Green Business Tools – Digital Operations and Workflow Platform (SaaS)
Green Business Tools – Digital Operations and Workflow Platform is a secure, browser-based SaaS solution for public-sector organisations. It provides centralised workflows for childcare services, digital menus, customer management, messaging, appointments, forms and secure data handling. The scalable, mobile-responsive platform reduces paperwork, improves data accuracy and supports GDPR-compliant service delivery.
Features
- Browser-based cloud platform accessible across desktop, tablet and mobile
- Secure email OTP authentication for user account access
- Role-based access controls for different user responsibilities
- Centralised dashboards for service, user and workflow management
- Digital forms supporting structured data collection
- Automated workflows for routine operational processes
- Real-time data storage and service status updates
- Integrated childcare, menus, messaging, appointments and customer-management modules
- Encryption protects data in transit and at rest
- Automated backups, uptime monitoring and integration-ready APIs
Benefits
- Reduce paperwork by digitising routine administrative processes
- Save staff time through automated workflows
- Improve data accuracy and reduce manual re-entry
- Control access using secure role-based permissions
- Manage services, users and activities from one dashboard
- Work securely across authorised desktop, tablet and mobile devices
- Onboard organisations, staff and service users efficiently
- Scale services as users and data volumes grow
- Collaborate effectively using shared, up-to-date operational information
- Support consistent, secure and GDPR-compliant service delivery
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 3 1 8 8 8 6 8 0 3 0 2 5 5 3
Contact
Green Business Tools
Samaresh Bhowmik
Telephone: 07484892130
Email: samareshbhowmik@yahoo.com
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service is available 24/7 with planned maintenance carried out during low-usage periods, normally with advance notice to users. Internet connectivity is required. Browser support is limited to modern versions of Chrome, Edge, Firefox and Safari. No specialised hardware is required. Occasional brief downtime may occur during updates or security patching.
- System requirements
-
- Modern web browser: Chrome, Edge, Firefox or Safari required.
- Stable internet connection for accessing cloud-based services.
- JavaScript enabled in the browser for full functionality.
- Minimum screen resolution 1280x720 for optimal display.
- Email access required for verification and notifications.
- Device running Windows, macOS, Linux, Android or iOS.
User support
- Email or online ticketing support
- Yes
- Support response times
-
You already provide email support through your domains (support@greenbusinesstools.net
, support@out-of-school.net
, etc.).
You can also respond using your current workflow (email + manual ticket tracking).
G-Cloud buyers expect email/ticket support as standard for SaaS services.
No need to charge extra at this stage — “Yes” is fully acceptable for small suppliers. - User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide three levels of support to meet the needs of public sector buyers:
1. Standard Support (Included in licence fees)
Email and ticketing support (Mon–Fri, 9am–5pm UK time).
Response within 4 working hours.
Access to online documentation and knowledge base.
2. Enhanced Support (Optional add-on)
Priority email and phone support (Mon–Fri, 8am–6pm).
Response within 2 working hours.
£150 per month per organisation.
3. Premium Support (Optional add-on)
Extended-hours support (Mon–Sun, 8am–8pm).
Dedicated technical support contact.
Response within 1 working hour.
£350 per month per organisation.
Onsite Support
Available on request for training, implementation or specialist assistance.
Charged at £450 per day + travel costs.
Technical Account Manager
Premium support includes access to a Technical Account Manager who helps with configuration, best-practice guidance, and optimisation of the service. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Users can begin using the Green Business Tools Cloud Platform immediately through a secure online onboarding process. We provide clear step-by-step guidance that helps organisations set up their account, add users, configure settings, and activate required modules such as Digital Menu, Nanny World, or Out-of-School services.
A full online help centre is available, including user guides, FAQs, and video walkthroughs. We also provide email support to assist buyers during the initial setup, including help with configuration, user management, or customisation options.
Optional remote training sessions can be arranged for administrators or staff, covering system navigation, workflow configuration, and best practice usage. Onsite training can be provided if required.
