Last reviewed: August 2026
Everything you need for your security review
Vitrue Health processes sensitive musculoskeletal and workplace health data on behalf of more than 100,000 employees. This Trust Centre brings together our certifications, policies and independent audit reports, so your team can find what it needs quickly.
Most requested
Restricted- ISO 27001:2022Information security
- Cyber EssentialsBritish Assessment Bureau
- UK & EU GDPRAligned policies & DPA
- AWS infrastructureSOC 2 & SOC 3 reports
- Annual penetration testIndependently assessed
Document access
How document access works
- 1
Browse the library
Certifications and selected policy statements are available to view straight away. Other documents are marked Restricted and can be requested.
- 2
Request a document
Tell us a little about yourself, including your name, work email, organisation and whether you're an existing customer or considering Vitrue Health.
- 3
We'll send it by email
We'll review your request and send the relevant documents directly to you, usually within one UK business day.
Document library
Certifications, policies and audit reports
Our certifications and audit reports are independently assessed and reviewed. Public documents open straight away; restricted ones are sent on request.
Security
What our ISO 27001 certification covers
Here's a summary of the key areas covered by our security policies. Full policy documents are available on request from the library above.
Hundredsof companies around the world
trust these controls with their musculoskeletal and workplace health data.
Access control
Role-based access, least privilege and regular access reviews across systems handling customer data.
Encryption
Data is encrypted in transit and at rest, in line with our Cryptography Policy.
Secure development
Change management and secure development controls are applied throughout the development of VIDA.
Incident response
A documented Incident Management Procedure, with clear escalation paths and response timelines.
Business continuity
Business Continuity, ICT Continuity and Emergency Preparedness plans, with annual testing.
Vendor risk
Our Supplier Security Policy and Transfer Impact Assessments help us assess and manage sub-processor risk.
CSR & ethics
Corporate and social responsibility
This section covers our policies on ethics, the environment and our people. Some are available to view openly, while others can be requested from the library above.
Modern slavery
Our approach to identifying and preventing modern slavery and human trafficking across our business and supply chain.
PublicWhistleblowing
How employees and contractors can raise concerns about wrongdoing confidentially and without fear of reprisal.
Anti-bribery & corruption
Our policy on bribery and corruption, including the controls we use to prevent it.
Conflict of interest
How we identify, declare and manage conflicts of interest across the business.
Environmental & sustainability
Our approach to reducing environmental impact and supporting sustainable working practices.
PublicHealth & safety
Our approach to maintaining a safe working environment for employees, contractors and visitors.
Privacy & data protection
The third parties that process data for VIDA
The sub-processors that process data on our behalf as part of the VIDA product.
| Sub-processor | Region of processing | Purpose |
|---|---|---|
| AWS Europe (Amazon Web Services EMEA SARL) | UK by default; configurable to other regions on request | Back-end and data storage infrastructure for VIDA |
| SendGrid | Herndon, VA; Las Vegas, NV; Chicago, IL (US) | Email delivery. Only name and email address are processed. |
| Sentry | Iowa, US (Google Cloud) | Incident logging. Identifiable information is removed before transfer. |
| Hotjar | AWS Ireland | Product analytics. Identifiable information is removed before transfer. |
| WorkOS | US | User provisioning and SSO, only for clients who enable this. |
| OpenAI | US | AI-enabled features, only for clients who enable this. |
| Microsoft Azure | UK by default; configurable to other regions on request | Additional cloud infrastructure for VIDA |
Source: our current sub-processor contract list.
Why are some documents restricted?
Certifications and selected policy statements are published openly. Documents containing more detailed operational, audit or architectural information are restricted so that we can verify who is requesting them and keep a record of what has been shared.
How long does a request take?
Requests are usually reviewed within one UK business day. If you're working to a specific deadline, for example completing a security questionnaire, let us know in your request and we'll do our best to accommodate it.
Can you complete a security questionnaire directly?
Yes. Include a link to, or copy of, the questionnaire with your request and our team will complete it directly, rather than supplying source documents alone.
Where is Vitrue Health's infrastructure hosted?
Our infrastructure is hosted on AWS. AWS's SOC 2 and SOC 3 reports covering that infrastructure are listed in the document library above and can be requested in the same way.
Who should I contact if I can't find what I need?
Email security@vitruehealth.com and we'll get back to you directly.
Can't find what you're looking for?
If you can't find what you need, contact us and we'll help.