Security and compliance

Security designed into every service.

Govform helps organisations create and operate secure digital services without building the underlying infrastructure themselves. Encryption, access control, isolated environments, audit trails and UK-hosted data processing are built into the platform from the start.

  • ISO 27001:2022 certified
  • Cyber Essentials Plus
  • UK-hosted infrastructure
  • Regular penetration testing
Independent assurance

Security your organisation can verify.

Our policies, processes and technical controls are independently assessed and regularly reviewed, helping security and procurement teams evaluate Govform with confidence.

ISO 27001:2022

Our information security management system covers the design, development, hosting and support of the Govform platform. It is independently audited as part of an ongoing certification programme.

Cyber Essentials Plus

Our technical security controls are independently tested against the UK Government-backed Cyber Essentials Plus standard.

ISO 9001:2015

Our quality management system covers platform development, customer support and service delivery, helping us maintain consistent standards across the organisation.

Independent penetration testing

The Govform platform undergoes regular independent penetration testing. Findings are reviewed, prioritised and managed through our security improvement process.

Public-sector procurement

Govform is available through established Crown Commercial Service procurement routes, including G-Cloud, helping public-sector organisations buy through recognised frameworks.

Data protection

Protected in transit, at rest and throughout the service journey.

Govform uses established encryption standards to protect service designs, submissions, uploaded files and platform communications.

Encryption in transit

TLS 1.2 or higher protects communication between users, deployed services, the Govform builder and connected systems. This includes submissions, file uploads, builder sessions and API requests.

Encryption at rest

Submission data, uploaded files and service configurations are protected using AES-256 encryption within Govform’s UK-hosted infrastructure.

Managed encryption keys

Encryption keys are managed through AWS Key Management Service, with controlled access and automatic key rotation.

Secure API connections

Outbound API actions support configurable authentication, secure headers and mutual TLS using client certificates.

Custom-domain security

Services hosted on your organisation’s domain can use managed SSL certificates, or a certificate supplied by your organisation.

Secure file handling

Accept supporting evidence safely.

File-upload controls help protect your service and give you control over the files users can submit.

  • Uploaded files are checked through virus-scanning controls.
  • File types and maximum sizes can be restricted at platform level.
  • Optional face blurring can help protect identities in submitted images.
  • Files can be retained within Govform or routed to approved external storage.
  • Supported destinations include AWS S3, Google Cloud Storage and Azure Blob Storage.
Identity and access

Give people only the access they need.

Role-based permissions protect the Govform builder and operational service data. Access can be configured for different teams, organisational units and service responsibilities.

Five builder access levels

Admin

Manage the library, users, services and security settings, including MFA enforcement.

Live Data

Access production submission data and operational analytics without changing service designs.

Designer + Analytics

Create and update services while viewing service-performance information.

Read-only

Review service designs without permission to make changes.

QA Tester

Access services deployed to the QA environment for testing and acceptance.

Permissions are assigned at library level, allowing the same person to hold different roles across different organisational areas.

Authentication and service access

Choose the sign-in and access model appropriate for each service and its users.

  • Anonymous access for open public services
  • Passwordless email sign-in
  • OIDC/OAuth 2.0 identity providers, including Microsoft Entra ID
  • AWS Cognito with multi-factor authentication
  • Configurable inactivity timeouts and user warnings
  • Save-and-return options
  • Group-based submission sharing
  • Read-only access for review and audit scenarios

Multi-factor authentication

Administrators can enforce multi-factor authentication across a library, adding a second layer of protection for builder and live-data access.

Secrets and integrations

Keep production credentials out of service designs.

API keys, credentials and configuration values are managed separately from the service content your teams design.

Environment-specific configuration

Maintain separate properties and secrets for Prototype, QA and Production, so test services do not need access to production credentials.

Restricted access

Access to sensitive configuration is controlled through user roles. Secret values are not displayed in shared prototypes or within the user-facing service journey.

Scoped API access

Dedicated Govform API keys can provide controlled programmatic access for approved external tools and deployment processes without exposing individual builder credentials.

Environment isolation

Test changes without touching live services or data.

Every service uses separate Prototype, QA and Production environments, each with its own data, configuration and integration settings.

Prototype

Build and preview changes as they are made. Prototype data is kept separate from QA and Production, and shareable preview links can be used for research and stakeholder feedback.

