Skip to main content

Help us improve the Digital Marketplace - send your feedback

XERINI LIMITED

Xefr

Xefr securely unifies siloed data across disparate systems without replacing existing infrastructure, creating a single intelligent portal. AI-powered natural language processing enables instant semantic search, automated document analysis, and conversational data querying. Transforms fragmented information into actionable insights while eliminating manual processes and Excel-based workflows.

Features

  • AI-powered natural language querying across all unified data
  • Automated document tagging, classification and metadata extraction using AI
  • Connect disparate systems without replacing existing infrastructure investments
  • Business intelligence dashboards with advanced charting and reporting
  • Full GIS support including mapping, LiDAR and geospatial analytics
  • Workflow automation with conditional routing and approval chains
  • Semantic search across documents, databases, images and emails
  • Real-time data streaming with IoT and smart building integration
  • White-label multi-tenant portal with role-based access control
  • Dynamic document generation with advanced PDF manipulation capabilities

Benefits

  • Eliminate manual data entry saving hundreds of staff hours
  • Find information instantly reducing search time by 90%
  • Break down silos enabling cross-departmental collaboration and insights
  • Reduce Power BI licensing costs through built-in analytics
  • Make data-driven decisions with real-time operational intelligence
  • Automate compliance reporting reducing risk and audit preparation
  • Preserve existing IT investments avoiding costly system replacements
  • Enable citizen self-service reducing call centre enquiry volumes
  • Improve data quality through AI validation and cleansing
  • Accelerate FOI responses through instant document discovery capabilities

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at admin@xerini.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 5 6 6 0 0 5 4 7 1 9 9 9 6 0

Contact

XERINI LIMITED Alex Luketa
Telephone: +44 0333 242 5204
Email: admin@xerini.co.uk

About your service

Service categories

Application Development and Deployment

AI platforms

  • Search and knowledge discovery

AI life cycle

  • Data Labeling Software

AI software services

  • Conversational AI Software Services
  • Generative AI Software Services
  • Document AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Scheduled maintenance windows occur monthly, typically performed during weekends between 02:00-06:00 GMT to minimise service disruption. Critical security patches may require additional maintenance with 72 hours advance notice. The service requires modern web browsers (Chrome, Edge, Firefox, Safari released within last 2 years) for optimal functionality. API rate limits apply to prevent system abuse, with standard thresholds suitable for typical government usage patterns. Custom integrations may require additional configuration time during initial deployment phase.
System requirements
  • Modern web browser
  • Stable internet connection with minimum 10Mbps for optimal performance
  • JavaScript enabled in browser for full functionality
  • For API access: OData v4.0 compliant client capability
  • For self-hosted heavy data processing: Consider 16GB+ RAM
  • Cookies and local storage enabled for session management
  • No additional software licences required beyond existing systems

User support

Email or online ticketing support
Yes
Support response times
Email support provided at support@xerini.co.uk with tiered response times:

P1 (Service Down): 1-hour response, 24/7 monitoring
P2 (Service Impaired): 4-hour response
P3 (General Queries): Next business day

Business Hours: 8:00 - 18:00 GMT/BST Monday-Friday (excluding UK bank holidays)

Weekends/Bank Holidays: Critical issues only with 2-hour response for service restoration. Other enquiries queued for next business day.

Response times indicate first acknowledgement. Resolution varies by complexity. All customers receive documentation portal access and quarterly service reviews. Enhanced SLAs available through Premier Support package.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Standard Support is included in all licences, providing business hours coverage from 8:00-18:00 GMT/BST Monday-Friday. This encompasses critical bug fixes, security patches, service monitoring, and incident response with tiered SLAs of one hour for P1, four hours for P2, and next business day for P3 issues. Customers receive documentation portal access and quarterly service reviews to ensure optimal platform utilisation.

Enhanced Support, ranging from £500-£6,000 monthly based on system complexity, includes everything in Standard plus a named technical support engineer who understands your specific configuration. This tier adds proactive integration monitoring, monthly health checks, dedicated support for data quality and integration issues, and a 20% discount on Professional Services engagements.

Enterprise Support offers bespoke pricing for organisations requiring comprehensive coverage. This includes a dedicated Technical Account Manager, fortnightly reviews, priority support queue, included Professional Services days, strategic roadmap planning, and on-site support options.

