Prova Risk
PROVA Risk is a UK-developed compliance and risk management platform built to help organisations meet their statutory duties under the Terrorism (Protection of Premises) Act 2025 (aka Martyn's Law). The system provides a structured Reasonably Practicable Test that determines proportionate public protection procedures and measures for any qualifying premises.
Features
- Cloud‑based platform accessible via standard web browsers.
- Secure user authentication with role‑based access controls.
- Legislation aligned, structured Reasonably Practicable Test and planning templates.
- Centralised document and plan management for risk and security documentation.
- Multi‑site and multi‑organisation support for complex estates.
- Version‑controlled plans and policy documentation with clear change history.
- Built‑in digital video guidance and contextual tooltips to support users.
- Exportable reports in PDF and CSV formats.
- Configurable user permissions and organisational hierarchies.
- Audit trails for changes, updates, and user activity.
Benefits
- Enable compliance with legislation through simple, quick, automated work flows.
- Standardise risk management across sites and teams.
- Enable consistent planning without specialist risk expertise.
- Support governance with clear, auditable risk evidence.
- Simplify collaboration on risk plans across organisations.
- Accelerate onboarding with guided, intuitive workflows.
- Maintain continuity with up‑to‑date, accessible plans.
- Avoid vendor lock‑in with standard data exports.
- Scale risk management consistently as organisations grow.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 2 5 2 4 3 6 1 8 5 4 2 9 7 9
Contact
PROVA RISK LTD.
Chris Hotchkiss
Telephone: +447984522288
Email: info@provarisk.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Public Order and Safety
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- N/A
- System requirements
-
- A supported web browser (e.g. Chrome, Edge, Firefox, or Safari).
- A stable internet connection.
- Device with a screen resolution of at least 1280×768.
- Standard corporate security controls such as endpoint protection.
User support
- Email or online ticketing support
- Yes
- Support response times
-
For incidents and support requests raised via the defined support channels:
• P1 - Critical (service unavailable or severely degraded for all users). Target initial response: within 2 business hours.
• P2 - High (major functionality impaired, significant impact on critical users). Target initial response: within 4 hours during UK business hours.
• P3 - Medium (degraded functionality, workarounds available). Target initial response: by next business day.
• P4 - Low (how‑to questions, minor issues, enhancement requests). Target initial response: within 2 business days. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- The service includes web based chat functionality delivered using standard web technologies and third party components. Accessibility has been addressed through standards based testing aligned to WCAG 2.2 AA, focused on configuration and validation rather than bespoke development. Testing has confirmed keyboard only operability, predictable focus order, visible focus indicators, and no reliance on pointer only interactions. Screen reader checks using NVDA and VoiceOver have been performed to validate announcement of controls, message content, and notifications using appropriate semantic structure. Where chat functionality relies on third party components, supplier accessibility documentation and conformance statements are reviewed as part of assurance. Direct testing with assistive technology users is planned as usage scales and feedback is gathered.
- Onsite support
- Yes, at extra cost
- Support levels
-
Prova Risk provide proportionate, service-appropriate support aligned to the size, criticality, and deployment context of the service.
Standard Support (included).
Standard support is included as part of the core service subscription. This covers access to support via email or service support workflows, incident reporting, and general service queries. Issues are triaged based on impact and urgency, with priority given to service-affecting or security-related matters.
Enhanced Support (optional).
Enhanced support can be provided by agreement for clients requiring defined response times, additional assurance, or closer operational engagement. This may include faster response targets, scheduled service check-ins, and enhanced incident communication. Pricing for enhanced support is agreed contractually and reflects scope and service level requirements rather than fixed tiers.
Technical Account Management.
For standard support, a named technical account manager is not provided. For enhanced support arrangements, a named technical point of contact can be assigned to coordinate support, changes, and escalation, acting as the interface between the client and the delivery team. This model ensures support remains responsive, transparent, and sustainable while avoiding unnecessary cost for clients who do not require enhanced service levels. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Prova Risk support users to start using the service quickly and confidently through a proportionate onboarding approach, tailored to organisational size and deployment context.
For larger or multi-site organisations, a proportionate onboarding process is provided, with a named Key Account Manager assigned to coordinate initial setup, rollout, and early adoption.
This includes remote onboarding sessions for administrators and key users, support with configuration, and guidance on embedding the service into existing operational practices.
For all users, onboarding is reinforced through in-application guidance, ensuring users receive support at the point of need.
