Approved Applications
Applications and Cloud Services Register
Cyber Essentials evidence – approved software, devices and cloud services
Organisation: CarefulAI Ltd
Owner / responsible person: Joseph Connor
Date last reviewed: 01 / 07/ 2026
As the sole user and decision-maker, I approve every application before it is installed and use only applications from official, code-signed app stores. All cloud services listed are accessed under valid accounts protected by a strong, unique password and multi-factor authentication (MFA). I review this register periodically and whenever a device, application or service is added or removed.
Approved applications and devices
| Application | Device(s) | Business purpose |
|---|---|---|
| Bitdefender Total Security | Laptop, Phone | Anti-malware / endpoint protection and firewall |
| Windows Defender Firewall | Laptop | Built-in software firewall (managed by Bitdefender) |
| Web browser (Chrome / Edge) | Laptop, Phone | Accessing web-based business services securely |
| Google Workspace apps (Docs, Sheets, Slides, Drive) | Laptop, Phone | Document creation, storage and collaboration |
| Gmail app | Phone | Accessing business email on mobile |
Cloud services in scope
All cloud services below are third-party services consumed by the organisation. None are self-hosted. MFA is enabled on every account; Google Workspace additionally has MFA enforced.
| Cloud service | Type | Business purpose | MFA status |
|---|---|---|---|
| Google Workspace | SaaS | Email, documents, file storage, collaboration | Enabled & enforced |
| Calendly | SaaS | Appointment scheduling | Enabled |
| SaaS | Business networking / social media | Enabled | |
| Otter.ai | SaaS | Meeting transcription | Enabled |
| Square | SaaS | Website hosting / provider | Enabled |
| Stripe | SaaS | Online payment processing | Enabled |
| Starling Bank | SaaS | Online business banking | Enabled |
| GitHub / Codespaces | PaaS | Cloud software development environment | Enabled |
| GOV.UK (HMRC / Gov Gateway) | SaaS | Tax administration and tenders | Enabled |
Controls applied
Applications are installed only from official app stores (code-signed); unsigned apps and untrusted sources are blocked and no device is rooted or jailbroken. Anti-malware (Bitdefender Total Security) is active on all in-scope devices with real-time and web protection enabled, and all software is kept current with automatic updates. Each cloud service account uses a strong, unique password and MFA. Unused accounts and unnecessary third-party app connections have been removed, and unconfigured third-party app access to Google Workspace is blocked by default.
Review record
This register is reviewed at least annually and whenever a new application, device or cloud service is introduced. Items no longer required are removed promptly.