Security
Is your data safe?
Last checked 19 September 2026
The GOV.UK provider list cannot tell you. It now carries 121 providers, and being on it means one thing: the product is connected to DEFRA’s Report receipt of waste service and has been through the production approval tests. It says nothing about how the records you file through that product are protected — where they are stored, who can read them, whether the company behind the product has had its own security checked. That is a separate question, and it is yours to ask.
Five questions to put to any provider
- Do you hold a Cyber Essentials certificate, and what is its registry link? Cyber Essentials is the UK government-backed scheme run by IASME for the National Cyber Security Centre. Every current certificate is on a public register. A provider that holds one can send the link in seconds; the register entry names the organisation, the level and the expiry date. A badge on a website is not a certificate. The register entry is.
- Where are my records stored? Which country, and which country the software runs in. If either is outside the UK or the EEA, ask what transfer safeguards are in place, because you are the data controller for the personal data in your own records.
- Do you carry cyber insurance? Not a guarantee of anything, but a company that has been underwritten has been asked the questions above by someone whose money depends on the answers.
- Who in my business can see and change a record? A driver, a weighbridge operator and an office administrator should not have the same access, and the rules that separate them should be enforced by the system, not by a setting someone remembers to tick.
- Once a record is filed and signed, can it be changed? A duty-of-care record that can be quietly edited afterwards is worth less to you in an inspection than one that cannot.
Our answers
- Cyber Essentials: DutyOS Ltd holds a Cyber Essentials certificate for the whole organisation, assessed 18 September 2026 and valid for twelve months. Verify it on the IASME registry.
- Where your records live: in the UK, in London. The software runs in the EU, in Amsterdam. Both are inside the UK/EEA, so no international transfer safeguards are needed.
- Cyber insurance: in place, underwritten by AIG UK through the IASME scheme, with an incident response line. It runs with the certificate.
- Who can see what: nine roles with separate permissions, enforced by row-level security in the database itself. The policies protecting every table are read back from the live database and checked against what they are meant to be, rather than taken on trust from the code that created them.
- Filed records: once a note is filed with a signature, that signature and its evidence become immutable, enforced in the database. Even a typo in a signed name cannot be edited away afterwards.
What we can and cannot say about the other providers
On 18 September 2026 we read the public websites of 20 providers on the GOV.UK list. None displayed a Cyber Essentials certificate or a registry link. That is a fact about their pages, not about what they hold: a company can hold a certificate and never mention it. So we do not say who holds one and who does not. We say ask, and we give you ours.
The list: GOV.UK, Report receipt of waste: choose a software provider. All of the providers on it are compared in our guide to choosing one. DutyOS Ltd is one of them and is not affiliated with DEFRA.