ISO 27001:2022
Our information security management system covers the design, development, hosting and support of the Govform platform. It is independently audited as part of an ongoing certification programme.
Govform helps organisations create and operate secure digital services without building the underlying infrastructure themselves. Encryption, access control, isolated environments, audit trails and UK-hosted data processing are built into the platform from the start.
Our policies, processes and technical controls are independently assessed and regularly reviewed, helping security and procurement teams evaluate Govform with confidence.
Our information security management system covers the design, development, hosting and support of the Govform platform. It is independently audited as part of an ongoing certification programme.
Our technical security controls are independently tested against the UK Government-backed Cyber Essentials Plus standard.
Our quality management system covers platform development, customer support and service delivery, helping us maintain consistent standards across the organisation.
The Govform platform undergoes regular independent penetration testing. Findings are reviewed, prioritised and managed through our security improvement process.
Govform is available through established Crown Commercial Service procurement routes, including G-Cloud, helping public-sector organisations buy through recognised frameworks.
Govform uses established encryption standards to protect service designs, submissions, uploaded files and platform communications.
TLS 1.2 or higher protects communication between users, deployed services, the Govform builder and connected systems. This includes submissions, file uploads, builder sessions and API requests.
Submission data, uploaded files and service configurations are protected using AES-256 encryption within Govform’s UK-hosted infrastructure.
Encryption keys are managed through AWS Key Management Service, with controlled access and automatic key rotation.
Outbound API actions support configurable authentication, secure headers and mutual TLS using client certificates.
Services hosted on your organisation’s domain can use managed SSL certificates, or a certificate supplied by your organisation.
File-upload controls help protect your service and give you control over the files users can submit.
Role-based permissions protect the Govform builder and operational service data. Access can be configured for different teams, organisational units and service responsibilities.
Manage the library, users, services and security settings, including MFA enforcement.
Access production submission data and operational analytics without changing service designs.
Create and update services while viewing service-performance information.
Review service designs without permission to make changes.
Access services deployed to the QA environment for testing and acceptance.
Permissions are assigned at library level, allowing the same person to hold different roles across different organisational areas.
Choose the sign-in and access model appropriate for each service and its users.
Administrators can enforce multi-factor authentication across a library, adding a second layer of protection for builder and live-data access.
API keys, credentials and configuration values are managed separately from the service content your teams design.
Maintain separate properties and secrets for Prototype, QA and Production, so test services do not need access to production credentials.
Access to sensitive configuration is controlled through user roles. Secret values are not displayed in shared prototypes or within the user-facing service journey.
Dedicated Govform API keys can provide controlled programmatic access for approved external tools and deployment processes without exposing individual builder credentials.
Every service uses separate Prototype, QA and Production environments, each with its own data, configuration and integration settings.
Build and preview changes as they are made. Prototype data is kept separate from QA and Production, and shareable preview links can be used for research and stakeholder feedback.
Test complete service journeys, authentication and integrations against non-production systems. QA has separate data, API endpoints, credentials and analytics.
Operate the approved public-facing or staff-facing service using dedicated production settings, secrets and integrations.
Changes move between environments through an explicit release action rather than being published automatically. Promotion activity is recorded so teams can see what changed, who released it and when.
Dedicated infrastructure can be discussed for organisations with additional isolation, sovereignty or hosting requirements.
Govform records service activity and provides the operational information teams need to review decisions, investigate issues and improve performance.
Review recorded events such as submissions, validation outcomes, workflow actions, errors and review decisions, with relevant timestamps and user identifiers.
For multi-stage review services, Govform preserves decisions, comments, returns to applicants, cancellations and withdrawals across the review journey.
Changes to pages, content, rules and action configurations are tracked across users. Teams can review earlier versions and revert when necessary.
Configure alerts for failed production actions, including API requests and email notifications, so integration issues can be investigated quickly.
Authorised users can search and filter submissions, inspect individual records, follow their review status and export permitted data.
Monitor completion rates, drop-off points, validation failures, journey times and device information using server-side service analytics, without placing analytics cookies on users’ devices.
Govform’s managed platform infrastructure, databases and backups are hosted in AWS UK regions. Your organisation controls what information is collected, who can access it and which external systems receive it.
Govform’s core compute, storage, database and managed backup infrastructure is located in UK AWS regions.
Managed platform backups remain within UK data centres. Enhanced support arrangements can include a one-hour Recovery Point Objective and a 24-hour Recovery Time Objective.
Govform acts as a data processor when processing submission data on behalf of your organisation as data controller. Encryption, permissions, audit trails and data-management tools help support your organisation’s GDPR obligations.
Authorised users can export submission information or route it to approved organisational systems through APIs, SharePoint or supported cloud-storage integrations.
Your organisation decides which external systems a service connects to. Where an integration sends information to a third party, its destination and processing arrangements remain under your organisation’s control.
Govform’s managed platform infrastructure, databases and backups are hosted in AWS UK regions. Customer-configured integrations may send information to external systems selected by the customer.
Yes. TLS 1.2 or higher protects data in transit, and AES-256 encryption protects submission data, uploaded files and service configurations at rest.
Yes. Deployed services can connect to compatible OIDC/OAuth 2.0 identity providers, including Microsoft Entra ID. AWS Cognito with MFA and passwordless email sign-in are also supported.
Yes. Prototype, QA and Production have separate data, configuration, credentials and integration endpoints. Changes are promoted through controlled, recorded release actions.
Access to production data is controlled through defined user roles. Only authorised users with the appropriate Live Data or administrative permissions can access submission information.
Yes. Multi-factor authentication can be enforced for users accessing a Govform library. Service-user authentication can also support MFA through compatible identity providers and AWS Cognito.
Govform supports file-type and size restrictions, virus-scanning controls and optional face blurring. Files can be stored within Govform or routed to an approved customer-controlled storage destination.
Govform’s service analytics are collected server-side, so Govform analytics do not require analytics cookies to be placed on the user’s device. Any additional third-party technologies introduced by the customer should be assessed separately.
Yes. The platform undergoes regular independent penetration testing. Supporting information can be made available to eligible customers and procurement teams on request.
Yes. Contact our team to request relevant certificates, security documentation and data-protection information for your technical, procurement or information-governance review.
Talk to us about your organisation’s security, hosting and compliance requirements, or request the documentation needed for your technical and procurement review.