Skip to main content

Help us improve the Digital Marketplace - send your feedback

ARDOQ UK LIMITED

Automated, data-driven SaaS for Enterprise Architecture and Digital Transformation

Ardoq, a modern tool for Enterprise Architecture, helping organisations with change management across their projects, strategies, processes, applications, infrastructure, capabilities. Ardoq goes beyond traditional enterprise architecture modelling through its automated, data-driven, AI-powered approach to EA. Impact assessment, managing change, analysing interdependencies, are all easier, resulting in quicker, more reliable decision-making.

Features

  • Data-driven, interconnected, automated repository for all aspects of enterprise architecture
  • Proven use-case templates following industry best-practices to drive business outcomes
  • Crowd-source data through customisable surveys, automated alerts, and bespoke workflows
  • Business-friendly UI to enable data exploration via dynamic, automated views
  • Compare and analyse as-is and to-be states for change management
  • Automatic calculation of attributes like risk, cost, and criticality
  • Automatic visualisations that can be shared as business-friendly, explorable presentations
  • Out-of-the-box integrations plus open API for creating new connectors
  • AI augmentation. Opt-in functionality: generate/analyse data, and recommend improvements
  • True-SaaS, cloud-hosted, modern, flexible Enterprise Architecture solution with quick time-to-value

Benefits

  • Automate organisational documentation for business transparency and organisational governance
  • Faster change planning, and prioritisation of initiatives underpinning business objectives
  • Optimise application portfolio and reduce operational costs through rationalisation
  • Better quality, faster decision making via board-friendly insights
  • Improve change possibilities and change success by distributing decision-making
  • Improve accessibility of enterprise architecture and efficiency of data collection
  • Engage users in change initiatives and enable business agility
  • Collect data and update data easily using integrations and crowd-sourcing
  • Improve efficiency by automating tasks - always with human approval
  • Instant browser access, with daily updates and minimal downtime

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at robin.fitzhugh@ardoq.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 2 3 9 0 8 8 4 8 2 8 0 0 9 9

Contact

ARDOQ UK LIMITED Robin Fitzhugh
Telephone: 07983 583988
Email: robin.fitzhugh@ardoq.com

About your service

Service categories

Application Development and Deployment

Application development

Modelling and architecture

  • Object Modelling Tools
  • Business Process Modelling Tools
  • Enterprise Architecture Tools
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Ardoq is a cloud-native SaaS application hosted on AWS in Ireland, and is accessible 24-7-365 with support available from 8am-5pm GMT Monday to Friday (excluding holidays). Ardoq has no maintenance windows. Ardoq may have Planned Downtime up to 4 times each calendar year. Ardoq will, if possible, notify at least 5 business days in advance of Planned Downtime occurring outside of normal business hours (Monday to Friday 0900-1700 CET for the EU datacenter). For planned downtime (which may last up to 24 hours) during normal business hours, notification shall be given at least ten business days in advance if possible.
System requirements
  • Latest versions of Chrome / Firefox / Safari / Edge
  • Minimum of 8 GB ram
  • Minimum of 2,4Ghz of CPU
  • Live internet connection

User support

Email or online ticketing support
Yes
Support response times
We usually respond within 2 hours of receipt of request between Monday and Friday. Requests received during weekends are answered on Monday. Support is available from 8am to 5pm GMT Monday to Friday (not including public holidays). Currently (October 2025), customers receive a response from a human technical consultant within 15 minutes.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Ardoq use Intercom for web chat support. Based on the current documentation, the new web Messenger and mobile SDKs haven't been re-assessed and certified for WCAG compliance yet.
However, Intercom do recognize the importance of accessibility features like screen reader compatibility, keyboard navigation, good color contrast, and accessible content creation (captions, alt text, etc.).
While they work toward improving accessibility compliance, the current state means our chat and ticketing features may not fully meet established accessibility standards like WCAG at this time.
https://www.intercom.com/help/en/articles/6612597-messenger-faqs
Web chat accessibility testing
Ardoq uses Intercom for web chat so Ardoq does not conduct its own testing
Onsite support
Yes, at extra cost
Support levels
Onboarding:
Upon contract finalisation a new client is assigned two distinct resources at Ardoq:
• A Customer Success Manager - responsible for the ongoing relationship with the client and its day-to-day management
• An Enterprise Architecture consultant - responsible for deployment of the core/foundation module; implementation of selected outcome(s) / use case(s)
Note: Additional resources (e.g. Senior Advisors, Integration Specialists, Engagement Managers, etc.) may be assigned, as needed.