This includes built-in digital video tool tips embedded within the platform, providing short, contextual guidance to improve usability and reduce training overhead.
A written support and usage wiki is also provided, offering clear, accessible guidance on core functionality, common tasks, and good practice.
This resource is available on demand and maintained in line with service updates.
Onsite training is not typically required due to the self-guided nature of the platform, but can be discussed where operationally necessary.
This layered approach ensures rapid adoption, consistent use, and scalable onboarding across organisations of different sizes and levels of complexity. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Users retain ownership of their data and can extract it in a structured and usable format when the contract ends.
At the end of the contract, users are able to download their data directly from the service without the need for proprietary tools or specialist support.
The following data extraction options are provided:
• Plans and policy documentation can be downloaded in PDF format, ensuring content remains accessible and readable outside the platform.
• Training and exercise records can be exported in CSV format, enabling reuse, analysis, and import into other systems.
• Site event chronology and activity records can be downloaded in PDF format to provide a clear, time-ordered record of events and actions.
Where required, users are provided with guidance on how to complete data extraction prior to contract expiry.
Following confirmation that data extraction has been completed, data held within the service is securely deleted in line with contractual obligations and data protection requirements.
This approach ensures data portability, continuity of operations, and compliance with UK public sector and data protection expectations while avoiding vendor lock-in. - End-of-contract process
-
At the end of the contract, users retain full ownership of their data and are supported to conclude the service in a controlled and transparent manner.
The contract price includes access to the service for the agreed term, in-application guidance, standard support, and the ability to extract user data in supported formats prior to contract expiry.
There are no additional charges for standard end-of-contract activities.
Before contract end, users are able to download their data directly from the service, including plans and policy documentation, training and exercise records, and site event chronology, using built-in export functionality.
Where required, guidance is provided to support data extraction and service offboarding.
Following contract expiry, user access is disabled and data is securely deleted in line with contractual terms and data protection obligations.
Any optional services beyond standard contract scope, such as bespoke reporting or extended access beyond the contract term, would only be provided by mutual agreement and may be subject to additional cost.
This approach ensures clarity, fairness, and avoids vendor lock-in. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- All UIs are responsive to enable a full user experience on a mobile device
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
The service is accessed through a secure, web-based user interface available via standard modern browsers.
No specialist software or client installation is required.
Access is controlled through user authentication and role-based access controls (RBAC).
The interface is designed to be intuitive and accessible, with in-application guidance and embedded digital tooltips to support ease of use.
Users can create, view, and manage risk plans, policies, and related records through the interface, with permissions governed by RBAC, and export data in standard formats where required.
The service supports remote access for authorised users across multiple sites and organisations. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Accessibility has been considered throughout the design and development of the service, with alignment to WCAG 2.2 AA principles.
Interface testing has included structured testing using common assistive technologies and accessibility features to validate usability for users with different access needs.
This includes testing with screen readers such as NVDA and VoiceOver to confirm correct semantic structure, heading hierarchy, form labelling, and predictable navigation.
Keyboard-only navigation testing has been performed across key user journeys to ensure all functionality is operable without a mouse, with visible focus indicators and logical tab order.
Testing has also covered colour contrast, text resizing, zoom to 400%, and content reflow to ensure usability under magnification and high-contrast settings.
Accessibility checks have been applied to authentication flows, form inputs, error messaging, and interactive elements, including WCAG 2.2 requirements such as focus appearance and pointer target sizing.
Where direct testing with end users who rely on assistive technologies has not yet been undertaken, this is planned as part of future user research and iterative improvement.
Accessibility is reviewed continuously as the service evolves, rather than treated as a one-off exercise. - API
- Yes
- What users can and can't do using the API
-
The service provides a secure, read-only API designed to support oversight, reporting, and management information use cases, particularly for government and multi-organisation environments.
Through the API, authorised users can:
• Retrieve aggregated and anonymised compliance data for reporting and analysis, such as national or regional compliance trends and risk levels.
• Query dashboards and management information across multiple sites or organisations to support oversight and assurance.
• Export structured datasets in standard formats (JSON or CSV) for use in business intelligence and analytics tools. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The service supports configuration rather than bespoke customisation, ensuring consistency, security, and ease of use.
Users can customise:
• Organisational structure, including sites, premises, and groupings.
• User roles and permissions, using role-based access controls to reflect responsibilities.
• Plans and templates, adapting them to organisational context and risk profile.
• Branding elements, such as organisation name and visual identifiers, where appropriate.