Professional Services are available on a Time & Materials basis for complex integrations, data migration, custom workflows, and troubleshooting. Day rates are provided upon request, with discounted rates for Enhanced and Enterprise customers. This flexible approach ensures appropriate support from basic SaaS maintenance through complex multi-system integrations, with transparent pricing scaling to organisational needs.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Xefr provides comprehensive onboarding support to ensure successful platform adoption across all user levels.

Documentation forms the foundation of our support, including detailed system administrator guides covering configuration, integration, and security settings. All documentation is accessible through our integrated help system with context-sensitive assistance.

The platform itself facilitates user adoption through built-in guidance features including interactive tooltips on hover, contextual help panels explaining current screen functionality, and customisable information displays that administrators can configure to provide department-specific instructions.

For organisations requiring hands-on support, we offer professional onboarding services at additional cost, including on-site training workshops tailored to your use cases, train-the-trainer sessions for your super users, remote configuration assistance via screen sharing, and post-deployment review sessions to optimise adoption.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Xefr ensures complete data portability with multiple extraction options available at no additional cost, enabling smooth transitions and maintaining data sovereignty.

Administrators can export all data through the platform interface where every data view, report, and dashboard supports CSV download functionality. This includes filtered views, allowing selective exports of specific datasets, time periods, or business units. Standard users can also export from data screens where administrators have enabled download permissions, ensuring controlled data access throughout the contract.

For comprehensive data migration, we provide full database dumps in either JSON or BSON format, preserving data structures, relationships, and metadata. This includes all transactional data, uploaded documents, configuration settings, custom schemas, workflow definitions, and audit logs. Document attachments are provided in their original formats.

We guarantee data availability for 30 days post-contract termination, allowing adequate time for verification and migration. All exports comply with GDPR requirements for data portability.
End-of-contract process
Upon contract termination, whether at natural expiry or with 30 days notice for early termination, Xefr follows a structured offboarding process ensuring complete data return and secure deletion.

Included at no additional cost: Platform access continues until the contract end date. Full data extraction via CSV downloads or database dumps (JSON/BSON) is provided. Data remains available for 30 days post-termination for verification. Standard documentation covers extraction procedures. Certificate of secure data deletion is issued after the retention period.

Available at additional cost: Extended data retention beyond 30 days. Technical migration assistance at standard day rates. Knowledge transfer sessions or training for replacement suppliers. Expedited extraction for emergency terminations.

The offboarding process includes a final account review, confirmation of data extraction, return of any client-specific configurations or customisations, and orderly shutdown of user access. We maintain professional indemnity insurance covering the transition period.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Our documentation is provided in HTML format through our web-based help portal, which inherits the browser's accessibility features including zoom functionality, high-contrast modes, and basic keyboard navigation. The documentation structure uses semantic HTML with proper heading hierarchies and logical navigation flow.

Current accessibility limitations mirror our main platform: screen reader compatibility has not been formally tested, images and diagrams may lack comprehensive alt-text descriptions, complex technical diagrams don't have text alternatives, and PDF exports from the documentation may not be fully accessible.

We recognise these limitations fall short of government accessibility standards. As part of our commitment to achieving WCAG 2.2 AA compliance for the platform, we will simultaneously upgrade our documentation to meet the same standards. This includes adding proper ARIA labels, comprehensive alt-text, accessible alternatives for technical diagrams, and ensuring all instructional content is available in screen-reader friendly formats.

In the interim, we can provide documentation in alternative formats upon request and offer telephone or video support for users who cannot access the current documentation. We welcome feedback from users with accessibility needs to prioritise improvements.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Xefr is desktop-first but fully responsive on mobile devices with all functionality maintained. On mobile, dashboard layouts reflow into single-column format for optimal viewing, whilst multi-panel desktop views become scrollable sections.

