Skip to main content

Help us improve the Digital Marketplace - send your feedback

VOT Health

V-Suite

The V-Suite is a cloud-based platform that provides market leading visibility and insight over mental health pathways, flow and the efficacy and efficiency of inpatient and community services. It is an essential tool for delivering evidence-based improvement to ensure the effective deployment of multi-million pound budgets.

Features

  • Cloud-hosted on UK servers, no hidden infrastructure costs
  • Browser based platform, with no software installation needed
  • Role-based access controls governed by you
  • Tried and tested with leading NHS providers
  • Agnostic to internal BI platform and EPR system
  • Integrates with Microsoft Authentication meaning no additional logins required
  • Data ingested via SFTP and always encrypted in transit

Benefits

  • Improved time-to-insight
  • Evidence-based clinical, financial, and operational decision making
  • Improved data engagement culture
  • Minimal BI team input required, build and development fully managed
  • Each client supported by subject matter expert analysts
  • Out of the box financial and operational improvement opportunities
  • Enables robust allocation of millions of pounds of resource
  • Complements existing business intelligence tools and resources

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@vothealth.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 2 1 7 6 4 0 4 8 6 4 9 3 8 5

Contact

VOT Health Rob Stafford
Telephone: 07703537953
Email: info@vothealth.co.uk

About your service

Service categories

Application Development and Deployment

Analytics and business intelligence

  • Business Intelligence
  • Advanced and predictive analytics
  • Location and geospatial data management and analytics
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Microsoft Authentication integration to enable simpler login is only possible
for users on a Microsoft tenancy
System requirements
  • Modern web browser
  • Ability to provide data via SFTP
  • Access to an internet connection

User support

Email or online ticketing support
Yes
Support response times
We accept support requests via email. All enquiries are responded to within an agreed Service Level Agreement (SLA). Our support team is committed to achieving the highest standards of communication and will follow up questions by phone or email as needed to ensure a prompt and relevant response.

Whilst weekend working is not the norm, we will work weekends and unsocial hours to meet any urgent client needs.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
Support via email or phone during and if needed outside of business hours is included in the overall cost.

A 'navigator', who acts as a customer success/technical account manager and main point of contact, is dedicated to each account and can help triage needs and provide progress updates to users.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
A dedicated ‘Navigator’ - a subject matter expert analyst from the VOT Health team - will be introduced prior to kick-off. Navigators are specialists at leveraging maximum value from data, building and configuring reports, data analysis and presentation. An additional member of the VOT team will act as a client satisfaction lead and will support successful evidence-based delivery.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
In app user guides, accessible via a one click button
End-of-contract data extraction
Upon contract end, we ensure a smooth data extraction process for our
clients by converting the information stored in database tables into CSV extracts. These extracts are then placed in a shared folder within the relevant client's tenancy. The client can then securely access, transfer or download these files at their discretion. This approach ensures a smooth transition, allowing users to retain ownership and control over their data even if discontinuing our services. By providing access to CSV extracts in a shared folder, we prioritise data accessibility and ease of retrieval for our clients, empowering them to seamlessly integrate their data into alternative systems or workflows as needed. This user-centric approach reflects our commitment to transparency, data portability, avoidance of vendor lock-in and customer satisfaction throughout the entire lifecycle of our services
End-of-contract process
As well as extracting client data into CSV extract files stored in a shared
folder within their tenancy, we also assist in closing services by discontinuing platform access, revoking user permissions, and deactivating accounts as per contract terms. We review final billing to settle any outstanding payments or fees, including prorated charges.

Included in the contract price are core services like platform access, support, updates, maintenance, and data storage within defined limits. Additional costs may arise for optional services or customisations. We prioritise transparency and clarity in communicating these costs upfront, ensuring clients understand and agree before implementation. Our goal is to maintain fairness and satisfaction throughout the contract, including its conclusion.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
V-Suite is accessed via a web-based interface. Users sign in and interact with dashboards, reports and filters in the browser to explore pathway flow, activity and performance metrics. Power BI is used; reports are delivered through the Power BI Service with role-based access control. The service supports standard modern browsers and is designed for keyboard and screen-reader compatible navigation for core user journeys.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Designed to meet WCAG 2.2 AA for core user journeys. We conduct internal accessibility reviews using assistive technologies and automated checks.
API
No
Customisation available
Yes
Description of customisation
Each V-Suite is configured for a mental health provider or collaborative's unique set of services. Insight tools and visualisations can be renamed or rebadged as requested. Reports are entirely customisable to meet user and project needs. Custom needs can be met by a VOT Health staff member in a controlled manner.

