Security & trust

Hosting & Risk Profile

UK cloud hosting, dedicated deployment options and practical control over where your service data goes.

Managed hosting in the UK

Run your services on Govform’s managed cloud, hosted on Amazon Web Services (AWS) in the UK. We manage the application infrastructure, platform updates, monitoring and backups, so your team can focus on designing and operating services. Production application hosting and Govform’s application object storage are located in the UK.

  • Encrypted file storage with access controls protects information held by the platform.
  • Secure HTTPS connections protect people as they use your services.
  • Hosting, product support and platform maintenance are included under the applicable service plan.
Explore managed support

Choose the hosting model that fits

Start with managed Cloud or discuss a dedicated environment for a larger service estate. Your organisation’s security boundaries, procurement requirements and operating responsibilities help determine the right arrangement.

Managed Cloud

Govform runs the shared cloud platform for you. Choose Cloud plans for individual services or Cloud Estate for a broader portfolio, with managed hosting and platform updates.

Compare Cloud plans

Central government

Central government services use an Enhanced tier with additional security hardening, governance and assurance support, and hosting in a separate government cloud environment.

Explore government hosting

Private Cloud

For estates of 100 or more services, run the Govform application and data in a dedicated environment within your own AWS, Google Cloud or Azure accounts. Agree deployment and support responsibilities with our team.

Explore Private Cloud

Built to keep services running

The managed production infrastructure runs across multiple data centres in the UK. Application instances run on private networks behind a load balancer, and capacity scales automatically with application demand. Platform monitoring helps our team identify operational issues.

  • Production services operate against a 99.9% platform-availability target, subject to the applicable service agreement.
  • Managed backups support recovery of service data and configuration under your plan.
  • Institutional arrangements can include agreed service levels, escalation routes and recovery objectives covering how much data could be lost and how quickly service is restored.
Discuss service levels and recovery

Choose where uploaded files go

Use Govform’s file storage or connect your own SharePoint, AWS S3, Google Cloud Storage or Azure Blob Storage. File storage settings and upload actions let you route evidence and documents to the systems your organisation already manages.

  • Configure destinations separately for QA and Production to keep testing and live operations apart.
  • Set retention for information stored in Govform and manage retention in your connected file stores.
  • Review your full data journey: application hosting, databases, files, backups, identity providers and integrations each form part of your data-location requirements.
Explore storage and integrations

Secure delivery for your users

A global delivery network serves shared static assets, such as scripts and styles, to help services load efficiently. Dynamic application responses are not cached by the delivery network. Your hosting review can cover delivery services alongside application and storage locations.

Explore data protection

Test before you publish

Prototype, QA and Production separate service data and configuration. Test journeys and integrations in QA, use environment-specific secrets and destinations, then deploy approved versions to Production. Library permissions let you control who can publish changes.

Explore the release workflow

More regional choice — planned

UK hosting is available today. Regional compute and data residency options for the EU, Canada and the US are planned. These will give organisations more choice over where their Govform services run. Talk to our team if a specific region is part of your procurement or service requirements.

Discuss regional requirements

Control access to sensitive data

Choose who can design services, deploy changes and work with live submissions. Service authentication and library permissions help you tailor access to the sensitivity of your information. Require MFA for Builder users and connect service journeys to your chosen identity provider.

Explore access controls

Plan your hosting with our team

Bring your hosting requirements into the conversation early. We can help you choose the deployment model and scope the assurance, integration and support work needed for your services.

  • Where your applications, data, files and backups need to be located.
  • Expected demand, service criticality and required availability.
  • Identity, connected systems, retention and recovery requirements.
  • Responsibilities for infrastructure, updates, monitoring and support.
Talk about your hosting requirements
Build with confidence

Secure services start with a conversation.

Talk to our team about your organisation’s security requirements, hosting choices and the services you want to deliver.