Skip to main content

Help us improve the Digital Marketplace - send your feedback

ARUVR LIMITED

ARuVR® Immersive Training Platform: High-Consequence Safety & Competence Management

ARuVR is an enterprise-grade SaaS platform for high-consequence industries. Utilizing our IMPACT™ framework, we replace passive learning with immersive "Affective Realism" to bridge the context gap. We deliver defensible, measurable competence through centralized cloud management, real-time analytics, and seamless LMS integration, reducing operational risk and accelerating time-to-competence for safety-critical workforces.

Features

  • Centralised cloud-based VR/AR content management and distribution system.
  • IMPACT™ framework tools for outcome-based training simulation design.
  • Cross-platform deployment to VR headsets, tablets, mobile, and desktop.
  • Real-time learner telemetry and automated behavioral analytics dashboard.
  • Seamless LMS/LXP integration via standard xAPI and SCORM protocols.
  • Enterprise-grade platform security with certified ISO 27001 compliance.
  • Rapid "no-code" cloud updates for instant content distribution.
  • Automated Kirkpatrick Level 3 and 4 performance reporting.
  • Multi-user collaborative environments for team-based safety-critical simulations.
  • Live "Instructor-Led" remote VR training for synchronous learning sessions.

Benefits

  • Reduces operational risk through "Affective Realism" decision-practice simulations.
  • Accelerates time-to-competence for staff in safety-critical operational roles.
  • Provides defensible evidence of compliance for high-consequence industries.
  • Significant carbon reduction by replacing physical asset-heavy training.
  • Minimizes "training debt" through seamless integration with existing systems.
  • Improves staff retention via high-quality, engaging, and immersive learning.
  • Scalable delivery across diverse geographical locations from a central cloud.
  • Reduces training costs by eliminating expensive physical mock-up requirements.
  • Enhances public safety by reducing human error in the field.
  • Directly supports Social Value goals through skills and sustainability.

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at paul@aruvr.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 4 6 3 6 9 7 7 7 4 2 1 1 9 2

Contact

ARUVR LIMITED Paul Morton
Telephone: 07775938904
Email: paul@aruvr.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Education
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
ARuVR is a standalone platform that also extends enterprise LMS, LXP, and LRS ecosystems. It integrates via xAPI, SCORM, and SSO to provide immersive training layers for systems like Moodle, Totara, and Kallidus, bridging the gap between theoretical classroom records and practical, high-consequence operational competence data.
Cloud deployment model
Public cloud
Service constraints
Standard maintenance windows occur during low-usage periods (00:00-04:00 GMT) with 48-hour advance notification. Service is optimized for enterprise XR hardware, (e.g., Quest 3, Pico 4) but can work with limitations, with much older devices. Minimum 10Mbps bandwidth per user is recommended for collaborative simulations to maintain "Affective Realism" and technical performance standards, offline available.
System requirements
  • Modern web browser (Chrome, Edge, Safari) for administrative portal access.
  • Stable internet connection with minimum 10Mbps per active user recommended.
  • Standalone VR headsets: Meta Quest 3/Pro, Pico 4, HTC VIVE.
  • Mobile devices: iOS 13.0+ or Android 10+ for VR viewing.
  • Dedicated ARuVR PC Desktop App for high-fidelity immersive content viewing.
  • Optional tethered VR: High-performance GPU (NVIDIA RTX series) and CPU.
  • LMS integration: xAPI or SCORM 1.2/2004 compliant learning systems.
  • Network security: Open ports for HTTPS/WSS and content delivery networks.
  • Identity management: SAML 2.0 or OAuth for Single Sign-On (SSO).
  • Zero local software installation required for standard administrative management.

User support

Email or online ticketing support
Yes
Support response times
We provide a centralized ticketing system with targeted response times based on severity: Priority 1 (Critical) within 2 hours; Priority 2 (High) within 4 hours; Priority 3 (Standard) within 8 business hours. Standard support is available 09:00–17:00 GMT, Monday to Friday. Weekend support is available for Priority 1 issues via our Premium Support tier.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes, at an extra cost
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Our web chat (via Jira Service Management) is tested by Atlassian using automated tools (Axe, Nu HTML) and manual sessions with assistive technologies. Testing includes JAWS and NVDA screen readers on Windows, and VoiceOver on macOS, ensuring full compatibility with keyboard-only navigation and high-contrast modes to meet WCAG 2.2 AA.
Onsite support
Yes, at extra cost
Support levels
We provide three support tiers: Bronze (Standard), Silver (Priority), and Gold (Enterprise).