Mobile access suits reviewing data, checking reports, and urgent tasks whilst away from desk. Desktop is recommended for intensive data entry, complex report or dashboard creation, and detailed analysis requiring multiple simultaneous data views. This aligns with typical usage patterns where mobile provides complementary access for field workers and executives, whilst desktop remains primary for daily operations.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Xefr provides an intuitive web-based interface featuring customisable dashboards with drag-and-drop components including charts, maps, pivot tables, and data grids. Users navigate through a hierarchical menu structure with role-based visibility. The interface includes a global search bar supporting natural language queries, contextual help system, and AI-powered chat assistant. Interactive elements support drill-down analysis, with real-time data updates reflected immediately across all components. The responsive design adapts layouts for different screen sizes whilst maintaining functionality. User preferences, saved views, and custom dashboard configurations persist between sessions.
Accessibility standards
None or don’t know
Description of accessibility
Xefr uses HTML5 standards enabling basic keyboard navigation and browser zoom functionality. The responsive design supports screen magnification and high-contrast browser modes. Users can access most read-only functions via keyboard and navigate through logical tab order.

Current limitations include incomplete screen reader support, charts requiring mouse interaction, drag-and-drop dashboard configuration not keyboard accessible, and inconsistent alt-text. Some form controls and dynamic content lack ARIA labels. Complex data visualisations don't have text alternatives.

We acknowledge these gaps and are committed to achieving WCAG 2.2 AA compliance. We'll provide a remediation roadmap with timelines upon request and welcome government accessibility guidance.
Accessibility testing
We have not yet conducted formal accessibility testing with assistive technology users. We acknowledge this gap and are committed to achieving WCAG 2.2 AA compliance as a priority. Initial informal assessment using automated tools indicates areas for improvement. We welcome government partnership in conducting user testing with assistive technology users to ensure our platform meets all accessibility requirements. We can commit to addressing identified accessibility issues within agreed timescales as part of any contract.
API
Yes
What users can and can't do using the API
Xefr provides two API options: a RESTful API documented via Swagger/OpenAPI and an OData v4.0 service with standard metadata descriptions, ideal for Power BI, Excel, and Tableau integration.

Through the API, users can query all data schemas with filtering, sorting, and pagination, perform full CRUD operations where permissions allow, execute saved queries and reports, access document metadata, initiate document processing workflows, retrieve real-time analytics data, and perform bulk data operations.

Authentication is handled via OAuth 2.0 or API keys with role-based access controls enforced throughout.

Standard rate limiting of 1000 requests per hour applies but is negotiable for enterprise clients. Maximum payload size is 10MB per request. Complex dashboard configurations and some AI-powered features require UI access or special endpoints. Both REST and OData support JSON responses with XML additionally available for OData.

Test environments are provisioned upon request with sample data for development and integration testing before production deployment.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Xefr offers extensive customisation at both administrative and user levels, enabling organisations to tailor the platform to their specific needs.

Administrators can fully customise the data architecture including schema definitions, field types, validation rules, and relationships between datasets. They control dashboard layouts by selecting and positioning components such as charts, maps, tables, and KPIs using our drag-and-drop designer. The entire platform appearance can be white-labelled with custom branding, logos, colour schemes, and CSS styling to match organisational identity. Administrators also configure workflows, approval chains, automated processes, user roles and permissions, integration mappings, and notification rules.

Individual users can personalise their workspace by saving custom dashboard views, adjusting data grid column positions, widths and sort orders, creating saved searches and filters.

System administrators and designated power users with appropriate role permissions can make platform-wide customisations through the admin console. Individual customisations are available to all authenticated users for their personal workspace. Changes are version-controlled with rollback capability, ensuring safe experimentation with configurations.

Scaling

Independence of resources
Xefr employs a dual approach to ensure resource independence. For shared infrastructure tiers, we implement real-time monitoring with automated alerts triggering scaling actions when usage thresholds are reached. Rate limiting, connection pooling, and query optimisation prevent any single tenant from monopolising resources. For enterprise and government clients, we provide fully dedicated deployments with ring-fenced resources including separate compute, memory, and database instances, ensuring complete isolation from other users' demand. Both approaches include proactive capacity management, with performance baselines established during onboarding and regular reviews to anticipate scaling requirements before they impact service delivery.

