Skip to main content

Help us improve the Digital Marketplace - send your feedback

PROVA RISK LTD.

Prova Risk

PROVA Risk is a UK-developed compliance and risk management platform built to help organisations meet their statutory duties under the Terrorism (Protection of Premises) Act 2025 (aka Martyn's Law). The system provides a structured Reasonably Practicable Test that determines proportionate public protection procedures and measures for any qualifying premises.

Features

  • Cloud‑based platform accessible via standard web browsers.
  • Secure user authentication with role‑based access controls.
  • Legislation aligned, structured Reasonably Practicable Test and planning templates.
  • Centralised document and plan management for risk and security documentation.
  • Multi‑site and multi‑organisation support for complex estates.
  • Version‑controlled plans and policy documentation with clear change history.
  • Built‑in digital video guidance and contextual tooltips to support users.
  • Exportable reports in PDF and CSV formats.
  • Configurable user permissions and organisational hierarchies.
  • Audit trails for changes, updates, and user activity.

Benefits

  • Enable compliance with legislation through simple, quick, automated work flows.
  • Standardise risk management across sites and teams.
  • Enable consistent planning without specialist risk expertise.
  • Support governance with clear, auditable risk evidence.
  • Simplify collaboration on risk plans across organisations.
  • Accelerate onboarding with guided, intuitive workflows.
  • Maintain continuity with up‑to‑date, accessible plans.
  • Avoid vendor lock‑in with standard data exports.
  • Scale risk management consistently as organisations grow.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@provarisk.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 2 5 2 4 3 6 1 8 5 4 2 9 7 9

Contact

PROVA RISK LTD. Chris Hotchkiss
Telephone: +447984522288
Email: info@provarisk.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Public Order and Safety
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
N/A
System requirements
  • A supported web browser (e.g. Chrome, Edge, Firefox, or Safari).
  • A stable internet connection.
  • Device with a screen resolution of at least 1280×768.
  • Standard corporate security controls such as endpoint protection.

User support

Email or online ticketing support
Yes
Support response times
For incidents and support requests raised via the defined support channels:

• P1 - Critical (service unavailable or severely degraded for all users). Target initial response: within 2 business hours.
• P2 - High (major functionality impaired, significant impact on critical users). Target initial response: within 4 hours during UK business hours.
• P3 - Medium (degraded functionality, workarounds available). Target initial response: by next business day.
• P4 - Low (how‑to questions, minor issues, enhancement requests). Target initial response: within 2 business days.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
The service includes web based chat functionality delivered using standard web technologies and third party components. Accessibility has been addressed through standards based testing aligned to WCAG 2.2 AA, focused on configuration and validation rather than bespoke development. Testing has confirmed keyboard only operability, predictable focus order, visible focus indicators, and no reliance on pointer only interactions. Screen reader checks using NVDA and VoiceOver have been performed to validate announcement of controls, message content, and notifications using appropriate semantic structure. Where chat functionality relies on third party components, supplier accessibility documentation and conformance statements are reviewed as part of assurance. Direct testing with assistive technology users is planned as usage scales and feedback is gathered.
Onsite support
Yes, at extra cost
Support levels
Prova Risk provide proportionate, service-appropriate support aligned to the size, criticality, and deployment context of the service.

Standard Support (included).
Standard support is included as part of the core service subscription. This covers access to support via email or service support workflows, incident reporting, and general service queries. Issues are triaged based on impact and urgency, with priority given to service-affecting or security-related matters.

Enhanced Support (optional).
Enhanced support can be provided by agreement for clients requiring defined response times, additional assurance, or closer operational engagement. This may include faster response targets, scheduled service check-ins, and enhanced incident communication. Pricing for enhanced support is agreed contractually and reflects scope and service level requirements rather than fixed tiers.

Technical Account Management.
For standard support, a named technical account manager is not provided. For enhanced support arrangements, a named technical point of contact can be assigned to coordinate support, changes, and escalation, acting as the interface between the client and the delivery team. This model ensures support remains responsive, transparent, and sustainable while avoiding unnecessary cost for clients who do not require enhanced service levels.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Prova Risk support users to start using the service quickly and confidently through a proportionate onboarding approach, tailored to organisational size and deployment context.

For larger or multi-site organisations, a proportionate onboarding process is provided, with a named Key Account Manager assigned to coordinate initial setup, rollout, and early adoption.
This includes remote onboarding sessions for administrators and key users, support with configuration, and guidance on embedding the service into existing operational practices.