Bronze (Included): Reactive support via email/ticketing. Standard 8-hour response.

Silver (15% of license fee): Expedited 4-hour response, phone support, and access to a Cloud Support Engineer for technical troubleshooting.

Gold (25% of license fee): 2-hour critical response, 24/7 emergency access, and a dedicated Technical Account Manager (TAM).

The TAM provides proactive guidance on the IMPACT™ framework, strategic roadmap alignment, and quarterly performance reviews, while our Cloud Support Engineers ensure technical operational reliability.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
We provide a structured onboarding journey focused on technical self-sufficiency and operational impact:

Discovery & Blueprinting: We conduct intensive workshops to align the platform with specific learning outcomes and failure modes, defining a clear ROI roadmap.

ARuVR University (Academy): A centralized, self-service knowledge hub built on Confluence. It provides 24/7 access to technical manuals, video tutorials, and pedagogical best practices.

Onsite Skills Transfer: We deliver "Train-the-Trainer" sessions, empowering L&D teams to create high-fidelity 3D/360° content 5-10x faster than traditional methods using our no-code editor.

Technical Integration: Our XR Solution Architects oversee SSO, LMS (Moodle/Totara) integration, and network optimization for the Windows Desktop and Headset apps.

The IMPACT™ Framework: We guide users through a 5-stage deployment process—identifying needs, mapping scenarios, preparing the environment, immersing learners, and analyzing performance data.

Rapid Deployment: We typically deliver a Minimum Viable Product (MVP) within 6 weeks, ensuring a fast transition from procurement to active training.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
ARuVR ensures a seamless and secure offboarding process, guaranteeing that buyers retain full ownership of their data. At the end of the contract, users can extract data through the following methods:

SCORM/xAPI Content Export: Users can export interactive 3D and 360° training modules as SCORM 1.2/2004 packages. This allows the content to be hosted and tracked within the buyer's own LMS (e.g., Moodle, Totara).

Licensing Note: While content is portable via SCORM, the high-fidelity 3D playback and VR headset functionality require the ARuVR native player engine. Therefore, a valid software license is required to view/run these exported packages within a headset or the Windows Desktop App.

Self-Service Analytics: Administrators can export granular learner performance data and session telemetry directly from the portal in CSV and JSON formats.

Asset Retrieval: Original media and 3D assets uploaded by the buyer remain their property and can be retrieved in native formats.

Secure Data Purging: Following successful extraction, ARuVR performs a secure data wipe from our AWS environment in accordance with ISO 27001 and UK GDPR standards.
End-of-contract process
Upon contract termination or expiry, the transition is managed to prevent data loss:

Access & Retrieval: Administrative access to the ARuVR Cloud Portal and content streaming will cease. A 30-day grace period is provided for buyers to extract all learner telemetry (CSV/JSON formats) and retrieve original media assets uploaded during the term.

Decommissioning: Following buyer confirmation of data receipt, ARuVR performs a secure "Proof of Deletion." All buyer-specific data, including virtual environments and user profiles, is purged from our AWS environment in accordance with ISO 27001 and GDPR "Right to Erasure" protocols.

Included in the contract price:

Self-Service Extraction: Tools for exporting analytics, learner records, and original assets.

SCORM Packaging: Users can package created 3D/360° modules as SCORM files for hosting on their own LMS.

Secure Purging: Standard data deletion from the production environment.

Additional costs:

Extended Retention: Storage of data beyond the 30-day grace period.

Transition Support: Technical consultancy for migrating large libraries or complex integrations.

