Security and data protection

Security

Trusted by operators, councils, NHS partners and commercial fleets.

Built to stringent security standards, with the administration and access controls that protect your organisation and the people it carries. Everything below is how Road XS works for every customer, not a paid tier.

Built in, not added on

You hold sensitive data. So do we.

We understand the work our customers do, whether that is a community transport charity, a council, a non-emergency patient transport provider or a commercial operator running secure transfers under contract, and the nature of the personal data that comes with it. That demands high standards of security, resilience and data integrity. Road XS arrives pre-configured with controls that meet or exceed what the sector expects, covering how people get in, how data is protected, and how the service stays available.

Cloudflare
Google Cloud
Registered with the Information Commissioner's Office
Beagle Security penetration testing
ISO 27001
1 HR Hourly automated
backups

Road XS runs on Google Cloud infrastructure, independently certified to ISO 27001, ISO 27017, ISO 27018, ISO 27701, SOC 1, SOC 2, SOC 3 and PCI DSS. Google Cloud also holds UK NCSC Cyber Essentials Plus and maps to the NHS (UK) framework.

Our information security management aligns with ISO 27001 controls, penetration testing is carried out independently, and OJE Technology Ltd is registered with the Information Commissioner’s Office. Live service health is published at status.roadxs.com.

Access and accounts

Who gets in, and what they see once they are there

Access is the part most breaches turn on, so it is configured tightly by default. Sign-in can follow your own identity provider through SSO, every user sees only what their role permits, and key actions are logged with a timestamp against the person who took them.

Single sign on (SSO) Two factor authentication (2FA) Role based access (RBAC) Audit trails Session controls
SSO · 2FA

Sign in

Your identity provider, or ours

Access follows your joiner and leaver process.

Single sign on (SSO) Supported
Two factor auth (2FA) Google Authenticator
Leavers removed With your directory
Shared logins None
RBAC · Enforced

Roles

Scoped by role

Four roles, four different views.

Driver Their journeys only
Coordinator Their service
Finance Fees and invoices
Administrator Configuration
Audit · Live

Audit log

Timestamped, and attributed

Evidence for a review, already there.

Journey created, K Bennett 09:04
Driver allocated, checks verified 09:11
Route amended, M Ellis 09:42
Journey closed 11:58
Sessions · Managed

Sessions

Closed when nobody is there

Standards enforced, not suggested.

Password standards Enforced
Inactive sessions Expire automatically
Unattended access Reduced
Password reuse Blocked

Data protection

Encrypted in transit, encrypted at rest

Traffic between your team and Road XS is served exclusively over HTTPS using TLS 1.2 and TLS 1.3, and stored data is encrypted at rest with AES-256. Location data is processed to support journeys in progress and kept only as far as operational need goes.

TLS 1.2 and TLS 1.3 AES-256 at rest HTTPS only Hourly backups Location data
Encrypted · Always

Encryption

Both ends covered

In transit and at rest, as standard.

In transit HTTPS, TLS 1.2 / 1.3
At rest AES-256
Plain HTTP Not served
Latency Minimised by design
Backups · Hourly

Backups

Hourly, then daily

A recent copy, always available.

Mon
Tue
Wed
Thu
Fri
Sat
Sun
Backed up No gap
Location · Scoped

Location

Used, then done with

Operational need, not indefinite storage.

Live location While the journey runs
Route history For efficiency reviews
Pickup and drop-off times Recorded
Indefinite retention None

Infrastructure

A platform that stays up, and turns away what should not get in

Traffic is filtered at the edge before it ever reaches the application, a web application firewall screens what remains, and the infrastructure behind it is redundant and monitored around the clock. Live service health is published.

Cloudflare edge Web application firewall Redundant infrastructure Continuous monitoring 99.9% uptime
Edge · Filtered

Edge

Stopped at the perimeter

Before it reaches the application.

DDoS mitigation At the edge
Malicious requests Blocked
Web application firewall In front of the app
Direct exposure None
Uptime · Live

Availability

Published, not promised

Live status at status.roadxs.com.

99.9% Uptime
Monitoring Around the clock
Status page Public
Silent outages None
Infra · Redundant

Resilience

No single point of failure

Redundant, monitored, alerted.

Redundancy Core paths
Monitoring 24/7
Alerting Automatic

Servers and data centres

Where your data lives

Your data is hosted in secure, professionally managed UK data centres, with London as our primary location. If you operate abroad or have to meet a different data protection regime, other regions are available on request.

UK hosting London primary Other regions on request Physical security Certified facility
Hosting · UK

Regions

London, primary

Other regions where you need them.

LondonPrimaryEurope4 regionsUSA4 regionsSingaporeSydney
London, primary Available on request
Physical · Secured

Facility

Physically protected

Access controlled and monitored 24/7.

Access Controlled and logged
Monitoring 24/7
Fire suppression In place
Power UPS and generators
Certified · Facility

Certification

Assured by third parties

Not a self-assessment.

ISO 27001
SOC 1, 2 and 3
PCI DSS

Compliance and standards

The frameworks we build to

Road XS is designed around UK GDPR and the Data Protection Act 2018, supports the evidence expected under the NHS Data Security and Protection Toolkit, and aligns its information security management with ISO 27001 controls.

UK GDPR Data Protection Act 2018 NHS DSPT ISO 27001 Policies published
UK GDPR · By design

Data protection

Built around the principles

Your obligations, supported properly.

Lawful basis Supported by records
Access controls Role based
Audit trail Timestamped
Paper run sheets Retired
DSPT · Supported

NHS DSPT

Evidence you can submit

For patient transport and NHS work.

Access controls Evidenced
Data handling Documented
Incident process In place
Assurance by assertion No
Policies · Public

Policies

Published, not on request

Read them before you talk to us.

Privacy Published
EULA In the software
Modern slavery Published

Questions we get asked

The security questions people ask

If your procurement or IT team needs something that is not here, ask. You will get a straight answer from someone who knows the platform.

In secure, professionally managed UK data centres, with London as the primary location, on Google Cloud infrastructure. If you operate abroad or have to meet a different data protection regime, Europe, the United States, Singapore and Sydney are available on request.

Yes. SSO lets users sign in through your organisation existing identity provider, so access follows your own joiner and leaver process. Your IT team gives us the details and we configure it. Two factor authentication is available for everyone else, currently through Google Authenticator.

Everything is served over HTTPS using TLS 1.2 and TLS 1.3, so nothing travels in the clear, and stored data is encrypted at rest with AES-256. Plain HTTP is not served at all.

Every hour, as well as daily, so a recent restorable copy is always available. That is standard for every customer rather than an option.

It is processed to support journeys in progress. Route history and pickup and drop-off times are kept so you can compare the route planned with the route taken and review efficiency, and location data is not retained beyond operational need.

Our information security management aligns with ISO 27001 controls, and the Google Cloud infrastructure Road XS runs on is independently certified to ISO 27001, 27017, 27018 and 27701, SOC 1, 2 and 3, and PCI DSS.

Yes. Road XS supports the evidence and controls expected of providers working with NHS and patient transport data. Tell us what your submission needs and we will tell you plainly what we can evidence.

Yes, independently rather than as a self-assessment, and the platform sits behind Cloudflare edge filtering and a web application firewall in front of the application itself.