Data Exchange Platform
The Data Exchange Platform is a cloud-based service that enables organisations to securely share data between partners using schema-driven submission, policy-controlled access and full auditability. It supports regulated data exchange across government and regulated sectors, enforcing field-level governance, consent rules and compliance requirements.
Features
- Schema-driven dataset definitions with version control
- Field-level metadata tagging for governance and compliance
- Policy-controlled data visibility per partner and use case
- Consent-aware data filtering and access enforcement
- No-code portal for schema and policy configuration
- Auto-generated web forms, Excel templates and APIs
- Secure API access with authentication and encryption
- Multi-partner data routing from single submission
- Tamper-evident audit logging of all data exchanges
- UK-hosted cloud deployment supporting data residency
Benefits
- Share regulated data securely without bespoke integrations
- Reduce compliance risk through automated governance controls
- Enable multiple partners using a single data submission
- Improve audit readiness with complete data exchange records
- Accelerate onboarding of new data sharing partners
- Adapt quickly to regulatory or schema changes
- Reduce operational cost of managing data integrations
- Support cross-organisation collaboration with controlled data access
- Improve trust through transparent and auditable data sharing
- Maintain data sovereignty aligned with public sector requirements
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 3 0 0 2 2 8 2 2 6 1 4 8 5 4
Contact
ULTRA DYNAMIX LTD
Muhammad Umer Ishtiaq
Telephone: +61 424060800
Email: umer.ishtiaq@ultradynamix.com
About your service
- Service categories
-
Application Development and Deployment
Data management
Data integration and intelligence
- Data Ingestion and Transformation Software
- Dynamic Data Movement Software
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
-
Integrate with other systems (via APIs, Excel ingestion, portals, Dataverse/Azure)
Operate independently as its own SaaS (schema definition, submission, governance, audit) - Cloud deployment model
- Private cloud
- Service constraints
- The service is delivered as a cloud-based SaaS and requires reliable internet connectivity. Availability may be affected during planned maintenance, which is communicated in advance and scheduled outside standard business hours where possible. Support is provided during UK business hours. Configuration limits may apply based on selected service tier. The service integrates with customer systems using standard APIs or file-based submission formats and does not include bespoke custom development as part of the standard offering.
- System requirements
-
- Reliable internet connection for secure cloud service access
- Modern web browser supporting current HTML5 standards
- Organisational user accounts for authentication and access control
- Ability to access secure HTTPS endpoints
- Supported spreadsheet software for CSV or Excel file handling
- Secure network configuration allowing outbound cloud connections
- Administrative access for initial service configuration
- Optional API client capability for system integrations
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support is available Monday to Friday, 9am to 5pm UK time, excluding UK public holidays.
Response targets during support hours are:
• Critical incidents: within 4 hours
• High priority: within 8 hours
• Normal priority: within 24 hours
• Low priority: within 48 hours
Requests received outside support hours, including weekends and UK public holidays, are logged and responded to on the next business day. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Standard Support (included):
All customers receive standard support at no additional cost. This includes email and phone support available Monday to Friday, 9am to 5pm UK time, excluding UK public holidays. Response targets are: Critical incidents within 4 hours, High priority within 8 hours, Normal priority within 24 hours, and Low priority within 48 hours. Standard support includes access to documentation, routine updates and bug fixes.
Premium Support (optional):
Premium support is available at an additional cost of £995 per month. This includes all standard support features, prioritised responses, and scheduled service review calls.
Account Management and Technical Support (optional):
A dedicated account manager is available at £500 per month. A technical account manager or cloud support engineer is not provided as standard but can be made available for larger implementations at £500 per month.
Onsite Support (optional):
Onsite support, including workshops and training, is available at additional cost and charged per day plus travel expenses. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Users are supported through a structured onboarding process. This includes access to online user guides and setup documentation, initial configuration guidance for administrators, and remote onboarding sessions to help organisations configure schemas, workflows, access permissions and integrations.
Optional training sessions can be provided for administrators and end users, delivered remotely or onsite at additional cost. Ongoing support is available through email and phone support channels during UK business hours to assist users as they begin using the service. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At the end of the contract, authorised users can extract their data using built-in export functionality provided by the service. Data can be exported in common, open formats suitable for reporting, archiving or transfer to other systems. Users are able to perform data exports during the contract term and up to contract end. Support is available to assist with data extraction if required.
- End-of-contract process
-
At the end of the contract, access to the service is scheduled for closure in line with agreed notice periods. During the contract term and up to contract end, authorised users can export their data using standard export functionality. Following contract termination and confirmation, customer data is securely deleted in accordance with data retention and sanitisation policies.
The contract price includes standard support, access to the service, and use of built-in data export features. Additional services, such as assisted data extraction, extended access periods, bespoke transition support, or onsite assistance, are available at additional cost if required. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service provides the same core functionality on mobile and desktop devices. On mobile, the user interface is optimised for smaller screens with simplified layouts and touch-friendly controls. Configuration, administration and detailed reporting activities are more easily performed on desktop devices due to screen size.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure, web-based interface using a modern browser. It provides role-based views for users, administrators and partners to submit data, configure schemas and policies, manage access permissions, review audit logs and access reports. The interface is responsive and adapts to desktop, tablet and mobile devices, supporting secure data submission and management without local software installation.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service interface has been tested using common assistive technologies, including screen readers, keyboard-only navigation and browser accessibility tools. Testing focuses on ensuring that content is readable, controls are operable without a mouse, form fields are correctly labelled, and key workflows such as data submission and review can be completed using assistive technologies. Accessibility checks are performed as part of ongoing service improvement, and feedback is incorporated into interface updates to support inclusive access.
