operate during business hours with email-based authentication for customer identity verification. Administrative functions are separated from standard user access, and session timeouts enforce re-authentication. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials certified. Cloud infrastructure operates on ISO 27001-certified Google Cloud Platform.
- Information security policies and processes
-
Circadacare is Cyber Essentials certified with the CTO holding accountability for information security. We maintain documented, version-controlled policies covering asset and patch management, malware protection and endpoint security, network and firewall security, user account and access control, mobile device security, LLM and AI tool usage, and computer security guidelines.
Technical security operates on Google Cloud Platform's ISO 27001-certified infrastructure providing encryption, access management, and automated backups. Compliance is maintained through team training, onboarding processes, and annual Cyber Essentials recertification. As a healthcare technology provider, security and data protection are embedded organizational priorities. Policies are reviewed and updated regularly. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Application code is managed through version control with full change history tracking. Changes undergo peer review and testing in non-production environments before deployment. The CTO approves significant changes with security impact assessment based on data access, authentication mechanisms, and customer-facing functionality.
Infrastructure is defined as code using Terraform, providing version-controlled, auditable infrastructure configurations on Google Cloud Platform. All infrastructure changes are tracked through Terraform state management with GCP maintaining audit logs under SOC 2-certified change control processes.
Asset and patch management policies document our approach to tracking software components, dependencies, and security updates throughout their lifecycle. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Vulnerabilities are identified through automated dependency scanning of application code, security advisories from Google Cloud Platform, and monitoring of relevant CVE databases and security bulletins. Critical vulnerabilities affecting healthcare data or service availability are prioritized for immediate remediation.
Critical security patches are deployed within 24-48 hours following testing. Standard patches follow our regular deployment cycle with assessment of security impact. Infrastructure patches are managed through GCP's automated update systems for underlying services. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Google Cloud Platform provides continuous monitoring with automated alerts for suspicious activity including unauthorized access attempts, unusual traffic patterns, and configuration changes. Application logs are centralized and monitored for anomalies.
Potential compromises trigger immediate CTO notification during business hours with escalation procedures for out-of-hours incidents. Response includes isolating affected systems, assessing impact scope, implementing containment measures, and notifying affected parties as required.
Critical incidents affecting customer data or service availability receive immediate response. Standard security events are investigated within business hours. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Incident response is managed by the CTO with procedures documented in our Computer Security Guidelines. Common scenarios including service outages, security concerns, and system issues are handled through established workflows.
Users report incidents via email to support channels during business hours (9:00-17:30, Monday-Friday) with emergency contact procedures for critical issues. All incidents are logged and tracked through resolution.
Customers are notified of incidents affecting their service with information on the issue and resolution. Significant security incidents are reported to affected parties as required. Google Cloud Platform monitoring provides automated alerting for infrastructure-level incidents. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Dfbbf3fb-3e2b-4676-98cb-9b45e96a3572
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-