Skip to main content

Help us improve the Digital Marketplace - send your feedback

RED KITE BPM LTD

Kissflow Low Code/No Code Platform

Kissflow is a unified low-code/no-code workflow and business process management platform that empowers organisations to build custom apps, automate workflows, and manage tasks without deep programming expertise. It offers drag-and-drop design, forms, approvals, integrations and real-time analytics - enabling faster deployment, improved efficiency, and seamless collaboration across teams.

Features

  • Low-code application builder enhanced by AI automation intelligence.
  • AI-powered document extraction and intelligent data processing.
  • Smart form builder with AI-generated field suggestions.
  • AI-based task assignment improving efficiency and workload distribution.
  • UK-hosted, secure cloud ensuring public sector data compliance.
  • Automated routing, escalations and SLA-driven workflows.
  • Scalable multi-team automation platform supporting continuous improvement.
  • Complete audit trails for traceability and regulatory assurance.
  • PWA-driven mobile and tablet accessibility for seamless usage.
  • No-code integrations with APIs and external applications.

Benefits

  • Accelerate workflow delivery using AI-assisted low-code app building.
  • Reduce manual effort through AI-powered document and data extraction.
  • Improve decision-making with predictive analytics and real-time insights.
  • Enable faster approvals via mobile and PWA access.
  • Increase productivity through automated task routing and SLA escalations.
  • Standardise processes and eliminate spreadsheet/email workflows.
  • Enhance compliance with audit trails and access governance.
  • Scale operations across teams without infrastructure overhead.
  • Lower development time and cost vs traditional applications.
  • Speed up adoption with intuitive UI and guided AI assistance.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at guru.karuppasamy@redkitebpm.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 0 8 3 7 5 6 4 3 7 7 8 5 6 4

Contact

RED KITE BPM LTD GURUNATHAN KARUPPASAMY
Telephone: 07424413368
Email: guru.karuppasamy@redkitebpm.co.uk

About your service

Service categories

Application Development and Deployment

Application platforms

  • Model driven application platforms
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
Currently compatible with Google Cloud, AWS and Azure. Future ready will be on Oracle Cloud.
System requirements
  • Modern web browser like Chrome, Edge, Firefox, or Safari.
  • Stable internet connection for uninterrupted cloud platform access.
  • Devices supporting HTML5 and secure PWA rendering.
  • Access to email or SSO for account authentication.
  • Optional MFA enabled for enhanced login security.
  • JavaScript enabled browser for full feature performance.
  • Recommended minimum 4GB RAM for heavy usage.
  • Updated OS versions on desktop or mobile devices.
  • Pop-ups allowed for notifications and workflow prompts.
  • Admin users require onboarding to configure roles and permissions.

