We have a SQL Server Always On availability group setup between our main and DR site locations, so that we have real-time replication of data to an off-site location in case of disaster.
With our hosting provider Rackspace all data is held within UK Data Centres in a private environment with specific sensitive fields within the database that are encrypted using AES 256bit encryption. All data also uses the Pseudonymization procedure to protect and replace field with artificial identifiers wherever possible.
Vulnerability tests are taken regularly at CSS to ensure data security with independent tests taking place annually as part of our Cyber Essentials Plus testing. Independent annual penetration testing also takes place with an independent Crest approved auditor.