Skip to main content

Help us improve the Digital Marketplace - send your feedback

CobbleStone Systems Corp. DBA CobbleStone Software

Contract Insight Enterprise

Contract Insight Enterprise is a scalable enterprise contract management system is designed to work with organizations of all sizes and in all industries. Allows for organizations to manage the entire lifecycle cradle to grave.

Features

  • Rules Based Workflow
  • Contract Artificial Intelligence
  • Contract Document Collaboration
  • eSignature Capability
  • Contract Risk Analysis
  • Contract Lifecycle Management
  • Sourcing to Contract Software
  • Contract Automation
  • Ad-hoc Reports
  • Vendor Management

Benefits

  • Automated Workflow Processes
  • Adhoc reporting capabilities
  • Risk Analysis
  • Contract Artificial Intelligence
  • Legal Workflow Automation
  • Contract Repository
  • Procurement Software
  • Contract Analytics
  • Document Assembly
  • Contract Data Extraction

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at partners@cobblestonesoftware.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 1 7 1 7 4 1 6 3 1 1 1 3 6 9

Contact

CobbleStone Systems Corp. DBA CobbleStone Software Anthony Fusco
Telephone: +1 856-784-1139
Email: partners@cobblestonesoftware.com

About your service

Service categories

Applications

Content workflow and management

  • Capture
  • Document

Content services

  • Enterprise Content Management Applications

Persuasive content management

  • Website Software
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
CobbleStone Software is a commercial off the shelf product that is a web based application that can be accessed via a web browser with internet access. No other hardware requirements are required.
System requirements
  • Best with Chrome, Firefox, Edge, Safari, Opera; others partial.
  • Perform acceptably on internet connections as minimal as 128 KBPS.

User support

Email or online ticketing support
Yes
Support response times
CobbleStone Software provides support levels up to 24 x 7 x 365 user and technical critical support via telephone, email, and customer care portal. Standard hours of support are 9 AM to 8 PM Eastern Time Monday through Friday, exclusive of US Federal Holidays. Standard emergency supports includes 24-hour, 7-day support for mission critical problems with a targeted response time consistent with problem severity as designated by CobbleStone Software.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
No
Support levels
CobbleStone Software provides support levels up to 24 x 7 x 365 user and technical critical support via telephone, email, and customer care portal. Standard hours of support are 9 AM to 8 PM Eastern Time Monday through Friday, exclusive of US Federal Holidays. Standard emergency support includes 24-hour, 7 day support for mission critical problems with targeted response time consistent with problem severity as designated by CobbleStone Software.

CobbleStone Software does not outsource support services, rather we employ a support staff of customer representatives. CobbleStone Software reserves the right to provide next day responses to non-emergency issues. CobbleStone's typical response times are based upon Standard, Diamond and Emerald packages.
Support available to third parties
No

Onboarding and offboarding

Getting started
The CobbleStone Training Sessions are live online meetings intended to prepare customers for implementation and instruct users how to manage/use the system. The training sessions offered are Core System Administrator Training, System Administrator Module Training, End User Training, and tailored training as needed.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
CobbleStone does not claim ownership of any client data. In the event of non-renewal or cancellation of the agreement, CobbleStone will provide your organization with a full extract of all metadata and electronic files/attachments uploaded by your team.

The extracted meta-data will be in spreadsheet (XLSX) format and will have the fields as the column names and record meta-data in the spreadsheet rows (exactly how the spreadsheet would be setup when importing data into Contract Insight).

For the files that were uploaded/attached to records (company records, PO records, request records, contract records, solicitation/eSourcing records, etc.) they will be provided back to you in their native format (i.e. if the file was uploaded into Contract Insight as a PDF then it will be in PDF format when extracted) and will be sorted into folders where the folder name is the ID of the record the file(s) are associated with.

Once the data is extracted CobbleStone will send a link to download the folder of extracted data and then, in a separate email, will send you the password to extract the data from the downloaded folder.
End-of-contract process
CobbleStone does not claim ownership of client data. In the event of non-renewal or cancellation of the agreement, CobbleStone will provide your organizations with a full extract of metadata and electronic files/attachments uploaded by your team. The link to download the data will be available for you to use for approximately 90 days unless you need for it to be available longer or removed before the 90 days is reached. CobbleStone will schedule a decommission and remove access right once the cancelation or non renewal is set.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Contract Insight Enterprise offers an optimized, responsive user interface which can be accessed from mobile devices. On mobile devices, authorized users may access the system using a modern web browser such as Google Chrome, Safari, Firefox, etc. Alternatively, authorized users may access the system using CobbleStone’s optional mobile application. CobbleStone’s complimentary mobile application is compatible with both iOS and Android devices and may be downloaded from their device’s applicable app store.
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
CobbleStone offers complimentary access to its REST APIs, allowing your organization to setup an integration between our system and other applications without needing to purchase CobbleStone’s Integration Platform and/or professional services. This option requires your technical resources to be capable of working with REST APIs.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Contract Insight Enterprise is a commercial off-the-shelf product. CobbleStone does not typically provide customizations to the software to ensure it stays on the standard release path. However, CobbleStone does support technical configurations for systems which are designed to ensure support from version-to-version. Technical Configuration Professional Services are priced separately.

System Administrators are provided with a highly configurable solution which allows them to easily configure and setup the system according to their organization’s needs.
Contract Insight Enterprise provides a highly configurable solution, which allows authorized users to configure the system to your organization’s corporate design and branding. The system also provides configurable security and permissions (either individually or by security groups), configurable fields by contract type with many field type options (with field validation), field groups, add custom-defined tables and sub-grids, flexible searching/reporting, configurable workflow based on contract record field values, configurable dashboards and much more.