User support

Email or online ticketing support
Yes
Support response times
Red Kite provides dedicated support for Kissflow users through email, ticketing and remote assistance. Standard response time for support queries is within four business hours, Monday to Friday, excluding UK public holidays. High-priority or critical issues are acknowledged faster based on severity (in 10 to 15 mins), with escalation paths available for service-impacting incidents. Weekend and out-of-hours queries are handled on a best-effort basis, with urgent issues prioritised when notified through the support desk. Resolution timelines depend on complexity, impact and priority classification. Users receive regular progress updates, and performance metrics are monitored to ensure consistent support quality and efficiency.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Red Kite has not yet completed formal structured testing of web chat functionality with assistive technology users specifically within the Kissflow platform. However, our approach to accessibility is proactive and continuous, and we recognise the importance of ensuring that all users, including those relying on assistive tools, can interact with service features without barriers. Kissflow’s interface is built to support standard browser-based assistive technologies such as screen readers, keyboard navigation, high-contrast display modes, and alternative input mechanisms. Initial internal evaluations confirm that web elements within the platform respond to ARIA attributes and semantic HTML structure, enabling compatibility with widely used assistive technologies. As part of our service roadmap, Red Kite intends to introduce a structured accessibility test cycle specifically for web chat interactions. This will include engagement with users who rely on assistive technologies for everyday digital access, allowing us to gather real-world usability feedback. Planned evaluation areas include screen reader flow, tab sequencing, focus indicators, voice-driven message input and the ability to navigate and submit messages without a mouse. Feedback collected through support channels and user accessibility reports will be reviewed to inform enhancements. Our aim is to meet or exceed WCAG accessibility guidelines as the platform evolves.
Onsite support
Yes
Support levels
Red Kite provides structured support for Kissflow through three service tiers designed to suit varying customer needs. Standard Support is included for all customers and covers email/ticket support during business hours, response within four working hours, issue triaging, knowledge-base access, and operational guidance. Enhanced Support offers extended coverage with faster response targets, dedicated escalation handling, regular performance reviews, and monthly service reports. Premium Support is designed for public sector environments requiring higher assurance and provides priority routing, 1–2 hour response for critical incidents, quarterly optimisation workshops, workflow performance tuning, and strategic advisory. Costs for Enhanced and Premium Support are determined based on user volume and deployment scale, and are quoted transparently as part of the service engagement. For customers requiring technical oversight, Red Kite can assign a Technical Account Manager (TAM) or Cloud Support Engineer to oversee adoption, manage escalations, support new workflow design, and ensure continued value realisation across departments. This role is available as an optional add-on to Enhanced and Premium plans. Our support structure ensures public sector buyers receive responsive, expert assistance throughout implementation and ongoing usage, with the flexibility to scale support as their automation footprint grows.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Kissflow is designed for rapid adoption, allowing users to onboard quickly without requiring extensive technical knowledge. As a low-code/no-code platform, most users are able to learn the core capabilities and start developing applications within approximately three weeks. Red Kite offer both online and onsite training, depending on customer preference, scale of onboarding and delivery model. Our training programmes include interactive hands-on workshops, where participants build real applications, configure workflows, create forms, define business rules, and integrate systems during the session itself. This ensures that learning is not passive but experience-driven, enabling users to apply concepts to real business use cases from day one. Our workshops are designed to progressively move users from guided learning to self-led development, ensuring confidence and autonomy in using the platform without long-term dependency. In addition, Kissflow provides comprehensive self-learning material through its Kissflow Academy, including structured modules, guided video lessons, sample exercises, documentation, best practice patterns and certification paths. This blended learning approach - live enablement supported by structured digital content - helps users gain skills faster, reduce adoption time and achieve quicker business value. Red Kite ensures that every customer is set up for successful long-term usage and innovation on the platform.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, customers maintain full ownership and control of all data generated or stored within their Kissflow instance. The platform provides multiple mechanisms for data extraction, ensuring that users can export information in a secure, structured, and compliant manner before service termination. Data such as application records, process histories, audit trails, attachments, and integration outputs can be exported directly through the administrative interface in standard formats including CSV, or Excel. This allows customers to migrate historical and operational data into alternative systems with minimal dependency. For larger datasets or organisations requiring bulk or automated export, Kissflow offers API-based retrieval. Through authenticated REST APIs, customers can extract data programmatically and integrate it into data warehouses, archival systems, or other workflow platforms. Scheduled exports or full-instance data pull can be arranged based on customer preference. Red Kite provides support during offboarding, including guidance on export best practices, format selection, and verification to ensure all required information is successfully transferred. Once data extraction is completed, customers may request secure deletion of their tenancy, databases, and stored files in line with compliance requirements and governance policies. This ensures a smooth, risk-free exit with no loss of ownership or accessibility.
End-of-contract process
During the exit phase, customers continue to retain full access to their Kissflow environment until the contract end date, ensuring uninterrupted use while planning transition or renewal. Red Kite supports this process through a clearly defined offboarding framework to ensure a smooth and controlled exit. Data extraction capabilities are included as part of the standard subscription, enabling customers to export application data, workflow records, audit logs, attachments, configuration metadata, and user activity history in common formats such as CSV, Excel, JSON and PDF. Standard guidance on data export and closure steps is also included within the contract price. Additional costs may apply if customers require extended platform access beyond the contract expiry, large-scale managed extraction, custom data formatting, bulk API-based export support, or migration services to other workflow platforms. Consultancy for knowledge transition, re-platforming, or third-party system integration during exit is also available as an optional paid service. Once data is successfully extracted and verified, customers may request full environment and data deletion, carried out securely in accordance with data protection regulations and retention policies.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Kissflow offers a consistent experience across desktop and mobile devices, with differences based on usability. The desktop web interface provides full feature set, including application design, workflow configuration, reporting, integrations, and administrative management. The mobile experience, delivered through responsive design and Progressive Web App (PWA) rendering, is optimised for task execution. Mobile users can view and update records, submit forms, approve workflows, upload attachments, receive notifications, and track case progress. Advanced configuration, application building, and system administration are intentionally restricted to desktop to ensure accuracy, security, and usability. Both interfaces share the same backend services, security controls, and data storage.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Kissflow provides a secure, web-based service interface designed for ease of use and rapid adoption. Users interact with the service through intuitive dashboards, task lists, forms, and case views, enabling them to submit requests, manage workflows, collaborate through comments, and track progress in real time. Role-based navigation ensures users see only the functions and data relevant to their responsibilities. The interface supports accessibility standards, configurable layouts, search, filtering, and notifications, ensuring efficient daily use while maintaining strong security and governance controls.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Kissflow, in partnership with Red Kite, undertakes structured interface accessibility testing to ensure the service is usable by people relying on assistive technologies. Kissflow performs platform-level testing across core user journeys using screen readers such as NVDA, JAWS, and VoiceOver, as well as keyboard-only navigation, browser zoom up to 400%, and high-contrast display modes. These tests validate accessibility for dashboards, forms, task lists, approvals, reporting views, and notifications, and are aligned with WCAG 2.1 AA principles. Semantic HTML, appropriate ARIA attributes, and automated accessibility scanning tools are used to identify and remediate issues.

