Evira
Digital platform supporting clinician-led obesity care, including lifestyle and medication. Patients use the Evira app and graphics with a numberless scale for goal-oriented self-monitoring. Providers use a dashboard for monitoring, MDT collaboration and communication with the patients. Clinical studies in paediatric obesity show improved outcomes and reduced drop-out.
Features
- Individualised goal-setting and feedback for patients to improve self-control.
- Goal-based remote follow-up with dashboards and visual progress graphics.
- Automated care provider notifications highlighting patient changes and deviations
- Real-time overview of patients and outcomes.
- Medication tracking including initiation, dose changes and outcomes.
- MDT task management with shared patient data and communication.
- Follow-up optimisation using targets, trends and patient messaging.
- Numberless weight tracking at home with trend visualisation.
- Clinic-level outcome dashboards and reporting tools for service evaluation.
- Platform design based on established theoretical frameworks and research.
Benefits
- Enable structured, goal-based remote support between appointments.
- Enables timely outreach using MDT notifications highlighting change or deviations.
- Provide up-to-date overview to prioritise clinical workload efficiently.
- Facilitates medication monitoring and titration using in-platform follow-up.
- Strengthen MDT collaboration through task-management, shared patient data and communication.
- Streamline follow-up with targets, trend monitoring and secure messaging.
- Improve patient engagement through clear goals and progress feedback.
- Reduce stigma by focusing on trends using numberless scales.
- Support service evaluation using clinic-level outcome graphs and reporting.
- Support evidence-based care, with published paediatric outcome data.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 8 4 8 7 4 1 9 9 4 7 8 6 2 1
Contact
EVIRA LTD
Malin Ramkloo
Telephone: +46 76-308 60 93
Email: info@evira.se
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Evira requires a reliable internet access and HTTPS (port 443) connectivity to *.evira.se and *.evira.care. The clinic interface is browser-based and works with modern browsers. The family interface requires a compatible iOS/Android device with Bluetooth enabled. Android devices also require location services for Bluetooth access. Evira integrates with body scales via BLE; full support requires devices meeting defined accuracy and interface specifications, and certain clinical outcomes assume use of a non-display scale. Planned maintenance and software updates may occur and are communicated in advance. Support is provided via in-platform channels, email, and phone for urgent clinical cases.
- System requirements
-
- Modern web browser: (Chrome, Safari, Firefox, Edge)
- Up to date anti-virus software on all devices
- Internet access with HTTPS enabled (port 443)
- Network allowlisting for *.evira.se and *.evira.care
- IOS 13+ or Android 5+ device for family mobile app
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 3 working days (e.g., not during weekends or bank holidays)
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Evira provides support primarily to health care professionals and clinic teams. Support is delivered mainly through secure support tickets within the platform, which is the recommended channel to ensure patient information is handled safely. Support requests are typically answered within three business days.
For urgent issues, we also provide telephone support, for example if there is a technical problem while a patient is present at the clinic (e.g. during inclusion/onboarding). Support is available on weekdays, excluding bank holidays.
Standard support is included in the service subscription. Where required, additional support packages can be agreed, such as extended hours, increased availability during roll-outs, or additional training sessions. Pricing for enhanced support depends on scope and is provided on request.
Evira does not routinely provide direct support to patients. If a patient contacts Evira support, we can provide general non-clinical guidance and, where appropriate, coordinate with the clinic team. The clinic remains responsible for patient care and clinical decision-making.
Each customer is assigned a named contact person who can support day-to-day questions and coordination. Evira does not provide a formal Technical Account Manager role as standard. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Evira provides a structured onboarding process for new clinics and for existing customers expanding to new clinics. Onboarding is delivered remotely and/or on-site, supported by documentation and practical guidance to enable safe and effective implementation.
Onboarding typically includes a combination of:
(1) a start-up meeting to coordinate clinic set-up and training,
(2) a clinical introduction covering the method and evidence base,
(3) practical training on workflows and patient interaction, and,
(4) a follow-up session for Q&A once the clinic has started using Evira.
Training is delivered by experienced health care professionals and can be adapted to local needs and team size. User documentation is provided in advance.
