Approach

How we work

These are the standards applied when AyVex builds and operates a product.

  • Privacy-aware design

    Privacy is decided at the point a feature is designed, not audited afterwards. What a feature needs to know, and for how long, is part of the specification for it.

  • Data minimisation

    Products are built to hold the information required to do their job and no more. Where a value can be derived rather than stored, or discarded once used, that is the preference.

  • Access controls

    Access to systems and data is granted on the basis of what a role actually requires, and reviewed when that changes. Administrative access is kept separate from routine use.

  • Encryption where appropriate

    Traffic is served over HTTPS. Where a product stores information that warrants it, encryption at rest is applied in line with what the data is and what is holding it.

  • Responsible secrets management

    Credentials, keys and tokens are held in managed secret storage, never in source control. They are scoped to the environment they belong to and rotated when circumstances require it.

  • Controlled use of third-party services

    Third-party services are introduced deliberately. Before a dependency is added, what it would process and why it is needed are considered explicitly, and unnecessary ones are not adopted.

  • Secure development principles

    Dependencies are kept current and monitored for known vulnerabilities. Input from outside a system is treated as untrusted, and changes are reviewed before they reach a live environment.

  • Separation of environments

    Development, testing and live environments are kept separate, with their own configuration and credentials. Live data is not used as test data.

Per product

Product-specific information

Each AyVex product processes different information for different reasons, so the detail that matters — what is collected, where it is stored, who can reach it and how long it is kept — belongs with the product rather than with the company.

The security and privacy information for an individual AyVex product is published by that product, and is the authoritative source for how it handles data. This page describes the standards those products are built to; it does not replace them.

Scope

What AyVex does not claim

Describing good practice is not the same as holding a certification. AyVex Ltd does not currently hold, and does not claim to hold, any of the following:

  • ISO 27001 certification
  • SOC 2 attestation
  • Cyber Essentials certification
  • NHS Data Security and Protection Toolkit status
  • NHS approval, endorsement or accreditation
  • Financial Conduct Authority authorisation
  • Government approval or endorsement

If any of these are obtained in future, they will be stated here with the issuing body and the scope of the assessment, and nowhere before that.

Disclosure

Reporting a security concern

If you believe you have found a security vulnerability in this website or in an AyVex product, please report it by email. Include enough detail to reproduce the issue, and please do not disclose it publicly until it has been addressed.

contact@ayvexltd.com

AyVex does not currently operate a paid vulnerability disclosure programme.