Customisation is performed directly through the secure web-based interface using guided configuration options and in-application support.
No specialist development or technical knowledge is required.
Customisation actions are restricted by role.
Administrative users can manage organisational structure, roles, permissions, and branding.
Standard users can complete and update plans and records within the permissions assigned to them.
Bespoke feature development, code-level changes, or deep workflow modification are not provided as standard, ensuring platform stability and assurance.
Scaling
- Independence of resources
-
The service is delivered using a cloud-based, multi-tenant architecture designed to scale with demand.
Underlying infrastructure capacity is managed by contracted cloud and SaaS providers, ensuring resources such as compute, storage, and network capacity automatically scale to accommodate varying usage levels.
Usage controls and platform-level safeguards are in place to prevent any single user from disproportionately impacting service performance.
This approach ensures fair resource allocation and consistent performance for all users, even during periods of increased demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Prova Risk provides service usage visibility through an activity chronology that records and displays key updates and changes within the platform.
This includes logging of major actions and updates, supporting governance, assurance, and operational oversight.
The service also records training and exercise activity, enabling organisations to evidence engagement and preparedness over time.
User login activity data is captured at a system level but is not currently visualised within the platform.
The introduction of enhanced usage metrics, is included on the product roadmap.
This approach provides meaningful, role-appropriate usage insight while remaining proportionate to the service’s purpose and maturity. - Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Data at rest is protected through encryption provided by the underlying cloud hosting environment. All customer data stored within the service is encrypted at rest using industry-standard encryption mechanisms managed by the cloud provider. Physical storage media is protected through the provider’s accredited data centre controls, including physical access restrictions and secure handling of storage devices. The service does not manage or access unencrypted physical media directly. This approach aligns with the Government’s Asset Protection and Resilience principle and reflects a shared-responsibility SaaS model appropriate to the service’s operating context.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Users can export their data directly from the service using built-in export functionality, without the need for specialist tools or support.
Plans and policy documentation can be downloaded in PDF/A format, training and exercise records can be exported in CSV format, and site event chronology can be downloaded in PDF/A format.
Data export is available throughout the contract term and prior to contract expiry, ensuring data portability and continuity.
Guidance is provided where required to support users in completing data exports efficiently and securely. - Data export formats
-
- CSV
- Other
- Other data export formats
- PDF/A
- Data import formats
- Other
- Other data import formats
- PDF/A
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is delivered using cloud‑hosted infrastructure designed for high availability and resilience, aligned with the commitments of our underlying cloud and SaaS providers.
We target a monthly service availability of 99.5%, excluding planned maintenance that is notified to users in advance where reasonably practicable. This target is designed to be realistic and proportionate to the service’s risk profile and operational use in public‑sector environments.
Service availability is monitored using platform‑level health indicators and provider status notifications, and availability incidents are triaged and resolved as a priority in line with our documented incident management processes.
Standard pricing does not include automatic service credits; however, where a Buyer requires enhanced availability commitments or service credits, these can be discussed and, if agreed, defined in the applicable G‑Cloud Call‑Off Contract (for example, as credits against future invoices where availability falls below an agreed threshold).
This approach provides transparency and proportionality for Buyers, while avoiding unnecessary cost escalation for those who do not require higher availability guarantees, and ensures that any bespoke SLAs or service credits are clearly documented in the Call‑Off where operationally required. - Approach to resilience
-
The service is designed for resilience using cloud-native SaaS principles, supporting availability, fault tolerance and recovery without reliance on single points of failure.
The platform is hosted on managed public cloud infrastructure, with resilience provided through the underlying cloud provider’s multi-zone architecture, redundant power and network connectivity, and physical security controls within accredited data centres. Detailed data centre information can be provided on request.
Application components are designed to tolerate component failure, using managed services where possible to reduce operational risk and simplify recovery. Customer data is protected through provider-managed replication and backup mechanisms, supporting restoration following service disruption.
Service resilience is further supported by operational processes, including continuous monitoring of service health, defined incident response procedures, and reliance on SaaS dependencies with established availability and resilience commitments. Service dependencies and incidents are reviewed periodically to inform continuous improvement.
This approach aligns with NCSC Cloud Security Principle 2 by protecting assets, minimising service disruption, and enabling recovery through proportionate, cloud-native controls appropriate to the service’s scale and deployment context. - Outage reporting
-
Service outages and significant service degradation are communicated to users in a timely and transparent manner.
At present, outage reporting is delivered primarily through direct client email notifications.
