Skip to main content

Help us improve the Digital Marketplace - send your feedback

PEN-LINK TECHNOLOGIES UK LTD.

PLX by Penlink

From call detail records to social media and mobile extractions, PLX creates a unified timeline so you can quickly spot connections and build stronger cases.

Features

  • Call detail records
  • Social media extractions
  • Mobile forensic extractions
  • Artificial intelligence powered
  • Report and summarise

Benefits

  • Unify call detail, social media, and mobile forensic files
  • Timeline conversations, interactions and movement
  • Identify and link connections
  • Surface insights from huge amounts of data
  • Graphical and textual summary of large data sets

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at paul.miller@penlink.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 9 2 3 7 8 8 0 0 4 1 1 3 7 5

Contact

PEN-LINK TECHNOLOGIES UK LTD. Paul Miller
Telephone: 07552 424231
Email: paul.miller@penlink.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Public Order and Safety
  • Police
  • Defence
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
No constraints. Deployment and future maintenance is all done in coordination with client.
System requirements
  • Minimum internet connection of 50Mbps
  • Minimum 16GB RAM
  • Minimum 256GB Disk Space
  • Windows 10 and up preferred
  • Chrome browser preferred

User support

Email or online ticketing support
Yes
Support response times
Critical matters - within 4 hours
Major matters - within 6 hours
Minor matters - within 1 business day
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Through support portal which registered users have access to.
Web chat accessibility testing
N/A.
Onsite support
Yes
Support levels
Registered system users have access to support portal in which they can view frequently asked questions as well as contact support team by message, phone and chat. For some system technical support, our engineers may need to connect to a clients system but will only do so under written instruction from clients. In cases where it is necessary, our engineers can visit client sites.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Training is discussed during the sales conversation so that buyers obtain the specific level of service to suit their needs. Typically users begin with 2 days of onboard training, followed by a further 2 days of enhanced training, followed by a further 1 day of thematic training. This can be condensed or expanded to suit needs and can incorporate additional vocational training to develop foundational understanding before, during and after learning system specifics.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Users can export data in formatted reports using either standard system report formats or customised ones. Additionally data can be exported in formats such as PDF, CSV, and JSON.
End-of-contract process
Should a contract come to an end, users will be informed beforehand and will have the opportunity to export any and all data before system shutdown. Following system shutdown, data will be forensically expunged.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Available from within the system itself, from within the learning management system, and can also be sent directly upon request.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Mobile application is licenced separately and offers simplified functionality.
Service interface
No
User support accessibility
None or don’t know
API
No
Customisation available
Yes
Description of customisation
Buyers can select which modules to include / exclude, what AI features to include / exclude, and what of all of this to deploy to each user profile.

Scaling

Independence of resources
Each client system runs in its own private cloud built to a specification to support their size of system. Our support engineers run diagnostics regularly to track systems are staying within their forecasted use and will expand build specification if there is risk a client is nearing their limit.

Analytics

Service usage metrics
Yes
Metrics types
Users can view their own usage (for example number of searches performed, success/failure rate, and so on). Supervisors can view the above for their team. All hierarchy users can view their respective teams, up to administrators who can view the metrics system wide.
Reporting types
Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export data in formatted reports using either standard system report formats or customised ones. Additionally data can be exported in formats such as PDF, CSV, and JSON.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • JSON
Data import formats
  • CSV
  • Other
Other data import formats
  • PDF
  • JSON

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
PenLink's Disaster Recovery plan leverages Azure Recovery Vault capabilities, enabling the recovery of Customer Azure Virtual Machines from the latest available VM snapshot within an estimated 5-hour duration. The platform is deployed in a High Availability (HA) configuration, with disaster recovery configuration also supported and customizable based on preferred cloud instance requirements. Hardware and Virtual Machine availability SLA adhere to Azure or AWS hardware availability commitments, ensuring reliable performance and uptime, as validated by certifications such as SOC2 and ISO.
Approach to resilience
PenLink's Disaster Recovery plan leverages Azure Recovery Vault capabilities, enabling the recovery of Customer Azure Virtual Machines from the latest available VM snapshot within an estimated 5-hour duration. The platform is deployed in a High Availability (HA) configuration, with disaster recovery configuration also supported and customizable based on preferred cloud instance requirements. Hardware and Virtual Machine availability SLA adhere to Azure or AWS hardware availability commitments, ensuring reliable performance and uptime, as validated by certifications such as SOC2 and ISO.
Outage reporting
We have several monitoring tools used on a production system. For the backend services our DevOps have a monitor and tester to each source service and they are all monitored 24/7:

• Application errors
• Infrastructure issues
• CPU ,RAM and disk utilizations.

For the customer system itself as part of the installation we deploy an agent that monitors the system CPU RAM and Disk utilization . In cases utilization exceeds a preset threshold, we will be notified.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
User identities are verified and managed with formal procedures, including access control, role-based privileges, and regular audits, all validated during SOC2 audits. Security measures include two-factor authentication, regular access reviews, and monitoring of remote connections, ensuring robust protection of sensitive data and prompt response to security incidents.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Extensive set of policies and procedures directly related to our SOC2 and ISO standards.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
A meticulous change control process is fundamental to our Secure Software Development Life Cycle (S-SDLC), where all codebase modifications undergo rigorous approval, validation, documentation, and testing, ensuring changes maintain system security and integrity, as confirmed during ongoing SOC2 audits. Tight management of change control minimizes the risk of unauthorized alterations and vulnerabilities.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We maintain an inventory of assets and services, categorized based on criticality and information classification. Protection requirements are aligned accordingly. Regular reviews ensure accuracy, and authorized personnel are identified for system components.

Applications adhere to secure coding guidelines undergoing testing to prevent vulnerabilities. System and information integrity requirements are documented, disseminated, and updated.

A technical vulnerability management program monitors, assesses, ranks, and remediates vulnerabilities identified. Patches are rigorously tested before installation.

Regular penetration testing is conducted by independent agents. Historic audit logs are reviewed to identify exploited vulnerabilities, and monthly vulnerability scans are conducted automatically.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Cloud resource utilization and status are continually monitored through a dedicated agent, providing real-time status information and alerts, as confirmed during ongoing SOC2 audits.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Identification: System and security alerts are analyzed, incidents investigated, and severity classified for escalation within PenLink, involving product, security, and engineering specialists.

Containment: Escalation teams assess incident scope and impact, prioritize containment to safeguard data, and implement response measures, including forensic analysis if needed.

Eradication: After containment, efforts focus on eliminating damage and identifying root causes, with vulnerabilities reported to product engineering for resolution.

Recovery: System updates and services restoration are undertaken to return operations to full capacity.

Lessons Learned: Each incident is analyzed to apply appropriate mitigations, ensuring future protection against recurrence.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Length and specifics are discussed with potential buyers beforehand on a case by case basis. Generally, a trial will last for 1-2 weeks, will begin with training input, include check-ins throughout, and conclude with a debrief.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
6%
Between £500,001 and £1,000,000
6%
Between £1,000,001 and £2,500,000
12%
Between £2,500,001 and £5,000,000
25%
Over £5,000,001
35%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
SII audited us, ANAB audited SII
ISO/IEC 27001 accreditation date
Monday 17 February 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Monday 8 April 2024
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
N/A
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
  • SOC 2 Type 2
  • SOC 3
  • ISO/IEC 27017
  • ISO/IEC 27018
  • NIST SP 800-171
  • TX-RAMP Level 2

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at paul.miller@penlink.com. Tell them what format you need. It will help if you say what assistive technology you use.