CARE4U · SELF-HOSTED EDITION · VERSION 1.0 · 8 OCTOBER 2026

Your staff compliance workspace, on your hosting

This package runs independently of ChatGPT. Staff sign in with Care4U accounts. Your hosting stores the records, passwords and uploaded documents. You continue paying for your domain and hosting; this application has no ChatGPT subscription or API requirement.

Recommended address: https://compliance.care4u.healthcare. This is a proposed address and has not been created. Keep it separate from your existing public website.

1. Check the hosting options

In Namecheap, open Hosting List → Go to cPanel → Setup Node.js App. Choose a current, supported Node.js 24 version (Node.js 22.13 or later is also supported). Namecheap currently lists Node.js 22 and 24 on shared hosting, but the options on your actual account still need confirmation. This app uses Node's built-in SQLite database; no MySQL database or production npm installation is needed.

If this menu or a compatible version is missing, ask Namecheap to confirm support before uploading staff records. The package is not a PHP application. Uploading it into an ordinary static web folder will not make it run.

2. Create the subdomain and secure connection

  1. In cPanel → Domains, create compliance.care4u.healthcare with its own document root. Do not reuse the main website's document root.
  2. Use Namecheap SSL/AutoSSL to enable a valid certificate for the subdomain.
  3. Enable Force HTTPS Redirect for the subdomain. Check that opening its http:// address takes you to https://.
  4. Exclude this entire subdomain from public CDN/page caching. Responses and files should not be cached by a shared proxy.

Use SFTP, FTPS or the authenticated cPanel File Manager to upload files. Avoid unencrypted plain FTP for account credentials or staff information.

3. Put the files in the right place

This ZIP includes your original worker-register JSON. Keep it private. Do not upload the ZIP, migration folder, database or source files into public_html. Do not send the archive to staff as their way to access the system.

Extract the archive on your computer. In cPanel File Manager, start at your hosting account's home directory, one level above public_html. Create an application folder and a separate data folder:

PurposeExample location
Application files/home/YOUR_CPANEL_USER/care4u-compliance
Private database and documents/home/YOUR_CPANEL_USER/care4u-private-data
Private full backups/home/YOUR_CPANEL_USER/care4u-private-backups

Replace YOUR_CPANEL_USER with the actual account name shown in cPanel. These are examples, not confirmed paths for your account.

Upload app.js, package.json and the server, public and tools folders into the application folder. The public folder contains the already-built screen assets; keep it inside the application folder. The frontend and tests folders are source/development files and are not needed on the hosting server. Keep migration/original-register.json on your computer for authenticated import later.

Only the hosting account should be able to read the private data and backups. Use directory permissions 700 and private file permissions 600; do not use 777. The app applies these permissions to its private data. Avoid overwriting any .htaccess generated by cPanel.

4. Register the application in cPanel

In Setup Node.js App → Create application, use:

SettingValue
Node.js versionCurrent supported 24.x, or 22.13+ if required
Application modeProduction
Application rootcare4u-compliance, relative to your hosting home; confirm it matches the private folder above
Application URLYour new compliance subdomain, at its root path
Startup fileapp.js

Add these environment variables:

NameValue
CARE4U_ORIGINhttps://compliance.care4u.healthcare — exact address, no final slash
CARE4U_DATA_DIRThe absolute private data-folder path from step 3
CARE4U_SETUP_TOKENA fresh, random setup key of at least 32 characters, generated by your password manager. Keep it private.

The setup key is not a staff password. Save the application and restart it. There are no production dependencies to install. Do not run the frontend build on shared hosting; the browser files are supplied already built.

If the app cannot start, check the Node.js version, exact folder paths and environment variables. Namecheap's application log can help identify a Passenger/runtime configuration issue. Do not post secrets or staff records from logs into public support tickets.

5. Create your administrator account

  1. Open the new HTTPS address. You should see “Create your administrator account”.
  2. Enter your name, email, private setup key and a unique password of at least 14 characters.
  3. After creation, remove CARE4U_SETUP_TOKEN from cPanel and restart the app. The setup endpoint also locks automatically once the first account exists.
  4. Open My account to manage staff, import the register and change your password.

6. Check the installation before moving records

Start with one synthetic worker and a harmless test document. Verify that:

Use a temporary data directory for this test. Once satisfied, stop the application, point CARE4U_DATA_DIR to a new empty production directory, restart and create the real administrator using a new setup key. Keep the original test installation isolated; do not merge its test records into your live register. Record who will maintain hosting updates, access reviews, backups and incident handling.

