Skip to main content

Security

Your patients’ data. Our responsibility.

Every system on your practice website is handled to NHS-contractual standards — independently verified, annually renewed.

Accreditations

%

WCAG 2.2 AA

Annual

Pen testing

UK-only

Data hosting

Accreditations

Our security posture.

Independently verified. Annually renewed. The complete picture of how we protect your patients’ data.

In house, continuous

Continuous Penetration Testing

Our own AI-assisted security suite runs seventeen test modules mapped to the OWASP Top 10 against isolated replicas of our production stack, using the same techniques real attackers use.

Why it matters

Findings are triaged by CVSS severity and fixed by the developers who wrote the code. The full report is available on request.

UK Government certified

Cyber Essentials

The UK Government's baseline cyber security certification — firewalls, secure configuration, access controls, malware protection, patch management.

Why it matters

Mandatory for NHS digital suppliers. We meet the government-mandated baseline.

Above NHS standard

Highest UK cyber cert

Cyber Essentials Plus

The independently verified higher tier — accredited assessors actively test our systems, not just review them. The highest UK Government cyber certification available.

Why it matters

Most providers hold standard Cyber Essentials. We hold the independently verified version that exceeds NHS requirements.

NHS mandatory compliance

DSP Toolkit Accredited

Annual NHS Data Security and Protection Toolkit submission, measured against the National Data Guardian's 10 data security standards.

Why it matters

All NHS digital suppliers must achieve Standards Met. We complete this annually.

UK data protection law

GDPR Compliant

Patient data submitted through your website is processed lawfully, stored securely, and handled to strict data minimisation principles under UK GDPR.

Why it matters

Your practice is a data controller. We're a compliant data processor — that's the legal floor.

Information Commissioner's Office

ICO Registered

Registered with the UK's independent data protection regulator. A legal requirement for organisations that process personal data — independently verifiable.

Why it matters

Your practice can verify our registration directly with the ICO at any time.

NHS standards

Built to every NHS design standard.

Compliance isn’t just about security. Every website we build follows the NHS’s own design and content principles.

NHS Frontend Design

Built on the same design system used by NHS.UK itself. Patients experience a familiar interface they already recognise and trust.

Why it matters

Familiar design reduces friction and increases patient engagement.

NHS Content Guide

All content written and structured to NHS Content Guide standards — plain English, jargon-free, accessible to every literacy level.

Why it matters

NHS contractual requirements specify GP website content must meet these standards. Every page does.

NHS GP Website Benchmarking Tool

Every site we deliver is scored and optimised against the NHS's official measurement framework for GP website quality.

Why it matters

NHS England uses this to assess contractual compliance. Our sites score at the top of the framework.

NHS Usability & Accessibility Guide

NHS England's guidance on usable, accessible GP websites — navigation, page hierarchy, patient journeys, accessibility beyond the WCAG baseline.

Why it matters

Compliance isn't enough if patients can't use it. Our sites are designed around how patients actually behave.

Accessibility

WCAG 2.2 AA — the latest standard.

The current legal standard for public sector website accessibility. We build to it from day one.

WCAG 2.2 is the most recent version of the guidelines, introducing new requirements beyond the older 2.1 standard. Most GP website providers still reference 2.1. We build to 2.2 — keeping your practice ahead of the requirement.

Under the Public Sector Bodies Accessibility Regulations 2018, NHS GP practice websites are legally required to meet accessibility standards. Non-compliance puts your practice at risk of regulatory action and NHS contract breach.

Premium and Ultimate customers receive annual accessibility audits — independent verification that your site remains fully compliant as your content evolves.

Accessibility standard

WCAG 2.2 AA

  • Built to it from day one — not retrofitted
  • Independently audited annually (Premium & Ultimate)
  • Most providers still reference the older 2.1 standard

Infrastructure

Security in every layer.

Accreditations are the proof. Here’s how the platform is actually built and run.

Secure UK hosting

All websites are hosted exclusively on UK-based servers — patient data never leaves the United Kingdom. Enterprise-grade infrastructure with 99.9% uptime, redundant systems, and physical server security.

SSL encryption on every site

Every website includes a fully validated SSL certificate. All data transmitted between patients and your practice is encrypted in transit from day one. No exceptions.

Automated daily backups

Your website data is automatically backed up every day, stored securely and separately from the live environment. Full restoration available quickly in the event of any issue.

Proactive security patching

Our custom-built platform — not WordPress, not open-source — means we control the entire security patch cycle. Patches are applied proactively before vulnerabilities can be exploited.

The vulnerabilities we don’t have.

In 2025 alone, 11,334 new vulnerabilities were found in the WordPress ecosystem, nine in ten of them in plugins. Every one is somebody’s emergency. None of them are ours, because no Tree View Designs website has ever run WordPress, a plugin, or a shared theme.

