Skip to main content

Help us improve the Digital Marketplace - send your feedback

CIRCADIAN LIGHTING LIMITED

AI Powered Remote Monitoring Circadian Smart Bulb

The Circadacare AI powered device is transferable to any care setting or eco-system, supporting healthier sleep/wake cycles, reducing falls, and alleviating challenging sun downing behaviours in care homes or in the community. This system provides live environment & behavioural insights & reporting via integrated sensors paired with an accessible dashboard.

Features

  • "Circadian Lighting"
  • "falls prevention"
  • "remote monitoring"
  • "reporting"
  • "data insights"
  • "integration"

Benefits

  • "sundowning"
  • "falls prevention"
  • "healthier outcomes"
  • "improved sleep patterns"
  • "care interventions"
  • "care insights"
  • "healthy circadian rythms"
  • "improved care planning"

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@circadacare.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 8 9 6 6 2 3 5 6 5 4 2 8 9 6

Contact

CIRCADIAN LIGHTING LIMITED Dan Waller
Telephone: 07595601398
Email: hello@circadacare.com

About your service

Service categories

Application Development and Deployment

AI platforms

  • Search and knowledge discovery

AI software services

  • Anomaly Detection AI Software Services
  • Forecast AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
This system has an API, so interoperability with other digital platforms, although not required, is encouraged. We have active partnerships in place with care management platforms (PCS) alarm receiving centres, (UMO) and digital care hubs (2iC-Care).
Cloud deployment model
Public cloud
Service constraints
None.
System requirements
  • "Digital inclusion"
  • "WIFI"

User support

Email or online ticketing support
Yes
Support response times
Our SLA for responding to email tickets is 24 hours from 09:00 - 17:30, Monday to Friday
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
Circadacare offers onsite support for full or partial installations and can also manage the replacement of existing equipment. All costs are scoped and tailored to the needs of each customer.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide user documentation on installation best practice, onsite installation training, remote/onsite training on accessing the care platform, and ongoing support on data insights reports.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
  • "digital videos"
  • "best practice guides"
  • "FAQs"
End-of-contract data extraction
Users can request an export of the data.
End-of-contract process
Access the the platform is revoked and the bulb's circadian output is fixed at a standard colour temperature. There is no additional cost for this.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Ultimately accessing the dashboard from either device is the same, but the mobile app was designed for non fixed locations, or to provide access to remote family members, carers or community support.
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
Yes. The service includes a secure, browser-based web interface for authorised users to access data, review alerts and manage system settings. No local installation is required.
Accessibility standards
WCAG 2.2 A
Accessibility testing
Users of our interface are care professionals - service users do not need to access the platform at all.
API
Yes
What users can and can't do using the API
Integrations managed case by case via technical team.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Pulling data into desired platforms, adding integrations to our platform and configuring alerts.

Scaling

Independence of resources
The service is highly predictable due to it being an IoT-based solution that regularly communicates with the cloud. We can accurately predict the load on our system. However, we also have auto-scale capabilities built into our system to handle increase in device number & therefore demand.

Analytics

Service usage metrics
Yes
Metrics types
We provide metrics regarding anomaly alerts, dashboard reports, or requested bespoke insights reports regarding specific trends that are identified via internal data analysts. We can also provide reports regarding WiFi health on the premises, and whether hardware is currently communicating with the platform.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Carers with relevant permissions accessing the platform can export data on service users via pdf reporting.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • Excel
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Circadacare operates on Google Cloud Platform infrastructure, which provides enterprise-grade availability SLAs ranging from 99.5% to 99.95% depending on service configuration. Full GCP SLA details are available at https://cloud.google.com/terms/sla.

We maintain automated monitoring with alerting for service disruptions during business hours (9:00-17:30, Monday to Friday). Incident response protocols ensure rapid resolution of critical issues during operating hours, with escalation procedures for urgent matters. Scheduled maintenance is performed during low-usage periods with advance customer notification, and we conduct post-incident reviews to prevent recurrence.

