Skip to main content

Trust & compliance

The evidence behind the software

Health data is the most sensitive data there is. This page sets out what we hold, what we are working towards and — the part most suppliers leave out — what we do not have.

ICO registration

Registered data controller, annual fee paid

Company number

QuoVira Health Ltd, England and Wales

VAT number
525574969

UK VAT registered, Making Tax Digital

Data residency
UK-hosted

Platform production in the London (UK) region; any transfer assessed under Chapter V

Our ICO entry and Companies House record are public — the links above go straight to the registers so you can verify them without taking our word for it.

Where we are today

An honest assurance position

A list of only strengths is no use to an information governance reviewer. Every line below carries a status, and the ones that are not green say so.

Each line is also labelled with what it applies to. QuoVira Health Ltd covers us as an organisation and data controller. Platform we run covers the consumer product we build and operate ourselves, and the same controls are what we bring to a client build.

  • ICO registration

    QuoVira Health Ltd

    Registered as a data controller under the Data Protection Act 2018, fee paid, renewed annually.

    In place
  • UK GDPR programme

    QuoVira Health Ltd

    Data protection impact assessment, Article 30 record of processing, transfer risk assessment and a retention and anonymisation schedule, all maintained as living documents.

    In place
  • ICO Children’s Code

    Platform we run

    Conformance assessed against all fifteen standards for our own products, with a child-facing privacy summary published alongside the full notice.

    In place
  • Information security policy set

    QuoVira Health Ltd

    Top-level security policy, secure development policy, acceptable use and privileged access agreement, records management and retention policy.

    In place
  • Incident response

    QuoVira Health Ltd

    Documented breach procedure with the 72-hour ICO reporting clock, named roles, a breach register and rehearsed playbooks.

    In place
  • Backup and disaster recovery

    Platform we run

    Two independent daily backups, off-host encrypted copies and restore tests exercised on both paths — see the measured figures below.

    In place
  • NHS Data Security and Protection Toolkit

    QuoVira Health Ltd

    Registered on the Toolkit. Our 2025/26 self-assessment is prepared against all ten National Data Guardian standards and is being completed — it has not yet been submitted or published.

    In progress
  • Cyber Essentials

    QuoVira Health Ltd

    Full readiness audit and a completed mock assessment workbook against the five control themes. The certificate itself has not been issued, so we do not describe ourselves as certified.

    In progress
  • Clinical safety (DCB0129 / DCB0160)

    Platform we run

    We prepare hazard logs and safety-case evidence as part of delivery. A clinical safety officer is appointed per engagement — we do not hold a standing safety case for our own products.

    In progress
  • Independent penetration test

    Platform we run

    Scoped and planned for the platform we run. Until it is done we state plainly that we have no independent validation of that application boundary.

    Not yet held

Data protection

UK GDPR as a design constraint

Compliance work that starts after the build is remediation. Ours starts at discovery and produces the evidence a buyer’s governance team will ask for.

Assessed before it is built

A data protection impact assessment covers our processing of children’s and health data, and is revisited whenever the processing changes rather than filed and forgotten.

Every processor accounted for

Our Article 30 record lists each processor and sub-processor with its region and data processing agreement, alongside a Chapter V transfer risk assessment for anything leaving the UK.

Built for the Children’s Code

Where a product is likely to be accessed by children, we design to the ICO’s age-appropriate design standards — data minimised by default, no nudge techniques, and a privacy summary a child can read.

Erasure and portability are features

Consent, data export, erasure and the retention and anonymisation boundary are implemented in the product, not handled as manual back-office requests.

Security engineering

Controls in the code, not in a policy binder

These are the controls on the platform we build and run, and the baseline we bring to a client build. Our security audits are grounded in the running system — read from the infrastructure and the repository rather than from last year’s document. Where the two disagree, the system wins and the document gets corrected.

  • Full security header set on every response — CSP, HSTS, frame denial, MIME-type and referrer controls
  • Secrets held as encrypted platform variables, never in source control, with a documented secret inventory and expiry tracking
  • Least-privilege database access and role-based authorisation enforced server side, not in the interface
  • Databases firewalled to known sources; no direct public exposure
  • Automated dependency alerting with a documented patching commitment — zero open advisories at our last review
  • A code-grounded technical security audit mapped to the DTAC security standard and NCSC CAF-aligned outcomes
Stated deliberately

What we do not claim

Each of these is a deliberate decision or a funding constraint, and each one is tracked with an owner. You should hear them from us, not discover them in an assessment.

QuoVira Health Ltd

We are not Cyber Essentials certified

The readiness audit and mock assessment workbook are complete, but the certificate has not been issued to the company. We will say so the day it is.

Platform we run

The platform has not had an independent penetration test

This is the largest single gap in our assurance position. It is scoped, planned and stated openly rather than left for an assessor to find.

QuoVira Health Ltd

We have not appointed a data protection officer

The Article 37 threshold was formally assessed for the company and documented as not met at our current scale. A founder cannot act as their own DPO, so we claim neither.

Platform we run

The platform is not highly available yet

The production database runs on a single node today, so recovery from a node failure is the measured 7m 31s restore above rather than an instant failover. A standby is part of our go-live plan — we will publish the failover figure once it is in place and tested, not before.

Ask us for the evidence pack

Procurement, information governance and clinical safety reviewers can request our documentation index — the security and data protection policy set, the impact assessment, the processing record and supplier list, the disaster recovery evidence and the risk register. It is the same pack we would hand an auditor, shared under a mutual NDA.

If you are completing a supplier assurance questionnaire, send it over — we would rather answer your form than ask you to read ours.

Governance & privacy enquiries
[email protected]
Reporting a vulnerability

Email the same address with SECURITY in the subject line. We acknowledge reports within one business day and will not pursue researchers who act in good faith.

Personal data breaches

Assessed against the 72-hour reporting clock and escalated to the ICO where the threshold is met.

This page is reviewed whenever a control or a status changes, and at least every six months. Last reviewed 24 August 2026. Registrations are stated as facts and link to the public registers; we use no regulator logos and claim no regulator endorsement — the ICO, MHRA and NHS do not accredit or approve products.

Got a health product in mind?

Whether it's a consumer app or a tool for your organisation, tell us the problem and we'll tell you how we'd build it. First conversation is free.