Trust

The answers your security review wants, published before you ask

Everything a procurement questionnaire asks is on this page, in writing, with the honest partials marked as partials. The record below is the live one, not a screenshot.

Uptime commitment
99.95%
Data residency
London or Dublin
Incident disclosure
Within 24 hours
Deep green gradient backdrop

Booking service

99.98%

Last 60 days

Where your data lives

Your records stay in the country you chose, on infrastructure we can name.

No data leaves the region you select at sign-up, including backups. The list of every company that touches it is published and versioned, and you are told thirty days before it changes.

The plain facts

Hosted in
London and Dublin, your choice
Backups
Hourly, held 35 days, same region
Encryption
TLS 1.3 in transit, AES-256 at rest
Sub-processors
Four, all listed publicly
Uptime, last 12 months
99.98%
Independent audit
Annual, report on request
See the sub-processor list

Figures are from the last twelve months and are updated on the first working day of each quarter.

Deep green gradient backdrop

Sites on this plan

United Kingdom

Bramble Health

Bristol

6 rooms

Kingsway Clinic

Leeds

4 rooms

Harbour Practice

Southampton

3 rooms
13rooms live across three sites
The questionnaire

Answered in full, including where the answer is not yes

This is the same document we return to procurement teams. Three answers are partial and they are marked as partial, with what is missing and when it lands.

Access and identity

Is access scoped by role?

Yes

Every permission is attached to a role, and a request to widen one is recorded with who approved it and why.

Do you support single sign-on?

Yes

SAML and OIDC on the Group plan, with SCIM provisioning and de-provisioning.

Is multi-factor authentication enforced?

Partial

Available on every plan and enforceable per practice. Enforcing it across an entire group from one switch lands in the first quarter.

Data handling

Is data encrypted at rest and in transit?

Yes

AES-256 at rest, TLS 1.3 in transit, with keys rotated annually.

Can we choose where data is stored?

Yes

London or Dublin, chosen at sign-up and fixed after it. Backups never leave the region.

Can we export everything?

Yes

One click in settings, in a format another system can read, with no ticket and no exit fee.

Do you offer customer-managed encryption keys?

Not yet

Not today, and we will say so rather than imply otherwise. It is not on the roadmap for this year.

Operations

Is there an immutable audit log?

Yes

Every read and write against a member record, kept for six years and exportable in full.

How quickly are incidents disclosed?

Yes

Within 24 hours to affected practices, publicly on the status page, with a written post-mortem inside five working days.

Do you penetration test?

Partial

Annual third-party test with the summary available under NDA. Quarterly testing begins this year.

The trust pack

The full questionnaire, the audit summary, our sub-processor list and the standard data processing agreement, in one download. No form and no sales call attached to it.

Still reviewing

Put the questionnaire in front of the person who answers it

Thirty minutes with the engineer who maintains this page, not an account manager reading from it. Bring your own document and we will go through it line by line.

Security enquiries
security@sirius.example
Data protection officer
dpo@sirius.example
Status and incidents
status.sirius.example

Who you would speak to

Portrait of Priya Nandan

Priya Nandan

Security engineer

Free from 09:30 today

Call length30 minutes
Based inBristol, UK
Reviews handled120+ this year
Book the review call

No sales team on the call unless you ask for one.