Security & Reliability

Security is designed into Motion Health from the ground up. This page explains our certifications, how we protect data, and how we keep the service available.

Motion logomark

Certifications

We are Cyber Essentials Plus certified - the higher, independently audited tier of the UK National Cyber Security Centre (NCSC) scheme, which verifies our protection against common cyber threats through hands-on technical testing.

View our Cyber Essentials and Cyber Essentials Plus certificates.

Encryption

In transit: all data is encrypted using TLS 1.2 or higher.

At rest: database is encrypted using AES-256.

Hosting & infrastructure

Our services are hosted on established cloud infrastructure in UK/EU data centres. Infrastructure is provisioned as code, patched regularly, and isolated using private networking.

Access control

Access to production systems and data follows the principle of least privilege.

Multi-factor authentication is enforced for staff access to critical systems.

Access is reviewed regularly and revoked promptly when no longer required.

Availability & reliability

We monitor our services continuously and design for resilience with automated backups and recovery procedures. Target availability and any service-level commitments are set out in your contract or order form.

Vulnerability management & testing

Dependencies and infrastructure are monitored for known vulnerabilities.

We carry out regular security testing, including independent testing.

Reporting a vulnerability

If you believe you have found a security vulnerability, please contact us at info@motion.org.uk so we can investigate. Please do not publicly disclose the issue until we have had a chance to respond.