Everything a procurement questionnaire asks is on this page, in writing, with the honest partials marked as partials. The record below is the live one, not a screenshot.
Booking service
99.98%Last 60 days
No data leaves the region you select at sign-up, including backups. The list of every company that touches it is published and versioned, and you are told thirty days before it changes.
The plain facts
Figures are from the last twelve months and are updated on the first working day of each quarter.
Sites on this plan
United KingdomBramble Health
Bristol
Kingsway Clinic
Leeds
Harbour Practice
Southampton
This is the same document we return to procurement teams. Three answers are partial and they are marked as partial, with what is missing and when it lands.
Is access scoped by role?
YesEvery permission is attached to a role, and a request to widen one is recorded with who approved it and why.
Do you support single sign-on?
YesSAML and OIDC on the Group plan, with SCIM provisioning and de-provisioning.
Is multi-factor authentication enforced?
PartialAvailable on every plan and enforceable per practice. Enforcing it across an entire group from one switch lands in the first quarter.
Is data encrypted at rest and in transit?
YesAES-256 at rest, TLS 1.3 in transit, with keys rotated annually.
Can we choose where data is stored?
YesLondon or Dublin, chosen at sign-up and fixed after it. Backups never leave the region.
Can we export everything?
YesOne click in settings, in a format another system can read, with no ticket and no exit fee.
Do you offer customer-managed encryption keys?
Not yetNot today, and we will say so rather than imply otherwise. It is not on the roadmap for this year.
Is there an immutable audit log?
YesEvery read and write against a member record, kept for six years and exportable in full.
How quickly are incidents disclosed?
YesWithin 24 hours to affected practices, publicly on the status page, with a written post-mortem inside five working days.
Do you penetration test?
PartialAnnual third-party test with the summary available under NDA. Quarterly testing begins this year.
The full questionnaire, the audit summary, our sub-processor list and the standard data processing agreement, in one download. No form and no sales call attached to it.
Questions and answers are published on this page, attributed to the practice that asked unless they would rather not be. If the answer is unflattering it goes up anyway.
Answered within two working days by a named engineer, then published here with your name only if you allow it.
“What happens to our data if we stop paying?”
The account goes read-only for thirty days so you can export everything, then it is deleted and the deletion is confirmed in writing. We never hold data hostage against an invoice.
Ridgeway Family Health
“Has Sirius ever had a breach?”
No breach of member data. We had a two-hour outage in March 2025 caused by our own migration, the post-mortem is on the status page, and nothing was lost.
Northgate Clinics
“Do your engineers see our records?”
Only on a support request, only with a named approver, and every one of those sessions is in your audit log with the reason attached.
Eastgate Health
“Who owns the data we put in?”
You do, in the contract as well as in principle. We are a processor, you are the controller, and the agreement says so in the first clause rather than the fortieth.
A group that asked not to be named
Thirty minutes with the engineer who maintains this page, not an account manager reading from it. Bring your own document and we will go through it line by line.
Who you would speak to
Priya Nandan
Security engineer
Free from 09:30 today
No sales team on the call unless you ask for one.