Security and data.
Assure holds some of the most sensitive records a care service keeps. This page sets out where that data lives, how we protect it and what happens to it. If your organisation needs more detail for a supplier questionnaire, email info@eviqa.health.
Where your data is stored
- Assure is hosted on Amazon Web Services in London (eu-west-2).
- Your database, uploaded files, backups and snapshots all stay in the UK.
- We do not use analytics, advertising or tracking tools inside the Assure app.
Encryption
- All connections to Assure use HTTPS.
- Your database and uploaded files are stored on an encrypted disk.
- Backups are encrypted with AES-256 before they leave the server, and sent over HTTPS to encrypted storage in London.
- A copy of the backup encryption keys is kept separately from the server, so backups can be restored even if the server is lost.
Backups and recovery
- Your database is backed up every day, with continuous logging so it can be restored to a point in time.
- Uploaded files are backed up every day.
- Daily snapshots of the Assure data disk are kept for 7 days.
- Database backups are kept for about seven weeks, then overwritten.
- We test a full restore on a separate server at least every six months and after any change to how we back up or store data. Our most recent test, in September 2026, restored the database and every uploaded file with nothing missing, in under two minutes.
Signing in
- Multi-factor sign-in with an authenticator app, with single-use recovery codes.
- Passkeys, using Face ID, Touch ID or Windows Hello.
- Managers can require multi-factor sign-in for everyone in their organisation.
- Accounts lock for 15 minutes after 5 failed attempts.
- Passwords are never emailed, and managers never set them. New staff get a one-time link that expires after 72 hours. Password reset links expire after 1 hour.
Who can see what
- Each organisation's data is visible only to its own signed-in staff.
- Staff see what their role allows. CPD evidence is visible only to the person it belongs to and their managers.
- Uploaded documents open through a secure link that expires after 5 minutes. They are not publicly reachable.
- Opening CPD evidence, resetting a staff member's sign-in and other key actions are recorded in the audit log.
Emails
- Alert emails never contain client names or incident details. They tell the recipient something needs review and ask them to sign in.
- Daily summaries show counts only.
Keeping the service separate
- The Assure app runs in its own restricted account on the server, with no admin rights. It can only write to its own storage.
- Our public website and its enquiry forms run separately and cannot reach Assure's data or settings.
Who processes your data
You are the data controller for the records your service keeps in Assure. Eviqa Ltd acts as your data processor, under a data processing agreement that meets Article 28 of the UK GDPR.
We use two sub-processors for Assure:
| Sub-processor | What for | Where |
|---|---|---|
| Amazon Web Services | Hosting, storage, backups | UK (London) |
| Brevo | Sending Assure's emails | EU |
We give customers 30 days' notice before adding or changing a sub-processor.
If something goes wrong
- If a personal data breach affects your data, we will tell you without undue delay and within 48 hours of becoming aware of it, with what we know and what we are doing about it.
- We will support you with any report you need to make to the ICO.
When you leave
- At the end of your subscription we can return your data to you, and then delete it within 60 days.
- Backup copies are overwritten in the normal cycle, within about eight weeks.
Certifications
We are working towards Cyber Essentials certification and the NHS Data Security and Protection Toolkit. We will list them here once achieved.
Reporting a security concern
If you think you have found a security issue in Assure, email info@eviqa.health with "Security" in the subject line. We will respond within 1 working day.
Our subscription terms and data processing agreement are available on request from info@eviqa.health.
Security questions
Is our data stored in the UK?
Yes. Hosting, storage, backups and snapshots are all in London. The only processing outside the UK is Brevo sending emails from the EU, and those emails contain no client or incident details.
Can Eviqa staff see our records?
Only where needed to support you or keep the service running, and under the confidentiality terms of our data processing agreement.
Do you use our data to train AI or for marketing?
No. We only use your data to provide Assure to you.
Can we make multi-factor sign-in compulsory?
Yes. A manager can switch it on for the whole organisation in Settings, under Sign-in security.
What happens if a staff member loses their phone?
A manager can reset their authenticator from the staff member's profile. The reset is recorded in the audit log.
How quickly could you recover from a serious failure?
Our restore tests bring back the full database and all uploaded files in a couple of minutes on a fresh server. Total recovery time depends on the failure, but backups and snapshots are held separately from the live server.
Will you complete our supplier security questionnaire?
Yes. Email info@eviqa.health.
Need more detail for your questionnaire?
Email info@eviqa.health and we will complete your supplier security questionnaire, or book a demo and ask us directly.
Plans from £119 a month, with every feature and onboarding included. See pricing