RPA Platforms, AI Platforms and Automation Platforms
Resale and management of UiPath Cloud licences, Druid AI licenses and Otera licences, for agentic AI automation and conversational AI automation. Covers licence procurement, licence renewal, AI onboarding guidance and usage optimisation support, providing safe AI adoption, secure ai adoption, usage optimisation support and cross-service value scaling
Features
- Cloud licence provisioning, renewal management and licence co-termination support
- Remote admin access controls, role based permissions, secure single sign-on
- Activity utilisation tracking, license utilisation tracking, audit logging, operational reporting
- Service desk portal incident logging, service desk portal request logging
- Scalable automation governance, deployment governance and deployment design governance
- Agentic self-service, conversational AI digital front door
- Contact centre AI assistants, mobile AI assistants, web AI assistants
- AI agent orchestration governance, AI agent automated workflows
- Intelligent document processing, automated document extraction, automated document validation
- Enterprise platform integration, API integration, existing system integration
Benefits
- Uipath robots and AI orchestrated workflows automate repetitive tasks
- AI agent deployment for end to end case processing
- Druid conversational AI, conversational AI triage, digital front door
- Otera AI agents for AI document validation, AI document classification
- Faster time to value, AI onboarding support, AI renewals support
- Multiple data source integration and existing API integration
- Automation reduced turnaround times for straight through processing
- Improved processes compliance, improve processes consistency, auditable logging
- Automated operations scaling, automated workflow scaling, automated workflow improvements
- Dashboard performance tracking, insights performance tracking, continuous optimisation tracking
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 5 3 4 3 1 3 4 5 5 0 2 5 2 0
Contact
Org
Greg Coulson
Telephone: +44 (0)7393 148163
Email: bids@thisisorg.com
About your service
- Service categories
-
Application Development and Deployment
AI platforms
- Search and knowledge discovery
AI life cycle
- Data Labeling Software
- AI Build Software
- MLOps and Foundation Model Ops Software
AI software services
- Conversational AI Software Services
- Computer Vision AI Software Services
- Generative AI Software Services
- Document AI Software Services
- Anomaly Detection AI Software Services
- Personalize AI Software Services
- Forecast AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Our service is an extension to the UiPath Automation Platform and can complement existing enterprise tooling, including Microsoft Power Platform, Dynamics365, ServiceNow and common integration layers. It integrates with test and delivery toolchains such as Azure DevOps and Jenkins for CI/CD and continuous testing and analytics platforms for operational reporting.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- Constraints and service limits apply across UiPath, Druid and Otera in line with each vendor’s cloud service. Planned maintenance and upgrades are scheduled by the vendors (with notice where possible) and may temporarily affect availability. Functionality is provided as standard cloud software; buyers cannot request unsupported platform changes. Integrations depend on customer network access, identity configuration, and availability of target systems and APIs. Service levels and support hours are limited to the purchased support package and agreed hours of cover. Some capabilities may require specific licensing tiers, AI units or consumption bundles.
- System requirements
-
- Active UiPath Cloud, Druid, or Otera subscription licences, as required.
- Secure internet access to vendor cloud services and admin consoles.
- Supported modern browser: Edge, Chrome, or Firefox, latest versions.
- Single Sign On ready: Azure AD, SAML, or OpenID Connect.
- Approved endpoints and firewall allow-lists for vendor service domains.
- TLS 1.2 or higher for all connections and integrations.
- Endpoint security: managed anti virus, EDR, and patching compliance.
- Service accounts with least privilege access to target systems.
- Integration access: APIs, HL7 feeds, databases, or file shares.
- For unattended automation: Windows virtual machines or servers available.
User support
- Email or online ticketing support
- Yes
- Support response times
-
User support is provided Monday to Friday, 8am to 5pm (excluding public holidays), via email and ticketing.
During support hours, we aim to acknowledge all new queries within 4 business hours and provide an initial response or action plan within 1 business day, depending on complexity and severity.
Outside of these hours (evenings and weekends), tickets can still be logged, but they will be picked up from 8am on the next business day. If weekend cover is required, this can be agreed separately at extra cost and documented in the Order Form/SOW, including the relevant response targets. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- EN 301 549
- Web chat accessibility testing
-
Our service uses Jira Service Management as the primary support portal, with tickets raised via the web portal and email. For some customers we offer a dedicated live web chat channel as part of this support model.
