Black Rainbow: NIMBUS Forensics Case & Quality Management for External & Internal Investigations
NIMBUS Forensics is a comprehensive COTS Forensic Case and Quality Management System/LIMS for Forensic Science disciplines; Crime Scene Investigators, Digital (Mobile, CCTV, Video, Cellsite, etc) and Traditional Forensics (Fingerprints, DNA, Ballistics/Firearms etc), Forensic Collision including Exhibit & Asset Management, workflows, Staffing Competency/Training, ISO17025/ISO17020 compliance, auditing, reporting and data retention management
Features
- End to End Case Management
- Crime Scene Management
- Exhibit and Asset Management
- Forensic Workflows Management
- Integrated Submission Portal
- Forensic Management Unit
- MI Reporting and Evidential Reporting
- Data Retention Management
- Integrated Quality Management System, including Audits, Staffing, Competencies
- Access Control and Audit Management
Benefits
- SOP-Aligned Automation and Workflows, Increasing Quality
- Real Time Case Visibility and Reporting
- Discipline specific configuration and workflows
- Faster Case Progression and Victim Support
- Comprehensive and Auditable Chain of Custody Record
- Regulatory Compliant Data Retention and Disclosure
- Unified System for all Forensics Science Disciplines
- Integrated QMS, Supporting Standards incl. ISO/IEC 17020 and ISO/IEC 17025
- User Enablement, Training and Support
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 2 6 1 6 2 6 2 6 1 9 1 4 6 4
Contact
BLACK RAINBOW CONSULTING LIMITED
Ian O'Callaghan
Telephone: +353872335214
Email: ops@blackrainbow.com
About the service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Public Order and Safety
- Police
- Defence
- Other
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
Standard support is provided Monday to Friday, 09:00–17:00 UK time, excluding public holidays.
An optional 24/7 support package is available as a separately priced service and can be included upon request during the call‑off agreement stage. - System requirements
-
- Modern browser: Chrome, Edge, or Safari (latest versions).
- Stable internet connection with minimum 10 Mbps bandwidth.
- Device with minimum 8GB RAM for optimal performance.
- Screen resolution of 1280x720 or higher recommended.
- JavaScript and cookies enabled in browser settings.
- PDF reader for accessing system-generated reports
- Secure email client for notifications and alerts.
- Optional VPN for secure remote access if required.
- SSO integration requires Active Directory or equivalent service.
- TLS 1.2 or higher supported for secure connections.
User support
- Email or online ticketing support
- Yes
- Support response times
- BlackRainbow provide email and online ticketing support as standard through our Support Portal. All support requests are logged, prioritised, and tracked through our secure ticketing system. Our standard response time is within one business hour for critical issues and four business hours for non-critical queries during Monday to Friday, 09:00–17:00 (UK time).
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
BlackRainbow provide tiered support designed to meet operational needs and ensure continuity of service.
Standard Support: Included in the subscription cost. Available Monday to Friday, 09:00–17:00 (UK time). Covers email and ticketing support, phone assistance, and access to our knowledge base. Response times: critical issues within one business hour; non-critical within four hours.
Enhanced Support: Available at extra cost. Includes extended hours, priority escalation, and out-of-hours coverage for urgent incidents. Pricing is based on scope and agreed during onboarding.
A Technical Account Manager is provided under Enhanced Support to act as a single point of contact for strategic guidance, service reviews, and escalation management. For complex deployments, a Cloud Support Engineer can be engaged for technical troubleshooting and configuration support.
This structure ensures buyers have flexibility to choose the level of assurance and responsiveness that aligns with their operational risk and resource requirements. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
BlackRainbow works with customers to agree the specific NIMBUS configuration, installation timeline, and key dates. These may be defined within a jointly completed Statement of Work (SOW) to ensure alignment on project goals and deliverables. Our preferred approach is to enable customers to configure the system themselves from the outset, supported by BlackRainbow guidance. This ensures customers are educated and enabled from day one and reduces the need for ongoing professional services.
Customers who self‑host in their own cloud environment may choose to initially configure NIMBUS in a dedicated BlackRainbow cloud environment. This enables quick installation and changes during configuration, while providing time to prepare their production environment in parallel. Projects typically follow the steps below:
BlackRainbow provides a standard “out‑of‑the‑box” NIMBUS build.
Customers progress through Enablement training.
Configuration support is provided as agreed.
Workflow training is delivered to support customer independence.
User training is provided before UAT.
UAT is undertaken by the customer.
Go‑live is customer‑driven, with a BlackRainbow technical lead available if required.