Player Licenses: View-only licenses are available at a price to allow continued 3D playback of exported SCORM packages in headsets or the Windows Desktop App.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile experience is optimized for field-based learning via native apps. While the Windows Desktop App uses mouse/keyboard navigation, the mobile service utilizes the device’s built-in gyroscope for intuitive "magic window" 360-degree viewing. Management functions remain on the desktop browser, while mobile focuses on high-performance, immersive content consumption.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
ARuVR provides a web-based Graphic User Interface (GUI) for centralized content management and administrative control. For machine-to-machine interaction, we provide a REST API and support xAPI/SCORM protocols. This dual-interface approach ensures ease of use for training managers while enabling seamless automated integration with existing public sector LMS ecosystems.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We perform regular accessibility audits using automated tools (Axe/Lighthouse) and manual testing with assistive technologies. This includes navigating the management portal and Windows Desktop App using JAWS and NVDA screen readers, keyboard-only interaction, and high-contrast mode verification to ensure an inclusive experience for all administrative and learner roles.
API
Yes
What users can and can't do using the API
Our REST API and specialized Unity endpoints are designed to integrate the platform seamlessly into existing enterprise ecosystems like Moodle, Totara, and Kallidus.

How users can set up and make changes:

Automated Provisioning: Users can programmatically manage user accounts, roles, and privileges, ensuring alignment with organizational security policies.

Content Synchronization: The API allows for the automated synchronization of training content across platforms and the deployment of updates to headsets and the Windows Desktop App.

Data Integration: Users can export granular real-time performance telemetry and behavioral analytics (e.g., eye-tracking, reaction times) to external LMS/LXP systems via xAPI and SCORM protocols.

Limitations:

Write Access: While the API facilitates robust management and data export, certain "high-risk" administrative functions—such as direct modifications to the core cloud infrastructure (AWS Lambda) or security-critical system configurations—are restricted to manual oversight by the CTO for security and compliance.

Rate Limits: API usage is subject to standard enterprise rate limits to maintain optimal platform performance and stability during high-consequence concurrent training sessions
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Buyers can fully white-label the management portal and learner interfaces with departmental branding, logos, and color schemes. The platform supports custom virtual training environments, bespoke interactive workflows, and configurable data dashboards, ensuring the service aligns perfectly with specific public sector operational requirements and organizational identity.

Scaling

Independence of resources
ARuVR utilizes a serverless, cloud-native architecture on AWS to ensure total resource independence.

Elastic Scaling: Using AWS Lambda, the platform scales horizontally and instantaneously. Each user session triggers its own isolated execution environment, meaning a surge in demand from one client cannot impact the performance or latency of another.

Content Delivery: We employ Amazon CloudFront (CDN) to distribute heavy 3D/360° assets globally. This ensures high-speed, jitter-free streaming by serving content from edge locations nearest to the user.

Throttling: API Gateways implement rate-limiting to prevent any single entity from monopolizing system bandwidth or database connections.

Analytics

Service usage metrics
Yes
Metrics types
ARuVR provides comprehensive real-time analytics across two levels: platform usage and learner performance. Usage metrics include active users, session duration, and content engagement rates. Learner metrics capture granular behavioral data, including gaze-tracking (heatmaps), decision-point accuracy, and completion times. These metrics are mapped against "Failure Modes" and "Critical Decisions" defined during onboarding. Performance data is presented via intuitive visual dashboards and can be exported for external analysis. This telemetry enables public sector stakeholders to measure training ROI and identify specific competency gaps across the workforce.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
Data is encrypted at rest using industry-standard AES-256 encryption managed via AWS KMS. Our underlying infrastructure (AWS) maintains rigorous physical security protocols and is certified to ISO 27001, SOC 2, and PCI DSS Level 1, ensuring comprehensive protection of all stored training assets and user data.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can export data through a combination of self-service tools and automated integrations.

Analytics & Telemetry: Administrators can export granular learner performance and behavioral data (e.g., gaze-tracking, decision points) directly from the management portal in CSV or JSON formats.

LMS Sync: Real-time data is pushed to platforms like Moodle or Totara via xAPI or SCORM statements.

Interactive Content: Training modules can be exported as SCORM 1.2/2004 packages for external hosting.

Media Assets: All original 360° videos, images, and 3D assets remain buyer property and are retrievable in their native formats.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON format for granular behavioral telemetry and performance data export.
  • SCORM packages provided for external LMS hosting and content portability.
  • Original media assets retrievable in native, non-proprietary open file formats.
  • XAPI statements for real-time data streaming to external record stores.
Data import formats
  • CSV
  • Other
Other data import formats
  • CSV files for bulk user provisioning and administrative data management.
  • MP4 video files for high-resolution 360-degree and 2D immersive content.
  • JPG and PNG formats for 360-degree imagery and interface textures.
  • GLB and FBX open formats for importing 3D model assets.
  • JSON files for importing structured interactive scenario and metadata.

