Trust Centre

Compliance status

Last updated 10 July 2026

These statuses are honest, current and conservative. We only show a badge for something we genuinely hold and that you can verify — everything else is marked 'in progress' or 'planned', and this page updates as each item lands.

Verifiable today

The controls below are live now — the foundations our assurances rest on.

UK data residency

The active service stores and processes data in the UK (London, eu-west-2) — database, authentication, file storage and backups — and the AI runs on AWS Bedrock in London behind a guard that refuses non-UK routing.

No patient-identifiable data by design

AyrisIQ is governance tooling, not a patient record. A patient-identifier check runs in the app and again server-side before any text reaches the AI, and refuses to send it.

Per-practice isolation & least privilege

Every practice's data is separated at the database with row-level security and role-based access; an append-only audit trail records changes.

Encryption in transit and at rest

TLS in transit (Cloudflare) and encryption at rest on the managed UK platforms.

Standards & certifications

UK GDPR / Data Protection Act 2018
In progress

We align our processing to UK GDPR / DPA 2018, backed by a DPIA, a customer data-processing agreement and a sub-processor register. (UK GDPR has no certificate; open items remain — see below.)

ICO registration (data-protection fee)
Achieved

AyrisIQ Ltd (company 17342611) is registered with the ICO under the Data Protection Act 2018 (reference C1985535); verifiable on the ICO public register.

UK data residency
In progress

The active service runs in the UK (London). A historical copy in a retired EU project is pending deletion, so we do not yet claim 'UK-only at rest'. Email (EU) and CDN (global edge) carry only metadata, not governance content.

NHS Data Security & Protection Toolkit (DSPT v8)
In progress

Being completed voluntarily as a trust signal (AyrisIQ is below the mandatory large-supplier threshold; the independent audit applies to large Category 1/2 suppliers). No status is published until it genuinely exists on the DSPT portal.

NHS DTAC 2.0
In progress

A DTAC 2.0 evidence pack is prepared and completed on request for NHS procurement. (DTAC is buyer-completed; there is no DTAC certificate to hold.)

Cyber Essentials
In progress

Self-assessment submitted (July 2026), awaiting the assessor's result; the badge will appear here only once IASME awards certification.

Cyber Essentials Plus
Planned

On the roadmap after Cyber Essentials self-assessment is awarded.

DCB0129 clinical safety
In progress

Applied proportionately: assessed as not a medical device, Clinical Safety Officer appointed, and the clinical risk management plan, hazard log and safety case are in place and maintained. (DCB0129 is a manufacturer self-declaration, not an external certificate.)

Independent penetration test
In progress

Being commissioned with a CREST-accredited tester now the access-control hardening is deployed; no test has been performed yet.

WCAG 2.2 AA accessibility
In progress

An accessibility statement is published; a formal WCAG 2.2 AA audit is planned. We do not yet claim AA conformance.

Insurance (professional indemnity, cyber, public liability)
Planned

Being arranged for AyrisIQ Ltd; certificates will be available in the evidence room on request.

ISO/IEC 27001
Not pursued

Not currently pursued — the NHS-native path (DSPT, DTAC, Cyber Essentials) comes first; ISO 27001 is a possible later step. Our infrastructure providers hold their own ISO 27001, which is theirs, not ours.

SOC 2
Not pursued

Not pursued — SOC 2 is a US assurance framework, not the relevant UK/NHS procurement route.

Why we publish it this way

AyrisIQ exists because governance claims should be evidence-linked. We hold ourselves to the same bar: if a control or certification isn't in place, this page says so — no badge we haven't earned, no certificate number we don't hold. The moment an item is genuinely awarded (ICO registration first), it becomes a definitive, verifiable statement here.

Need a specific attestation for your procurement? Ask us — we'll share the real state and the underlying evidence under NDA rather than decorate this page.