CobbleStone offers organizations the ability to add on select modules to the core license and services to best support their needs from our pricing catalog.

Scaling

Independence of resources
The scaling model for our platform is a high availability environment utilizing load balancing for the IIS web servers and HA for the Cloud SQL databases. Resources for the web servers and number of web servers are set to scale automatically with demand and usage. Similarly the Cloud SQL databases are set to scale resources automatically with demand and usage.

Analytics

Service usage metrics
Yes
Metrics types
Priced Separately, is CobbleStones Uptime Dashboard that allows authorized users to view the System Uptime report.
Reporting types
Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Contract Insight Enterprise allows authorized users to export data at the click of a button to a variety of formats. The following areas support the export of data: Search result screens can be exported to the following formats: MS Excel format. Ad-hoc Reports can be exported to the following formats: MS Excel format. Custom Reports can be exported to a variety of formats including (but not limited to): MS Word/MS Excel/PDF, CSV, XML, HTML, DBF, CSV, Rich Text, Image formats, and many more. CobbleStone can provide each hosted/SaaS client with one complimentary data extract per annual term upon request
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
99.9% uptime. CobbleStone will provide a copy of our SLA in the Terms and conditions to further clarify. Applicable SLA credits will be applied following CobbleStone's confirmation of the customer's report of an issue. CobbleStone offers standard SLA levels to all clients. Any additional service level requirements can be individually priced upon request.
Approach to resilience
The scaling model for our Platform is a high availability environment utilizing load balancing for the IIS web servers and High Availability for the Cloud SQL databases, with geographically separated failover datacenters containing daily backups with 30-day retention for full regional Disaster Recovery scenarios

CobbleStone ensures high availability of SQL server instances for SaaS clients by using robust strategies, including data replication across multiple zones and automatic failover mechanisms.
Outage reporting
CobbleStone will notify clients upon CobbleStone confirming there is a true intrusion, attack and/or full denial of service affecting the system(s) a client resides on as soon as possible after confirmation or one hour has elapsed without resolution.

This notification will include a description of the incident, a description of the type of information that was subject to the unauthorized access, a description of the actions taken to protect the personal information from further unauthorized access, and a telephone number that the person may call for further information and assistance.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Only key IT resource stakeholders have access to CobbleStone’s datacenters for the purpose of maintenance, security updates, and new client installations. Internally at CobbleStone, these roles are managed through Active Directory and GPO using the principle of least privilege.

CobbleStone utilizes NetSupport and Datadog for monitoring and logging access to all corporate and SaaS machines.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • Other
Other security governance standards
CobbleStone generally complies with NIST 800-53, NIST 800-171, and CobbleStone maintains a semiannual SOC 1&2 Type 2 along with CSA Star self-attestation, CMMC level 2 self-attestation
Information security policies and processes
CobbleStone generally complies with NIST 800-53, NIST 800-171, and CobbleStone maintains a semiannual SOC 1&2 Type 2 along with CSA Star self-attestation, CMMC level 2 self-attestation.

CobbleStone’s security organization is the CobbleStone Information Technology Security Group (ITSG). The ITSG is a part of all security and compliance for all IT issued policies and procedures.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
This policy covers changes to CobbleStone IT supported systems and information resources upon which any functional unit of the business rely on in order to perform its normal business activities. This includes systems and information resources located in CobbleStone’s Corporate Network (CSCN), as well as CobbleStone’s Production and DR Datacenter environments. In this section, the scope is described and includes areas which are both within and outside of the change management process scope.

In scope includes SDLC, Hardware, Software, Application, System Configuration, Schedule Changes, Telophony and other general changes associated.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
CobbleStone conducts and releases monthly VulPen testing/reports.

The primary scanner is Qualys, but we also run specialized tests with PenTest Tools, Probely, and ImmuniWeb.

Critical OS and software patches will be applied immediately upon verification of the patch to mitigate security risks. If there is a circumstance where a critical patch cannot be immediately applied, the affected services will be disabled until the patch can be applied.

CobbleStone subscribes to multiple newsletters, including NIST and CISA to stay up to date on vulnerabilities, changes in compliance requirements, and security best practices.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
CobbleStone utilizes Qualys Guard Platform’s Indication of Compromise module, Google Cloud’s IDS, and DataDog to monitor server events and logs for alerts on potential intrusions.

CobbleStone will notify clients once confirming a true intrusion, attack, and/or full denial of service affecting the client’s system as soon as possible after confirmation or after one hour without resolution.
This notification will include:
a description of the incident
the type of information subject to unauthorized access
actions taken to protect the information from further access
a telephone number for additional information and assistance
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
CobbleStone will notify clients once confirming a true intrusion, attack, and/or full denial of service affecting the client’s system as soon as possible after confirmation or after one hour without resolution.
This notification will include:
a description of the incident
the type of information subject to unauthorized access
actions taken to protect the information from further access
a telephone number for additional information and assistance
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
CobbleStone Software offers free thirty (30) day trial options for organizations interested in a hands-on test drive of our software. During that trial period, CobbleStone can provide your organization with an out-of-the-box environment for testing. CobbleStone also offers some complimentary configuration assistance during the trial period.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0.1%
Between £250,000 and £500,000
0.25%
Between £500,001 and £1,000,000
0.5%
Between £1,000,001 and £2,500,000
0.75%
Between £2,500,001 and £5,000,000
1%
Over £5,000,001
1.25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
Yes
CSA STAR accreditation date
Monday 17 February 2020
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
CSA Star covers CobbleStones Contract Insight editions SaaS offering and related modules which is priced in this offer.
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
Yes
Any other security certifications
  • TxRAMP Level 2 Certification
  • FedRAMP Ready Status

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at partners@cobblestonesoftware.com. Tell them what format you need. It will help if you say what assistive technology you use.