Skip to main content

Help us improve the Digital Marketplace - send your feedback

EMBRIDGE CONSULTING (UK) LIMITED

LEO - B2B Data Integration and Transformation

Removing the burden of integration complexity, LEO will extract, transform and load data between B2B systems, in different styles and formats, in a managed service delivered through a subscription-based fully managed Integration-as-a-Service model.

Features

  • Supports both batch and near-real-time flows for operational flexibility
  • Standardises file ingestion regardless of structure, reducing partner onboarding effort
  • Supports high-volume processing without performance degradation during peak periods
  • Enables predictable execution times through monitored and optimised data pipelines
  • Automatically retries transient failures, reducing manual intervention and operational noise
  • Prevents data loss through controlled buffering during target system unavailability
  • Provides clear error diagnostics, shortening investigation and resolution times
  • Controls execution order to respect system dependencies and processing windows
  • Provides traceability from source records to target transactions for audits
  • Adapts to source schema changes without breaking existing integrations

Benefits

  • Reduced integration overhead through fully managed, scalable, reliable operations
  • Predictable costs with transparent pricing replacing unpredictable integration maintenance expenses
  • Reduced operational risk via monitored, supported, and continuously improved integrations
  • Lower dependency on scarce integration specialists within customer teams globally
  • Clear accountability with single service owner responsible end-to-end delivery outcomes
  • Freedom to focus internal teams on core business initiatives strategically
  • Reduced onboarding effort for new systems using standardised integration frameworks
  • Faster issue resolution via proactive alerts and expert support teams
  • Lower total cost of ownership compared to self-managed integration stacks
  • Future-ready foundation supporting AI, automation, and advanced analytics at scale

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at enquiries@embridgeconsulting.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 5 4 8 0 8 1 6 5 8 3 6 4 4 7

Contact

EMBRIDGE CONSULTING (UK) LIMITED Emma O'Brien
Telephone: 01474555505
Email: enquiries@embridgeconsulting.com

About your service

Service categories

Application Development and Deployment

Data management

Data integration and intelligence

  • Data Ingestion and Transformation Software
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
LEO operates within clearly defined service boundaries to ensure reliability and compliance.

End-to-end performance depends on source and target system availability, data quality, and vendor-imposed API limits.

Processing volumes, execution windows, and near-real-time behavior are constrained by upstream system capabilities and vendor-imposed limits.

Changes to schemas, data models, or business rules may require impact assessment and controlled updates.

Data residency, retention, and security policies may restrict processing options.

Third-party outages and breaking changes are outside direct control.

Service outcomes rely on timely customer collaboration for issue resolution and change approval.
System requirements
  • Source/Destination systems must expose data via files, APIs, or database
  • Stable network connectivity between customer systems and integration service

User support

Email or online ticketing support
Yes
Support response times
Response and resolution times are defined on the SLAs, which are dependent on the product (solution) and the band (contract) the customer adopts, when onboarded. The core SLAs are stipulated in the terms attached.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support Levels are defined on the SLAs, which are dependent on the product (solution) and the band (contract) the customer adopts, when onboarded. The core SLAs are stipulated in the terms attached.
Support available to third parties
No

Onboarding and offboarding

Getting started
Every delivery includes an onboarding stage to facilitate users to start using LEO services, up to the point the customer is ready to go live.

Depending on the product/solution the onboarding stage may include online training (on the associated technologies) but mostly is composed by configuration support for both producer and consumer systems, that will be served by the integration eventually deployed.

Onboarding also includes consultancy support to help implement the designed end-to-end business process, as well as facilitating the engagement with other software parties/vendors, involved on the technical delivery of the adopted solution.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
LEO integration service doesn't store persistently any PII or relevant data, result of the transactional activities of the integration(s).

Customer data is mostly in transit from the data producer system to the data consumer system. After each integration run, all data and/or associated files are deleted one hour after being processed.

Only metadata is gathered and stored, for the purposes of reporting control or metrics.

When the contract ends and no more metric reports are required by the customer, they can raise a support ticket with customer support, to extract and delete any data relevant to the customer integration activity.

Their data will be delivered in CSV or Pipe Separated format and then deleted from our records.
End-of-contract process
There are no additional fees at the end of the contract.

If not renewed, any scheduled process/routine will be stopped.
Any API keys will be disabled and service access is removed.

The customer has the option to request their data and it to be removed from our servers. This is available via customer support request.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Customer will have access to documentation on the following ways:

- By accessing our live documentation repository, using an internet browser
- By receiving directly the documentation in PDF format, via email
- By downloading the documentation in PDF format, using a link provided.

Using the service

Web browser interface
No
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
When the subscribed LEO product (or integration solution) is made available via API, and depending on the product, the users can:

- Send data directly (or via the data producer system) to be ingested and processed
- Trigger an integration procedure
API documentation
Yes
API documentation formats
  • HTML
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
No

Scaling

Independence of resources
LEO architecture is designed to be scalable and agile.
- The back-end is currently made of a cluster with 2 servers, ready to scale vertically or horizontally
- The cloud infrastructure is designed with load balancer at the infrastructure level to distribute the load between the available servers
- The back end system in cluster format also handles the load , balancing each routine within the integration run between the cluster nodes for more efficiency.

Analytics

Service usage metrics
Yes
Metrics types
Depending on the service subscribed, LEO provides:

- Weekly reports: Operational style report regarding the weekly run, success rate, etc.
- Monthly reports: More complete report, with credit balances (where applicable), year to date figures, etc.

