Cerina Mental Health CBT App
A digital support service complementing NHS and DWP-funded work and health programmes, including WorkWell, helping people engage earlier, stay engaged, and maintain progress after formal support ends. The mobile app makes the waiting period a supported phase, offering multilingual conversational support, MHRA-regulated Class-I CBT self-help, mood tracking, self-referral and signposting.
Features
- Conversational agent supporting 100+ languages
- CBT-informed self-help content for anxiety, stress and confidence
- MHRA-regulated Class I SaMD, DTAC-compliant
- Two-way NHS interoperability
- Validated measures: PHQ-9, GAD-7 and DIALOG
- Integration with local and national crisis helplines and services
- Configurable branding and visual identity
- Configurable onboarding and registration workflows
- Automated risk detection with immediate safety signposting
- Analytics dashboard with real-time monitoring
Benefits
- Improves engagement across DWP WorkWell and Work and Health programmes
- Supports prevention and sustained outcomes beyond initial intervention
- Low-risk, low-complexity digital enhancement to existing services
- Scales easily across populations without added clinical capacity
- Reinforces coaching between sessions with self-directed tools
- Immediate, evidence-based support instead of an unmonitored wait
- Unguided model, no added clinician workload
- Mood tracking and reflective tools support self-awareness
- Evidence base: unguided RCT (n=158) published in JMIR (2025)
- Users access support privately and flexibly in their language
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 9 4 8 1 3 0 9 3 4 2 6 3 7 0
Contact
NOSUFFERING LIMITED
Prasannajeet Mane
Telephone: 07404717777
Email: prasannajeet.mane@cerina.co
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
Planned maintenance is carried out periodically to apply updates, security patches, and improvements. Where possible, maintenance is scheduled outside UK business hours, and customers are notified in advance of any planned service disruption.
The service requires a stable internet connection and is supported on current and commonly used versions of mobile operating systems. Support for older or end-of-life mobile operating system versions may be limited.
Updates to the mobile application are distributed via standard app store mechanisms and may be subject to platform approval processes.
Support is provided remotely and during UK business hours unless otherwise agreed at call-off. - System requirements
-
- Supported smartphone running current mobile operating system
- Stable internet connection required for normal service operation
- Application installed via official mobile app store
- No additional software, plugins, or specialist hardware required
User support
- Email or online ticketing support
- Yes
- Support response times
- 2 working days.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Accessibility has been considered through internal testing and the use of recognised accessibility guidance, including manual checks such as keyboard-only navigation, focus management, screen reader behaviour, colour contrast, and text resizing within the web chat interface.
Accessibility considerations are incorporated into ongoing development, and any issues identified through internal testing or user feedback are prioritised for remediation. More structured accessibility testing, including testing with assistive technology users, is planned as the service continues to evolve. - Onsite support
- Yes, at extra cost
- Support levels
-
Standard support (included)
Email-based support during UK business hours (Monday to Friday, excluding public holidays)
Incident logging and triage
Bug fixes and service-related queries
Access to product updates and documentation
Typical response times aligned to issue severity (e.g. critical incidents prioritised)
Cost:
Included in the standard service subscription
Enhanced support (optional)
Priority email support with faster response times
Scheduled support check-ins where required
Support for integration and configuration queries
Escalation management for incidents
Cost:
Charged as an additional annual or monthly fee (priced on request depending on scope and customer requirements)
Technical account management / cloud support
A dedicated technical account manager (TAM) is not provided as standard
For customers requiring enhanced support, a named technical contact can be assigned to coordinate support, manage escalations, and act as a primary liaison
Support is delivered by experienced technical staff familiar with the service and its hosting environment
Important clarifications (this protects you)
Support is provided remotely
No on-site support is included unless separately agreed
Service levels and response times can be agreed at call-off
All support is delivered in line with agreed data protection and security controls - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Users are supported to start using the service through a combination of in-app guidance, digital onboarding, and user documentation.