In addition, customers also have access to:
1. In-app chat - We usually respond within 2 hours of receipt of request between Monday and Friday. Requests received during weekends are answered on Monday. Support is available from 8am to 5pm GMT Monday to Friday (not including public holidays). Currently (October 2025), customers receive a response from a human technical consultant within 15 minutes;
2. Knowledge base of help articles;
3. Gamified online training.

Ardoq offers multiple services offerings and pricing options to support the deployment of the core/foundation module and selected outcome / use case modules.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Onboarding:
Upon contract finalisation a new client is assigned two distinct resources at Ardoq as part of their subscription:
• A Customer Success Manager - responsible for the ongoing relationship with the client and its day-to-day management
• An Enterprise Architecture consultant - responsible for deployment of the core/foundation module; implementation of selected outcome(s) / use case(s)
Note: Additional resources (e.g. Senior Advisors, Integration Specialists, Engagement Managers, etc.) may be assigned, as needed.

In addition, at no extra cost, customers also have access to:
1. In-app chat;
2. Knowledge base of help articles;
3. Gamified online training.

Ardoq offers multiple services offerings and pricing options to support the deployment of the core/foundation module and selected outcome / use case modules.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
  • MS PowerPoint
  • MS Word
  • Google Slides
End-of-contract data extraction
Customers access to their data until the subscription end date. The account will be deleted 90 days after the subscription ends. All backups will be deleted 90 days thereafter (in short, all data will be permanently deleted within 180 days after the subscription ends).
Data can easily be downloaded in bulk with no vendor lock-in. There are different ways to export your data. You can export:
1. Your entire workspace to excel (.XLS);
2. The visualisations/graphs from your views to .PNG and .SVG or PDF;
3. Custom Export via Reporting;
4. via Ardoq's API.
End-of-contract process
When approaching the end of an agreement, the client will have the option to cancel or renew the agreement for an additional term. Customers will have access to their data until the subscription ends. Data is easy to export, but if a customer requires support, their CSM will establish a plan with them to assist with the offboarding so no data or assets are lost. Support with offboarding is provided at no extra cost.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Standard Data Sheets and Use Case documents are screen-reader compatible. Meanwhile our online documentation such as help.ardoq.com is designed to be accessible. For example, it contains a "Skip to main content" Link, a critical feature that meets a key WCAG (Web Content Accessibility Guidelines) success criterion (2.4.1 Bypass Blocks). It allows users navigating by keyboard or screen reader to quickly jump past repetitive navigation and header elements to reach the main article content, improving efficiency and reducing frustration.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Mobile can be used to access pre-created content, rather than create content from scratch. For example, users on mobile can view and interact with dashboards but won't be able to create dashboards from scratch - this functionality is reserved for the app accessed via desktop browser.
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
Ardoq offers a REST API. Users can use the API to integrate with Ardoq, e.g. to automate data sharing, or to create custom tools that make use of data from Ardoq.
Prerequisites:
1. An Ardoq account with read and write permissions. (Contact your dedicated Customer Success Manager if you don’t have one);
2. Your API token for authorisation.

With the API you can for instance perform CRUD operations or load the results of a report. The API also supports batch operations, that should be used when updating multiple entities at the same time.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Ardoq allows users with the correct permissions the ability to customise the structure and metamodel of the repository. This includes, for example, the ability to create custom object types, relationship types, and object and relationship attributes/properties, without the need for configuration from personnel at Ardoq. UI elements such as logos and shapes can also be tailored.

Scaling

Independence of resources
Ardoq leverages cloud auto scaling - this automatically adjusts capacity to maintains steady, predictable performance to all customers.