7. Import the register and plan the changeover

The supplied migration/original-register.json contains the original 145 workers and 166 CoS history entries. It does not contain subsequent edits or uploaded files from the earlier hosted app. Historical records are included; these numbers do not mean 145 current employees.

  1. If the earlier app has been updated, stop edits there temporarily and download its latest Audit centre → All records · JSON export. Also inventory and download uploaded evidence files.
  2. For an unchanged original register, use the supplied original-register JSON. For a newer export with no uploaded documents, use that export.
  3. In the new app, open My account → Import a worker register, select the JSON, check the displayed counts and press Import these records.
  4. Check totals, worker details, CoS history, dates and action owners. Unknown immigration-expiry and RTW dates remain blank; source checklist ticks are not document files.
  5. Confirm the new system is ready before directing staff to it. Keep the former system read-only during the changeover to avoid conflicting edits.
An earlier-app export containing evidence metadata is deliberately rejected by the simple importer: the JSON does not contain document bytes. Those cases need a separate migration that preserves document links and review history. Do not clear the document list just to make an export importable. The included full backup/restore tools work for this standalone edition, not for the former Sites/R2 storage.

8. Give selected staff access

RoleCan do
AdministratorManage accounts and licence settings; edit, upload, review, download, import and export records
EditorEdit workers/actions, upload and review evidence, view records and download CSVs/documents
Read-onlyView all worker records, actions, audit history and licence settings; download documents and CSVs

Each account has its own email and password. Create it under My account and pass the generated temporary password to that person through a secure channel. They must change it on their first sign-in. Accounts are not sent by email automatically. Disable staff access when it is no longer needed. All three roles can see all worker files; there are no branch-specific or worker-specific restrictions.

Sessions expire after 30 minutes without server activity and after eight hours at most. Password changes, access changes, account disabling and resets revoke the relevant sessions. Administrators can reset another staff member's password. For a lost sole-admin password, a hosting administrator can use the recovery command described in README.txt.

9. Set up daily full backups

The JSON download inside the app is a records export, not a complete backup. A complete backup includes the database, accounts, audit trail and document bytes.

From the app's Node.js virtual environment in cPanel Terminal/SSH:

node /home/YOUR_CPANEL_USER/care4u-compliance/tools/backup.mjs /home/YOUR_CPANEL_USER/care4u-private-data /home/YOUR_CPANEL_USER/care4u-private-backups

The tool takes a consistent SQLite snapshot and copies the documents referenced by it, with SHA-256 checksums. Schedule it daily in cPanel Cron Jobs using the exact Node binary path shown by which node after activating the application environment. The schedule, retention and off-server encrypted copy are not configured automatically. Assign an owner, monitor failures, check disk usage, and test restoration. Retain backups according to Care4U's agreed policy.

Restore to a new empty private directory while the application is stopped:

node /home/YOUR_CPANEL_USER/care4u-compliance/tools/restore.mjs /absolute/path/to/one-backup /home/YOUR_CPANEL_USER/care4u-restored-data

The restore verifies checksums, checks database integrity and removes old sessions. Point CARE4U_DATA_DIR at the restored directory and restart. Keep the previous directory until verification is complete. Hosting disk encryption and protection of backup copies depend on your hosting and backup arrangements; this application does not encrypt database/document contents itself.

What is included, and what still needs operating

Included: individual password accounts, three staff roles, private document downloads, change history, expiry flags, records exports, optimistic edit-conflict handling, full backup and restore tools. The application makes no calls to ChatGPT or OpenAI services.

Not included: multi-factor authentication, malware scanning of uploads, automatic email reminders, payroll/rota connections, automatic SMS reporting, automatic legal-rule updates, granular permissions for individual worker files, or offline editing and synchronisation. Upload signature checks are not malware scanning. Alerts and review records support your team; they do not establish legal compliance.

The application can run locally on a laptop with Node.js, but that is a separate installation and database. It will not automatically synchronise with your online staff system. Use the online installation as the shared source of records.

Validation and handover

Local verification: TypeScript checking, production frontend build, eight backend integration groups, real-register import counts, permissions, private upload/download, edit conflicts, account revocation, login throttling and full backup/restore. See TESTING.txt for browser verification status and remaining hosting checks. The package has not been deployed to or tested on Care4U's Namecheap account, and has not had an independent security assessment. Before staff use, complete the hosting checks above and review the hosting arrangement for your staff records.

Official hosting references

Open this guide from your computer. It does not need to be uploaded to the public website.