Our onboarding team supports users throughout the setup phase to ensure the platform is configured correctly and ready for operational use. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- Other
- Other documentation formats
-
- Video tutorials
- Email-based guidance
- End-of-contract data extraction
-
Users can extract their data at the end of the contract through multiple self-service options. Administrators can download all records, reports, and configuration data directly from the web dashboard in common formats including CSV, Excel, and PDF. Data exports can be generated on demand or scheduled.
If required, buyers may request a full structured data export, which is provided securely via encrypted download or secure file transfer. This includes all user data, activity logs, and system configuration relevant to their organisation.
We offer email support during the offboarding period to assist buyers with the extraction process and ensure all required data is successfully retrieved before account closure. - End-of-contract process
-
At the end of the contract, the buyer is notified in advance and provided access to export all of their data through the platform’s built-in data extraction tools. Administrators can download all records, reports, documents, and configuration data in standard formats (CSV, Excel, PDF) at no additional cost.
During the offboarding period, users retain full access to their account for data retrieval until the agreed contract end date. Email support is included at no extra cost to help buyers extract their data and ensure a smooth transition.
Once all data is extracted, the account is securely deactivated, and all data is permanently deleted in accordance with GDPR and the buyer’s instructions.
If a buyer requires additional support—such as a full structured database export, extended access beyond the contract end date, or assisted migration to another system—this can be provided on request at an additional cost.
All basic offboarding activities and standard data exports are included in the contract price. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
✔ Mobile phones
✔ Tablets
✔ Small screens
✔ Touch interfaces - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Web-based interface with dashboards, admin portals, user login areas, management tools, and interactive forms designed for simple navigation and task completion. Responsive across desktop and mobile.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have carried out accessibility testing using a combination of automated and manual methods. Automated checks were completed using WAVE, Axe, and browser accessibility tools to identify issues related to structure, labels, contrast, and keyboard focus. Manual keyboard-only testing was performed to ensure all navigation, forms, and interactive components can be used without a mouse. The interface was reviewed with screen readers including NVDA and VoiceOver to verify compatibility with spoken feedback, logical reading order, and clear alternative text. We also tested with browser features such as zoom, high contrast mode, and reduced motion settings. Feedback from internal testers using assistive technologies guided improvements to form labels, heading structure, focus indicators, and error messages. Accessibility reviews will continue throughout the service lifecycle as part of ongoing compliance.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise the Green Business Tools Cloud Platform to meet their specific operational needs. Customisation options include branding (logos, colours, organisation details), user roles and permissions, form fields, business workflows, and optional service modules such as Digital Menu, Nanny World, or Out-of-School features.
Administrators can configure these settings directly through the online admin dashboard without needing technical skills. They can create custom templates, update business information, manage user access, and activate/deactivate modules based on their organisation’s requirements. Buyers can also adjust notification settings, email templates, and integration preferences.
Advanced customisation, such as API-driven integrations or bespoke workflows, can be requested and implemented by authorised technical users or through our support team. All changes are applied securely and instantly across the cloud platform.
Scaling
- Independence of resources
- The platform uses containerised services and load-balanced cloud infrastructure to ensure workloads are isolated between customers. Each organisation operates within its own logically separated environment with independent databases and resource limits. Auto-scaling manages increased demand, ensuring consistent performance. Traffic spikes from one buyer do not impact others, maintaining stable and predictable service levels.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide usage metrics including number of active users, login activity, module usage (Digital Menu, Nanny World, Out-of-School), data storage usage, API calls, form submissions, menu updates, and audit logs. Administrators can view real-time system activity, user engagement trends, and operational performance indicators to support reporting, optimisation, and governance.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Other
- Other data at rest protection approach
- “Data at rest is protected through strong encryption (AES-256) applied to all databases, storage volumes, and backups. Physical access to datacentres is restricted and controlled under CSA CCM v4.0–aligned security standards provided by our hosting partners. Additional controls include role-based access, server hardening, and continuous monitoring to prevent unauthorised access.”