This report is delivered via email.
Reporting types
Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
Within Microsoft Azure UK datacentres, data is stored in Azure Storage Accounts which are protected using layered physical, technical, and operational controls. Data residency is enforced by region selection, ensuring data remains within the UK. Datacentres are physically secured with 24/7 monitoring, controlled access, and independent audits. All data at rest is encrypted by default using industry-standard AES-256 encryption. Encryption keys are securely managed by Azure. When hardware is retired, data is securely sanitised or destroyed. Storage services are designed with built-in redundancy to ensure durability, resilience, and high availability.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Users will be provided with their data in CSV or Pipe separated format.
To export data, users should raise a ticket request with customer support.
When ready, a link to download the file(s) will be provided.

Only metadata is persistently stored within our servers. this data is used for metric reports.
Exported data will be metadata related to integration transactions.

Customer processed data is only in transit and is deleted 1 hour after being processed.
Data export formats
  • CSV
  • Other
Other data export formats
Pipe separated format
Data import formats
  • CSV
  • Other
Other data import formats
Pipe separated format

Data-in-transit protection

Data protection between buyer and supplier networks
Other
Other protection between networks
Inbound data is protected in the following way:
- LEO API endpoints are published under HTTPS using TLS v1.3.
- Customers must provide an sFTP server with authentication for data pull.
- Customers must provide a secure tunnel (VPN), in case of direct database access.

Outbound data is protected in the following way:
- Customers must provide API endpoints published under HTTPS using TLS v1.2 or above.
- Customers must provide an sFTP server with authentication for data push.
- Customers must provide a secure tunnel (VPN), in case of direct database access..
Data protection within supplier network
Other
Other protection within supplier network
LEO cloud infrastructure is provided with:
- Azure Front Door - firewall to prevent attacks and overload.
- API Management - enforcing security, policies and usage limits.
- Back-end behind Azure V-NET where communication uses encrypted protocols (HTTPS/TLS v2 or above) over private IP addresses, not accessible from outside.
- Inbound access (for admin) secured by IP address control.
- Internal transit with other Azure services securely transported using HTTPS/TLS v2 or above and controlled by Azure Managed Identity.
- All secrets stored on Azure Key Vault.

Availability and resilience

Guaranteed availability
Core SLAs are stipulated in the terms attached.
Approach to resilience
This is available on request.
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
Other
Other user authentication
When the service is provided with API, users use API keys
Access restrictions in management interfaces and support channels
The management interface is secured by MFA and also IP address restriction.

The support channel is restricted to registered email addresses only and username and password credentials (if directly logged via the support portal).
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Other
Description of management access authentication
IP address control.

Audit information for users

Access to user activity audit information
No audit information available
Access to supplier activity audit information
No audit information available
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
ISO27001 certified, we have a suite of Information Security Management policies and procedures, all externally audited at least annually. Compliance is monitored and enforced by allocated compliance resources and Senior Leaders of the business.

All our procedures are documented in our ISO9001 certified Quality Management System (QMS).

Monitoring policy/process adherence, compliance review meetings are held frequently with Senior Leaders/Embridge Board to document that processes have been complied with across the business and identify where (if any) there are risks or issues, including documented mitigations to resolve challenges or identified non-compliances.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Services are tracked through our "LEO Guardian" back-up and error tracking system. This regularly monitors and 'calls' the integrations being provided to ensure that the integrations are operationally flowing as desired.

In addition, the infrastructure itself is based on Microsoft Azure and we are notified by Microsoft should there be any impacts or alerts that Azure users should be aware of. ISO27001-certified, we have business solution development processes to ensure updates required to the LEO infrastructure from Azure notifications (i.e., technical updates) are applied within the time required, ensuring customers see no change in service.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
The LEO infrastructure is based on Microsoft Azure. We are notified by Microsoft should there be any potential threats identified or patches to be deployed.

We also carry out various operational checks via our "LEO Guardian" monitoring/error checking system, which identifies integration performance issues should they be present which will be investigated and actioned upon.

Our regular penetration testing will also identify potential threats, from which we will action changes as required to reduce and mitigate threats.

LEO integrates buyer solutions; we will work collaboratively with customers to co-operate with their own vulnerability management applied to their processes and systems.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
The LEO infrastructure is based on Microsoft Azure. We are notified by Microsoft should there be any potential compromises identified. We respond using our ISO-27001 certified business continuity procedures.

We utilise API "keys" as a security layer; these keys are rotated and changed on a frequent basis as part of our protection approach. The keys are stored separately to the APIs, ensuring dynamic ring-fencing to increase security protections.

LEO integrates buyer solutions; we work collaboratively with customers, co-operating with their protective monitoring approach applied to their processes and systems, including/not limited to user access controls/secure dynamic credential storage approach.
Incident management type
Supplier-defined controls
Incident management approach
ISO-27001 certified, we have a suite of Information Security Management policies and procedures which stipulate how the business expects its staff/operations to respond to incidents either suspected or known. These processes are tested regularly. Senior Leaders of the business are involved, ensuring the highest level of oversight and scrutiny is applied until resolution achieved and actions post-report are documented and completed. Flexibly, any incident reports where needed are supplied through a manner agreed with the corresponding party.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Thursday 16 October 2025
What the ISO/IEC 27001 doesn’t cover
N/A - all our business services are covered by our ISO certification.

As part of our services, we resell and implement partner technology software; for completeness and assurance of processes, all our partners who are vendors of the software being sold also hold ISO/IEC 27001 certification.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau
ISO 9001 accreditation date
Thursday 16 October 2025
What the ISO 9001 doesn’t cover
N/A - all our business services are covered by our ISO certification
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
8752ae8d-ed5b-48f4-9a1f-dac7441f9dab
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at enquiries@embridgeconsulting.com. Tell them what format you need. It will help if you say what assistive technology you use.