Have a security question we haven't answered here? security@vitruehealth.com Back to vitruehealth.com

Last reviewed: August 2026

Everything you need for your security review

Vitrue Health processes sensitive musculoskeletal and workplace health data on behalf of more than 100,000 employees. This Trust Centre brings together our certifications, policies and independent audit reports, so your team can find what it needs quickly.

View document library

Most requested

Restricted
44 documents in the libraryBrowse all
  • ISO 27001:2022Information security
  • Cyber EssentialsBritish Assessment Bureau
  • UK & EU GDPRAligned policies & DPA
  • AWS infrastructureSOC 2 & SOC 3 reports
  • Annual penetration testIndependently assessed

Document access

How document access works

  1. 1

    Browse the library

    Certifications and selected policy statements are available to view straight away. Other documents are marked Restricted and can be requested.

  2. 2

    Request a document

    Tell us a little about yourself, including your name, work email, organisation and whether you're an existing customer or considering Vitrue Health.

  3. 3

    We'll send it by email

    We'll review your request and send the relevant documents directly to you, usually within one UK business day.

Document library

Certifications, policies and audit reports

Our certifications and audit reports are independently assessed and reviewed. Public documents open straight away; restricted ones are sent on request.

Security

What our ISO 27001 certification covers

Here's a summary of the key areas covered by our security policies. Full policy documents are available on request from the library above.

Hundredsof companies around the world

trust these controls with their musculoskeletal and workplace health data.

  • Access control

    Role-based access, least privilege and regular access reviews across systems handling customer data.

  • Encryption

    Data is encrypted in transit and at rest, in line with our Cryptography Policy.

  • Secure development

    Change management and secure development controls are applied throughout the development of VIDA.

  • Incident response

    A documented Incident Management Procedure, with clear escalation paths and response timelines.

  • Business continuity

    Business Continuity, ICT Continuity and Emergency Preparedness plans, with annual testing.

  • Vendor risk

    Our Supplier Security Policy and Transfer Impact Assessments help us assess and manage sub-processor risk.

CSR & ethics

Corporate and social responsibility

This section covers our policies on ethics, the environment and our people. Some are available to view openly, while others can be requested from the library above.

  • Modern slavery

    Our approach to identifying and preventing modern slavery and human trafficking across our business and supply chain.

    Public
  • Whistleblowing

    How employees and contractors can raise concerns about wrongdoing confidentially and without fear of reprisal.

  • Anti-bribery & corruption

    Our policy on bribery and corruption, including the controls we use to prevent it.

  • Conflict of interest

    How we identify, declare and manage conflicts of interest across the business.

  • Environmental & sustainability

    Our approach to reducing environmental impact and supporting sustainable working practices.

    Public
  • Health & safety

    Our approach to maintaining a safe working environment for employees, contractors and visitors.

Privacy & data protection

The third parties that process data for VIDA

The sub-processors that process data on our behalf as part of the VIDA product.

Sub-processorRegion of processingPurpose
AWS Europe (Amazon Web Services EMEA SARL)UK by default; configurable to other regions on requestBack-end and data storage infrastructure for VIDA
SendGridHerndon, VA; Las Vegas, NV; Chicago, IL (US)Email delivery. Only name and email address are processed.
SentryIowa, US (Google Cloud)Incident logging. Identifiable information is removed before transfer.
HotjarAWS IrelandProduct analytics. Identifiable information is removed before transfer.
WorkOSUSUser provisioning and SSO, only for clients who enable this.
OpenAIUSAI-enabled features, only for clients who enable this.
Microsoft AzureUK by default; configurable to other regions on requestAdditional cloud infrastructure for VIDA

Source: our current sub-processor contract list.

FAQ

Frequently asked questions

Can't see your question? Email security@vitruehealth.com.

Why are some documents restricted?

Certifications and selected policy statements are published openly. Documents containing more detailed operational, audit or architectural information are restricted so that we can verify who is requesting them and keep a record of what has been shared.

How long does a request take?

Requests are usually reviewed within one UK business day. If you're working to a specific deadline, for example completing a security questionnaire, let us know in your request and we'll do our best to accommodate it.

Can you complete a security questionnaire directly?

Yes. Include a link to, or copy of, the questionnaire with your request and our team will complete it directly, rather than supplying source documents alone.

Where is Vitrue Health's infrastructure hosted?

Our infrastructure is hosted on AWS. AWS's SOC 2 and SOC 3 reports covering that infrastructure are listed in the document library above and can be requested in the same way.

Who should I contact if I can't find what I need?

Email security@vitruehealth.com and we'll get back to you directly.

Can't find what you're looking for?

If you can't find what you need, contact us and we'll help.