From an accessibility and usability perspective, we validate the end-to-end support journey using assistive technologies by testing the key user tasks: logging in, creating a request, adding attachments, viewing ticket status, and responding to updates. This includes keyboard-only navigation and screen reader checks, and we also verify that email-based ticket creation and updates provide an accessible alternative for users who prefer not to use the portal.
Constraints: accessibility behaviour is dependent on the customer’s browser settings and any organisation-specific Jira configuration (fields, workflows, templates). Where a buyer has specific accessibility requirements, we will agree the approach during onboarding and document it in the Order Form. - Onsite support
- No
- Support levels
-
Org provides structured user support across Level one, Level two and Level three support, aligned to the SaaS service and agreed support scope. Level one support covers user assistance, incident logging, initial triage and guidance on use of the AI platform. Level one support is provided during agreed service hours.Level two support provides deeper technical investigation, configuration support, data ingestion troubleshooting and resolution of platform issues. This level supports operational continuity and correct platform configuration.
Level three support provides specialist product and engineering support for complex or high impact issues, including advanced troubleshooting, performance optimisation and product level defects.
Support is delivered remotely via integrated ticketing within the platform and by email. A named Cloud Support Engineer is available for Level two and Level three support. A dedicated technical account manager is not included as standard but can be provided by agreement where required. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
To help customers start using Org’s support service (covering UiPath, Otera and Druid AI), we provide a structured onboarding process using our Jira Service Management portal.
Getting started includes:
Onboarding call/workshop to confirm scope (what’s in support vs change), environments, contacts, and escalation routes.
Jira setup: we create customer users, queues, priorities, SLAs, and agreed ticket categories (incident, service request, how-to, access).
Knowledge pack: short user guide on how to raise tickets, what information to include (process name, screenshots, logs, steps to reproduce), and how we communicate updates.
Operational handover from delivery to support, including runbooks, exception handling notes, credentials approach, and monitoring/alerting set-up (where applicable).
Training options: remote walkthroughs for admins and key users; optional onsite sessions by request.
Customers can log and track support tickets via the Jira portal or email, with full visibility of status and history. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
When the Call Off Contract ends, the buyer can extract their data in line with the relevant platform terms and the agreed Order Form.
UiPath Cloud: Buyer data (for example automations packages, logs, queues, and configuration) can be exported using UiPath’s built in export features and administrative tools. Org will support a controlled export if requested, including confirming what data is required and the preferred format.
Druid AI: Conversation transcripts, bot configurations, and analytics can be exported using the platform’s administrative export options, subject to role based access controls and retention settings agreed with the buyer.
Otera: Case and document processing outputs, audit information, and configuration data can be exported using the platform’s export and reporting capabilities, subject to buyer permissions and retention policies.
Support and ticketing (Jira): The buyer can export ticket history and metadata as CSV and, where required, provide a copy of attachments they supplied. Org will remove buyer access after confirmation and apply data retention and deletion in line with contractual and regulatory requirements. - End-of-contract process
-
At the end of the Call off Contract for software licences purchased through Org under G-Cloud, we will agree an offboarding plan with the buyer and the relevant vendor(s) UiPath, Druid AI and Otera.
What happens at end of contract
We confirm whether the buyer is renewing, transferring to another reseller, or ending the service.
If ending, we support a controlled close out: confirm licence end dates, user access removal, and data export requirements (as permitted by each platform).
We provide a final service summary covering open support items, outstanding actions, and agreed data retention or deletion steps.
Included in the contract price
Licence resale at vendor list price as per the Order Form.
Standard renewal coordination and contract administration.
Offboarding coordination and guidance, including signposting vendor export options and timelines.
Additional cost
Any hands on extraction support, data packaging, or migration activity beyond standard guidance (for example, exporting large volumes, transforming data, moving configurations, or assisting with cutover) can be provided under a separate Statement of Work.
Optional extended support beyond contract end date, if requested, is chargeable. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Even though the documentation is provided in PowerPoint, PDF, HTML and Word, we aim to make it accessible and usable for as many people as possible.
HTML documentation is structured with headings, clear navigation, meaningful link text, and works with screen readers and keyboard-only use.