Evira supports information governance preparation, including assistance related to legal, cyber security, and clinical compliance. Technical parameters such as data retention and access administration are configured during onboarding and can be adjusted at any time. Clinics can extract their data from Evira when required.
Ongoing training and support are available through regular check-ins and planned additional sessions. Formal offboarding is not typically required; however, data extraction and access adjustments can be completed at any time. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
There is a per-patient extract functionality one click-away in the platform.
The clinic can request a full data extraction at any time. - End-of-contract process
- No additional costs. The service will stop functioning for the Trust and patients. The clinic can extract all their information. Evira can retain information as a service for the clinic for a fee.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Patients and their families interact with the Evira mobile app. Care providers use a web-based service through normal browsers, intended for use on desktop or laptop computers for efficient and ergonomic use.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Clinic dashboard for healthcare professionals working with Evira accessible through any modern browser. It's a browser based interface enabling all the platform functionality.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
Using Evira requires the user (healthcare provider and/or patient) to be able to see and understand visualizations of data that we have so far been unable to make completely accessible. In the case of children, Evira can be applicable for families where only one parent or care giver is able to access information.
Evira is designed with inclusive and accessible principles in mind, using clear layouts, visual cues (e.g. traffic-light indicators) and multilingual options to support users with varying communication needs and digital literacy. - Accessibility testing
-
Evira has not yet completed formal accessibility testing sessions with users who rely on assistive technologies such as screen readers, switch devices, or alternative input methods. However, accessibility is considered during development through general usability practices and quality assurance. The clinic interface is browser-based and tested across modern browsers, and the family interface is tested on supported iOS and Android versions. We aim to ensure that key user flows such as login, navigation, form completion, and viewing measurement results remain functional with keyboard navigation and common platform accessibility settings (e.g., text scaling).
We also monitor user feedback and support requests received through in-platform support channels and email, which helps identify usability and accessibility issues in real-world use. When issues are discovered, they are prioritized and addressed as part of ongoing product improvements. - API
- No
- Customisation available
- Yes
- Description of customisation
- Trusts using Evira can commission deep customization of our services and platform. This includes but is not limited to API services and white label services.
Scaling
- Independence of resources
- Evira delivery is structured so that each clinic/Trust operates independently and is not affected by the demand other organisations place on the service. Clinics have separate access and data areas, and usage from one clinic does not impact another clinic’s ability to use the platform. We continuously monitor performance and capacity and scale the service as needed to maintain stable operation as usage increases. We have experience supporting clinics of varying sizes. Practical scaling is also supported through structured onboarding, ensuring clinics can safely increase the number of active patients in a controlled way.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide metrics on average treatment outcomes and how clinics work with and manage their patients, e.g., to what extent different platform functionality is used on an aggregated level.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Evira supports controlled data export through the clinical web interface. Professional healthcare staff can generate built-in exports for clinical use and archiving purposes and, where appropriate, provide these exports to patients or families as part of clinical routines. Export access is restricted by role-based permissions and strong authentication, and all export actions are logged for traceability. For additional or non-standard exports, the clinic or user can submit a request via Evira’s built-in support tool. Evira then facilitates the export in accordance with the clinic’s instructions, applicable agreements, and data minimisation principles.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
- Can support any standard format on request
- Data import formats
- Other
- Other data import formats
- Generally not applicable, but if necessary and standard format
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Evira provides the service using resilient cloud infrastructure hosted on Microsoft Azure within EEA. The service is designed to achieve a target availability of 99.9%, excluding planned maintenance and events outside Evira’s reasonable control. High availability is supported through redundant infrastructure, automated recovery mechanisms, continuous monitoring, and regular backups. Availability commitments and any remedies for failure to meet target availability are defined contractually with customers. Where availability targets are not met, service credits or other appropriate remedies may be applied in accordance with the agreed contract or SLA.
- Approach to resilience
- The service is designed for resilience using managed cloud infrastructure hosted in Microsoft Azure datacentres within the EU/EEA. The underlying datacentre environment provides physical resilience through redundant power, cooling, networking, and controlled physical access, with no single point of failure. The application is deployed on resilient cloud services that support automatic recovery, redundancy, and scalability. Data is stored on resilient storage with regular backups and defined retention periods, enabling restoration in the event of failure or data corruption. Service health is continuously monitored and incidents are responded to using documented operational procedures. Responsibility for physical datacentre resilience is managed by the cloud infrastructure provider, while Evira is responsible for application-level resilience, monitoring, and recovery processes.