Post–go‑live knowledge‑share sessions are provided for six weeks.
Ongoing support is transitioned to the BlackRainbow service support team and dedicated Account Manager. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
-
When a contract ends, buyers can extract all their data securely from NIMBUS using our built-in export tools. Data can be exported in open formats such as CSV, XML, or JSON, ensuring compatibility with other systems and compliance with UK Government standards. This includes all case records, entity data (Person, Object, Location, Event), attachments, and audit logs.
Buyers can choose to perform the export themselves or request assistance from our technical team. For large datasets, we recommend scheduling extraction in advance to maintain performance and security.
All data remains under the buyer’s control throughout the process. Once extraction is complete, we follow strict data sanitisation procedures to securely remove residual data from our systems in line with GDPR and UK policing requirements. - End-of-contract process
-
At the end of the contract, buyers retain full control of their data. We provide clear guidance and tools to support secure data extraction in open formats such as CSV, XML, or JSON and ensures buyers can transition without disruption.
Once data extraction is complete, we follow strict data sanitisation procedures to permanently remove residual data from our systems in line with GDPR and UK policing standards.
Optional services, such as extended access to the platform after contract expiry or technical consultancy for complex migrations, are available at extra cost and agreed in advance.
Our approach ensures transparency, compliance, and continuity for organisations moving away from the service while maintaining security throughout the process. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Change in resolution to suit the mobile device.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- We use a COTS Information Technology Service Management Tool which is accessible via any modern web browser. Customers can self-sign-up to raise incidents, seek product help or change management setting priority levels, description (add attachments) of the request and status updates. In addition access to knowledge base materials and product version release notes.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have tested the NIMBUS portal interface against WCAG 2.2 AA standards to ensure accessibility for users with disabilities. Testing included screen reader compatibility (NVDA and JAWS), keyboard-only navigation, and colour contrast validation. These tests confirmed that all core workflows, including case creation, updates, and navigation through dashboards, are fully accessible without reliance on a mouse. We also validated form fields for correct labelling and error messaging to support users with visual or cognitive impairments. Feedback from assistive technology users was incorporated into design refinements, ensuring the portal remains inclusive and compliant with UK public sector accessibility requirements.
- API
- Yes
- What users can and can't do using the API
- BlackRainbow provides opportunities for integrations with NIMBUS through our REST API. We have extensive experience designing and delivering successful integrations across a wide range of enterprise environments. Our approach is always to scope integrations collaboratively with the customer to ensure they are clearly understood, technically feasible, and aligned with operational priorities.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- NIMBUS guarantees resource independence through a multi-tenant architecture designed to isolate each customer environment. Every organisation operates within its own logically separated instance, ensuring that demand from other users does not impact performance or availability. We allocate dedicated compute, storage, and bandwidth resources within our cloud infrastructure, supported by auto-scaling capabilities to handle peak loads without degradation. Continuous monitoring of system health and capacity allows us to proactively manage performance and maintain service levels. This approach ensures consistent uptime, predictable response times, and a secure environment for all customers, regardless of overall platform demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
NIMBUS provides service usage metrics.
We monitor and report on key service performance indicators, including system availability, which is maintained at 99.5% uptime under normal operating conditions. Metrics include uptime statistics, incident response and resolution times, and capacity monitoring to ensure scalability. These are tracked continuously and made available through scheduled reports or on request, giving organisations clear visibility of service reliability. - Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data directly through NIMBUS using secure, built-in export tools. All case records, entity data (Person, Object, Location, Event), attachments, and audit logs can be extracted in open formats such as CSV, XML, or JSON.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
BlackRainbow guarantees an availability target of 99.5% for the service, supported by an agreed RTO of less than eight hours and an RPO of zero hours through multi site replication and failover capability in our cloud environments. Our architecture is built across a minimum of three UK availability zones and uses replica aware services, automated scaling and continuous monitoring through Application Insights. This gives early visibility of issues and allows us to maintain performance during periods of high demand.
If availability drops below 99.5% in any measured month, service credits can be applied. These credits are calculated against the monthly service charge and scaled according to the level of disruption.