Where a service-affecting incident is identified, affected users are informed as soon as practicable, with updates provided as the situation develops and upon resolution.
Outage communications include a summary of the issue, known impact, actions being taken, and any guidance for users.
Post-incident communication is provided where appropriate to confirm resolution and outline any lessons identified.
The service does not currently provide a public status dashboard or outage reporting API.
However, the introduction of a service status dashboard is included on the product roadmap and will be delivered as the platform matures.
This approach ensures clear and direct communication with users while avoiding reliance on channels that may not be actively monitored during an incident.
Outage reporting processes are aligned with the service’s incident management procedures and reviewed periodically to ensure they remain effective and appropriate to service scale.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is based on the principle of least privilege.
Administrative access is restricted to authorised personnel, granted on a role-based basis and reviewed periodically.
Strong authentication controls are enforced, including unique user accounts and multi-factor authentication.
Shared or generic administrator accounts are not permitted.
Support access is limited to defined activities and does not provide unrestricted access to customer data.
Where access is required, it is controlled, logged, time-limited, and restricted to the minimum scope necessary.
All management and support access is auditable and aligned with Cyber Essentials and ISO 27001 good practice. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
Cyber Essentials
ISO27001 in progress - Information security policies and processes
- Our information security policies and processes are risk-based and aligned to good practice. We follow a structured set of information security policies covering areas such as access control, data protection, incident management, vulnerability management, secure configuration, supplier assurance, and user responsibilities. These policies are informed by frameworks including ISO 27001 principles and NCSC guidance. Information security governance is overseen through a defined reporting structure, with clear accountability for security decision-making and risk ownership. Security risks, incidents, and material issues are escalated through management channels as required, ensuring appropriate oversight and timely decision-making. Policy compliance is achieved through a combination of design controls, operational processes, and assurance activities. Security requirements are embedded into service design, supplier selection, and configuration decisions rather than applied retrospectively. Where third-party SaaS providers are used, we rely on their certified controls and contractual assurances, supplemented by internal review of documentation, certifications, and security posture. Policies are communicated to relevant personnel and reinforced through practical guidance and operational processes. Adherence is monitored through incident reviews, risk assessments, and periodic checks, with policies reviewed and updated to reflect changes in risk, technology, or regulatory expectations. This approach ensures information security is actively governed, consistently applied, and continuously improved.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management is governed through documented, supplier-defined controls supporting operational security and service stability. Changes are managed through a controlled process including assessment, approval, testing and release, with additional scrutiny applied to security, availability and data protection impacts. Configuration is centrally managed with role-based access controls and secure baseline settings. Updates and patches are delivered through planned releases, with defined exception handling for emergency changes. Change and configuration activities are logged to support traceability, incident investigation and assurance. These controls align with the Government’s Operational Security principle and are informed by ISO 27001 concepts and NCSC guidance.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management is implemented using a risk-based approach aligned to the shared-responsibility model for SaaS services. For third-party platforms, vulnerability identification and patching are primarily managed by the service providers, supported by contractual assurances, published security documentation, and continuous monitoring of vendor disclosures. Potential vulnerabilities are assessed based on service architecture, data sensitivity, and operational impact, informed by CVE disclosures, NCSC guidance, and vendor security advisories. Components under supplier control are patched in line with assessed severity and risk, with critical vulnerabilities prioritised for remediation. Patch deployment follows controlled processes to balance security, stability, and service availability, ensuring proportionate response.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is implemented using a proportionate, risk-based approach aligned with the shared-responsibility model for SaaS platforms. Potential security compromises are identified through a combination of cloud provider monitoring, audit logging, alerting, and platform-level anomaly detection, supplemented by review of application logs and access activity within supplier-controlled components. Suspected incidents are triaged to confirm scope and impact, with containment actions taken where required, including access restriction or account suspension. Incidents are handled based on severity, with high-risk events investigated immediately and escalated in line with contractual and customer reporting requirements.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Our incident management process is structured, proportionate, and aligned to recognised good practice. We maintain pre-defined incident response processes for common events, including service disruption, security incidents, and data-related issues, with clear roles, escalation paths, and decision points. Users can report incidents via established support channels, including email and service support workflows, with incidents logged, tracked, and prioritised based on impact and urgency. Incident reports are provided to clients as appropriate and include a clear summary of the issue, timeline, impact, actions taken, and any lessons identified, ensuring transparency, accountability, and continuous improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- 30 days access to the platform
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 12.5%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 17.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-