Fusion
Fusion is a cloud-based integration platform for schools. It connects key systems, keeps data in sync, and automates everyday admin tasks. Fusion manages mapping and workflow rules, with monitoring and audit trails - reducing manual effort and improving confidence in data.
Features
- Connectors
- Workflows
- Data-mapping
- Sync
- Validation
- Scheduling
- Monitoring
- Audit-trails
- Alerts
- API
Benefits
- Less-admin
- Faster-processes
- Fewer-errors
- Better-visibility
- Cleaner-data
- Higher-reliability
- Stronger-compliance
- Easier-reporting
- Reliable-operations
- Happier-users
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 2 2 0 0 2 6 3 1 6 6 1 7 5 2
Contact
North27 Limited
Kate Fox
Telephone: 07974179058
Email: kate.fox@north27.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Education
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Fusion extends existing education and public sector systems by providing the integration layer between them. It connects services such as MIS, identity providers, learning platforms and finance/HR tools, synchronising data and automating workflows via APIs and secure file transfer (REST, SOAP, SFTP).
- Cloud deployment model
- Public cloud
- Service constraints
- Fusion is delivered as a cloud-based service and normally requires internet connectivity for administration and integrations. Automated workflows depend on access to third-party systems (for example availability of APIs, credentials and any supplier rate limits) and on the quality of source data. Some legacy systems may require additional discovery and mapping before integration can be enabled. Planned maintenance is scheduled outside core hours where possible and communicated in advance.
- System requirements
-
- Modern-browser
- Internet-access
- IOS/Anroid device
- Email-account
- Supported EPOS hardware
- School MIS access
User support
- Email or online ticketing support
- Yes
- Support response times
- “We acknowledge support tickets within 1 business day (priority incidents faster, typically within 1 hour for critical issues during business hours).”
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We have not yet carried out formal user testing of our web chat with assistive-technology users. We aim to ensure support remains accessible by providing alternative channels (Freshdesk email/ticketing and phone support) and by testing key chat journeys (starting a chat, sending messages, file links) using standard browser accessibility tools (keyboard-only navigation, screen reader checks where available).
- Onsite support
- Yes
- Support levels
-
Support levels are:
Standard Support (included): business-hours support with ticketing/email and phone; onboarding guidance and access to documentation.
Enhanced Support (optional, additional cost): faster response targets, scheduled check-ins, and additional onboarding/training sessions.
Out-of-hours incident support (optional, additional cost): for critical incidents only, agreed per customer.
Support costs depend on organisation size, modules, and required service hours, and are provided in the Pricing Document. A named Technical Account Manager can be provided as part of Enhanced Support (or assigned Cloud Support Engineer where required for integration/onboarding work). - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We help users get started through a guided onboarding process, including initial setup and configuration, data import/integration support where needed, and role-based training for administrators, teachers and school staff. Training can be delivered online and onsite where required. We provide user documentation, plus ongoing support through ticketing/email and phone.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Fusion provides this detail as an export.
- End-of-contract process
-
At the end of the contract we agree an exit plan and timetable with the customer. We provide an export of the customer’s data and reports in standard formats (for example CSV/Excel) and support validation during the transition. Service access continues until the agreed end date. After contract end, we securely delete customer data in line with agreed retention periods and provide confirmation on request.
Data export and standard offboarding support are included in the contract price. Additional costs may apply for bespoke exports, accelerated timescales, complex migration support, or onsite assistance, where requested. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Fusion is accessed through a secure web interface designed for school and trust administrators. Users can configure connections to third-party systems, manage data mappings, define workflow rules, and schedule synchronisation jobs. A dashboard provides status, health checks and recent activity, with clear visibility of successes, warnings and failures. Each run includes logs and audit trails so users can understand what happened and why, and can re-run jobs where appropriate. Role-based permissions control who can view, edit or approve configuration changes. The interface also supports reporting and exports to help operational teams track integrations over time.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have not yet completed formal usability testing of the Fusion interface with assistive-technology users. We carry out accessibility checks during development and release using automated testing and manual verification of key journeys (keyboard navigation, focus order, labels and contrast) and we prioritise improvements raised through customer feedback. Alternative support channels (ticketing/email and phone) are available where required.
