Flexigrant
Flexigrant® is a provided as a cloud-based, software as a service (SaaS), scalable grant management software solution. Catering for 3 to over 100 concurrent users Flexigrant® is a highly configurable grant management system that can be rapidly set up and deployed.
Features
- Build your own online applications, claim and monitoring report forms
- Build/configure grant schemes and workflows the way you work
- Designed to be implemented rapidly by non-technical staff
- Graphical reporting including mapping of all your data
- Manage your external reviewers, review panels and shortlisting
- Integrated document generation (e.g. for awards and panel/board papers)
- Fully customisable. Customise everything from workflow to language and branding
- Comprehensive role-based security controlling access to functions and data
- Designed with data migration and integration in mind
- Annual product roadmap and monthly upgrades
Benefits
- Designed for rapid set up and deployment by non-technical staff
- Minimal training time before you start using
- Online training materials and support
- No limit on the number of schemes/funds you can create
- No limit on the number of reviewers (internal or external)
- Modern interface using the latest technologies for ease of adoption
- Product aligned to grant management best practice
- Product under continuous development and improvement
- Completely scalable if your staff and client numbers increase
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 2 0 4 7 1 3 9 3 6 1 3 5 9 8
Contact
FLUENT TECHNOLOGY LIMITED
Gary McNally
Telephone: 02890690020
Email: gary.mcnally@fluenttechnology.com
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Hybrid cloud
- Service constraints
-
After the system has been configured and handed over Clients are responsible for:
- The on-going management of users, roles and permissions and all system codes and parameters,
- The on-going management of scheme/fund set up (unless additional implementation services are procured) - System requirements
-
- Users must have internet access to access Flexigrant®
- PC or mobile device with modern browser
User support
- Email or online ticketing support
- Yes
- Support response times
-
Email support and online ticketing support has four priority status's which determine the response time. The response times are as follows:
Critical - Initial response within 30 mins | Target resolution within 8 hours thereafter.
Significant Impact - Initial response within 2 hours | Target resolution within 12 hours thereafter.
Minor Impact - Initial response within 4 hours | Target resolution within 24 hours thereafter.
Low Priority - Initial response within 24 hours | Target resolution by agreement.
Email support/online ticketing support is provided Monday to Friday 9am to 5pm excluding Northern Ireland public/bank holidays. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We will provide ongoing support:
Email support (as standard) to our help-desk to provide first-line technical support for the Software to the Customer.
Remote diagnosis and (where reasonably possible) correction of faults by code updates.
Flexigrant® have a dedicated support line for critical and significant impact support queries where our Customer Success team provide first-line technical support for the Software to the Customer (included in Flexigrant® package).
Fluent Technology shall provide support in respect of the Software as currently forming part of the Software as a Service.
Fluent Technology will respond to all support requests as quickly as is reasonably possible and supports the following target response times once a request from the Customer has been recorded:
Email support and online ticketing support has four priority status's which determine the response time. The response times are as follows:
Critical - Initial response within 30 mins | Target resolution within 8 hours thereafter.
Significant Impact - Initial response within 2 hours | Target resolution within 12 hours thereafter.
Minor Impact - Initial response within 4 hours | Target resolution within 24 hours thereafter.
Low Priority - Initial response within 24 hours | Target resolution by agreement. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Clients are actively involved in the implementation process through various stages. Initially, they complete a 'Discovery Questionnaire' to provide insight into their grant management processes, and attend a discovery workshop to review the questionnaire responses and clarify any additional points. A project initiation meeting follows, where the project brief, plan, and RAID Log are reviewed and approved with key stakeholders.
During the configuration phase, clients are responsible for reviewing and providing timely feedback on the work completed. They also participate in testing and sign-off of key functionalities such as application forms, workflow, templates, award, post-award, and payment/claims processes.
The onboarding process includes training to ensure teams are ready to work with the software from day one. This MS Teams training is designed to be interactive, enabling clients to grasp and understand the topics covered before moving on to the next one. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- On termination we typically provide an export of all data held or agree to hold the data in a restricted instance of the system for archival access. The costs of these services are typically discussed on contract agreement and finalised before termination. Any data to be transferred to a client would be transferred securely in accordance with our ISO 9001 and ISO 27001 accredited procedures. Please note that Flexigrant® includes a Query & Export tool that allows users to export data in Excel format. The costs of additional data extraction services are typically discussed on contract agreement and finalised before termination (if required).
- End-of-contract process
-
We do not believe in subjecting clients to complicated or lengthy termination clauses. Typically, we require 3 months’ notice of termination and this is discussed and the notice period agreed on contract agreement. Failure to advise Fluent of termination will result in continuity of the service unless otherwise agreed with Fluent, please refer to our Standard Terms and Conditions for a full description.
