
Frequently Asked Questions
Identity & Authentication
Yes, MFA is enforced for all users.
Yes. RBAC is enforced for all roles, including clinicians, social prescribers, commissioners, and Joy admins.
Encryption
Yes, we encrypt all data at rest using AES-256 with periodically rotated encryption keys.
Yes, we encrypt all data in transit using TLS 1.2+.
Backups & Recovery
Yes, all backups are encrypted using AES-256.
Subprocessors & Hosting
Data is hosted in the UK only.
DSPT
8KN75
ZA658349