Skip to main content

Security, with accountability

Your patients’ data.
Our responsibility.

NHS website security is more than a badge. It is the people, processes and protection behind your practice website, every day.

Explore our credentials

Protection, layer by layer

Cyber Essentials

Government-backed certification

UK hosting

Secure infrastructure

Test & improve

Continuous in-house testing

Real people

Clear responsibility

01 / Credentials you can check

Trust starts with
clear evidence.

Certification, assessment and registration each tell you something different. Here is what they mean for your practice.

Government-backed certification

Cyber Essentials

Certified · Plus renewal in progress

We hold Cyber Essentials certification under the UK Government-backed scheme. We have also held Cyber Essentials Plus, the higher level, which adds hands-on technical verification of the same core controls, and our renewal assessment is in progress.

Built on the five Cyber Essentials controls

Firewalls, secure configuration, access control, malware protection and security updates.

NHS data security self-assessment

Data Security and Protection Toolkit

2025–26 · Standards met

Our NHS DSP Toolkit submission assesses our data security against the National Data Guardian’s ten standards. Our 2025–26 assessment was published on 30 June 2026.

View DSPT record · 8KK67 (opens in a new tab)

Data protection registration

ICO registered

Registration · ZA655395

We are registered with the Information Commissioner’s Office. Registration is a public record, rather than a certification of GDPR compliance.

View ICO registration ZA655395 (opens in a new tab)

02 / Protection in practice

The work behind the reassurance.

From the first connection to recovery planning, security is an ongoing part of running your website.

Protect the data

UK-based hosting and SSL certificates protect the connection between your patients and your website. Form submissions are encrypted in transit.

Control access

Access to patient submissions is restricted to authorised staff. Your practice also has a part to play in managing users and keeping account details safe.

Test and improve

Continuous in-house penetration testing helps us find weaknesses. Findings are assessed using CVSS severity ratings to inform remediation priorities.

Back up and recover

Daily automated backups are stored separately from the live website. Ask us about the retention and recovery arrangements for your service.

Look closer / Application security

Continuous Penetration Testing

Ask about the latest report →

Our team runs an AI-assisted suite with seventeen test modules mapped to the OWASP Top 10 against isolated replicas of our production stack. Testing is continuous, with reporting brought together annually.

This is our own in-house programme, distinct from our Cyber Essentials Plus assessment. Ask us about the test scope, findings and remediation recorded in the latest report.

03 / Designed for NHS patients

Safe to use.
Easy to use.

Security, accessibility and good NHS website design work together. They are different disciplines, with the same purpose: helping patients.

Accessibility by design

WCAG 2.2 AA accessibility

We build towards WCAG 2.2 AA and help practices maintain accessible content. Accessibility needs ongoing attention as pages and documents change. Premium includes annual accessibility audits and active accessibility compliance support.

NHS Frontend Design

Familiar components and patterns help patients recognise how to use your website.

NHS Content Guide

Clear language and useful structure make information easier to understand and act on.

NHS England GP website benchmarking

A practical framework for reviewing the information and journeys patients need from a GP website.

NHS usability and accessibility guidance

Patient journeys, navigation and accessible interactions inform the way we design and review websites.

04 / People who take responsibility

Know who is behind
your website.

We have been building GP practice websites since 2009. Our team understands the platform and takes responsibility for its development, maintenance and support.

Paul Chapman

Managing Director

Security & governance

Data Protection Lead

Sebastian Sulinski

Chief Technical Officer

Security & governance

Senior Information Risk Owner (SIRO)

Tamsin Rudolph

Sales & Marketing Manager

Security & governance

Information Governance Lead

A bespoke platform, with ongoing care

Our CMS is purpose-built for NHS practices, rather than assembled from WordPress plugins. It uses established open-source foundations, alongside our own code. Every part still needs maintenance, security updates and testing.

Why we build our own platform →

AI helps. Our expertise remains.

We use AI because we choose to, not because we need it to keep the service running. Our developers remain responsible for the code and its review. If AI-assisted security tooling became unavailable, we could commission external testing and continue maintaining your website.

Our next-generation AI-driven CMS →

05 / Your supplier checks, made easier

Ask us to show
our working.

Reviewing UK GDPR responsibilities or completing a supplier assessment? We can help you get the right evidence for the services you use.

Request security information →
Certification & assessment
Current certificate, its scope and the relevant DSP Toolkit submission.
Testing & remediation
Latest penetration testing report, test scope and how findings were addressed.
Data protection & access
Service-specific processing agreement, subprocessors, retention, deletion and access arrangements.
Backups & continuity
Backup retention, recovery arrangements and applicable availability targets.

Straight answers

Your security questions.

What happens if there is a data breach?

We have documented incident response procedures. If an incident affects your practice, we work with you to contain it, understand the impact and support your reporting obligations. Ask us for the incident notification and escalation arrangements that apply to your service.

Is patient data submitted through our website stored securely?

Data submitted through our forms and SmartForms is encrypted in transit and stored on secure UK-based servers, accessible only to authorised staff. The information collected, retention periods and processing arrangements depend on the service your practice uses. We can explain these and provide the relevant data processing agreement before you make a decision.

How do you verify your accreditations?

Ask us for our current Cyber Essentials certificate and its scope, our NHS Data Security and Protection Toolkit submission, and our ICO registration details. You can also search the official registers linked on this page. These are different forms of assurance: certification, a self-assessment and registration respectively. Our penetration testing is run in house, and reports are available on request.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessed certification against five core security controls. Cyber Essentials Plus adds independent, hands-on technical verification of those controls. It is the higher level within the Cyber Essentials scheme; the certificate scope identifies what has been assessed. We hold Cyber Essentials, and our Cyber Essentials Plus certification is currently being renewed.

What does WCAG 2.2 AA mean for our practice?

WCAG 2.2 AA is the accessibility standard we build towards, covering how patients perceive, navigate and use your website. Accessibility also depends on the content and documents added over time. We help practices maintain accessible websites and publish an accessibility statement. Ask us about the accessibility review and support included in your package.

How does your security approach protect our NHS contract compliance?

Our security controls, NHS design approach and accessibility work support your practice in meeting its responsibilities. Compliance also depends on your own processes, content and how services are used. We can provide evidence for your supplier assessment and explain which responsibilities sit with us and which remain with your practice.

Can we review data retention, suppliers and recovery arrangements?

Yes. Ask for the arrangements relevant to your website and any forms or SmartForms you use, including retention and deletion, subprocessors, access controls, backups and recovery. We will help you review the service-specific details rather than assume one policy covers every type of information.

Here to help

A question, or a security concern?

Contact our team and tell us what you need. To report a suspected security issue, describe the affected page or service without including patient information or passwords.