- Outage reporting
- Evira does not operate a public status dashboard or outage reporting API. Service outages or significant service degradation are identified through internal monitoring and communicated directly to customers via email and an internal news feed within the web portal. Where appropriate, customers are also informed through agreed support and incident management channels. Outage communication processes, response times, and escalation routes are defined contractually and aligned with customer requirements.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is strictly role-based and limited to authorised personnel under confidentiality agreements. All access requires multi-factor authentication (MFA) using personal credentials and time-limited tokens. IP whitelisting is enforced for administrative access, and privileged accounts are only accessible via company-managed devices. Support engineers access data solely for troubleshooting and are logged with full audit trails. Sensitive actions are recorded and encrypted per user. Access rights are reviewed regularly, and revoked immediately upon staff departure or role change
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Evira follows a structured suite of information security policies based on ISO 27001 principles, including a core Information Security Policy and an Information Security Standards Policy. These define requirements around access control, encryption, patching, network protection, remote working, and incident handling. Security policies apply to all employees, contractors, and sub-processors.
Evira enforces role-based access control, mandatory multi-factor authentication, device hardening, and regular audit logging. All personal data is encrypted in transit (TLS 1.3) and at rest (AES-256 with FIPS 140 compliant modules). Penetration testing is carried out regularly by certified third parties.
Compliance is overseen by the Data Protection Officer and the IT Security Lead, reporting to the senior management team. Policies are reviewed annually or following major changes. Employees receive onboarding and annual mandatory training on data protection and information security.
Policy adherence is monitored through regular internal audits and technical controls (e.g. session timeouts, access revocation processes). Any policy breaches are reported internally and escalated as needed to regulatory authorities in accordance with GDPR and CE requirements for medical software - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Evira operates an Information Security Management System (ISMS) aligned with ISO/IEC 27001 principles and maintains internal configuration and change management standards consistent with those controls. All changes to the service are managed and documented within a CE-certified Quality Management System under the Medical Device Regulation (MDR). This includes formal change assessment, security and risk evaluation, code review, testing, and documented approval prior to deployment. Service components and configurations are version controlled and tracked throughout their lifecycle, with changes logged and traceable to support operational security and auditability.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Evira operates vulnerability management as part of its ISMS aligned with ISO/IEC 27001 principles and its MDR-compliant Quality Management System. Potential threats are identified through automated vulnerability scanning, dependency and code review, continuous monitoring of security advisories, and regular external penetration testing by certified security specialists. Vulnerabilities are prioritised based on severity and impact, with critical issues addressed as a priority, typically within 24–48 hours following validation and testing, and lower-risk updates applied through scheduled release cycles. Threat intelligence is obtained from cloud provider security advisories, software vendors, recognised vulnerability databases, and external security testing.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Evira operates protective monitoring as part of its ISMS aligned with ISO/IEC 27001 principles and its MDR-compliant Quality Management System. Potential compromises are identified through continuous monitoring of access and application logs, automated security alerts, vulnerability scanning, and cloud-provider security signals. All access to data is logged and monitored to detect anomalous or unauthorised activity. When a potential compromise is identified, incidents are handled through documented incident response procedures, including containment, investigation, remediation, and escalation. High-risk security incidents are prioritised for immediate assessment, with initial response typically initiated within hours and actions taken without undue delay.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Evira operates documented incident management processes as part of its ISMS aligned with ISO/IEC 27001 principles and its MDR-compliant Quality Management System. Pre-defined procedures exist for common security and operational incidents, including access issues, service disruption, and potential data protection incidents. Users report incidents via agreed support channels, including in-platform support and email. Incidents are logged, assessed, and managed according to severity, with defined escalation and response procedures. Where required, customers are provided with incident reports outlining the nature of the incident, impact, actions taken, and any follow-up measures, in line with contractual and regulatory obligations.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 3%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 9%
- Over £5,000,001
- 11%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5879e56c-86e5-4b4f-871d-a53fd2402af4
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
- ISO/IEC 27001 certification – to be certified in 2026
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Plans for positive actions with community groups.
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-