QA

Test complete service journeys, authentication and integrations against non-production systems. QA has separate data, API endpoints, credentials and analytics.

Production

Operate the approved public-facing or staff-facing service using dedicated production settings, secrets and integrations.

Controlled promotion

Changes move between environments through an explicit release action rather than being published automatically. Promotion activity is recorded so teams can see what changed, who released it and when.

Private infrastructure options

Dedicated infrastructure can be discussed for organisations with additional isolation, sovereignty or hosting requirements.

Audit and monitoring

See what happened, and respond when something goes wrong.

Govform records service activity and provides the operational information teams need to review decisions, investigate issues and improve performance.

Event-level audit logs

Review recorded events such as submissions, validation outcomes, workflow actions, errors and review decisions, with relevant timestamps and user identifiers.

Review history

For multi-stage review services, Govform preserves decisions, comments, returns to applicants, cancellations and withdrawals across the review journey.

Complete revision history

Changes to pages, content, rules and action configurations are tracked across users. Teams can review earlier versions and revert when necessary.

Production failure alerts

Configure alerts for failed production actions, including API requests and email notifications, so integration issues can be investigated quickly.

Submission management

Authorised users can search and filter submissions, inspect individual records, follow their review status and export permitted data.

Server-side analytics

Monitor completion rates, drop-off points, validation failures, journey times and device information using server-side service analytics, without placing analytics cookies on users’ devices.

Data residency and privacy

UK-hosted platform data, with clear organisational control.

Govform’s managed platform infrastructure, databases and backups are hosted in AWS UK regions. Your organisation controls what information is collected, who can access it and which external systems receive it.

UK-hosted infrastructure

Govform’s core compute, storage, database and managed backup infrastructure is located in UK AWS regions.

UK-resident backups

Managed platform backups remain within UK data centres. Enhanced support arrangements can include a one-hour Recovery Point Objective and a 24-hour Recovery Time Objective.

GDPR support

Govform acts as a data processor when processing submission data on behalf of your organisation as data controller. Encryption, permissions, audit trails and data-management tools help support your organisation’s GDPR obligations.

Data portability

Authorised users can export submission information or route it to approved organisational systems through APIs, SharePoint or supported cloud-storage integrations.

Customer-controlled integrations

Your organisation decides which external systems a service connects to. Where an integration sends information to a third party, its destination and processing arrangements remain under your organisation’s control.

Questions

Security and compliance FAQ

Where is Govform data hosted?

Govform’s managed platform infrastructure, databases and backups are hosted in AWS UK regions. Customer-configured integrations may send information to external systems selected by the customer.

Is data encrypted?

Yes. TLS 1.2 or higher protects data in transit, and AES-256 encryption protects submission data, uploaded files and service configurations at rest.

Can we use our existing identity provider?

Yes. Deployed services can connect to compatible OIDC/OAuth 2.0 identity providers, including Microsoft Entra ID. AWS Cognito with MFA and passwordless email sign-in are also supported.

Are test and production environments separated?

Yes. Prototype, QA and Production have separate data, configuration, credentials and integration endpoints. Changes are promoted through controlled, recorded release actions.

Can Govform administrators see all live data?

Access to production data is controlled through defined user roles. Only authorised users with the appropriate Live Data or administrative permissions can access submission information.

Does Govform support multi-factor authentication?

Yes. Multi-factor authentication can be enforced for users accessing a Govform library. Service-user authentication can also support MFA through compatible identity providers and AWS Cognito.

How are uploaded files protected?

Govform supports file-type and size restrictions, virus-scanning controls and optional face blurring. Files can be stored within Govform or routed to an approved customer-controlled storage destination.

Does Govform use analytics cookies on deployed services?

Govform’s service analytics are collected server-side, so Govform analytics do not require analytics cookies to be placed on the user’s device. Any additional third-party technologies introduced by the customer should be assessed separately.

Does Govform undergo penetration testing?

Yes. The platform undergoes regular independent penetration testing. Supporting information can be made available to eligible customers and procurement teams on request.

Can we review Govform’s security documentation?

Yes. Contact our team to request relevant certificates, security documentation and data-protection information for your technical, procurement or information-governance review.

Security review

Review Govform with your security team.

Talk to us about your organisation’s security, hosting and compliance requirements, or request the documentation needed for your technical and procurement review.