The mobile application includes guided onboarding to help users understand core features and how to use the service.
Supporting documentation and guidance can be provided digitally to organisational customers, and support is available via email during UK business hours to assist with setup and usage queries.
No on-site training is required, and the service is designed to be intuitive and self-guided for end users.
Administrative users can be supported with remote setup guidance where required.
Onsite and remote demonstrations can be provided on request. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
At the end of the contract, organisational customers can request extraction of their data by contacting the support team.
Data can be securely exported in a commonly used, machine-readable format and provided to the customer via a secure transfer method, subject to appropriate identity verification and data protection controls.
Following confirmation of successful data extraction and in line with contractual and data protection requirements, data is securely deleted from the service within agreed timescales. - End-of-contract process
-
At the end of the contract term, access to the service is disabled in line with the agreed contract end date.
Organisational customers may request extraction of their data prior to or at contract termination by contacting the support team. Data is securely exported in a commonly used, machine-readable format and provided via a secure transfer method, subject to appropriate identity verification and data protection controls.
Following confirmation that data extraction has been completed, customer data is securely deleted from the service in line with contractual terms, data protection requirements, and documented retention policies.
Where applicable, reasonable off-boarding support is provided remotely to support an orderly contract exit. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- No
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- We do not have a desktop version
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Mobile app
API (For integration) - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Accessibility has been considered through internal testing and the use of platform accessibility guidance, including manual checks such as keyboard and gesture navigation, screen reader behaviour using native mobile accessibility features (e.g. iOS VoiceOver / Android TalkBack), colour contrast, text scaling, and focus order.
Accessibility considerations are incorporated into ongoing product development, and feedback from users is reviewed and used to inform future improvements, including plans for more structured accessibility testing as the service continues to evolve. - API
- Yes
- What users can and can't do using the API
-
He service provides a RESTful API that enables authorised systems to integrate with the application and retrieve user-related data, such as assessment scores and usage metrics, subject to appropriate access controls and consent.
The API can be used to support integration with existing customer systems (for example clinical or reporting systems), allowing relevant data to be securely exchanged in line with agreed data protection and governance requirements. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Users onboarding flow
Questionnaires
Self care elements
Scaling
- Independence of resources
-
The service is hosted within a scalable cloud environment designed to support multiple customers concurrently. Resources are logically separated and managed to ensure that activity from one customer does not adversely impact others.
The underlying infrastructure uses capacity management, monitoring, and autoscaling controls to manage demand and maintain consistent performance. Service performance is monitored, and capacity is adjusted as required to respond to changes in usage.
This approach helps ensure that users experience a consistent level of service regardless of demand generated by other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The service provides a range of service and usage metrics to organisational customers to support monitoring and reporting.
Available metrics may include user activity and engagement measures (such as registrations, active users, engagement data and session activity), aggregated outcome or assessment scores where applicable, and basic service performance indicators.
Metrics can be provided through agreed reporting mechanisms, such as summary reports or secure data exports on request, and may also be made available via the service API where agreed.
All metrics are provided in line with data protection, consent, and information governance requirements. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Data is securely extracted in a commonly used, machine-readable format and provided via a secure transfer method, subject to appropriate identity verification and data protection controls.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is designed to be highly available and is hosted within a resilient cloud environment.
The service targets 99.5% availability, measured on a monthly basis, excluding planned maintenance. Planned maintenance is scheduled in advance where possible and customers are notified ahead of any expected disruption.
Availability is monitored, and incidents affecting service availability are prioritised for resolution. - Approach to resilience
-
The service is hosted within a resilient cloud environment designed to support high availability and fault tolerance. The underlying infrastructure uses redundant components and managed cloud services to reduce single points of failure.
Data is hosted in geographically resilient data centre locations operated by the cloud service provider. The provider is responsible for physical security, power, cooling, and network resilience, and operates multiple data centres to support service continuity.
The service is designed to recover from component or infrastructure failures through automated monitoring and recovery mechanisms. Regular backups are performed, and tested recovery processes are in place to support service restoration if required.