Why we’ve never used WordPress

WordPress-ecosystem vulnerabilities, 2025

0

that apply to our platform

Source: Patchstack, State of WordPress Security 2026.

Continuity

Who actually writes your code?

This is not an argument against AI. We use it, and we are building it into our next-generation CMS, because we choose to, not because we need it. It is an argument about what happens if it is taken away.

If AI tools were restricted or withdrawn tomorrow:

A provider built on AI

  • No specialist developers of its own
  • No way to keep building, fixing or supporting the websites it has already sold
  • No one left who understands how your website was actually built
  • Your practice is the one hunting for a new supplier

Tree View Designs

  • Senior developers in house, building this platform since 2009
  • Every line written, reviewed and owned by them, never shipped unreviewed
  • The people who built your website are the people who maintain it
  • Your website, hosting, patching and support carry on unchanged

That risk never stays with your provider. It becomes yours, and practices already know what that costs, because many are living through it right now. Sixteen years, three generations of our own platform, and the same developers who built all of it. That is the difference worth asking about.

Why it matters

Why our compliance level matters.

GP practices are data controllers. Choosing a website provider isn’t just a design decision — it’s a governance one.

GP practices are data controllers under UK GDPR. Every system you use to collect, store, or process patient data — including your website — must be operated by a compliant data processor.

Choosing a website provider isn’t just a design decision. It’s a governance decision. If your provider suffers a data breach or fails an accessibility audit, your practice faces ICO scrutiny, potential fines, and reputational damage alongside them.

Our accreditations are not marketing. They are independently verified, annually renewed proof that your digital front door is protected to the highest standards available in the UK.

Feature Tree View Designs Typical provider
Feature Tree View Designs Typical provider
In-House Pen Testing Continuous Rarely
Cyber Essentials Plus Certified Basic only
DSP Toolkit Annual Not always
GDPR Compliance Full Partial
ICO Registered Verified Not always
UK-only hosting Always No
Custom-built platform Full control WordPress/open source
WCAG 2.2 AA All sites 2.1 only
NHS Benchmarking Tool Every site Rarely tested
Annual accessibility audit Premium+ No

FAQ

Security and compliance, answered.

What happens if there is a data breach?

We have documented incident response procedures aligned with NHS and ICO requirements. In the event of any confirmed breach involving patient data, we notify your practice immediately, support your ICO reporting obligations, and take immediate remediation steps. Our continuous penetration testing and proactive patching are specifically designed to prevent breaches before they occur.

Is patient data submitted through our website stored securely?

Yes. All data submitted through forms and SmartForms is encrypted in transit and stored on secure UK-based servers, accessible only to authorised staff. We operate in full compliance with UK GDPR and the NHS DSP Toolkit requirements for data storage and processing.

How do you verify your accreditations?

Our Cyber Essentials Plus certification is independently verified by an accredited assessor and renewed annually, and our NHS Data Security and Protection Toolkit submission is published publicly, so any practice can look us up and see our status for themselves. Penetration testing is run in house by our own security team, using our own AI-assisted suite against isolated replicas of our production stack. We do it that way because it lets us test continuously rather than once a year, and at a fraction of what an external engagement costs, not because we depend on it: if AI tooling were ever restricted, we would simply commission an external firm and carry on. We will send you the full report, including anything it found and what we did about it.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessed certification against five core security controls. Cyber Essentials Plus requires independent, hands-on technical verification by an accredited assessor — our systems are actively tested, not just reviewed. Cyber Essentials Plus is the higher, independently verified standard and exceeds what the NHS DSP Toolkit requires. Most GP website providers hold only the basic certification.

What does WCAG 2.2 AA mean for our practice?

WCAG 2.2 AA is the current legal standard for public sector website accessibility in the UK. Under the Public Sector Bodies Accessibility Regulations 2018, NHS GP practice websites are legally required to meet this standard. Building to WCAG 2.2 AA — the latest version — means your website is not only legally compliant but accessible to patients with disabilities, visual impairments, and cognitive difficulties. We build to 2.2; many providers still only meet the older 2.1 standard.

How does your security approach protect our NHS contract compliance?

GP practices must ensure their digital suppliers meet NHS security and accessibility requirements. By choosing Tree View Designs, your website supplier holds Cyber Essentials Plus, DSP Toolkit accreditation, GDPR compliance and ICO registration, runs continuous in-house penetration testing, and builds to WCAG 2.2 AA and all NHS design standards, meeting or exceeding every security and compliance requirement relevant to your NHS contract.

Get in touch

Questions about our security or compliance?

Tell us about your practice. We’re happy to discuss our accreditations, infrastructure, and data protection practices in detail — no jargon, just straight answers.