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
ARuVR provides a highly resilient, enterprise-grade cloud platform with a guaranteed uptime of 99.9%. Hosted on AWS Lambda, the service utilizes a serverless architecture and Multi-AZ (Availability Zone) deployment to ensure continuous availability for high-consequence training.

Availability Guarantee
Service Level Agreement (SLA): We guarantee 99.9% uptime, calculated monthly. This excludes scheduled maintenance, which is typically performed during off-peak hours with at least 24 hours' notice.

Resilience: The platform is "always-on" and accessible 24/7/365 across all supported headsets, mobile devices, and desktop applications.

Refunds and Service Credits
If the platform falls below the guaranteed 99.9% uptime in any calendar month, buyers are entitled to service credits applied against their next subscription period:

<99.9% Availability: 10% credit of the monthly fee.

<99.0% Availability: 25% credit of the monthly fee.

<95.0% Availability: 100% credit of the monthly fee.

Support Response Times
We categorize incidents to ensure rapid resolution:

Critical (Service Unavailable): 4-hour response.

High (Significant Impairment): 8-hour response.

Medium/Low: 24-hour response.
Approach to resilience
ARuVR is built on a cloud-native, serverless architecture using Amazon Web Services (AWS), designed specifically to eliminate single points of failure.

Multi-AZ Deployment: Our service is distributed across multiple AWS Availability Zones (AZs). If an entire data center facility experiences an outage (due to power failure or fire), the platform automatically fails over to a secondary AZ in real-time, ensuring continuous service for headsets and desktop apps.

Serverless Resilience: By utilizing AWS Lambda, the platform does not rely on individual virtual machines. Each request is handled by a fresh execution environment that scales horizontally. If one instance fails, it is instantly replaced without affecting the user experience.

Data Persistence & Backups: All learner data and assets are stored in Amazon S3 and Amazon Aurora, which replicate data across multiple physical locations. We perform automated, encrypted daily backups with a Recovery Point Objective (RPO) of 24 hours and a Recovery Time Objective (RTO) of 4 hours.

Global Content Delivery: We use Amazon CloudFront (CDN) to cache heavy 3D/360° assets at the network edge, ensuring that even under heavy global load, training content remains accessible and performant.

Full details of our Disaster Recovery and Business Continuity Plan are available to buyers.
Outage reporting
ARuVR maintains a proactive and transparent incident communication strategy to ensure public sector buyers are informed of any service disruptions.

Public Status Dashboard: We provide a dedicated service health dashboard (e.g., trust.aruvr.com) that provides real-time visibility into the operational status of all platform components, including the CMS, API Gateway, and Content Delivery Network (CDN).

Email Alerts: Authorized administrative users can subscribe to automated email notifications. In the event of a service disruption, an initial notification is sent within 60 minutes of detection, followed by regular updates until resolution.

AWS Integration: Our status reporting is integrated with the AWS Health Dashboard. This ensures that any underlying infrastructure issues at the data center level are automatically reflected on our status page, providing a "single source of truth" for our users.

In-Platform Notifications: For non-critical updates or scheduled maintenance, we use in-app banners within the ARuVR CMS to notify administrators in advance.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
ARuVR enforces a Zero Trust model for all management and support interfaces. Access is governed by Role-Based Access Control (RBAC), ensuring the Principle of Least Privilege.

Management Interfaces: Access to the ARuVR CMS and AWS Console requires Mandatory Multi-Factor Authentication (MFA) and is restricted via IP Whitelisting and secure VPNs.

Support Channels: Our support team uses unique, auditable identities linked to our central directory. Impersonation or "view-as" actions for troubleshooting are strictly logged, and staff never have access to raw user passwords.

Auditability: All administrative actions are recorded in immutable AWS CloudTrail logs for forensic review.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials Plus certification validated by an independent external auditor.

Security management system aligns with international ISO 27001:2022 standards.

Development follows the NCSC’s secure-by-design software security principles.

Continuous security monitoring integrated into the core governance framework.

