Trust & compliance
Everything a buyer checks, in one place
This page states our clinical safety, information governance, security and data protection position. It is written for procurement, not for marketing. Where a value is not yet published it is marked rather than omitted.
Last reviewed
Clinical safety
Our products are developed under DCB0129. We maintain a Clinical Risk Management Plan, Hazard Log and Clinical Safety Case Report, overseen by our Clinical Safety Officer.
- Clinical Safety Officer
- Nagini Vallamkonda, GDC 190767
- Standard applied
- DCB0129 (clinical risk management for health IT manufacturers)
- Artefacts maintained
- Clinical Risk Management Plan, Hazard Log, Clinical Safety Case Report
- Reissue cadence
- Clinical Safety Case Reports are issued per release
- Availability to deploying organisations
- Available to deploying organisations to support their DCB0160 obligations, on request
Digital Technology Assessment Criteria (DTAC)
- Status
- We maintain a completed NHS Digital Technology Assessment Criteria response against the February 2026 form, available to NHS buyers on request.
- Form version
- February 2026
- Last completed
- [PLACEHOLDER: DTAC completion date]
Data Security and Protection Toolkit (DSPT)
As an IT supplier we file the standards-based version of the DSPT, not the CAF-aligned version that applies to NHS organisations.
- Status
- [PLACEHOLDER: DSPT status, e.g. Standards Met]
- Toolkit version
- [PLACEHOLDER: DSPT version filed]
- Publication date
- [PLACEHOLDER: DSPT publication date]
- ODS code
- B8D4Q
- Assessment type
- Standards-based (IT supplier), not CAF-aligned
Security certification
Certification claims are only meaningful with a certificate number, an expiry date and a named certification body. Undated badges are a red flag, so we publish the detail or we publish nothing.
| Certification | Certificate no. | Expires | Certification body | UKAS-accredited |
|---|---|---|---|---|
| Cyber Essentials | [PLACEHOLDER: certificate number or “not held”] | [PLACEHOLDER: expiry date] | [PLACEHOLDER: body] | [PLACEHOLDER: yes / no] |
| Cyber Essentials Plus | [PLACEHOLDER: certificate number or “not held”] | [PLACEHOLDER: expiry date] | [PLACEHOLDER: body] | [PLACEHOLDER: yes / no] |
| ISO/IEC 27001 | [PLACEHOLDER: certificate number or “not held”] | [PLACEHOLDER: expiry date] | [PLACEHOLDER: body] | [PLACEHOLDER: yes / no] |
Delete any row for a certification we do not hold rather than leaving it blank. An empty row reads as an expired certificate.
Data protection
We are a controller for the data we collect about our own customers and website visitors, and a processor for the patient data our customers put through our products. The distinction matters because it determines who answers a subject access request.
- ICO registration
- ZB235652 (Tier 1, renews 11 October 2026)
- Where we are a controller
- Customer contact details, billing records, support correspondence and website analytics.
- Where we are a processor
- Patient data entered into our products by a customer. The customer is the controller; we act on their documented instructions.
- Hosting region
- [PLACEHOLDER: hosting region, e.g. UK South]
- Hosting provider
- [PLACEHOLDER: hosting provider]
- International transfers
- [PLACEHOLDER: state whether any data leaves the UK, and under what mechanism]
- Data Protection Officer
- [PLACEHOLDER: DPO name and contact, or state that none is appointed and why]
Sub-processors
Last updated . We notify customers before adding a sub-processor that handles patient data.
| Sub-processor | Purpose | Data region |
|---|---|---|
| [PLACEHOLDER: sub-processor name] | [PLACEHOLDER: purpose] | [PLACEHOLDER: data region] |
| [PLACEHOLDER: sub-processor name] | [PLACEHOLDER: purpose] | [PLACEHOLDER: data region] |
AI and patient data
Buyers ask three questions about AI and patient data: does it reach a model provider, is it used for training, and how long is it kept. Silence on any of them is read as yes, so we answer all three.
- Does patient data reach a model provider?
- [PLACEHOLDER: yes / no — and if yes, which provider and under what contract]
- Is patient data used to train models?
- [PLACEHOLDER: yes / no — state the contractual basis for the answer]
- Retention period at the model provider
- [PLACEHOLDER: retention period, or state zero-retention if contracted]
- Retention period in our systems
- [PLACEHOLDER: retention period]
- Which products use a model provider
- [PLACEHOLDER: list products, or state none]
- Human review before anything is filed
- Yes. Every output is a draft until a clinician or Clinical Safety Officer reviews, edits and approves it.
Documents for buyers
These are available to NHS buyers and deploying organisations on request. A pre-populated DPIA template is provided so your information governance team starts from our answers rather than a blank form.