1. The NBS Chorus platform

1.1 Cyber Essentials Plus accreditation
NBS has achieved Cyber Essentials Plus accreditation. This is a UK Government certification scheme, with standards designed to protect businesses from cyberattacks. Following the standards of this certification means that NBS is practising preventative cyber hygiene, such as having firewalls enabled and using multifactor authentication. View the certificate.
1.2 Additional security testing
We test our platform against the Google VSAQ (Vendor Security Assessment Questionnaire) – the process that Google uses to assess vendor security to ensure the highest levels of compliance.
VSAQ is a collection of adaptable questionnaires for evaluating a given vendor’s security and privacy posture. Whilst we do not publicly publish the results of this questionnaire, we can make this information available upon request. For further details on VSAQ, click here.
Furthermore, we perform regular penetration testing on the NBS software platforms, in line with the latest National Cyber Security Centre Guidance.
1.3 Data storage
All data within Chorus is stored in secure data centres in London, operated by Amazon Web Services (AWS).
The AWS cloud is a network of remote servers hosted on the internet and used to store, manage and process data in place of local servers or personal computers.
Chorus runs with AWS’ state-of-the-art infrastructure, and uses its comprehensive security features to enforce rigorous access control and defend against threats such as DDoS attacks. Our policy is to keep data encrypted in transit and at rest, wherever possible, to eliminate the possibility of any unauthorized access.
1.4 Data ownership
NBS claims no ownership rights to data entered into NBS Chorus by users. All of the intellectual property rights in the NBS Chorus service, NBS content and any materials or software created or used in the provision of training are, and shall remain at all times, the sole and exclusive property of NBS or its licensors.
1.5 Data backup
Our infrastructure is designed to be extremely reliable, and uses the latest cloud technologies to minimize the risk of any data loss. Data is continually backed up, with a restoration window target of five minutes (the maximum potential period of any data loss in the unlikely event of a problem). In addition, data and backups are stored on systems with designed durability of 99.999999999%, giving robust protection from component failure leading to data loss.