Our SLAs are underpinned by disaster recovery procedures that include geo redundant backups, automated redeployment routines and the ability to rebuild an entire environment inside the agreed RTO if required. This provides a resilient service with clearly defined expectations and a fair remedy if availability falls short. - Approach to resilience
- NIMBUS is designed with resilience as a core principle, ensuring uninterrupted service even under adverse conditions. This is achieved through a layered approach that addresses component-level failures, full failover scenarios, and operational continuity across multiple environments. We operate from three UK datacentres simultaneously, providing geographic redundancy and high availability. This architecture ensures that if one datacentre experiences an outage, services can continue seamlessly from the remaining sites without disruption. At the component level, we implement automatic failover mechanisms. Each critical service runs in a clustered configuration, allowing workloads to shift instantly to healthy nodes in the event of a failure. This design minimizes downtime and prevents single points of failure. Our software is replica-aware, enabling intelligent load balancing and automatic switching between nodes. This ensures optimal performance and continuity even during maintenance or unexpected outages. Replication strategies are applied across application services and databases to maintain consistency and availability.
- Outage reporting
- BlackRainbow provides a customer nominated email alert so operational teams are notified when an incident is confirmed. Customers can also monitor a status end point, which supports automated polling and integration into existing monitoring tools. This gives organisations a straightforward way to track service availability without relying solely on email updates.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- BlackRainbow restricts access to management interfaces through controlled administrative pathways. Access is secured through a bastion host, supported by access control policies that limit who can reach administrative services. Just in time permissions are applied so elevated access is only granted for the specific task and for a limited duration. Support channels follow the same principle, with access controlled and activity tracked through our service desk processes. This ensures only authorised staff can access management functions or support environments, and that all activity is recorded and attributable.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
BlackRainbow is committed to robust security practices, underpinned by ISO/IEC 27001, ISO/IEC 9001, and Cyber Essentials Plus certifications, and aligned with NCSC Cloud Security Principles. All data at rest is encrypted using AES-256, with secure key management and rotation policies. NIMBUS supports secure authentication methods, including Microsoft Entra ID (Azure AD) and Windows Integrated Authentication, enabling Single Sign-On (SSO) and customer-controlled multifactor authentication.
Role-Based Access Control (RBAC) provides granular permissioning, allowing administrators to define roles and enforce least-privilege access. Authentication and role assignment are managed by the customer (e.g., via Entra ID), while BlackRainbow ensures solution availability and support. Regular audits and vulnerability management processes maintain compliance and security integrity. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- BlackRainbow manages configuration and change through a defined release cycle that moves work through development, testing, staging, quality checks and production. This provides a clear record of how components progress through their lifetime and keeps each stage traceable. Every release is first applied to a test instance where acceptance testing confirms the migration path and verifies that the update behaves as expected before deployment. Release notes document what is introduced or amended, giving customers the detail needed to review any impact. The testing and review process acts as the checkpoint for assessing operational and security considerations.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- BlackRainbow operates its vulnerability management activities within an ISO 27001 certified framework, which sets the structure for how risks and issues are identified and controlled. Telemetry, dependency behaviour and fault tracking are captured through Application Insights, giving visibility of conditions that may indicate a vulnerability. Threats are assessed during testing phases where every release is first applied to a test instance and validated before production deployment. This provides the checkpoint for identifying issues and confirming expected behaviour. Patches and updates are deployed through the same controlled release cycle and documented through release notes
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- BlackRainbow uses real time alerting across all environments to identify issues, including errors, slow requests, dependency timeouts and threshold breaches, which are automatically logged and triaged through the service desk system. Telemetry and fault tracking from Application Insights provide visibility of conditions that may indicate a potential compromise. When an alert is raised, support engineers review and assess the impact, applying workarounds where appropriate and progressing incidents through our ISO 27001 aligned incident management procedure. All incidents are recorded, prioritised, escalated and resolved using documented processes, with updates provided to the reporting party and full traceability throughout.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- BlackRainbow operates a documented incident management procedure that sits within its ISO 27001 accreditation. All incidents are recorded, uniquely identified and fully traceable through the service desk system. Users report incidents via the service desk using the portal, email or telephone. Incidents follow defined processes for recording, prioritisation, business impact assessment, classification, updating, escalation and closure, with responsibilities clearly assigned. Pre defined processes exist for common events through this structure. Resolution updates and closure notifications are provided to the reporting user, and BlackRainbow supplies root cause analysis for P1 and P2 incidents within agreed timeframes.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- CFA - Centre for Assessment
- ISO/IEC 27001 accreditation date
- Tuesday 22 June 2021
- What the ISO/IEC 27001 doesn’t cover
- All current business activity is covered under this certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- CFA - Centre for Assessment
- ISO 9001 accreditation date
- Tuesday 11 June 2024
- What the ISO 9001 doesn’t cover
- All current business activity is covered under this certification.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 6b61f38d-8d62-42b9-b417-73a1ab98254e
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- 452df442-4a6c-423a-8f76-b79e74abcb11
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition