What the software does — and doesn't do
KitCompliance helps you organise and evidence first-aid provision: kit contents, expiry dates, inspections, equipment servicing, first-aider certificates and accident records. It does not certify that your workplace is compliant. Under the Health and Safety (First-Aid) Regulations 1981, the employer remains responsible for assessing first-aid needs and making adequate and appropriate provision. Our checklists and kit templates follow published guidance (HSE L74, BS 8599-1) but are a starting point, not a substitute for your own needs assessment.
Audit trail
- Every kit inspection records the date, the person who carried it out (their user account and name) and when the next check is due.
- Key changes, such as adding or removing kits, users and training records, are written to an organisation-scoped audit log with the user and action.
- Inspection history is kept with the kit, so you can show an auditor when each kit was last checked and by whom.
- Reports and exports (PDF and CSV) are generated from these records, not typed by hand. See a sample audit report.
How compliance scores are calculated
The kit compliance score is the share of tracked kit items that are neither expired nor due to expire within 30 days:
score = (items − expired − expiring within 30 days) ÷ items
- Items with no expiry date (for example scissors) count as compliant.
- 90% and above is shown green, 70–89% amber, below 70% red.
- On the multi-site dashboard, a site's score also counts overdue kit inspections, because a kit nobody has checked is not evidence of anything.
- A score reflects the data entered. If items or inspections are not recorded, the score cannot account for them.
Access control
- Each organisation's data is isolated: every query is scoped to the signed-in user's organisation.
- Three roles — admin, manager and user — control who can invite people, manage sites, or only record inspections.
- Passwords are stored only as bcrypt hashes. Sign-in with Google is available. Sessions use an httpOnly cookie that page scripts cannot read, with CSRF protection on changes.
- Sign-in and API requests are rate-limited, and the site sends standard security headers.
Where your data lives
- Application data is held in a database on a persistent volume with our hosting provider, Railway. Uploaded photos are stored on the same volume and served through short-lived signed links.
- Email is sent through Resend; payments are handled by Stripe (we never see or store card numbers); optional error monitoring uses Sentry.
- Records stay until your organisation deletes them or asks us to close the account. Accident-book retention periods are set by health and safety law, so we don't delete those on a timer.
Full details are in our privacy policy.
Questions and security reports
For procurement or security questionnaires, email hello@kitcompliance.com. To report a vulnerability, email security@kitcompliance.com.