For all users, onboarding is reinforced through in-application guidance, ensuring users receive support at the point of need.
This includes built-in digital video tool tips embedded within the platform, providing short, contextual guidance to improve usability and reduce training overhead.

A written support and usage wiki is also provided, offering clear, accessible guidance on core functionality, common tasks, and good practice.
This resource is available on demand and maintained in line with service updates.

Onsite training is not typically required due to the self-guided nature of the platform, but can be discussed where operationally necessary.

This layered approach ensures rapid adoption, consistent use, and scalable onboarding across organisations of different sizes and levels of complexity.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Users retain ownership of their data and can extract it in a structured and usable format when the contract ends.

At the end of the contract, users are able to download their data directly from the service without the need for proprietary tools or specialist support.

The following data extraction options are provided:

• Plans and policy documentation can be downloaded in PDF format, ensuring content remains accessible and readable outside the platform.

• Training and exercise records can be exported in CSV format, enabling reuse, analysis, and import into other systems.

• Site event chronology and activity records can be downloaded in PDF format to provide a clear, time-ordered record of events and actions.

Where required, users are provided with guidance on how to complete data extraction prior to contract expiry.

Following confirmation that data extraction has been completed, data held within the service is securely deleted in line with contractual obligations and data protection requirements.

This approach ensures data portability, continuity of operations, and compliance with UK public sector and data protection expectations while avoiding vendor lock-in.
End-of-contract process
At the end of the contract, users retain full ownership of their data and are supported to conclude the service in a controlled and transparent manner.

The contract price includes access to the service for the agreed term, in-application guidance, standard support, and the ability to extract user data in supported formats prior to contract expiry.
There are no additional charges for standard end-of-contract activities.

Before contract end, users are able to download their data directly from the service, including plans and policy documentation, training and exercise records, and site event chronology, using built-in export functionality.

Where required, guidance is provided to support data extraction and service offboarding.

Following contract expiry, user access is disabled and data is securely deleted in line with contractual terms and data protection obligations.

Any optional services beyond standard contract scope, such as bespoke reporting or extended access beyond the contract term, would only be provided by mutual agreement and may be subject to additional cost.

This approach ensures clarity, fairness, and avoids vendor lock-in.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
All UIs are responsive to enable a full user experience on a mobile device
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a secure, web-based user interface available via standard modern browsers.

No specialist software or client installation is required.
Access is controlled through user authentication and role-based access controls (RBAC).

The interface is designed to be intuitive and accessible, with in-application guidance and embedded digital tooltips to support ease of use.

Users can create, view, and manage risk plans, policies, and related records through the interface, with permissions governed by RBAC, and export data in standard formats where required.

The service supports remote access for authorised users across multiple sites and organisations.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Accessibility has been considered throughout the design and development of the service, with alignment to WCAG 2.2 AA principles.

Interface testing has included structured testing using common assistive technologies and accessibility features to validate usability for users with different access needs.

This includes testing with screen readers such as NVDA and VoiceOver to confirm correct semantic structure, heading hierarchy, form labelling, and predictable navigation.

Keyboard-only navigation testing has been performed across key user journeys to ensure all functionality is operable without a mouse, with visible focus indicators and logical tab order.

Testing has also covered colour contrast, text resizing, zoom to 400%, and content reflow to ensure usability under magnification and high-contrast settings.

Accessibility checks have been applied to authentication flows, form inputs, error messaging, and interactive elements, including WCAG 2.2 requirements such as focus appearance and pointer target sizing.

Where direct testing with end users who rely on assistive technologies has not yet been undertaken, this is planned as part of future user research and iterative improvement.

Accessibility is reviewed continuously as the service evolves, rather than treated as a one-off exercise.
API
Yes
What users can and can't do using the API
The service provides a secure, read-only API designed to support oversight, reporting, and management information use cases, particularly for government and multi-organisation environments.

Through the API, authorised users can:

• Retrieve aggregated and anonymised compliance data for reporting and analysis, such as national or regional compliance trends and risk levels.
• Query dashboards and management information across multiple sites or organisations to support oversight and assurance.
• Export structured datasets in standard formats (JSON or CSV) for use in business intelligence and analytics tools.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The service supports configuration rather than bespoke customisation, ensuring consistency, security, and ease of use.

Users can customise:

• Organisational structure, including sites, premises, and groupings.
• User roles and permissions, using role-based access controls to reflect responsibilities.
• Plans and templates, adapting them to organisational context and risk profile.
• Branding elements, such as organisation name and visual identifiers, where appropriate.