- API
- Yes
- What users can and can't do using the API
-
The service provides secure APIs that allow authorised users and systems to submit data, retrieve submitted datasets, query submission status, and integrate with external systems. APIs can be used to automate data ingestion, validation and exchange workflows in line with configured schemas and policies.
Users can make changes to data submissions and retrieve results where permitted by their assigned roles and access permissions. API access is authenticated and authorised, and all activity is logged for audit purposes.
Service configuration activities such as creating schemas, defining governance rules, managing user roles, and changing core service settings are performed through the web-based interface rather than the API. The API does not support unrestricted administrative actions or bypassing governance controls. Usage limits and throttling may apply to ensure service performance and security. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The service can be customised through built-in configuration options rather than bespoke software development. Authorised administrators can configure dataset schemas, field definitions, validation rules, submission workflows, access permissions and data sharing policies using the web-based interface.
Users can customise views, filters and reporting outputs within the permissions assigned to them. Integration settings, such as API access and file-based submission options, can also be configured.
Customisation is performed by buyer-authorised administrators or designated partner users with appropriate roles. Core platform functionality and underlying service components are not modified, ensuring consistency, security and supportability across customers.
Scaling
- Independence of resources
- The service is delivered using a scalable, cloud-based architecture that allocates resources dynamically based on demand. Usage is monitored to ensure fair performance across customers, and controls are in place to prevent one customer’s activity from adversely affecting others. Capacity management, throttling and monitoring are used where appropriate to maintain service availability and performance for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides usage metrics including numbers of active users, data submissions processed, submission status, processing volumes and activity over time. Metrics can be used to support operational monitoring, capacity planning and reporting. Audit-related metrics support visibility of data exchange activity across partners and time periods.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Authorised users can export their data directly from the service using built-in export functionality. Data can be selected and downloaded on demand in common file formats for reporting, archiving or transfer to other systems. Exports can be performed by users with appropriate permissions without supplier involvement. Support is available to assist with exports if required.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is provided with a target availability of 99.9% per calendar month, excluding planned maintenance. Planned maintenance windows are communicated in advance and scheduled outside standard business hours where possible.
If the monthly availability target is not met, customers may request a service credit applied to their next billing period. Service credits are calculated on a pro-rata basis depending on the level of availability achieved. Service credits are the sole and exclusive remedy for failure to meet availability targets. - Approach to resilience
- The service is designed for resilience using a cloud-based architecture that supports redundancy and automated recovery. It is hosted on managed datacentre infrastructure with built-in resilience for power, networking and hardware. Service components are monitored continuously, with automated alerts and recovery processes in place to minimise disruption. Regular backups are performed to support data recovery. Further details of the resilience arrangements and architecture are available on request.
- Outage reporting
- Service outages and significant incidents are communicated to customers by email alerts sent to nominated contacts. Updates are provided during an incident where appropriate and once service is restored. The service does not provide a public status dashboard or an outage reporting API.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted using role-based access controls so that only authorised administrators can perform configuration and administrative tasks. Authentication is required for all management access and is protected using multi-factor authentication where supported. Support channels are limited to named contacts authorised by the customer, and identity is verified before support actions are taken. Administrative and support activities are logged to support accountability, monitoring and audit requirements.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- The organisation follows documented security governance practices aligned with the Software Security Code of Practice, including secure development, access control, vulnerability management, and incident response. While security governance is not formally certified to an external standard, controls are reviewed regularly and supported by external security testing.
- Information security policies and processes
-
The organisation follows documented information security policies covering access control, data protection, secure development, incident management and change management. Policies are approved and overseen by a named senior individual with board-level authority who is responsible for security governance and risk management.
Security responsibilities are defined through role-based access controls and segregation of duties. Compliance with policies is supported through staff awareness, onboarding guidance, and regular reviews. Operational controls, monitoring and periodic security testing are used to identify and address issues. Adherence to policies is monitored as part of routine service management and operational reporting, with issues escalated to senior management where required. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Service components are tracked throughout their lifecycle using internal configuration records that identify environments, versions and dependencies. Changes are logged, reviewed and approved by authorised personnel before deployment.
Each change is assessed for potential security and operational impact, including access control, data handling and service availability. Where relevant, changes are tested in a controlled environment prior to release, and rollback options are considered to minimise risk. Change activities are documented and monitored as part of routine service management. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Potential threats are identified through monitoring, periodic security testing, external penetration testing, and review of service changes. Vulnerabilities are assessed based on risk, likelihood and potential impact to confidentiality, integrity and availability. Critical security patches are prioritised and applied as soon as practicable, with lower-risk updates deployed through the standard change management process following testing. Information about threats is obtained from cloud platform security advisories, trusted industry sources, vulnerability disclosures, and findings from external testing and internal reviews.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is performed through continuous logging, alerting and review of service activity to identify unusual behaviour or potential security compromises. Logs and alerts are monitored to detect unauthorised access, abnormal usage patterns or security events. When a potential compromise is identified, it is investigated promptly, access may be restricted where necessary, and incident management procedures are followed. Incidents are prioritised based on severity, with critical security incidents responded to as soon as practicable and within defined response targets, and customers are notified where appropriate.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The organisation follows documented incident management procedures with predefined processes for common service and security events. Users can report incidents through email or the service support ticketing process. Reported incidents are logged, assessed, prioritised and tracked through to resolution in line with defined response targets. For significant incidents, customers are kept informed during the incident and provided with a summary report once resolved, including details of impact, actions taken and any corrective measures identified.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
-