Kefron AP
Supplier invoice automation transforms how organisations manage the accounts payable process, allowing you to do more with less and scale in ways never possible. Our Accounts Payable Solution integrates with your ERP system and digitises your entire invoice process for 360 visibility of your accounts payable process end-to-end.
Features
- Data extraction service with continuous optimisation
- Supplier invoice automation management
- Data analysis and reporting
- Facilitates audits and enhanced security.
- Purchase order creation and processing.
- Highly customisable solution to best suit your organisation's needs.
- Flat File Exchange (FFE) or API integration with ERPs.
- Supplier portal to reduce queries.
- PO and non-PO invoice with two/three way invoice matching.
- SSupplier statement reconciliation.
Benefits
- Provides 80% time saving in the accounts payable process.
- Strengthening vendor relationships and financial health.
- Reduces operational costs.
- Facilitates scalability and adaptability in finance operations.
- Enhances employee satisfaction and productivity.
- Increases security and compliance in the accounts payable process.
- Streamlines and standardises invoice processing.
- Organisations are better prepared for changing legal/regulatory landscapes.
- Enhanced visibility into entire invoicing process, including approvals.
- Facilitates better reporting and cashflow predications.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 2 3 3 5 6 9 4 0 3 0 6 2 6 8
Contact
Kefron International Limited
Brian Coyle
Telephone: 01189977380
Email: ecoogan@kefron.com
About your service
- Service categories
-
Application Development and Deployment
Software quality and life cycle
- Software change, configuration and process management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Clients are notified at least 5 days in advance of any planned maintenance or updates by email.
- System requirements
- N/A
User support
- Email or online ticketing support
- Yes
- Support response times
-
Kefron offer support through an online automated ticketing application, called “Help Desk.” Kefron will provide you with access to Help Desk application which can be accessed via the internet, to capture any issues, queries, or requests on an on-going basis. Tickets can be emailed directly to support@kefron.com. Support hours are Monday to Friday 9am-5pm.
Tailored support can be provided. All support and response times are documented into a tailored Service Level Agreement. An immediate response is provided confirming the receipt of the question. Detailed responses times range from within 3 hours for urgent issues up to 48hrs for non-urgent queries. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
1st level support will be provided internally within the client office. 1st level support includes, but is not limited to network connectivity on client side, administration of system, account lockouts, 3rd-party systems not supplied by Kefron, anything that can be performed via the user interface, hardware used to access the system, support for anyone without system training.
2nd level support will be provided by Kefron. This includes, but not limited to errors or issues with the code, customisations made by Kefron where the system does not operate as per the specification agreed with the client. 2nd level support will be provided remotely where appropriate, however on-site support can be provided if deemed appropriate. The monthly fee includes 2nd level support. All issues raised to Kefron will have been investigated in the first instance by the Client Super User and/or Client IT support personnel.
Kefron will provide the Client access to the Kefron Helpdesk application which can be accessed via the internet, to capture any issues, queries or requests on an on-going basis. This will allow both parties to meet at regular intervals and review and report on all cases raised in that period. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
1. Introduction Call: Kefron Project Manager and Implementation Consultant provide an overview of the implementation process.
2. Early System Access: Clients are provided early access to gain a beneficial overview of the Kefron system.
3. Champion Training: Users will be provided with high-level system training along with some training material for reference.
4. Detailed Scoping: Project scope is discussed in detail and documented for refinement.
5. User Training: Users are provided with comprehensive training.
6. Iterative Releases: Your Project Manager will collaborate with Kefron’s Digital Team to configure your Kefron AP solution to your requirements.
7. Testing and Feedback: As part of incremental releases and system refinement you will be responsible to test provided functionality and share feedback.
8. UAT Confirmation: User Acceptance Training (UAT) completed and signed off on Scoping Document. This will ensure a seamless Go-Live.
9. Go-Live: Final preparations are made for Go-Live and live invoice processing.
10. Hypercare: Kefron Project Manager will provide hypercare for a period of two weeks to ensure smooth user adoption.
11. Support Team Handover: After hypercare, the customer is handed over to our in-house support team for ongoing support. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- Other
- End-of-contract data extraction
- It is important to note that Kefron do not own the data. At the end of the service period or in the event of contract termination, Kefron will migrate the archived data to a mutually agreed format between the Client and Kefron (CSV format for example) and as such will drop this data to a secure location e.g., SFTP for the Client to access. This data will also include the original documents received by Kefron and the history associated with the documents for audit purposes. Depending on the volume and type of data required, the Client will expect a charge associated with this process to cover the Professional Service resource to complete the work.