Red Kite extends this testing during customer-specific implementations by validating accessibility within configured workflows, case management screens, and custom forms. Hands-on testing ensures that role-based navigation, error messages, field validation, and user interactions remain accessible when solutions are tailored for operational needs. Feedback from users and accessibility reviews is incorporated into configuration updates and release cycles.

Any identified accessibility issues are logged, prioritised, and addressed through structured product releases or configuration changes, ensuring inclusive, compliant, and consistent user experience across desktop and mobile interfaces.
API
Yes
What users can and can't do using the API
Using our API, users can fully integrate the service into their own applications without relying on the web interface. Users can set up the service programmatically by generating API credentials from their account and using them to create, configure, and deploy resources through REST endpoints. Standard operations such as onboarding users, provisioning environments, triggering workflows, updating configurations, and retrieving analytics or status reports can all be automated using the API. This enables seamless integration with CI/CD pipelines, enterprise systems, and external applications. Users can also make changes through the API, including modifying settings, updating policies, and scaling configurations. Automated workflows can be built to adjust parameters dynamically based on usage or demand, improving operational efficiency. Full documentation, sample scripts, and SDK support (where applicable) are provided to help developers adopt the API with ease. However, the API has some limitations. Initial account creation and subscription management must be done through the web interface. Some administrative and security settings - such as billing controls or high-risk configuration changes - may require manual approval for compliance reasons. Additionally, users must have appropriate permissions to make administrative API calls. Overall, the API supports robust automation with minimal manual intervention.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customise the Kissflow API service to integrate the platform with existing systems and tailor behaviour to organisational needs. Customisable elements include data models, workflow triggers, form fields, status updates, user roles, notifications, and integration logic with third-party applications such as identity providers, document repositories, and reporting tools.

Customisation is performed through secure REST APIs using authenticated API keys or OAuth tokens. Users can configure endpoints to create, read, update, and query records; initiate or progress workflows; manage users and roles; and exchange data with external systems. Webhooks and event-based triggers allow real-time synchronisation and automation. Configuration is documented and version-controlled to support safe change management.

Customisation is typically carried out by authorised administrators, technical users, or system integrators. Red Kite supports customers by designing, implementing, and validating API integrations in line with security and governance requirements. End users do not require API access, ensuring operational simplicity while maintaining strong access controls. All API access is logged and monitored to ensure traceability, security, and compliance.

Scaling

Independence of resources
Kissflow operates on a scalable multi-tenant cloud architecture designed to isolate resources and prevent performance impact between customers. Each organisation runs in logically separated environments, ensuring workloads do not overlap or compete. Auto-scaling infrastructure adjusts compute, storage, and network capacity based on demand, while load balancing distributes requests evenly to maintain stable response times. Workflow execution and API calls are processed in independent queues, reducing congestion during peak usage. Continuous monitoring, alerting, and automated optimisation help maintain consistent performance. If required, customers may opt for dedicated environments or enhanced resource tiers for higher-volume or mission-critical workloads.