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Data export approach — Suggested Answer (under 100 words)
Users can export their data at any time through the built-in data export tools available in the admin dashboard. Data can be downloaded directly as CSV, Excel, or PDF files. Administrators can export individual records, full datasets, reports, or audit logs. For larger exports, users can request a secure download link via email. All data exports are self-service and available without additional cost. - Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- XLSX (Excel)
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- XLSX (Excel)
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- “All data transmitted between the buyer’s network and the Green Business Tools Cloud Platform is protected using TLS 1.2+ with strong cipher suites. HSTS is enforced to prevent protocol downgrade attacks. Optional VPN tunnels can be provided for secure system-to-system integrations. Traffic is continuously monitored, and suspicious activity is blocked through firewalls and intrusion prevention controls.”
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- “Data within the Green Business Tools Cloud Platform is protected using TLS 1.2+ for all internal service communication. Sensitive workloads are isolated using network segmentation and firewalls. Access to internal systems is restricted via role-based access controls and multi-factor authentication. All traffic is monitored for anomalies, and intrusion detection systems block suspicious activity. Encryption in transit and strict access controls protect internal data flows.”
Availability and resilience
- Guaranteed availability
-
We guarantee 99.5% service availability for the Green Business Tools Cloud Platform. Availability is monitored continuously across all core services, including authentication, dashboards, and data APIs. Planned maintenance is scheduled outside business hours and communicated in advance.
If availability falls below the guaranteed level within a billing period, users are entitled to service credits, applied as a percentage discount on the next invoice depending on the duration and severity of the outage. Critical incidents affecting uptime are prioritised under our SLA and resolved by our technical team as quickly as possible.
The service is hosted on infrastructure with high-availability capabilities, including redundant networking, server failover, and geographic resilience provided by our cloud hosting partners. We maintain continuous monitoring to detect issues proactively and restore normal service rapidly. - Approach to resilience
-
The Green Business Tools Cloud Platform is designed with a resilient, fault-tolerant architecture. Core services are hosted in highly available cloud environments with built-in redundancy for compute, storage, and networking. Infrastructure is distributed across multiple availability zones to minimise the impact of localised failures.
All data is automatically backed up at scheduled intervals, with encrypted backups stored in separate physical locations. Disaster recovery procedures are in place to enable service restoration in the event of major incidents, and failover mechanisms ensure continuity of operations with minimal disruption.
Continuous monitoring is used to track system health, performance, and security events. Alerts enable our technical team to take immediate action to maintain service stability. Capacity is scaled automatically based on demand to prevent performance degradation during peak usage.
Datacentre resilience (including physical security, power redundancy, environmental controls, and multi-layer failover) is managed by our cloud hosting partners and complies with recognised international standards. More detailed datacentre resilience information is available to buyers on request. - Outage reporting
-
Service outages are reported through multiple channels to ensure buyers are informed quickly and consistently. We operate a public service-status page that displays real-time availability, planned maintenance schedules, and any ongoing incidents.
In the event of an outage, automated monitoring systems trigger alerts to our support team and generate notifications for registered users. Buyers receive updates via email alerts outlining the issue, expected impact, and estimated resolution time. Regular progress updates are provided until the service is fully restored.
A post-incident summary is shared with affected customers, including root-cause analysis and actions taken to prevent recurrence. API-based status feeds can be provided to buyers on request for integration into internal monitoring tools.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- Authentication includes email-based one-time passcodes (OTP), PIN verification, and secure token-based session management.