Analytics

Service usage metrics
Yes
Metrics types
Xefr captures comprehensive usage metrics when enabled, recording all endpoint access including user identification, IP addresses, timestamps, response times, and request metadata. This data can be visualised through custom Xefr dashboards tailored to specific reporting requirements, leveraging the platform's own analytics capabilities. For Azure-hosted deployments, we integrate with Azure Application Insights providing additional infrastructure metrics including performance monitoring, availability tracking, resource utilisation, and error rates. Metrics cover API usage, user activity patterns, data volume trends, query performance, and system health indicators. Custom alerts can be configured for threshold breaches. Historical data retention supports trend analysis and capacity planning.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Users export data through multiple methods integrated directly into Xefr's interface. Every data view, report, and dashboard includes a download button enabling CSV export with current filters applied. Administrators can access all system data while standard users export from permitted screens. Bulk exports are available through our OData API for programmatic extraction. For complete data migration, administrators can request full database dumps in JSON or BSON format containing all records, relationships, metadata, and document attachments. All export methods preserve data integrity and support incremental or selective extraction based on date ranges or business units.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • BSON
  • XML
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Xefr guarantees 99.9% monthly availability for production services, calculated as total minutes minus downtime divided by total minutes per month.

Availability excludes planned maintenance windows notified 72 hours in advance, customer-caused issues, third-party service failures beyond our control, force majeure events, and emergency security patches. Scheduled maintenance occurs during agreed windows, typically 02:00-06:00 GMT weekends.

Service credits apply when availability falls below guaranteed levels, calculated against monthly subscription fees and applied to the following invoice:

99.5%-99.89%: 5% credit
99.0%-99.49%: 10% credit
95.0%-98.99%: 25% credit
Below 95%: 50% credit

Customers must report availability issues within five business days to claim credits. Maximum liability is capped at 50% of monthly fees. Credits are the sole remedy for availability breaches.

Availability is continuously monitored using independent tools from multiple geographic locations. Azure's built-in monitoring supplements our application-level monitoring.
Approach to resilience
Xefr leverages Azure's enterprise-grade infrastructure for resilience, deployed on Azure App Services with configurable resilience levels based on client requirements.

Standard Deployment: Our standard configuration runs on Azure UK South with automatic platform-level resilience including redundant storage, automatic failover within the availability zone, continuous backups with point-in-time recovery, and auto-scaling to handle demand spikes. Azure App Service provides built-in load balancing, health monitoring, and automatic OS patching.

Data Resilience: MongoDB Atlas provides automated backups every 6 hours with point-in-time recovery, replica sets with automatic failover, and cross-region backup storage. Application data in Azure Storage is geo-redundantly replicated by default.

Enhanced Resilience (Available on Request): For mission-critical deployments, we offer active-active configuration across UK South and UK West regions, Traffic Manager for automatic geo-failover, read replicas for database load distribution.

Business Continuity: Incident response procedures are documented and tested quarterly. Azure's SLA for App Services underpins our availability commitments. Detailed resilience architecture diagrams and disaster recovery procedures are available under NDA.

Standard deployments meet most government requirements. Enhanced resilience options are priced on application based on specific requirements.
Outage reporting
Email Alerts: Azure App Services monitoring triggers automated email alerts to registered technical contacts when service availability issues are detected. Critical incidents generate immediate notifications with impact assessment and estimated resolution times. Updates are sent hourly during active incidents with resolution confirmation upon service restoration.

API Status Endpoint: Our REST API includes a /ping endpoint returning current service status in JSON format, enabling automated monitoring integration with client systems.

Direct Communication: Our support team proactively contacts affected clients during service-impacting events via email and, for critical clients, telephone escalation. Post-incident reports are provided within 5 business days.

Enterprise clients can request custom alerting integrations with their monitoring platforms via webhook or email distribution lists.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
Administrative interfaces are protected through OAuth2 authentication for enterprise/government clients, enforcing individual named accounts with role-based access control. Admin sections require elevated privileges granted only to authorised personnel. MFA is enforced through the identity provider configuration.

Support staff receive temporary elevated access on request, time-limited to specific support tickets. Database access is strictly controlled through IP whitelisting with temporary credentials issued only when required for production troubleshooting. All administrative and support access generates comprehensive audit logs tracking who accessed what, when, and why. Access reviews occur monthly with immediate revocation of unnecessary permissions. Audit logs are retained for compliance.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Xerini maintains comprehensive information security governance aligned with ISO 27001, for which we hold current certification. We're also Cyber Essentials certified, demonstrating our commitment to fundamental security controls.

