Compliance status
Last updated 10 July 2026
These statuses are honest, current and conservative. We only show a badge for something we genuinely hold and that you can verify — everything else is marked 'in progress' or 'planned', and this page updates as each item lands.
Verifiable today
The controls below are live now — the foundations our assurances rest on.
The active service stores and processes data in the UK (London, eu-west-2) — database, authentication, file storage and backups — and the AI runs on AWS Bedrock in London behind a guard that refuses non-UK routing.
AyrisIQ is governance tooling, not a patient record. A patient-identifier check runs in the app and again server-side before any text reaches the AI, and refuses to send it.
Every practice's data is separated at the database with row-level security and role-based access; an append-only audit trail records changes.
TLS in transit (Cloudflare) and encryption at rest on the managed UK platforms.
Standards & certifications
We align our processing to UK GDPR / DPA 2018, backed by a DPIA, a customer data-processing agreement and a sub-processor register. (UK GDPR has no certificate; open items remain — see below.)
AyrisIQ Ltd (company 17342611) is registered with the ICO under the Data Protection Act 2018 (reference C1985535); verifiable on the ICO public register.
The active service runs in the UK (London). A historical copy in a retired EU project is pending deletion, so we do not yet claim 'UK-only at rest'. Email (EU) and CDN (global edge) carry only metadata, not governance content.
Being completed voluntarily as a trust signal (AyrisIQ is below the mandatory large-supplier threshold; the independent audit applies to large Category 1/2 suppliers). No status is published until it genuinely exists on the DSPT portal.
A DTAC 2.0 evidence pack is prepared and completed on request for NHS procurement. (DTAC is buyer-completed; there is no DTAC certificate to hold.)
Self-assessment submitted (July 2026), awaiting the assessor's result; the badge will appear here only once IASME awards certification.
On the roadmap after Cyber Essentials self-assessment is awarded.
Applied proportionately: assessed as not a medical device, Clinical Safety Officer appointed, and the clinical risk management plan, hazard log and safety case are in place and maintained. (DCB0129 is a manufacturer self-declaration, not an external certificate.)
Being commissioned with a CREST-accredited tester now the access-control hardening is deployed; no test has been performed yet.
An accessibility statement is published; a formal WCAG 2.2 AA audit is planned. We do not yet claim AA conformance.
Being arranged for AyrisIQ Ltd; certificates will be available in the evidence room on request.
Not currently pursued — the NHS-native path (DSPT, DTAC, Cyber Essentials) comes first; ISO 27001 is a possible later step. Our infrastructure providers hold their own ISO 27001, which is theirs, not ours.
Not pursued — SOC 2 is a US assurance framework, not the relevant UK/NHS procurement route.
Why we publish it this way
AyrisIQ exists because governance claims should be evidence-linked. We hold ourselves to the same bar: if a control or certification isn't in place, this page says so — no badge we haven't earned, no certificate number we don't hold. The moment an item is genuinely awarded (ICO registration first), it becomes a definitive, verifiable statement here.
Need a specific attestation for your procurement? Ask us — we'll share the real state and the underlying evidence under NDA rather than decorate this page.