Customisation is performed directly through the secure web-based interface using guided configuration options and in-application support.
No specialist development or technical knowledge is required.

Customisation actions are restricted by role.
Administrative users can manage organisational structure, roles, permissions, and branding.
Standard users can complete and update plans and records within the permissions assigned to them.

Bespoke feature development, code-level changes, or deep workflow modification are not provided as standard, ensuring platform stability and assurance.

Scaling

Independence of resources
The service is delivered using a cloud-based, multi-tenant architecture designed to scale with demand.

Underlying infrastructure capacity is managed by contracted cloud and SaaS providers, ensuring resources such as compute, storage, and network capacity automatically scale to accommodate varying usage levels.

Usage controls and platform-level safeguards are in place to prevent any single user from disproportionately impacting service performance.

This approach ensures fair resource allocation and consistent performance for all users, even during periods of increased demand.

Analytics

Service usage metrics
Yes
Metrics types
Prova Risk provides service usage visibility through an activity chronology that records and displays key updates and changes within the platform.

This includes logging of major actions and updates, supporting governance, assurance, and operational oversight.

The service also records training and exercise activity, enabling organisations to evidence engagement and preparedness over time.

User login activity data is captured at a system level but is not currently visualised within the platform.
The introduction of enhanced usage metrics, is included on the product roadmap.

This approach provides meaningful, role-appropriate usage insight while remaining proportionate to the service’s purpose and maturity.
Reporting types
Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Data at rest is protected through encryption provided by the underlying cloud hosting environment. All customer data stored within the service is encrypted at rest using industry-standard encryption mechanisms managed by the cloud provider. Physical storage media is protected through the provider’s accredited data centre controls, including physical access restrictions and secure handling of storage devices. The service does not manage or access unencrypted physical media directly. This approach aligns with the Government’s Asset Protection and Resilience principle and reflects a shared-responsibility SaaS model appropriate to the service’s operating context.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data directly from the service using built-in export functionality, without the need for specialist tools or support.

Plans and policy documentation can be downloaded in PDF/A format, training and exercise records can be exported in CSV format, and site event chronology can be downloaded in PDF/A format.

Data export is available throughout the contract term and prior to contract expiry, ensuring data portability and continuity.

Guidance is provided where required to support users in completing data exports efficiently and securely.
Data export formats
  • CSV
  • Other
Other data export formats
PDF/A
Data import formats
Other
Other data import formats
PDF/A

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is delivered using cloud‑hosted infrastructure designed for high availability and resilience, aligned with the commitments of our underlying cloud and SaaS providers.

We target a monthly service availability of 99.5%, excluding planned maintenance that is notified to users in advance where reasonably practicable. This target is designed to be realistic and proportionate to the service’s risk profile and operational use in public‑sector environments.

Service availability is monitored using platform‑level health indicators and provider status notifications, and availability incidents are triaged and resolved as a priority in line with our documented incident management processes.

Standard pricing does not include automatic service credits; however, where a Buyer requires enhanced availability commitments or service credits, these can be discussed and, if agreed, defined in the applicable G‑Cloud Call‑Off Contract (for example, as credits against future invoices where availability falls below an agreed threshold).

This approach provides transparency and proportionality for Buyers, while avoiding unnecessary cost escalation for those who do not require higher availability guarantees, and ensures that any bespoke SLAs or service credits are clearly documented in the Call‑Off where operationally required.
Approach to resilience
The service is designed for resilience using cloud-native SaaS principles, supporting availability, fault tolerance and recovery without reliance on single points of failure.

The platform is hosted on managed public cloud infrastructure, with resilience provided through the underlying cloud provider’s multi-zone architecture, redundant power and network connectivity, and physical security controls within accredited data centres. Detailed data centre information can be provided on request.

Application components are designed to tolerate component failure, using managed services where possible to reduce operational risk and simplify recovery. Customer data is protected through provider-managed replication and backup mechanisms, supporting restoration following service disruption.

Service resilience is further supported by operational processes, including continuous monitoring of service health, defined incident response procedures, and reliance on SaaS dependencies with established availability and resilience commitments. Service dependencies and incidents are reviewed periodically to inform continuous improvement.

This approach aligns with NCSC Cloud Security Principle 2 by protecting assets, minimising service disruption, and enabling recovery through proportionate, cloud-native controls appropriate to the service’s scale and deployment context.
Outage reporting
Service outages and significant service degradation are communicated to users in a timely and transparent manner.

At present, outage reporting is delivered primarily through direct client email notifications.
Where a service-affecting incident is identified, affected users are informed as soon as practicable, with updates provided as the situation develops and upon resolution.