Analytics

Service usage metrics
Yes
Metrics types
Kissflow provides service metrics that enable users to monitor performance, usage, and operational effectiveness. Built-in dashboards display real-time and historical metrics such as workflow volumes, case throughput, task completion times, approval turnaround, and SLA adherence. Users can identify bottlenecks, track workload distribution, and measure process efficiency. System metrics include application availability, response times, API usage, and error rates. Audit logs provide visibility into user activity and data changes for compliance. Metrics can be filtered, exported in CSV or Excel formats, or accessed via APIs. Red Kite assists customers in defining KPIs and configuring dashboards aligned to business and governance needs.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Kissflow

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export data from Kissflow at any time using built-in tools or secure APIs. Authorised users can export application data, workflow records, case information, and reports through the web interface in standard formats such as CSV and Excel, with filtering options for dates and fields. For automated or ongoing extraction, REST APIs allow programmatic access to structured data. In cases involving large data volumes or complex historical datasets, Kissflow’s backend support team assists with controlled bulk exports to ensure data completeness and integrity. All export activities are role-based, audited, and securely managed.
Data export formats
  • CSV
  • Other
Other data export formats
Excel
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Kissflow provides a highly available cloud service designed for continuous operation with minimal service interruption. The standard platform availability commitment is 99% (but the actual is >99.5%) uptime, measured on a monthly basis, excluding scheduled maintenance windows and factors outside platform control (such as internet connectivity issues or force-majeure events). High availability is maintained through distributed system architecture, redundancy at application and database layers, automatic failover, load balancing and proactive monitoring. Service performance and uptime are continuously tracked, with incident response mechanisms in place to prevent prolonged disruption. If the guaranteed availability level falls below the agreed threshold within a billing period, customers are eligible for service credits based on the extent of deviation. Service credits are typically issued as a percentage reduction in the subsequent billing cycle or renewal invoice, proportionate to the downtime experienced. The objective is to ensure fair compensation and maintain transparent operational accountability.
Approach to resilience
Kissflow is architected for high resilience, ensuring continuity of service even during infrastructure or component-level disruptions. When deployed via Red Kite for UK Government clients, the platform is hosted within UK region cloud datacentres on either AWS or Google Cloud Platform (GCP), both of which provide advanced resilience, redundancy, and security by design. The underlying cloud infrastructure supports multi - Availability Zone deployment, allowing services to automatically fail over if a primary zone experiences a localised outage. Automated scaling and load distribution further enhance resilience by balancing traffic across multiple nodes, avoiding performance degradation during peak demand. Continuous monitoring, health checks, and automated failover ensure that services remain available even when individual components fail. Backups and snapshot mechanisms allow rapid restoration if needed, while disaster recovery processes support recovery within agreed SLAs. Physical resilience of datacentres - including power redundancy, cooling failover, network diversity, and 24/7 monitoring - is ensured by the cloud provider, complying with Tier-III or equivalent standards. Detailed infrastructure configurations and resilience documentation can be provided to buyers on request, in line with the UK Government’s Asset Protection and Resilience security principle. This architecture ensures strong operational stability and business continuity for public sector workloads.
Outage reporting
Kissflow communicates outages and service interruptions through multiple notification and reporting channels to ensure customers remain informed and can take timely action. A **public service status dashboard** is available for real-time visibility into platform availability, component health, scheduled maintenance, and incident resolution progress. Users can subscribe to email notifications to receive instant alerts if an outage or performance degradation occurs, along with periodic updates until service is fully restored. For automated monitoring, organisations may also access outage and incident information via **API**, enabling integration with internal monitoring tools or ITSM systems. Incident history and RCA (Root Cause Analysis) summaries are published for transparency once issues are resolved. In addition, Red Kite provides direct communication during major outages, including progress updates, impact details, estimated recovery timelines, and post-resolution summaries. This multi-channel approach ensures that users are informed quickly and consistently, supporting operational continuity.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
SAML based authentication
Access restrictions in management interfaces and support channels
Kissflow restricts access to management interfaces and support channels using strict role-based access control, least-privilege permissions, and multi-factor authentication for all administrative users. Access to production environments is limited to a small, vetted Operations and Security team with time-bound, audited access. Support staff cannot access customer data unless explicitly authorised through a controlled workflow. Any temporary access is approved, logged, and automatically revoked after issue resolution. Secure ticketing systems, credential encryption, and scoped API keys ensure all interactions remain protected and auditable.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
SAML based authentication

