
Security & privacy
Information deserves care.
AyVex products handle information that matters to the people it belongs to. This page explains how that responsibility is approached across the company.
For details about personal data on this website, read the Privacy page.
Approach
How we work
These are the standards applied when AyVex builds and operates a product.
Privacy-aware design
Privacy is decided at the point a feature is designed, not audited afterwards. What a feature needs to know, and for how long, is part of the specification for it.
Data minimisation
Products are built to hold the information required to do their job and no more. Where a value can be derived rather than stored, or discarded once used, that is the preference.
Access controls
Access to systems and data is granted on the basis of what a role actually requires, and reviewed when that changes. Administrative access is kept separate from routine use.
Encryption where appropriate
Traffic is served over HTTPS. Where a product stores information that warrants it, encryption at rest is applied in line with what the data is and what is holding it.
Responsible secrets management
Credentials, keys and tokens are held in managed secret storage, never in source control. They are scoped to the environment they belong to and rotated when circumstances require it.
Controlled use of third-party services
Third-party services are introduced deliberately. Before a dependency is added, what it would process and why it is needed are considered explicitly, and unnecessary ones are not adopted.
Secure development principles
Dependencies are kept current and monitored for known vulnerabilities. Input from outside a system is treated as untrusted, and changes are reviewed before they reach a live environment.
Separation of environments
Development, testing and live environments are kept separate, with their own configuration and credentials. Live data is not used as test data.
Per product
Product-specific information
Each AyVex product processes different information for different reasons, so the detail that matters — what is collected, where it is stored, who can reach it and how long it is kept — belongs with the product rather than with the company.
The security and privacy information for an individual AyVex product is published by that product, and is the authoritative source for how it handles data. This page describes the standards those products are built to; it does not replace them.
Scope
What AyVex does not claim
Describing good practice is not the same as holding a certification. AyVex Ltd does not currently hold, and does not claim to hold, any of the following:
- ISO 27001 certification
- SOC 2 attestation
- Cyber Essentials certification
- NHS Data Security and Protection Toolkit status
- NHS approval, endorsement or accreditation
- Financial Conduct Authority authorisation
- Government approval or endorsement
If any of these are obtained in future, they will be stated here with the issuing body and the scope of the assessment, and nowhere before that.
Disclosure
Reporting a security concern
If you believe you have found a security vulnerability in this website or in an AyVex product, please report it by email. Include enough detail to reproduce the issue, and please do not disclose it publicly until it has been addressed.
AyVex does not currently operate a paid vulnerability disclosure programme.