- Access restrictions in management interfaces and support channels
- Access to all management interfaces is restricted using role-based access control (RBAC), multi-factor authentication, and secure session management. Only authorised administrators can access management dashboards, and privileges are limited to the minimum required for each role. Administrative actions are logged and monitored. Support channels are accessed through authenticated accounts only, and support staff have restricted, audited access to customer information on a need-to-know basis. Sensitive operations require elevated permissions, which are reviewed regularly. All access is encrypted, and direct database access is limited to authorised technical personnel under strict controls.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- Management access to the Green Business Tools Cloud Platform is restricted to authorised administrative users through secure authentication controls. All admin accounts require strong passwords and are protected by Multi-Factor Authentication (MFA) before access is granted. Management interfaces are only accessible over encrypted HTTPS connections, and access is logged and monitored for unusual activity. Administrative privileges are role-based, ensuring users can only access the functions necessary for their duties. Access rights are reviewed regularly, and inactive or unnecessary accounts are promptly removed to maintain security.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Our organisation follows a structured security governance approach aligned with the UK Software Security Code of Practice. We apply clear roles and responsibilities for managing security, covering data protection, access control, incident handling, and secure development standards. Security is embedded throughout our software lifecycle, including code reviews, vulnerability checks, and change control procedures. We use encrypted infrastructure, access monitoring, and least-privilege principles for administrators. Policies are reviewed regularly, and risks are assessed as part of ongoing service management. Although we are not formally certified, we follow recognised best-practice controls suitable for a small cloud service provider.
- Information security policies and processes
-
We follow a structured set of information security policies covering data protection, access control, secure development, incident management, backup and recovery, encryption, change management and supplier management. Policies are reviewed annually and updated as required. Security responsibilities sit with the board-level security lead, who oversees implementation and ensures compliance.
Access to systems follows least-privilege principles, with MFA for administrative access and audit logs for all critical actions. Data is encrypted in transit and at rest, and regular vulnerability checks ensure risks are identified and addressed quickly. Incident response procedures define how security issues are reported, escalated, investigated and resolved. Staff receive guidance on data handling, password hygiene, and secure use of systems.
Compliance is monitored through routine checks, log reviews, and periodic testing. Any non-compliance is escalated to the security lead for corrective action. These processes ensure consistent, safe operation of the service and protection of user data. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our platform uses a structured change management process. All service components are version-controlled and tracked through their lifecycle using Git repositories, deployment logs, and configuration records. Changes are reviewed, documented, and tested in a staging environment before release. Any proposed change is assessed for potential security, performance, or user impact. Security-related updates follow an accelerated approval workflow. Only authorised personnel can deploy changes, and all deployments are logged and monitored. Regular audits ensure configuration consistency, and rollback procedures are in place to recover quickly from unexpected issues.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We operate a continuous vulnerability management process that monitors system health, security alerts, and emerging threats. Potential vulnerabilities are identified through automated scans, server-level monitoring, and alerts from trusted sources including NCSC advisories, vendor security bulletins, and industry threat intelligence feeds. Identified issues are assessed based on severity and potential impact to the service. Critical patches are deployed within 24 hours, high-risk issues within 48–72 hours, and standard updates during the next scheduled maintenance window. We regularly review logs, apply security updates to infrastructure and application components, and conduct periodic audits to ensure vulnerabilities are addressed promptly.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use continuous log monitoring to detect unusual activity across authentication, access, and system operations. Automated alerts highlight potential compromises such as repeated failed logins, abnormal traffic, or unauthorised access attempts. When a potential issue is identified, our team immediately investigates, validates the event, and applies containment steps such as blocking access, isolating services, or resetting credentials. Confirmed incidents are prioritised based on severity, with initial response typically within 1 hour. We review logs, implement fixes, deploy patches where required, and document the incident. Post-incident reviews ensure improvements to monitoring rules and future prevention.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate a formal incident management process with predefined procedures for common events such as service outages, security alerts, and data access issues. Users can report incidents through email support, phone support, or our online ticketing system. All incidents are logged, prioritised, and handled according to severity. Customers receive updates throughout the investigation, with a full incident report provided upon resolution. For significant incidents, we provide a post-incident review including root cause, impact assessment, remediation steps, and preventive actions. Our process aligns with recognised best practices to ensure rapid response, clear communication, and continuous service improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- A free 14-day trial is available, giving users access to core features including dashboards, user management, and basic module setup. Advanced features, extended storage, integrations, and custom branding are excluded. No payment details are required during the trial.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Volunteering opportunities for staff
-