- API
- Yes
- What users can and can't do using the API
- Users can use the Fusion API to manage integrations and automate administration. The API supports creating and updating connections, mappings and workflow configurations, triggering and scheduling runs, retrieving job status and logs, and exporting integration results and audit data. Some high-risk settings are restricted to authorised roles and may be managed through the web interface to support governance and approval.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Fusion can be customised through configuration. Authorised administrators can set up connectors, define data mappings and transformation rules, create workflow steps, schedules and alerts, and tailor validation and logging to local processes. Customisation is completed in the web interface (no code) and controlled by role-based permissions.
Scaling
- Independence of resources
- All core components of Fusion are independently scalable. We monitor capacity and performance and scale resources to handle peak demand. Resource limits and throttling are used where needed to prevent any single customer workload impacting other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Fusion provides operational metrics for integrations and workflows, including run frequency, success/failure rates, processing volumes, queue/backlog depth, execution time/latency, error types, retry counts, and connector availability. It also provides audit and governance metrics such as configuration changes, user actions, and job histories, with logs and exports to support reporting and compliance.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users export data from Fusion via the web interface and API. They can download reports and integration outputs, and retrieve job histories, logs and audit trails for operational review and compliance. Standard exports are provided in common formats (for example CSV/JSON), with additional formats available by agreement.
- Data export formats
-
- CSV
- ODF
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Availability is agreed on a customer-by-customer basis and set out in the individual contract/SLA, including how uptime is measured, planned maintenance windows and exclusions. If agreed availability targets are not met, remedies are handled in line with the customer’s SLA - typically service credits or other contractual remedies, applied to the next billing period where applicable.
- Approach to resilience
- Fusion is designed for resilience using scalable cloud infrastructure with redundancy across core services and regular backups with tested restore procedures. Workflows are queued and retried where appropriate, with monitoring and alerting to detect issues early. If a connected third-party system is unavailable, Fusion records the failure, pauses or retries according to policy, and resumes synchronisation when connectivity is restored. Planned maintenance is scheduled outside core hours where possible and communicated in advance.
- Outage reporting
- We monitor availability using updown.io. Customers can subscribe to updown.io notifications for status updates and receive alerts during incidents.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access control (RBAC). Only authorised users can access administrative functions, and permissions are granted on a least-privilege basis. Administrative access is limited to approved accounts, with access reviewed and removed promptly when no longer required.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security governance is led by senior management with clear accountability for service security. We maintain documented security policies and risk management processes, review security risks and incidents regularly, and ensure changes are assessed for security impact. We hold Cyber Essentials Plus certification and use role-based access controls, audit logging and monitoring. We commission security testing (including penetration testing where appropriate) and track remediation through to completion.
- Information security policies and processes
-
We follow documented information security policies covering access control, encryption, incident management, vulnerability management, secure development, supplier management, and backup and recovery. A named senior owner is accountable for information security, with day-to-day responsibility assigned to designated leads.
We ensure policies are followed through role-based access controls, staff onboarding/offboarding, security awareness training, and regular reviews of user access and system changes. Security risks and incidents are logged, escalated and reviewed by senior management, with corrective actions tracked to completion. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Describe your configuration and change management processes.
Include details of how:
the components of your services are tracked through their lifetime
changes are assessed for potential security impact. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We assess threats through automated vulnerability scanning, dependency monitoring and security reviews. Alerts are triaged by severity and exposure. Critical patches are prioritised and deployed as soon as practicable (often within days), with lower-severity fixes scheduled into normal release cycles. We track advisories from tooling and vendor feeds (for example security advisories from vendors and maintainers, and cloud provider notices).
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use logging and monitoring across key service components to detect unusual activity, errors and access patterns that could indicate compromise. Alerts are triaged by severity and investigated by authorised staff. When a potential compromise is suspected we contain access (e.g. revoke credentials, isolate affected components), assess impact, remediate, and communicate updates to nominated contacts. We respond to critical security incidents as soon as identified and prioritise immediate containment and service stabilisation.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We have documented incident processes, including predefined runbooks for common events (service outage, performance degradation, security incidents and payment issues). Users report incidents through our ticketing/email and phone support channels. We triage by severity, assign an incident owner, and provide updates to nominated contacts until resolution. After closure we provide an incident report on request, covering timeline, impact, root cause, corrective actions and any preventative changes.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 8d730adf-a264-4f79-ba73-f1913961276b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Cca3370e-3989-4e3d-b34b-22b6a4eb21db
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
-