Provider: RSMT Limited trading as Driver Codes
Version: v1.1 — May 2026
Published location: app.driver.codes/documents/security
This page is a public summary of how Driver Codes protects customer and driver data. A fuller Security and Technical Measures Pack is available to enterprise customers and procurement teams on request, under non-disclosure.
| Hosting | United Kingdom only (AWS eu-west-2, London) |
| International transfers | Core production hosting and driver-check records are held in the UK. Some limited support, messaging, payment, push-notification and observability data may be processed outside the UK by listed sub-processors under UK-recognised transfer safeguards. |
| Encryption | TLS in transit; AES-256 at rest |
| Multi-factor authentication | Mandatory on all administrative access and on the customer-facing checks portal |
| Monitoring | Continuous 24x7 automated security monitoring and alerting |
| Backups | Daily, encrypted, point-in-time recovery |
| Cyber Essentials | Certified; working towards Cyber Essentials Plus |
| Personal Data Breach notification | Within 48 hours of confirmation |
| DVLA registration | Access to Driver Data (ADD) Controller Operating Model |
| Information Commission registration | ZA788385 |
All core production services for the Customer Portal and driver-check records run in the United Kingdom, in Amazon Web Services' London region (eu-west-2). Core check records are not intentionally transferred outside the UK as part of normal production hosting.
Some ancillary service providers used for support, push notifications, payments, email, error monitoring or observability may process limited personal data outside the UK. Those providers, locations and transfer mechanisms are listed in our Sub-processor List.
Access to production systems and data is granted on a least-privilege basis: people only get access to what their role needs.
Data is encrypted in transit with TLS (1.2 or higher, modern cipher suites only) and at rest with AES-256. Backups are encrypted. Encryption keys are managed through AWS Key Management Service. Application secrets are stored in managed secrets services, never in source code.
We operate continuous 24x7 automated security monitoring and alerting on production infrastructure and applications, covering authentication events, administrative actions, material platform actions and access to sensitive resources. Security logs are retained for at least 12 months.
We have a documented incident response process. If a confirmed Personal Data Breach affects customer data, we will notify the affected customer within 48 hours of confirmation. Where required, we report to the Information Commission within 72 hours of becoming aware, in line with Article 33 UK GDPR.
Production data is backed up daily, encrypted, with point-in-time recovery. Backup restoration is tested on a defined cycle.
Our recovery objectives:
Backups are held within the AWS London region; we do not currently maintain cross-region replication.
We run automated vulnerability scanning across our infrastructure and software dependencies. We track security advisories and patch confirmed critical vulnerabilities within 5 days of an advisory becoming available.
If you've found something that looks like a security problem, email security@driver.codes. We will acknowledge legitimate reports promptly and triage on a risk basis.
We are Cyber Essentials certified and are working towards Cyber Essentials Plus certification.
We are not currently ISO 27001 certified. We operate to a control framework aligned with the ISO 27001 control families and we keep formal certification under review as the service grows.
We engage third-party providers for hosting, email delivery, push notifications, error monitoring, support tooling and similar. Each sub-processor is bound by a written contract requiring data protection obligations no less protective than those we accept in our own customer agreements.
A current list is published at app.driver.codes/documents/subprocessors. Customers receive at least 30 days' notice of changes.
We retain personal data only as long as we need it for the purpose for which we collected it. Specific retention periods are set out in our Driver Checks Privacy Notice and the Consumer App Privacy Notice. When a customer account is closed, our published terms set out export windows and the route to a deletion certificate.
Security is shared. To support the controls above, we expect customers and users to:
Self-serve customers can use this summary alongside our published privacy notices, sub-processor list and terms.
Enterprise prospects, procurement teams and security reviewers — we can provide a fuller Security and Technical Measures Pack under non-disclosure on request. Contact hello@driver.codes.
For data protection enquiries: privacy@driver.codes.
For security enquiries: security@driver.codes.
Note on regulator naming: at the version date of this document, the Information Commissioner's Office (ICO) remains the operative legal name of the UK data protection regulator. References in this document to the "Information Commission" anticipate the regulator's reconstitution under Part 6 of the Data (Use and Access) Act 2025. Our registration (ZA788385) is held with the regulator and will transfer to the Information Commission by operation of law on commencement of sections 118 and 119 of that Act.