Word documents use built-in styles (headings, lists, tables) so assistive technologies can interpret structure properly, and we avoid “text as images” where possible.
PowerPoint decks use slide titles, reading order, accessible layouts, and alt text for any meaningful visuals.
PDFs are provided in an accessible format where possible (tagged PDFs), and we’ll supply the source Word/HTML version on request if a user needs a more accessible alternative.
If a buyer has specific accessibility needs, we can agree an accessible format as part of onboarding and provide documents in the most suitable version.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There is no functional difference between mobile and desktop use of the Jira support portal. Users access the same service through a web browser, with the same ticket types, workflows, and visibility of requests. The only practical difference is the user experience: on mobile, the interface is responsive and optimised for smaller screens, so some fields, menus, or ticket details may appear collapsed or require additional scrolling compared to desktop.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Users access the service through a standard web browser (desktop or mobile). If users rely on assistive technologies, accessibility will depend on their browser and device settings, as well as the accessibility capabilities provided within Atlassian Jira Cloud. Org can provide alternative channels where required, including email-based ticket submission and updates, to support users who cannot use the portal. The service does not require specialist software beyond a modern browser and email access.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service is accessed through Jira (Atlassian), via a secure web portal and email-to-ticket. Users can log incidents, service requests and licence queries; upload files/logs; view status, SLAs and comments; approve changes; and access knowledge articles and runbooks. Service owners can view reports and dashboards on volumes, trends and resolution times. Users cannot access Org internal administration, customer environments, or vendor partner portals directly; those actions are completed by Org under agreed permissions. Access is controlled using role-based permissions and (where available) SSO/MFA.
- Accessibility testing
-
We haven’t completed dedicated accessibility testing of the Jira Service Management portal with assistive-technology users.
However, the portal is accessed through a standard web browser and supports common assistive technologies (for example, screen readers, keyboard-only navigation and browser zoom). If a buyer has specific accessibility needs, we can run user-led testing with their assistive-technology users during onboarding and agree any reasonable adjustments or alternative channels (for example, email-based ticket logging and updates) in the Order Form. - API
- Yes
- What users can and can't do using the API
-
Users can interact with the Jira Cloud service via Atlassian’s REST APIs to automate common service management and administration tasks.
What users can do via the API.
Set up and configure: create projects, issue types, fields (where permitted), workflows (via supported endpoints/apps), queues, and service desk settings (subject to Jira plan and permissions).
User and access management: manage users and groups through Atlassian Admin APIs (subject to organisation controls, SSO settings, and admin permissions).
Operate support: create, read, update and transition tickets; add comments and attachments; update priorities, labels, components, assignees; create subtasks; manage SLAs and request types (JSM).
Integrate tooling: connect monitoring/alerting tools to automatically raise incidents, update statuses, and post notifications.
What users can’t do / limitations.
Changes are permission-based (admin vs agent vs reporter) and plan-dependent (some configuration features vary by Jira/JSM edition).
Certain configuration actions may require admin console changes (for example SSO, data residency, security settings) rather than project-level APIs.
API usage is subject to Atlassian rate limits, authentication requirements, and any restrictions set by the buyer’s security policies (for example IP allowlists, approved integrations). - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise UiPath support delivered through Jira to match their operating model and governance.
What can be customised: request and incident categories (eg licences, Orchestrator, robots, AI/IDP, Test Suite), priority/severity rules, SLAs, approval steps for changes, escalation paths, notification rules, and reporting dashboards. Knowledgebase content and standard request forms (eg access requests, new robot requests, Test Suite set-up, regression pack runs) can also be tailored. Where agreed, we can align support to your release calendar and environments (DEV/UAT/PROD) with change windows.
How users customise: Org configures the Jira Service Management project, workflows, forms and dashboards based on your requirements. Service owners can request adjustments via a “service configuration change” ticket, or through agreed governance sessions (weekly/monthly service reviews).
Who can customise: your nominated Service Owner(s) and Jira Admins can approve and request changes; Org implements and validates them under change control. End users can self-select categories, add templates, and tailor notifications within their permissions.