- End-of-contract process
- Pricing includes a one-off professional services cost, a monthly subscription fee based on invoice volume, and end of contract data retrieval.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Kefron AP is accessed via browser, therefore there's no noticeable differences.
- Service interface
- No
- User support accessibility
- WCAG 2.2 A
- API
- Yes
- What users can and can't do using the API
-
Kefron AP provides a full and flexible API connection for integration with 3rd-party finance systems. Extensive API access automates data exchange between your systems. We also provide pre-built connectors for a selection of ERP systems. The Kefron API is REST based, uses the JSON data format and is secured with HTTPS.
A sandbox can be configured for customers as part of the engagement. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- There is a full configuration process as part of the onboarding process.
Scaling
- Independence of resources
-
A Layer 4 (TCP, UDP) load balancer that distributes incoming traffic among healthy instances of services defined in a load-balanced set for high availability and application performance. It can be configured to:
Public load balancing,
Internal load balancing,
Forward external traffic to a specific virtual machine.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
A Layer 4 (TCP, UDP) load balancer that distributes incoming traffic among healthy instances of services defined in a load-balanced set for high availability and application performance. It can be configured to:
Public load balancing,
Internal load balancing,
Forward external traffic to a specific virtual machine. - Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Data is imported and exported between Keforn AP and the client's ERP system using flat file exchange (FFE), pre-built connectors, or Kefron's API.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Custom formats can be developed for certain ERP systems
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Excel
- XML
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Kefron commits to 99.9% Kefron AP service availability. Downtime resulting from planned maintenance will be notified by email a minimum of 5 days in advance
- Approach to resilience
- All data hosted in Azure, VMs backed up in different zone within Azure. More detail is available on request.
- Outage reporting
- We notify our users via email of any outages. Planned outages are notified two weeks in advance of scheduled maintenance.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- Kefron AP authenticates users through unique login credentials, strong password requirements, optional multi-factor authentication, and support for Single Sign-On via SAML/Azure AD. Secure session management and role-based access controls ensure users only access the data and functions permitted by their organisation.
- Access restrictions in management interfaces and support channels
- Kefron use Active Directory, all user access is controlled using AD.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Contents of our Information Security Policy includes ISO 27001: 2013 Certification, Cyber Essentials Plus, and the following policies: Document Control, Kefron Information Security, Email, Internet Usage, Password Control, Social Engineering, Anti-Virus, Software Usage, Host Access Control, Mobile Computing, Back-Up, Connectivity and Encryption, VPN, Wireless, Physical Access Control, Key Control, Data Protection, Clean Desk Clear Screen, User Access Entitlement, Anti-Bribery & Corruption, Social Media Usage, Credit Card Processing, Secure Destruction of Confidential Material, IT Asset Management, Gift Policy, Software Development Security Policy, Information Classification Policy, Breach Notification Policy, CCTV Policy, Data Subject Rights Policy.
On discovery of a (potential) breach of data/security the incident must be reported immediately to the nearest Line Manager, who is responsible for communicating the incident to a Senior Manager as soon as possible. Senior Management will escalate notification to the Data Protection Officer (DPO) who will notify the Office of the Data Protection Commissioner, where appropriate. Senior Management will notify the Managing Director. All employees are provided with a security induction and a copy of the IS Policies, employees are required to sign a declaration of adherence to the policy and are required to complete mandatory GDPR training. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- ISO 27001 compliant. Kefron follow a strict change management processes as per ISO 27001 and are audited on a quarterly basis.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
We use Qualys software, which is a vulnerability management tool running nightly to check for potential threats
Depending on the severity of the issues, we usually respond and take actions as quickly as possible
Qualys contains the information about potential threats. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
We identify potential compromises by logs kept in the firewall software. All logs are sent to our SIEM system Rapid 7.
We have intrusion prevention switched on and set to block medium and high incidents.
We also geo-block.
We respond immediately upon detection and take actions as soon as possible to address incidents. - Incident management type
- Supplier-defined controls
- Incident management approach
- Kefron have a defined incident detection and response procedure and a non-conformance procedure which ensures that we can manage incidents in a uniform way. Issues are logged in our Business Improvements (BI) systems or the IT Helpdesk (SYSAID) for tracking and resolution. Users can email or login to the Helpdesk to raise a ticket. The Account Manager is responsible for ensuring that progress updates and incident reporting is followed through with the client.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- IQNET / NSAI / ISO
- ISO/IEC 27001 accreditation date
- Tuesday 22 April 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- NSAI
- ISO 9001 accreditation date
- Tuesday 25 March 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 93054492-980f-443d-928c-6cf568c71c66
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
-