On termination we typically provide an export of all data held in the system in an agreed format or agree to hold the data in a limited version of the system for future access. The costs of these services are typically discussed on contract agreement and finalised before termination. Any data to be transferred to a client would be transferred by secure media only and would be encrypted in accordance with our ISO9001 and ISO27001. - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service offers distinct experiences for mobile and desktop users. Primarily designed for desktops, laptops, and tablets, it features complex interfaces optimised for larger screens. While the system is accessible on mobile devices, it is not fully optimised for mobile phones, focusing instead on essential tasks. The desktop version provides a comprehensive user experience with full access to features, enabling detailed data handling and complex interactions. In contrast, the mobile experience is streamlined, offering basic functionality suitable for on-the-go management, with a user interface tailored for tablets.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- Yes, the service includes a user interface designed for seamless navigation between modules. It adheres to modern design principles, ensuring that fields and functions are logically organized and easy to access. This user-friendly layout enhances productivity by allowing users to move effortlessly between different areas of the system. Additionally, the platform supports modular upgrades and provides an intuitive user experience, making it straightforward for users to manage tasks effectively.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- The service has undergone accessibility audits to ensure compliance with accessibility standards. These audits include testing with various assistive technologies to identify and address potential barriers. Specific testing methods mentioned include the use of browser tools like WAVE and NVDA for in-house testing. Additionally, external accessibility audits have been commissioned to assess the system against WCAG standards. These efforts are part of a continuous process to enhance the platform's accessibility and usability for individuals using assistive technologies.
- API
- Yes
- What users can and can't do using the API
-
Users of the service can leverage its API for various integrations and data management tasks, though there are specific capabilities and limitations to be aware of:
Setting Up the Service: The API facilitates integration with external systems, such as finance and CRM platforms, enabling data exchange and synchronisation. Users can set up secure connections to streamline workflows and ensure data consistency across platforms. The API supports standard data formats like XML and CSV for imports and exports, making it easier to integrate with existing systems.
Making Changes: Through the API, users can manage data replication, allowing them to access and analyse their data within their own environments using preferred tools like Power BI or SQL. This enables custom reporting and insights without altering the core system.
Limitations: Users cannot independently create API clients or webhooks; vendor support is necessary. The service does not offer OData or ODBC connectors, and entity-relationship diagrams (ERDs) are not typically provided. Full end-to-end solutions require vendor involvement, and any breaking changes to the API come with advance notice to ensure users can adapt accordingly. These limitations mean users must coordinate with the vendor for significant API modifications or custom integrations. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Clients can extensively customise Flexigrant according to their specific needs, thanks to its self-service ethos. Once users receive training, they have the capability to maintain, amend, and build grant schemes without necessarily having to rely on Fluent staff. This includes creating an unlimited number of grant schemes, either from scratch or by copying an existing one.
The system offers a comprehensive form builder that allows authorised users to construct various forms, such as application, progress reporting, or claim forms, without the need for specialised skills or support from Fluent. The form builder includes a wide variety of question types and offers validation logic, as well as the ability to show or hide questions based on previous answers.
Administrators can control which grant schemes are open for applications and set specific submission deadlines. Each grant scheme can have its own configured workflow, which authorised users can manage using simple online tools.
Additionally, Flexigrant provides a range of premium features for further customisation, such as financial and payment management, application settings, reporting options, and more. These features are designed to cater to the unique needs of different organisations and can be discussed and tailored during the discovery phase with Flexigrant.
Scaling
- Independence of resources
- The service ensures resource independence through a multi-tenant architecture hosted on Microsoft Azure. This setup isolates each client's data and applications, preventing cross-tenant interference. Azure's scalable infrastructure dynamically allocates resources based on demand, maintaining consistent performance for all users. Load balancing and efficient data management further ensure that high demand from one user does not impact others. Additionally, robust monitoring tools continuously assess system performance, allowing for proactive adjustments to maintain optimal functionality and prevent any degradation in service quality due to varying user demands.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We actively monitor the numbers of users accessing the system as well as gathering detailed statistics on the volume of applications via an administrator dashboard.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Data at rest is stored encrypted using Microsoft Azure Transparent Data Encryption.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Flexigrant® includes an easy to use yet powerful data export tool, visual Insights Tool and Data Replication Service that allows authorised users to build queries based on the data held in the system and output the information in various formats. Data exports can also be carried out on audit logs, payment files and PDF generation of applications, board papers and score sheets can be done.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Docx
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Flexigrant® is hosted in Azure and includes 99.95% infrastructure availability guarantees. We will use commercially reasonable endeavours to ensure that the Flexigrant® SaaS Service is available to the customers 99.5% of the time during normal office hours in any one calendar month.