Outage communications include a summary of the issue, known impact, actions being taken, and any guidance for users.
Post-incident communication is provided where appropriate to confirm resolution and outline any lessons identified.

The service does not currently provide a public status dashboard or outage reporting API.
However, the introduction of a service status dashboard is included on the product roadmap and will be delivered as the platform matures.

This approach ensures clear and direct communication with users while avoiding reliance on channels that may not be actively monitored during an incident.

Outage reporting processes are aligned with the service’s incident management procedures and reviewed periodically to ensure they remain effective and appropriate to service scale.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is based on the principle of least privilege.

Administrative access is restricted to authorised personnel, granted on a role-based basis and reviewed periodically.
Strong authentication controls are enforced, including unique user accounts and multi-factor authentication.
Shared or generic administrator accounts are not permitted.

Support access is limited to defined activities and does not provide unrestricted access to customer data.
Where access is required, it is controlled, logged, time-limited, and restricted to the minimum scope necessary.

All management and support access is auditable and aligned with Cyber Essentials and ISO 27001 good practice.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials
ISO27001 in progress
Information security policies and processes
Our information security policies and processes are risk-based and aligned to good practice. We follow a structured set of information security policies covering areas such as access control, data protection, incident management, vulnerability management, secure configuration, supplier assurance, and user responsibilities. These policies are informed by frameworks including ISO 27001 principles and NCSC guidance. Information security governance is overseen through a defined reporting structure, with clear accountability for security decision-making and risk ownership. Security risks, incidents, and material issues are escalated through management channels as required, ensuring appropriate oversight and timely decision-making. Policy compliance is achieved through a combination of design controls, operational processes, and assurance activities. Security requirements are embedded into service design, supplier selection, and configuration decisions rather than applied retrospectively. Where third-party SaaS providers are used, we rely on their certified controls and contractual assurances, supplemented by internal review of documentation, certifications, and security posture. Policies are communicated to relevant personnel and reinforced through practical guidance and operational processes. Adherence is monitored through incident reviews, risk assessments, and periodic checks, with policies reviewed and updated to reflect changes in risk, technology, or regulatory expectations. This approach ensures information security is actively governed, consistently applied, and continuously improved.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and change management is governed through documented, supplier-defined controls supporting operational security and service stability. Changes are managed through a controlled process including assessment, approval, testing and release, with additional scrutiny applied to security, availability and data protection impacts. Configuration is centrally managed with role-based access controls and secure baseline settings. Updates and patches are delivered through planned releases, with defined exception handling for emergency changes. Change and configuration activities are logged to support traceability, incident investigation and assurance. These controls align with the Government’s Operational Security principle and are informed by ISO 27001 concepts and NCSC guidance.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerability management is implemented using a risk-based approach aligned to the shared-responsibility model for SaaS services. For third-party platforms, vulnerability identification and patching are primarily managed by the service providers, supported by contractual assurances, published security documentation, and continuous monitoring of vendor disclosures. Potential vulnerabilities are assessed based on service architecture, data sensitivity, and operational impact, informed by CVE disclosures, NCSC guidance, and vendor security advisories. Components under supplier control are patched in line with assessed severity and risk, with critical vulnerabilities prioritised for remediation. Patch deployment follows controlled processes to balance security, stability, and service availability, ensuring proportionate response.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is implemented using a proportionate, risk-based approach aligned with the shared-responsibility model for SaaS platforms. Potential security compromises are identified through a combination of cloud provider monitoring, audit logging, alerting, and platform-level anomaly detection, supplemented by review of application logs and access activity within supplier-controlled components. Suspected incidents are triaged to confirm scope and impact, with containment actions taken where required, including access restriction or account suspension. Incidents are handled based on severity, with high-risk events investigated immediately and escalated in line with contractual and customer reporting requirements.
Incident management type
Supplier-defined controls
Incident management approach
Our incident management process is structured, proportionate, and aligned to recognised good practice. We maintain pre-defined incident response processes for common events, including service disruption, security incidents, and data-related issues, with clear roles, escalation paths, and decision points. Users can report incidents via established support channels, including email and service support workflows, with incidents logged, tracked, and prioritised based on impact and urgency. Incident reports are provided to clients as appropriate and include a clear summary of the issue, timeline, impact, actions taken, and any lessons identified, ensuring transparency, accountability, and continuous improvement.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
30 days access to the platform

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
12.5%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
17.5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@provarisk.com. Tell them what format you need. It will help if you say what assistive technology you use.