Scaling
- Independence of resources
- We protect customers from other’s demand through vendor cloud isolation and capacity controls. UiPath Cloud, Druid and Otera are delivered as multi tenant SaaS on Microsoft Azure with logical tenant separation and platform level throttling and autoscaling. Each customer is provisioned with dedicated tenant resources and quotas as per their subscription, Another customer’s peak usage cannot consume your allocated capacity. Where orchestration is required, workloads are queued and prioritised within your own tenant, with monitoring and alerting on utilisation. Any capacity increases are handled by scaling your subscription and adding licences or consumption as needed, without impacting other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide service usage and operational metrics via each platform’s native reporting, plus Jira Service Management reporting for support. Metrics typically include login and usage trends, volumes by channel or queue (for conversational AI), automation runs and success rates, exception and human in the loop volumes, straight through processing rates, consumption indicators (for example AI unit or credit usage where applicable), incident and request volumes, response and resolution times, backlog and ageing, change request volumes, and release and deployment history. Reporting frequency and dashboards are agreed with Clients
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- UiPath, Druid AI, Otera
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export their data using the standard export tools provided by each platform (UiPath, Druid AI and Otera). Exports are typically performed by an authorised administrator via the product interface, and may include configuration data, logs, analytics outputs, conversation transcripts and workflow artefacts, subject to role-based access and retention settings. Where available, users can also export data via vendor-provided APIs and reporting connectors. Org can provide guidance on the export options and recommended approach, and can support additional export assistance under a separate Statement of Work if required.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Other
- Other protection between networks
- Data is protected in transit using encrypted connections end to end. All connectivity between the buyer’s network and the service uses TLS 1.2 or higher (HTTPS), with strong cipher suites and certificate validation. Where private connectivity is required, we support IP allow listing and secure VPN or private network connectivity options provided by the underlying Azure hosting model. Service accounts use least privilege and secrets are stored and rotated securely (for example, in Azure Key Vault or the vendor’s equivalent). We do not use unencrypted protocols for any data transfer.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- Within our network and the underlying vendor platforms, data in transit is protected using TLS 1.2 or higher for all internal service to service communications, including between application components, APIs, and databases. Network segmentation and firewalls restrict east west traffic to only required ports and endpoints. Access is controlled through role based access control and least privilege, with strong authentication and audited administrative access. Secrets and certificates are stored in secure vault services and rotated in line with policy. Where available, private endpoints are used to minimise exposure to the public internet.
Availability and resilience
- Guaranteed availability
-
The service is delivered as a cloud based Software as a Service platform designed for high availability and resilience. The service is hosted on resilient cloud infrastructure using managed services and redundancy to minimise the risk of service interruption.
Availability targets are defined within the service agreement and are measured on a monthly basis, excluding planned maintenance. Planned maintenance windows are infrequent and communicated to users in advance.
If availability falls below the agreed service level, service credits may be applied in line with the terms set out in the contract. Service credits are calculated based on the duration and severity of the availability impact.
The platform includes monitoring and alerting to support rapid identification and resolution of service issues. Disaster recovery and backup processes are in place to support service restoration following major incidents.
Specific availability commitments and remedies are confirmed as part of the contractual agreement with each customer. - Approach to resilience
-
The solution components are designed for security, high availability, resilience and recovery.
We propose to implement the solution using Microsoft Azure which provides a strategic approach to cloud adoption and infrastructure setup, ensuring scalability, security, and governance from project start. This approach is especially crucial for public sector entities that operate under strict regulatory and security requirements.
All platforms are delivered as Software-as-a-Service, hosted within UK or EU data centres. This arrangement adheres to public sector requirements for security, data residency, and compliance whilst ensuring high availability, scalability, resilience.Our recommended hosting makes full use of Azure’s resilience, redundancy, and integrated backup facilities. Data Protection Measures Include:
• Automated, scheduled backups.
• Geo-redundant storage housed in UK/EU approved regions.