Analytics

Service usage metrics
Yes
Metrics types
Uptime, ticket response time, ticket resolution. Reports available on request.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Physical security of data centres is assured by our Cloud Provider. AWS is CSA CCM v3.0 and SOC2 (SSAE-16) certified. We do not maintain data centres at all.
Data at rest stored in the Ardoq Cloud Platform is encrypted using 256-bit AES. Key management is supported by Hardware Security Modules (HSMs) validated under FIPS 140-2.

All endpoint devices are configured with full-disk encryption.
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Data can easily be downloaded in bulk with no vendor lock-in. There are different ways to export your data. You can export:
1. Your entire workspace to excel (.XLS);
2. The visualisations/graphs from your views to .PNG and .SVG or PDF;
3. Custom Export via Reporting;
4. via Ardoq's API.
Data export formats
  • CSV
  • Other
Other data export formats
  • .XLS
  • .PNG
  • .SVG
  • .PDF
  • Via API
Data import formats
  • CSV
  • Other
Other data import formats
  • .XLS
  • .XLSX
  • .XLSM

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
External Traffic (User to Platform) is secured by TLS 1.2 or TLS 1.3 with intermediate and final termination via an Application Load Balancer and Nginx Ingress Controller.
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Ardoq will, during the subscription term, provide the Services with an availability target of 99.5% measured per calendar month, excluding Planned Downtime as defined below (the “Availability Target”).
If Ardoq doesn't meet its Availability Target, the Customer is entitled to a free extension period as specified below.
Customer must notify Ardoq of the failure to meet the Availability Target within 10 days after the end of the applicable calendar month, and must at the latest claim such free extensions within 30 days after the notification was sent to Ardoq.

Availability per calendar month of:
1) 99.5%-99.0%
2) 98.9%- 96.0%
3) <96.0%

will entitle the customer to respectively:
1) 2 days extension of the service;
2) 4 days extension of the service;
3) 8 days extension of the service.

If the Service hasn't met the Availability Target for 3 consecutive months, Customer may terminate the Service upon 30 days’ notice to Ardoq, and will receive a pro-rata refund of any prepaid fees for the unused period of Service. The foregoing are Customer’s sole remedies for any failure of the Service to meet the Availability Target.

Ardoq’s monitoring and logging infrastructure will be the source of truth for determining availability.
Approach to resilience
Ardoq is hosted on AWS with backup service provided by Microsoft Azure. Ardoq does not manage data centres. Our Cloud Providers (AWS and MS Azure) maintain these responsibilities. Further info can be provided on request.
Outage reporting
Ardoq has a live status page which can be accessed at https://status.ardoq.com/. It is updated automatically if an outage is detected. This is our principal mechanism for reporting outages.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
In Ardoq users can be authenticated by the SSO solution integrated with such as Azure Active Directory, Okta, Google, GitHub, Ping Identity, NetIQ, or Safewhere. Customers are recommended to configure 2-factor authentication as part of their identity provider.
Access restrictions in management interfaces and support channels
For the application users it depends on them how they want to restrict admin access by the SSO configuration. Our management interfaces (e.g. AWS and back office support system) require use of MFA to login. Management access is restricted to individuals with specific roles and business purposes, and is reviewed quarterly.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Other
Description of management access authentication
For customers: Administrators (similar to regular users) can be authenticated by user name and password or in Ardoq users/administrators can be authenticated by SSO solution such as Azure Active Directory, Okta, Google, GitHub, Ping Identity, NetIQ, or Safewhere.

For Ardoq employees with specific roles that require them to have management or administrative access: authentication is performed via SSO that requires 2-factor authentication and specific roles.