Service level agreements, including specific availability targets, monitoring coverage, incident response times, and service commitments, are defined individually within each customer contract. This approach allows us to tailor availability guarantees to the specific operational requirements and risk profiles of different care environments. As a healthcare technology provider supporting vulnerable populations, our contractual approach emphasizes operational accountability, service reliability, and continuous improvement rather than financial compensation mechanisms.

Availability commitments exclude downtime caused by customer infrastructure issues, third-party service failures beyond our control, scheduled maintenance performed with appropriate notice, or force majeure events.
Approach to resilience
Available on request.
Outage reporting
Email alerts.

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted using Google Cloud Platform's identity and access management with role-based permissions following least privilege principles. Multi-factor authentication is enforced for all administrative access to cloud infrastructure and production systems. Access is granted only to authorized personnel based on job function, with the CTO approving elevated privileges.
Production system access is logged and auditable through GCP's monitoring. User account policies document access control procedures. Support channels operate during business hours with email-based authentication for customer identity verification. Administrative functions are separated from standard user access, and session timeouts enforce re-authentication.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials certified. Cloud infrastructure operates on ISO 27001-certified Google Cloud Platform.
Information security policies and processes
Circadacare is Cyber Essentials certified with the CTO holding accountability for information security. We maintain documented, version-controlled policies covering asset and patch management, malware protection and endpoint security, network and firewall security, user account and access control, mobile device security, LLM and AI tool usage, and computer security guidelines.

Technical security operates on Google Cloud Platform's ISO 27001-certified infrastructure providing encryption, access management, and automated backups. Compliance is maintained through team training, onboarding processes, and annual Cyber Essentials recertification. As a healthcare technology provider, security and data protection are embedded organizational priorities. Policies are reviewed and updated regularly.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Application code is managed through version control with full change history tracking. Changes undergo peer review and testing in non-production environments before deployment. The CTO approves significant changes with security impact assessment based on data access, authentication mechanisms, and customer-facing functionality.
Infrastructure is defined as code using Terraform, providing version-controlled, auditable infrastructure configurations on Google Cloud Platform. All infrastructure changes are tracked through Terraform state management with GCP maintaining audit logs under SOC 2-certified change control processes.
Asset and patch management policies document our approach to tracking software components, dependencies, and security updates throughout their lifecycle.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerabilities are identified through automated dependency scanning of application code, security advisories from Google Cloud Platform, and monitoring of relevant CVE databases and security bulletins. Critical vulnerabilities affecting healthcare data or service availability are prioritized for immediate remediation.
Critical security patches are deployed within 24-48 hours following testing. Standard patches follow our regular deployment cycle with assessment of security impact. Infrastructure patches are managed through GCP's automated update systems for underlying services.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Google Cloud Platform provides continuous monitoring with automated alerts for suspicious activity including unauthorized access attempts, unusual traffic patterns, and configuration changes. Application logs are centralized and monitored for anomalies.
Potential compromises trigger immediate CTO notification during business hours with escalation procedures for out-of-hours incidents. Response includes isolating affected systems, assessing impact scope, implementing containment measures, and notifying affected parties as required.
Critical incidents affecting customer data or service availability receive immediate response. Standard security events are investigated within business hours.
Incident management type
Supplier-defined controls
Incident management approach
Incident response is managed by the CTO with procedures documented in our Computer Security Guidelines. Common scenarios including service outages, security concerns, and system issues are handled through established workflows.
Users report incidents via email to support channels during business hours (9:00-17:30, Monday-Friday) with emergency contact procedures for critical issues. All incidents are logged and tracked through resolution.
Customers are notified of incidents affecting their service with information on the issue and resolution. Significant security incidents are reported to affected parties as required. Google Cloud Platform monitoring provides automated alerting for infrastructure-level incidents.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2.5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
7.5%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
12.5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Dfbbf3fb-3e2b-4676-98cb-9b45e96a3572
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@circadacare.com. Tell them what format you need. It will help if you say what assistive technology you use.