Regular board-level reviews ensure ongoing compliance with security policies.
Information security policies and processes
ARuVR operates under a formal Information Security Management System (ISMS) aligned with ISO 27001 and Cyber Essentials Plus. Our governance ensures that security is integrated into every stage of the service lifecycle, from design to decommissioning.

Board-Level Accountability: Our Chief Technology Officer (Marco Moncalvo) holds ultimate responsibility for organizational security. He provides monthly reports to the executive board, covering vulnerability status, risk management, and compliance metrics.

Documented Framework: We maintain a comprehensive suite of policies, including Access Control, Data Protection (UK GDPR), Incident Response, and Acceptable Use. These are reviewed annually to reflect emerging threats and technological changes.

Continuous Enforcement:

Automated Monitoring: We use AWS GuardDuty and Config for real-time compliance checks against security baselines.

Personnel Security: All staff undergo mandatory security training and vetting (BPSS-aligned).

Secure-by-Design: Our development follows the Software Security Code of Practice, utilizing threat modeling and automated supply-chain vulnerability scanning to ensure third-party libraries (e.g., Unity packages) remain secure.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
ARuVR utilizes a Secure DevOps (DevSecOps) model to manage and track every service component. We employ Infrastructure as Code (IaC), using version-controlled templates to define our AWS environment. This ensures every resource, from serverless functions to databases, is tracked throughout its lifecycle with a complete audit trail.

Before deployment, changes undergo a multi-stage Security Impact Assessment:

Automated Scans: CI/CD pipelines use SAST and dependency scanning (via tools like Snyk) to vet code and Unity packages.

Peer Review: Mandatory "Four-Eyes" reviews assess security implications before approval.

Staging: Changes are validated in an isolated environment mirroring production to prevent regressions.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
ARuVR uses a proactive, multi-layered approach to threat management. We assess vulnerabilities via continuous AI-driven penetration testing and automated Snyk/GitHub dependency scanning of our Unity packages and libraries. Threat intelligence is aggregated from the NCSC, AWS Security Bulletins, and the NIST National Vulnerability Database.

We prioritize remediation using the CVSS framework:

Critical: Patched within 24–48 hours.

High: Patched within 7–14 days.

Medium/Low: Addressed in the next 30-day release cycle.

For zero-day threats, we utilize AWS WAF to deploy "virtual patches," blocking exploits at the network edge immediately while code-level fixes are developed.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
ARuVR utilizes a multi-layered, automated strategy to identify and mitigate threats in real-time.

Identification: We employ AWS GuardDuty (AI-powered anomaly detection) and Security Hub to monitor all API calls, network flows, and administrative actions. Automated triggers detect suspicious logins, unauthorized configuration "drift," or potential data exfiltration.

Response: Potential compromises trigger instant alerts via Amazon SNS to our engineering team. We utilize automated "playbooks" (AWS Lambda) to isolate compromised resources or revoke temporary credentials immediately.

Response Timelines: * Critical (P1): Initial containment and mitigation within 30 minutes.

High (P2): Full investigation and response within 1 hour.

Medium/Low: Resolution within 4–8 hours.
Incident management type
Supplier-defined controls
Incident management approach
ARuVR follows a structured Incident Response Plan aligned with NCSC Principle 5. We use pre-defined Playbooks for common events like unauthorized access or service outages.

Reporting: Users report incidents via our Service Management Portal or by emailing support@aruvr.com. Critical issues are instantly escalated to our 24/7 engineering team via automated Amazon SNS alerts.

Resolution & Documentation: We prioritize critical incidents for containment within 30 minutes.

Post-Incident Reports (PIR): For major events, we provide buyers with a formal report within 5 business days, detailing the timeline, Root Cause Analysis (RCA), and long-term corrective actions taken.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
NQA
ISO/IEC 27001 accreditation date
Thursday 11 July 2024
What the ISO/IEC 27001 doesn’t cover
The physical security of the underlying data center infrastructure is managed by our hosting provider (Amazon Web Services), which maintains its own independent ISO 27001 certifications. ARuVR's certification covers all internal software design, development, testing, and support processes, as well as cloud-hosted service delivery and consultancy.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at paul@aruvr.com. Tell them what format you need. It will help if you say what assistive technology you use.