Security & assurance

What we hold, where it lives, and how it is protected.

Striova holds a record about a child, written by the people who know them. That is about as sensitive as personal data gets, so this page is written to be checked rather than admired.

Last reviewed 22 September 2026.

Cyber Essentials

Cyber Essentials certified

Whole organisation, 22 September 2026 to 22 September 2027. Certificate 6f372ac7-9d96-46ef-874f-c25dcbb4c48a, issued by Axiom Worknest under IASME.

ICO registration
ZC190656
VAT number
GB525574969
Operated by
QuoVira Health Ltd
Registered office
128 City Road, London, United Kingdom, EC1V 2NX
Where the data lives
United Kingdom — London region

What we commit to if something fails

These are objectives — the outer limits we hold ourselves to, not the times we expect. What we last measured is below them.

1 hour

Recovery time objective

The longest we commit to taking to bring the service back after a serious failure, including the application and not only the database.

4 hours

Recovery point objective

The most data we commit to losing in that situation. Point-in-time recovery is in place and was exercised on 24 August 2026, so in practice we expect far less.

Why those are more than aspirations

Recovery plans are common. Recovery plans somebody has actually run are not.

The restore is exercised, not just designed

A full recovery has been run end to end against real infrastructure — restoring the database, bringing it online and verifying the data — rather than existing only as a written procedure. It is repeated every six months.

Two independent daily backups

The managed platform's own daily backup, and a separate encrypted nightly copy that covers anything older than the platform's window.

The database fails over on its own

It runs as a primary with a standby, so a node failure moves to the standby rather than waiting for a restore.

Our assurance position

Each control, and the evidence behind it. The documents themselves are available to schools, trusts and NHS teams on request.

ControlStatusDetail
ICO registrationIn placeZC190656, on the public register.
UK GDPR programmeIn placeData protection impact assessment, record of processing, and a documented position for every processor.
ICO Children's CodeIn placeThe data subject is the child. Defaults, retention and profiling are set against the fifteen standards.
Information security policiesIn placeSecure development, acceptable use, records management and retention — written down and dated.
Incident responseIn placeA written plan, an exercised tabletop, and a 72-hour reporting commitment.
Backup and disaster recoveryIn placeTwo independent daily backups, and a restore that has been run end to end rather than only designed.
Internal security testingIn placeA grey-box test of the web app, API, mobile client and infrastructure in August 2026. Findings fixed and re-tested.
Cyber EssentialsIn placeCertified 22 September 2026 for the whole organisation against profile 3.3 (Danzell), certificate 6f372ac7-9d96-46ef-874f-c25dcbb4c48a, by Axiom Worknest under IASME. Recertification due 22 September 2027.
Medical device statusIn placeStriova is self-assessed as not a medical device under UK MDR 2002, and the MHRA raised no concerns when told how it works.

Controls in the code, not in a policy binder

The record stays in the UK

Application, database and file storage are all in London, checked against the hosting provider's own API rather than taken from a brochure. Error monitoring uses the European region.

Uploads are read, not trusted

A file a parent uploads is read from its actual bytes rather than trusted to be whatever the sending device says it is, and anything that is not a real image is refused. Anything that is not an image or a PDF downloads rather than opens.

Encryption keys are not in the backups

The two keys protecting the most sensitive columns are held separately by design, so a copy of the database on its own does not reveal them.

Staff access is logged, and needs a second factor

Two-factor authentication is required for staff accounts in production, and administrative views of a family's material are written to an append-only audit log.

Dependencies are watched and patched

Automated alerting on known vulnerabilities in the software we depend on, with a written log of what was found and what was done about it.

Releases only ship checked code

Type checking, linting and the test suite all run before anything is released, and a release is blocked if any of them fail.

Reporting something, or asking for evidence

Found a security problem?

Email [email protected] with SECURITY in the subject line. Machine-readable details are at /.well-known/security.txt. We will not pursue anyone who reports a genuine issue to us in good faith.

Schools, trusts and NHS teams

The documents behind this page — impact assessment, record of processing, retention schedule, incident plan and supplier register — are available for due diligence. Ask through our contact page. A personal data breach affecting UK individuals is reported to the ICO within 72 hours of us becoming aware.

Security & assurance — Striova