Security

How MYQER is secured.

This page covers security posture only: infrastructure, encryption, access control, retention, subprocessors and incident handling. For lawful bases, data subject rights and what information MYQER holds, see the Privacy Notice.

Operator THREEVION Ltd
Companies House 16861658
ICO Registration ZC076886
Version v1.0 · May 2026

01Posture in short

MYQER is built on minimum data and controlled access. Only essential emergency information is held. Only the person who entered it can edit it. It surfaces on a scan, read only, for the duration of that scan, and does not persist on the scanning device.

There is no behavioural tracking, no engagement scoring, no profiling, and no automated decision making anywhere in the platform.

Honest statement about certification

THREEVION Ltd itself is not currently ISO 27001 certified. Independent certification is on our roadmap as MYQER scales. What is verifiable today is that the infrastructure MYQER runs on holds ISO/IEC 27001:2022 and SOC 2 Type 2 certifications, and that the controls described on this page are implemented as stated.

02Infrastructure

Application hosting
Certified cloud provider
ISO/IEC 27001:2022 and SOC 2 Type 2. Provider named under DPA.
Database and authentication
Certified cloud provider
ISO/IEC 27001:2022 and SOC 2 Type 2. Provider named under DPA.
Data region
European Union
Data resides within EU data centres. UK adequacy framework applies.
Operating context
United Kingdom
THREEVION Ltd is the UK operator. The ICO is the supervisory authority.

We do not publish the names of our infrastructure providers on this page. Reducing publicly available detail about the stack is a deliberate security measure. Providers are named in full, with their certification evidence, to organisations under a Data Processing Agreement and to reviewers on request.

03Encryption

  • In transit. All data is transmitted over HTTPS using TLS 1.2 or higher. Plain HTTP requests are redirected to HTTPS at the edge.
  • At rest. Database storage is encrypted at rest using AES-256, managed by the hosting provider.
  • Backups. Daily encrypted backups are retained by the hosting provider in line with their certified backup procedures.
  • Secrets. Application secrets and API keys are held in provider managed environment variables, never in source code or publicly accessible storage.

04Access and authentication

Profile owners

Access to the profile management area uses email based magic link authentication. Passwords are not used, so there are no stored password hashes to compromise and no credential reuse risk. Sessions are time limited.

Emergency scan access

A scan reveals only the emergency view, which is read only. It surfaces on the scanning device for the duration of the scan session and does not persist afterwards.

Administrative access

Internal administrative access is restricted to named THREEVION personnel and uses authenticated sessions. Sensitive operations are recorded in an append only audit log. Administrative access does not include the ability to view or export personal health information held in profiles, beyond what is necessary to answer a support request made by the profile owner.

No organisational logins to profile content

Organisations deploying MYQER do not hold accounts that can read or edit profile content. This removes a large part of the credential related attack surface and one of the most common incident vectors in organisational software.

05Retention and deletion

  • Active profiles. Retained for as long as the owner maintains the profile.
  • Deletion requests. Profile data is deleted within thirty days of a verified request, with backups expiring within ninety days under standard rotation.
  • Inactivity. If a profile has not been accessed by its owner for twenty four months, we contact the registered email address before any retention action is taken.
  • Audit logs. Retained for twenty four months for security and integrity purposes, then deleted.
  • Aggregated operational data. Non identifying figures such as total scans per organisation per month may be retained for service operation and readiness reporting.

Full retention terms by deployment are set out in the Privacy Notice.

06Subprocessors

MYQER engages a small number of subprocessors to operate the platform. The functions are set out below. Infrastructure providers are identified by function rather than by name, for the reason given in section 02.

Subprocessor functions, purpose, region and disclosure status
Function Purpose Region Provider
Application hosting Web application and infrastructure EU Named under DPA
Database and authentication Data storage, authentication, file storage EU Named under DPA
Transactional email Invitations and service notifications EU and US Named under DPA
DNS, edge and TLS DNS, edge caching, TLS termination Global Named under DPA

Each subprocessor operates under its own data processing agreement with THREEVION Ltd, and each holds recognised security certifications. Organisations entering a DPA with THREEVION give general written authorisation for the engagement of these subprocessors, on the condition that we give advance notice of any new subprocessor and that the organisation may object on reasonable grounds.

07Breach notification

In the event of a personal data breach affecting an organisation or the people in its deployment, THREEVION Ltd will:

  • Investigate and contain the breach without undue delay.
  • Notify the organisation's designated contact, in writing, within seventy two hours of becoming aware of the breach.
  • Provide the information the organisation needs to discharge its own obligations to the ICO, including the nature of the breach, the categories of data and data subjects affected, likely consequences, and measures taken or proposed.
  • Notify the ICO directly where our own controller role requires it, in accordance with UK GDPR Article 33.
  • Cooperate fully with the organisation's incident response procedures and any subsequent regulatory enquiry.
Subprocessor incidents

If a security incident is reported by one of our subprocessors, we treat it as a potential breach and notify organisations to the same seventy two hour standard, even where THREEVION systems are not directly affected.

08Reporting a vulnerability

If you believe you have found a security vulnerability in MYQER, please report it to hello@myqer.com with "security" in the subject line. We aim to acknowledge within two working days.

Please include enough detail to reproduce the issue. We ask that you do not access, modify or delete data belonging to other people, do not degrade the service, and give us reasonable time to remediate before publishing. We will not pursue action against researchers who report in good faith and follow this.

09Documents on request

Available to organisations, data protection officers and procurement reviewers on request. We typically respond within two working days.

  • Data Protection Impact Assessment, covering data flows, risks and mitigations under UK GDPR Article 35.
  • Data Processing Agreement, draft for review and signature, aligned with Article 28.
  • Named subprocessor list, including infrastructure providers and their certification evidence.
  • Privacy Notice, also published at threevion.com/privacy.html.
  • Sample readiness report, the monthly operational summary organisations receive.
Provider certificates

Where a procurement process requires sight of the actual ISO 27001 or SOC 2 certificates of our infrastructure providers rather than public verification links, we will request a copy from the provider on the organisation's behalf, subject to that provider's confidentiality requirements.

10Contact

If you are reviewing MYQER and need something not covered here, contact us directly. We commit to responding to security and compliance enquiries within two working days.

Security and compliance
Operator
THREEVION Ltd
Registered in England and Wales
Company No. 16861658
ICO Reg. ZC076886
This document
Version 1.0, May 2026
Reviewed every six months, and after any material change.
threevion.com/security.html