Audit information for users

Access to user activity audit information
Users receive audit information on a regular basis
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
  • Other
Other security governance standards
SOC2 Type 2. Ardoq is also a member of the Cloud Security Alliance.
Information security policies and processes
Policies include:
Visitor Office Access,
Physical and Environmental Security Policy,
Access Control Policy,
Mobile Device Encryption Policy,
Password Policy,
Acceptable Encryption Policy,
IT Asset Management Policy,
Business Continuity Policy,
Change Management Policy,
Cloud Security Policy,
Code of Conduct,
Data Privacy,
Disciplinary Policy,
Employee Guidelines,
Incident Response Policy,
Information Classification and Handling Policy,
Information Security Policy,
Internal Privacy Policy,
Acceptable Use Security Policy,
Clean Desk Policy,
Environmental Protection Policy,
Equality and Diversity,
Corporate Ethics and Social Responsibility,
Personnel Security Policy,
Risk Assessment Policy,
Software Development Security Policy,
Vendor Risk Management Policy.
Every employee has to read and accept security policies relevant to their role and repeat that once a year. We ensure that policies are followed by audits for SOC2 and ISO27001 once a year, during internal audits, and through risk management and monitoring activities. We identify potential deviations and track them and mitigate. We have a Security Department responsible for managing security risk, lead by the CISO who reports to the Chief Operations Officer, who reports to the CEO.
Software Security Code of Practice
No

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
All changes to the Ardoq platform, including deployment of new features, technical improvements, bug fixes, and cloud configuration changes, must follow established Change Management Procedures. These procedures include:

1. Documentation and tracking of all changes, both scheduled and unscheduled.
2. Assessment of all changes for their risk and impact, with a particular focus on security.
3. Informing relevant stakeholders of upcoming changes that impact system availability or operations.
4. Planning and reviewing all changes by the responsible team and coordinating them across the organization.
Code is tested both automatically and manually, and automated code scanners are utilized.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We perform weekly vulnerability scans, and are continuously tested by security researchers through a bug bounty program managed by HackerOne. We also conduct annual penetration tests, and build security tests as part of our continuous development process. For any deployment we scan for third party vulnerabilities. Any report of a vulnerability from these activities follow a Vulnerability Management Procedure where we triage the issue, assign a criticality, and remediate or otherwise mitigate the issue. Based on the criticality we set ourselves a deadline varying from 24 hours for Critical to 180 days for Low risk issues.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Ardoq uses the SIEM module available in Elasticsearch that is fed with all available logs in the system, including audit information from all VMs, error logs, CSP reports, both reverse proxy and application-level request log, database logs, and backup logs.
We have incident response plan and procedure in place for response to potential incident. We respond to the incidents immediately.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Ardoq has a Security and Incident Response Plan that establishes the procedures to be undertaken in response to information security incidents. The phases of incident response, include preparation, identification, containment, eradication, recovery lessons learned. If an incident occurs and it needs to be communicated to clients, updates about the incident are communicated with contacts.
If customers notice an incident they can report that to regular point of contact, support team or directly to Ardoq's Security Team. We do not provide incident reports to our customers, only internally. Incidents that impact the confidentiality of customer data follow a breach notification process.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Ardoq offers a free 2 week 'Proof of Value' during which we offer a supported trial of Ardoq. This is generally framed by pre-agreed business questions/outcomes the customer wants achieve within those 2 weeks and can involve the use of a subset of client data to drive engagement and understanding.
Link to free trial
N/A. Speak to Ardoq rep or contact sales.uk@ardoq.com

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
20%
Between £1,000,001 and £2,500,000
25%
Between £2,500,001 and £5,000,000
30%
Over £5,000,001
35%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Linford & Co LLP
ISO/IEC 27001 accreditation date
Saturday 1 March 2025
What the ISO/IEC 27001 doesn’t cover
The scope of our ISO 27001 certification explicitly covers the development, operation, and maintenance of the Ardoq SaaS platform. This scope defines the boundaries of our Information Security Management System (ISMS). Consequently, areas of the business not directly related to these core SaaS platform delivery functions are not included within the certified scope.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
Yes
CSA STAR accreditation date
Friday 1 August 2025
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
N/A. All parts of our service are covered by our CSA CSTAR certification.
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
SOC2 Type 2

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at robin.fitzhugh@ardoq.com. Tell them what format you need. It will help if you say what assistive technology you use.