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
Kissflow follows a formal information security management framework aligned with ISO 27001 and industry-standard security controls. Policies cover data protection, access management, encryption, incident response, vulnerability management, secure development and disaster recovery. All staff undergo mandatory onboarding and recurring security training to ensure ongoing policy compliance. Access is controlled using role-based permissions, least-privilege allocation and MFA, with periodic review to prevent privilege escalation. Data is encrypted at rest and in transit using industry-approved standards. The platform is routinely penetration-tested, and vulnerabilities are remediated through a managed patching and review cycle. Operational logs, audit records and security events are continuously monitored. A dedicated Chief Information Security Officer (CISO) leads the security programme, supported by a Security Operations Team. The CISO reports directly to senior executive leadership, ensuring visibility and accountability. Internal audits are carried out regularly, and external audits may be conducted for compliance verification. Security incidents follow a documented escalation path: Security Analyst → Security Manager → CISO → Executive Leadership, with customer notification where applicable. Red Kite adheres to the same governance, handling, and compliance protocols throughout delivery, ensuring consistent protection across configuration, access, and support activities.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
The IT Infrastructure Change Management process, managed by the DevOps team, governs changes to IT resources to ensure system stability. It starts with initiating a Change Request through the Kissflow platform, classifying the change and documenting a rollback plan. Next, risks are analysed and assessed, including impacts on technical dependencies, cost, and effort. The request is then submitted for approval and authorization by Change Approvers and the Head of DevOps. Once approved, the change is planned and implemented, usually during non-business hours, with stakeholder coordination. Finally, testing and validation are completed, rollback executed if required, and monitoring continues.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
The Vulnerability Management process identifies and mitigates security risks, following the IT Security Policy. Potential threats are assessed through planned Vulnerability Assessments and Penetration Testing (VAPT), annual Risk Assessments for critical systems, and Code Scanning before every release. Major threats are handled via the Incident Management Process. Information about threats comes from the public contact point (security@kissflow.com), employee reporting, and external security forums. Patch deployment speed is determined by severity, with resolution timelines being strictly defined to maintain system stability. Critical vulnerabilities are resolved quickest. Critical:10 days High:30 days Medium:90 days Low/Tolerable Product Road Map.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
The protective monitoring process is part of the IT Security Policy, focusing on detection and correction. Potential compromises are identified by the Process Owner, who monitors networks, systems, and applications for anomalous behaviour. This monitoring includes reviewing Audit Logs for successful and failed user logins, and analysing Cloud service logs for connections to malicious servers. When an event is qualified as an incident, the Incident Management Process is followed. Issues identified during log analysis must be fixed according to the following Service Level Agreement (SLA)
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
The Security Incident Management process, overseed by the ISWG Committee, aims to minimize the impact of security incidents and maintain the confidentiality, integrity, and availability of information. All personnel must report security incidents, events, or threats to security@kissflow.com . In case of a breach, the regulatory authority (such as CERT-In) is notified within six hours of identification. The ISWG team analyses the incident, assesses severity and impact, identifies root causes, and defines response actions including containment and escalation. Corrective and recovery actions are implemented, incidents are formally closed, and lessons learned are documented to strengthen security controls.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
Public Services Network (PSN)

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
All features in App development, Process, Boards, Reports and Integrations are available with free trial version. No limitation on the features to tryout. The free trial version will be provided for 14 days.
Link to free trial
Write to Red Kite on our website https://redkite-solutions.com

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
2.5%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
12.5%
Between £2,500,001 and £5,000,000
12.5%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Intertek Certification Limited
ISO/IEC 27001 accreditation date
Sunday 25 October 2026
What the ISO/IEC 27001 doesn’t cover
Kissflow’s ISO/IEC 27001 certification covers the information security management system governing the development, operation, and support of the Kissflow SaaS platform. However, certain elements fall outside the scope of the certification. These include customer-managed configurations, business processes, data entered into the platform, and end-user devices or local networks used to access the service. Customer-specific integrations, custom workflows, and third-party systems connected via APIs are also not directly covered, although they are supported using secure integration practices. The underlying physical datacentre facilities are covered under the ISO certifications of the cloud infrastructure providers (AWS or Google Cloud Platform) rather than Kissflow’s certification. Red Kite’s implementation and advisory services follow aligned security practices but are governed under separate organisational controls. Customers retain responsibility for user access management, data classification, and compliance with their internal policies.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
None of the criteria
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
2da87e09-1980-40ad-b7e4-1dd49dd3b306
Other security certifications
Yes
Any other security certifications
  • SOC 1
  • SOC 2

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at guru.karuppasamy@redkitebpm.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.