NHS & Compliance

NHS Estate Compliance Management and Information Governance

Review ECO's alignment with NHS estate compliance management frameworks and DTAC requirements. Fully ISO 27001 certified for secure data governance.

Developed for the NHS by the NHS

  • DTAC‑aligned
  • ISO 27001 certified
  • WCAG 2.1 AA
  • UK data residency
  • MFA enforced

DTAC alignment

ECO is engineered for close alignment with the DTAC audit trail requirements, specifically addressing the core criteria outlined in Section 3.5.

The software maintains a tamper-evident, chronological log of all record modifications, data exports, and user interactions. This provides NHS Trusts with the robust technical foundation necessary to support a comprehensive compliance audit trail NHS software review.

Recognised security assurance

Information governance is central to public sector software integration. ECO is ISO 27001 certified.

This structural alignment ensures that the platform's underlying technical controls and data-handling workflows seamlessly support and simplify an organisation's broader NHS/ DTAC - accepted data security evidence.

WCAG 2.1 AA

Digital accessibility is a mandatory standard for modern healthcare systems. Both the public-facing marketing site and the core software platform are built to achieve full WCAG 2.1 AA NHS website compliance.

This universal design ensures that the interface remains accessible, stable, and usable for all estate staff, administrative teams, and external contractors, meeting mandatory public sector digital service standards.

Data retention and encryption

ECO protects your historical estate records through clear data lifecycle and security protocols:

Data Retention

Deleted records are never erased- they remain fully auditable and recoverable, so your historical compliance logs stay complete. Records are retained indefinitely, nothing is deleted.

Soft Deletion Architecture

Deleted records and files are never permanently erased from the underlying database. They remain fully auditable and recoverable, ensuring historical compliance logs remain complete.

Encrypted at Rest and in transit

Every connection to ECO is encrypted using TLS 1.2 or higher, end to end from your browser to the application, with HTTPS enforced throughout. Estate records, uploaded documents and storage volumes are encrypted at rest within the Cloud, so your data is protected both in transit and in storage.

MFA, user deactivation, UK data residency

The platform uses industry-standard security controls to satisfy institutional IT requirements and risk assessments:

Multi-Factor Authentication

MFA is universally enforced for all active users across the platform, mitigating credential-based security vulnerabilities.

One-Click User Deactivation

In strict alignment with NHS vendor security point 5.4 user deactivation standards, administrators can instantly revoke a profile, which revokes access immediately - the user is locked out on their next request and can no longer read, modify, or export any estate data.

UK Data Residency

To satisfy NHS information governance mandates, all platform data, backups, and processing environments are hosted entirely on secure, UK-based infrastructure.

Trusted by:

  • Central and North West London NHS Trust
  • East London NHS Foundation Trust
  • Gloucestershire Hospitals NHS Foundation Trust
  • Homerton Healthcare NHS Foundation Trust
  • Kingston Hospital NHS Trust
  • Royal Free London NHS Foundation Trust
  • London Southend Airport
  • Quality Trusted Solutions LLP

Ready to see it

See ECO managing your estate compliance

Book a short platform walkthrough and we'll show you how ECO keeps your asbestos register live, auditable, and inspection-ready.

Book a Demo

A short, tailored walkthrough of the platform.