Detailed information about the underlying data centre configuration and resilience measures can be provided on request. - Outage reporting
-
Service outages and significant incidents are communicated to organisational customers via email notifications.
Where appropriate, updates are provided during an incident and a follow-up summary can be shared once the issue is resolved.
The service does not currently provide a public status dashboard or outage reporting API.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is restricted to authorised personnel only. Access is granted on a least-privilege basis according to job role and is reviewed regularly.
Administrative access is protected through strong authentication controls and logging. Support channels are access-controlled, and customer data is only accessed where required to provide support and with appropriate authorisation.
Access rights are removed promptly when staff roles change or employment ends, and access activity is monitored as part of ongoing security controls. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
The service is operated in accordance with an ISO/IEC 27001 certified information security management system (ISMS).
Information security policies and processes are defined, documented, and maintained as part of the ISMS, covering areas such as access control, data protection, incident management, risk management, supplier security, and business continuity.
Responsibility for information security is clearly defined within the organisation. Senior management retains overall accountability for information security, with day-to-day oversight delegated to nominated security and operational leads.
Compliance with information security policies is ensured through a combination of staff training, documented procedures, risk assessments, internal audits, and management review. Policies and controls are reviewed regularly and updated as required to address changes in risk, technology, or regulatory requirements.
Information security incidents are reported, assessed, and managed in line with documented incident management procedures. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Service components, including application code, configuration items, and supporting infrastructure, are tracked using version control and configuration management practices. Changes are recorded, versioned, and traceable from development through testing and deployment, supporting accountability and auditability.
Proposed changes are assessed prior to implementation to evaluate potential impacts on security, clinical safety, data protection, and service availability. This includes risk and impact assessment in line with documented change management procedures established through compliance with DCB0129 and UKCA Medical Device Class I requirements.
Changes are reviewed, tested and approved before deployment. Post-change monitoring is performed to confirm successful implementation. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
The organisation operates a defined vulnerability management process as part of its information security controls. Potential threats are identified through risk assessments, monitoring of service components and dependencies, and review of relevant security advisories. Identified vulnerabilities are assessed for severity and potential impact on security, safety, data protection, and service availability.
Patches are prioritised based on risk, with high-severity issues addressed as a priority following assessment and testing, and lower-risk issues scheduled into planned release cycles. Information on emerging threats is obtained from cloud service provider notifications, software supplier advisories, and recognised vulnerability databases. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
The service uses protective monitoring to identify potential security compromises through logging, monitoring, and alerting of system and application activity. Alerts are reviewed to detect unusual or suspicious behaviour that may indicate a security incident.
When a potential compromise is identified, it is assessed promptly in line with documented incident management procedures, and appropriate containment, remediation, and escalation actions are taken.
Security incidents are prioritised based on severity, with high-risk incidents responded to as a priority to minimise impact and support timely resolution. - Incident management type
- Supplier-defined controls
- Incident management approach
-
The organisation operates documented incident management processes to handle security and service incidents. Pre-defined procedures are in place for common incident types to support consistent and timely response.
Users and organisational customers can report incidents by contacting the support team via email. Reported incidents are logged, assessed, and prioritised based on severity and potential impact.
Incident updates are provided to customers via email where appropriate, and a summary report can be shared following resolution to support transparency and service improvement. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 19%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 22%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Tuesday 15 April 2025
- What the ISO/IEC 27001 doesn’t cover
-
The ISO/IEC 27001 certification applies to the scope defined in the organisation’s Information Security Management System (ISMS).
Activities and systems outside the certified scope, such as third-party services not directly operated or controlled by the organisation, are not covered by the certification. Physical security of cloud data centres is managed by the cloud service provider and is outside the organisation’s direct ISO 27001 scope.
Any non-production environments or business functions not included in the ISMS scope are also outside certification coverage. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 03ba57fd-0223-4de8-bf33-8f114e5fb2bf
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
-