• High availability architecture with failover support. - Outage reporting
- Org uses continuous monitoring and alerting to identify service issues. Where a service outage or major incident occurs, customers are notified through agreed communication channels, including service notifications and support ticket updates. Incident progress and resolution updates are provided until service is restored. Post incident reviews can be shared where required to support transparency, assurance and operational learning.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is governed through security profiles, which define permissions per role, like agents or managers. These profiles restrict what tasks users can perform and which areas of the system they can access. The profiles are configured to adhere to the principle of least privilege, providing necessary permissions without overexposing sensitive areas. This control mechanism is pivotal in maintaining the integrity and security of the contact center's operations. The best practice is to tailor security profiles closely to job functions, thus minimising any potential security risks.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We have a comprehensive range of policies designed to maintain Information Security and a well-established Information Security Management System (ISMS). Our security policies are outlined at commencement of employment and available on our intranet. They include:
• Employee and Third Party Physical Access Policy
• Information Security Policy
• Networks and Systems Usage Policy
• Accessing Personal Account Information Policy
• E-mail and Internet Usage Policy
• Mobile Phone Policy
• Data Protection Policy (GDPR)
The scope of our ISMS is to provide a secure and standardised system so that confidential information can be stored, processed, transmitted and retrieved securely and to maintain a culture of information security throughout the organisation. We undergo regular internal and external audits to confirm that the ISMS is functioning correctly and hold ISO27001 accreditation.
Robust security controls are in place at all levels of the operation to prevent, detect and mitigate potential cyber-attacks, with all client data encrypted at rest and in transit. A 24/7 security operations centre delivers real-time monitoring of our IT systems to detect and respond to incidents and suspicious activity.
All staff receive annual refresher training and updated policies on the requirements, including Annual Data Protection and IT security training. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Change Control Requests (CCRs) are initiated, reviewed, and presented to the Change Advisory Board (CAB) for assessment following ITIL-aligned guidelines. Our Security Program Manager is an important member of CAB. Each CCR details the anticipated impact of its implementation or the consequences that would be experienced if not implemented. These impact assessments are essential for decision-making within the CAB, ensuring changes align with organisational objectives and risk management strategies and enables informed decisions that maximise service stability and minimise disruptions to operations. This approach drives a regular release management process that delivers regular service updates and process improvements.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Vulnerability and threats are reported to our Information Security team. Preventative measures include:
Real-time 24/7 SOC monitoring of on-premise and cloud IT systems. Palo Alto WildFire used for highly evasive zero-day exploits / malware at the perimeter level.
End User Devices: Non-compliant devices are identified, isolated and deregistered. Remote devices with inactive Trend Micro Endpoint security are denied access to our network by Microsoft Intune Device based compliance policies.
Patch management: Automated patch management provided by M365 Update policies or PatchMyPC and Firmware/device driver patching provided by Microsoft or Dell Update utilities. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Our protective monitoring employs CloudWatch dashboards with alarms to preemptively notify stakeholders of crucial operational impacts. It includes tracking maximum concurrency of contacts and real-time statistics to alert on unexpected spikes, ensuring limits are adjusted in a timely manner. Lambda monitoring scrutinizes API interactions, capturing durations and errors, with immediate alerts for anomalies. Network health is consistently observed. This proactive strategy is designed to quickly identify potential compromises and rapidly respond, prioritizing stakeholder awareness to expedite incident resolution.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Requesters log incidents through our online ticketing system. Our IT teams promptly engage with these incidents, working towards resolution according to predefined service levels and priorities.
Major incidents receive dedicated oversight from an Incident Manager to coordinate response efforts and ensure timely resolution. Functional escalation is utilised when necessary, to address complex or critical incidents.
Incident status is documented on a weekly basis for the Service Measurement and Reporting team, who report them to the Service Management team.
On a monthly basis, the status of each incident is reported by the Operational Risk team to update the Risk Committee. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Some UiPath services (for example Automation Hub) may be available as a time-limited trial (typically up to two months), subject to UiPath eligibility and approval.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 2.5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Amtivo (Ireland) Limited
- ISO/IEC 27001 accreditation date
- Tuesday 9 September 2025
- What the ISO/IEC 27001 doesn’t cover
- N/a
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Amtivo (Ireland) Limited
- ISO 9001 accreditation date
- Monday 3 March 2025
- What the ISO 9001 doesn’t cover
- N/a
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 60154503-8e3a-413a-95e0-4db4e972b973
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 70488f27-8aff-46e1-ab29-d33d6333c037
- Other security certifications
- Yes
- Any other security certifications
-
- Amazon Connect has CSA STAR CCM v4
- SequenceShift is a PCI-accredited payment gateway
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-