Scaling

Independence of resources
We provision each client with a separate, segregated set of service components (including dedicated data storage and segregated network/access controls). Compute capacity is managed to agreed service levels, with monitoring and scaling in place so one client’s usage does not adversely affect another.

Analytics

Service usage metrics
Yes
Metrics types
Who is accessing tools?; What are they accessing?; & For how long?
Reporting types
Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Tools can often be configured to allow end-users to export aggregate data. Other custom exports (e.g. to feed internal BI) can be discussed upon request.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
SLA in place for 24/7 and 99.5%. There is no refund policy
Approach to resilience
Available on request
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
We use multiple security methods. Access is controlled through RBAC (Role Based Access Control) at application and form level security, allowing individual users to be allocated to specified security groups based on their function. This ensures that permissions can be finely tuned. Sensitive data and operations are tightly regulated and accessible only to authorised personnel. Additionally, we maintain environments with read-only access to prevent unauthorised data modification. Support is only available to identifiable client staff users and configuration or access requests only from nominated service leads.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials
Data Security & Protection Toolkit
Information security policies and processes
Our infrastructure provision, development, delivery and support processes are governed by a comprehensive set of policies that address information security, data protection, access control, and incident management.

Our 'Data Protection Policy', for example, ensures compliance with GDPR principles and the correct, lawful, and fair handling of all personal data. We implement this policy through a comprehensive set of processes that define continuous monitoring, regular audits, and mandatory employee training. Our managing partner takes responsibility for overseeing compliance with this policy. Our CTO is accountable for ensuring our infrastructure is as secure as it can be. Each quarter the Board meets to formally review our data security against a best practice framework and ensure continuous learning is taking place as a result of any data breach. This structure ensures top-down commitment to security. Our policy and procedures are also externally audited annually.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All components of our services are meticulously tracked throughout their lifetime. For each service we maintain a Service Definition document that defines its components, identifying configuration and any dependencies and constraints such as minimum version numbers and compatibility. Development components are stored in our code repository system from development through to retirement. We produce release notes for each new system release and scrutinise changes for security impact via change control approval and release management processes in line with best practice guidance.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We adhere to security standards through a holistic approach, starting with architectural design that selects technical components to minimise threat vulnerability. Our configuration management tracks all components, monitored via vendor and third-party security lists. Vulnerability alerts for client systems are promptly reviewed, with updates aligned with risk severity. Security patches and antivirus updates are automatically enforced on all staff devices. User access is centrally controlled.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
All machines are connected to a remote monitoring and management (RMM) service provided by our IT support provider. We ensure all software & OS updates are promptly enacted. Bitdefender Endpoint Security Tools are installed, these tools enhance breach detection and prompt response with structured protocols. We have no unsupported software on machines. Our RMM ICT managed service provider acts as sole administrator. Response time to a potential compromise is immediate guided by our managed service provider to minimise impact.
We also perform penetration testing annually.
Incident management type
Supplier-defined controls
Incident management approach
Our incident management procedures include predefined processes for
various events. Staff report incidents to the Information Governance Lead, who coordinates investigations. We follow specific procedures for different breaches, such as theft or unauthorised access. All incidents are recorded using an incident report form and classified based on severity. The Information Governance lead determines if further reporting is needed, like informing the data controller, ICO, police or other authorities. Incident reports detail actions taken and risk assessments. These procedures ensure prompt and effective response to information security incidents, aligning with best practices and regulatory requirements.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Core functionality is included, with a focus on providing the insight support need for a single pressing mission-critical project, such as flow improvement through a pathway or service.

A trial period would normally be up to 3 months post platform go-live.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0.0%
Between £250,000 and £500,000
5.0%
Between £500,001 and £1,000,000
10.0%
Between £1,000,001 and £2,500,000
15.0%
Between £2,500,001 and £5,000,000
20.0%
Over £5,000,001
25.0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
1228f157-a243-4aec-a80b-599b4a2e44b8
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
NHS Data Security and Protection Toolkit

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@vothealth.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.