- Approach to resilience
- Reliability is one of our key tenets and our cloud platform has been designed to meet the needs of companies whose solution requires high availability network, infrastructure and uptime guarantees ensuring mission critical applications are always up and running. Our cloud environment features include: hardware redundancy and geographic failover across multiple sites in the event of a disaster; fully managed Infrastructure as a Service (IaaS) by Microsoft Azure; Zero-Downtime Network (fully resilient routers, switches and cabling); Access to 24x7x365 dedicated support team; Fully resilient DNS infrastructure; Fully resilient and redundant network infrastructure; Tier-1 network utilising multiple bandwidth providers; Managed Operating System patching.
- Outage reporting
- The service reports outages by escalating the suspected incident to the Issue Response team and moving the conversation to a dedicated channel. Engineers are given 15-30 minutes to investigate the cause and severity of the incident. In the meantime, all phone and email inquiries are promptly answered with a standard email message informing customers that the team is aware of the situation and is actively investigating. Once an incident is confirmed as major, updates are communicated through various channels, including a community portal post update, Mailchimp email, ticket updates, and direct account calls. The communications plan includes templates for initial issue notifications, updates during the issue, and notifications after resolution, both when the system performance has been restored and when detailed insights into the cause are available.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted in two ways. Full tenant administration access is restricted to Fluent only by username/password and IP address. For client system management access this is restricted by the Flexi-Grant® role based security model which requires client users to authenticate and access functions by role.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Flexigrant® has been developed to ensure compliance with information security standards. Fluent Technology Ltd, the authors of Flexigrant®, are accredited to the ISO9001, ISO27001 and Cyber Essentials Plus standards.
Our security policies are audited internally as part of our annual audit schedule and independently verified by our external auditors, NQA.
The organisation follows information security policies and processes that align with ISO 27001 standards, including an Information Security Management System (ISMS). This encompasses incident reporting, risk assessment, regular audits, and a commitment to continual improvement. The organisation also maintains Cyber Essentials Plus accreditation, which is a UK government-backed scheme that helps protect against a wide range of the most common cyber attacks. Additionally, there are documented incident management plans in place, and the organisation has been independently assessed to meet the ISO 27001 information security standards. Cybersecurity policies include a data breach response plan as part of the ISO 27001 framework, ensuring that any loss, corruption, or degradation of data is managed according to a defined procedure. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
All changes applied to our service are managed through a strict change control procedure. All changes are tested on a development environment that mirrors the live production environment before being deployed live.
As part of the planning of any change we assess the impact on security of the change and design appropriate test scenarios as part of any new developments. No change is deployed unless all testing, including security testing, has been completed successfully. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Our vulnerability management process involves regular scanning of our infrastructure using cloud-based scanning systems, such as Azure Defender for Cloud. Any vulnerabilities identified are assessed and remediated according to their severity. Critically identified vulnerabilities are addressed immediately. We also conduct independent penetration testing every year to ensure the security of our systems. Additionally, our servers are patched with critical security updates as they are released, and full patch management procedures are employed.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We proactively monitor our systems through a variety of measures. This includes uptime monitoring at one-minute intervals, port monitoring to detect service interruptions, and immediate notifications to engineers with automated processes to restart critical services. We also employ Infrastructure as a Service (IaaS) monitoring and Application Performance Monitoring (APM) to identify potential issues early on. In addition, built-in admin alerts in our software notify users about specific administrative tasks related to data maintenance. Our monitoring processes are designed to ensure prompt detection and response to any security events.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Our incident management process is aligned with ISO 27001 standards and involves an Incident Response Team (IRT) that coordinates the response to security incidents, conducts investigations, implements remediation measures, and communicates with stakeholders. Incidents are detected through monitoring tools, employee reports, and automated systems. Upon detection, the IRT works to contain the incident, eradicate the root cause, and recover normal operations. A post-incident review is conducted to analyse the response and identify improvements. Regular training ensures employees are aware of reporting procedures, and the process is reviewed annually with periodic testing through simulated exercises.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Free trial's of Flexigrant® give users access to all five key parts of the system: the back office 'Admin', the 'Manage Grants' section (central dashboard), the 'Manage Contacts' section (built in CRM), the 'Application Portal' where applicants go to apply and the 'Reviewer Portal' where reviewers go to review applications.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Thursday 19 April 2012
- What the ISO/IEC 27001 doesn’t cover
- Anything outside grant management and management information systems for public private and third sector clients.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- NQA
- ISO 9001 accreditation date
- Saturday 16 April 2005
- What the ISO 9001 doesn’t cover
- Anything outside grant management and management information systems for public private and third sector clients.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Cdd401cf-d610-4242-8b7f-ebe35e08cf47
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 3429cc54-ceca-4227-a302-6423f747df88
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-