Intelligent Automation / RPA Software (SS&C AI Gateway)
SS&C AI Gateway is a governance platform designed to facilitate responsible AI integration into business processes. It addresses governance, compliance, and security challenges providing audit trails, risk notifications, and role-based access control. Focussing on ensuring data protection, it enables organizations to leverage AI, minimizing risks and adhering to regulatory standards
Features
- AI risk management and compliance controls
- Hallucination, toxicity, accuracy and safety detection
- Plug-and-play framework works with existing AI models or third-party tools
- Built-in rules enforce governance standards across industries
- Prompt injection attack detection prevents adversarial manipulation
- Personally Identifiable Information (PII) – redaction
- Real-time risk notifications prevent unwanted sensitive data exposure
- Secure hosting
Benefits
- Faster, accurate decisions
- Accelerates workflows and minimizes risk
- Enhanced efficiency
- Automates critical financial and operational processes securely, ensuring compliance
- Secures large-scale data processing for AI/machine learning (ML) models
- Protects AI systems against adversarial attacks
- Maintains data privacy while using AI capabilities
- Adhers to complex, multi-layered regulatory regimes
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 6 7 9 5 8 6 4 0 6 8 8 1 4 4
Contact
e18 Innovation
Louise Wall
Telephone: 07979597396
Email: finance@e18-consulting.com
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI life cycle
- AI Build Software
- Trustworthy AI Software
AI software services
- Computer Vision AI Software Services
- Generative AI Software Services
- Document AI Software Services
- Anomaly Detection AI Software Services
- Personalize AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- SS&C Blue Prism Enterprise, SS&C Blue Prism Cloud, SS&C Blue Prism WorkHQ or any system that can drive an API
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- The SS&C AI Gateway service is made available according to the Service Availability - please refer to Terms and Conditions
- System requirements
-
- Requires UK Private Cloud API access; hyperscaler availability planned shortly
- Will be available on-premise soon
- Requires access to LLMs or use SS&C's own LLMs
User support
- Email or online ticketing support
- Yes
- Support response times
- P1 Issue Response 1hr P2 Issue Response 4hrs Mon-Fri only Enhanced (Business Critical) support with improved SLAs is available at extra cost
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- Production Maintenance and Support gives you peace of mind for all your important processes. You’ll benefit from response service level agreements (SLAs). Business-Critical Maintenance and Support is ideal if you’re automating business-critical processes and need 24x7 live support for high-priority issues. Enjoy a heightened response, target-resolution SLAs
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- There is a free University to learn how to build automated processes available https://university.blueprism.com/
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Through the export function in the Governance platform
- End-of-contract process
- The service stops - there will be no response from the service to a service request
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- Web-based Governance Platform
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- The web-based governance platform has been tested to WCAG 2.2A accessibility standard
- API
- Yes
- What users can and can't do using the API
- Please refer to https://docs.blueprism.com/en-US/bundle/ai-gateway-1-0/page/api/api-spec-home.htm
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users are required to customise the prompts they use to achieve the desired outcome
Scaling
- Independence of resources
- The service is monitored 24 x 7 for any conditions that would lead to a breach of the service level agreement (see Terms and Conditions)
Analytics
- Service usage metrics
- Yes
- Metrics types
- The Governance platform provides metrics of the calls to LLMs and the results of those calls, including tokens used and perplexity scores
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Blue Prism
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Through the export facility in the Governance platform
- Data export formats
- CSV
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- Any format
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.9% of scheduled uptime within the agreed availability window - please refer to Terms and Conditions for the Service Level Agreement
- Approach to resilience
- The SS&C AI Gateway service is built for High Availability and Disaster Recover - more information is available on request
- Outage reporting
- Outages on the SS&C AI Gateway are made available on a Public Dashboard and via email
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
- The platform allows for Role Based Access Control (RBAC)
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- SS&C Blue Prism operate an Information Security Management System as part of our ISO27001 certification
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Please refer to https://www.blueprism.com/blue-prism-security/
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- Security, privacy, and compliance are at the core of our development ethos. Our intelligent automation platform was designed using the latest in security standards and protocols, and we continue to enhance our methods and processes to keep you safe from the latest threats. The list of latest security updates can be found here https://portal.blueprism.com/security-updates
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- Security, privacy, and compliance are at the core of our development ethos. Our intelligent automation platform was designed using the latest in security standards and protocols, and we continue to enhance our methods and processes to keep you safe from the latest threats. The list of latest security updates can be found here https://portal.blueprism.com/security-updates
- Incident management type
- Undisclosed
- Incident management approach
- Security, privacy, and compliance are at the core of our development ethos. Our intelligent automation platform was designed using the latest in security standards and protocols, and we continue to enhance our methods and processes to keep you safe from the latest threats. The list of latest security updates can be found here https://portal.blueprism.com/security-updates
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Police National Network (PNN)
- Joint Academic Network (JANET)
- Scottish Wide Area Network (SWAN)
- Health and Social Care Network (HSCN)
- Other
- Other public sector networks
- Any network given the correct permissions
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Time limited trial - as part of a Try Before You Buy programme
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Kiwa Sertifiointi Oy
- ISO/IEC 27001 accreditation date
- Monday 23 June 2025
- What the ISO/IEC 27001 doesn’t cover
- We hold the ISO/IEC 27001 certification for our Information Security Management System, with the scope defined and audited in accordance with the standard. The certification covers all information security controls assessed as applicable within that scope, as documented in the Statement of Applicability. An area of exclusion relates to our internal R&D AI project team - this is mostly excluded.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-