Governance Structure: Our Information Security Management System (ISMS) is overseen by our Chief Technology Officer, with quarterly board reviews of security posture. We coordinate regular security operations, incident response, and policy compliance. Security responsibilities cascade through all development and operations teams.

Security Controls: Technical controls include OAuth2 authentication via Microsoft Azure/Entra with mandatory MFA, role-based access control with principle of least privilege, automated vulnerability scanning using MEND for application code and dependencies, regular penetration testing and security audits, encrypted data transmission (TLS 1.2+) and storage (AES-256), and comprehensive audit logging.

Compliance Assurance:Monthly internal audits verify control effectiveness. External ISO 27001 surveillance audits occur annually. All production changes follow secure development lifecycle practices with security review gates. Security training is mandatory for all staff annually, with additional role-specific training for developers.

Continuous Improvement: Regular vulnerability assessments drive our patching schedule. Production environments receive critical patches within 48 hours, standard patches during monthly maintenance windows. Security metrics are reviewed monthly with trends reported quarterly.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All code and configuration changes are tracked via Git version control with semantic versioning. Changes require pull requests with mandatory peer review, automated testing through CI/CD pipelines, and additional security scanning via Claude Code agents. Infrastructure as Code ensures all configurations are versioned.

Security impact assessment includes automated vulnerability scanning using MEND, static code analysis for common vulnerabilities, and additional security team review for authentication, cryptographic, or architectural changes. All components maintain full audit trails with rollback capability. Previous versions are retained for 90 days. Every change captures who, what, when, and justification for compliance tracking.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We conduct automated vulnerability assessments using MEND for application code and NPM audit for JavaScript dependencies, running daily in CI/CD pipelines. Critical vulnerabilities trigger immediate alerts to our security team.

We source threat information from the NIST National Vulnerability Database, vendor security advisories, UK NCSC threat notifications, and automated dependency scanning tools provide continuous threat intelligence.

We patch critical vulnerabilities within 48 hours maximum. High severity: 7 days. Medium: next maintenance window. Low: quarterly review.

Azure platform patches are automatically applied. Application patches follow our change management process with expedited approval for critical security fixes.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We implement multi-layered protective monitoring across application and infrastructure levels. Microsoft Azure Defender for App Services provides real-time threat detection for enterprise and government clients, identifying suspicious activities, potential breaches, and anomalous behaviours.

Security incidents trigger immediate automated containment (account suspension, IP blocking). Our incident response team investigates within 1 hour for critical issues, 4 hours for standard incidents. Response includes isolation, investigation, remediation, and client notification within regulatory timeframes. Post-incident reviews document lessons learned.
Incident management type
Supplier-defined controls
Incident management approach
Incident management follows established protocols with clear escalation paths. Users report incidents via support@xerini.co.uk, triggering immediate triage by our support team.

We maintain pre-defined processes for common event types. Service outages trigger immediate investigation and client notification. Security incidents follow our isolation, investigation and remediation playbook. Performance degradation initiates diagnostic data collection and root cause analysis.

Affected clients receive initial notification within 30 minutes of confirmed incidents, followed by hourly updates during resolution. Post-incident reports are delivered within 5 business days detailing root cause, impact assessment, remediation actions, and prevention measures.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Development instances available for qualified prospects for 30-day evaluation. Includes full platform functionality with usage limits on AI tokens and data storage. Configured with sample datasets to demonstrate key features. Extended trials available upon request. Full migration support provided when converting trial to production deployment.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
12%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Citation ISO Certification Limited
ISO/IEC 27001 accreditation date
Friday 26 September 2025
What the ISO/IEC 27001 doesn’t cover
Our ISO 27001 certification comprehensively covers the core service delivery of Xefr including software development, AI/ML capabilities, and consultancy services. The certification scope encompasses all development processes, code repositories, development environments, and intellectual property protection.

Areas outside the current certification scope include third-party infrastructure providers (Microsoft Azure and MongoDB Atlas maintain their own separate ISO 27001 certifications), customer-managed deployments where clients host Xefr in their own infrastructure, physical security of datacentres (covered by Azure's certifications), and certain support functions performed by subcontractors under separate agreements.

The certification applies to Xerini's UK operations. International subsidiaries or partners, if any, would require separate certification. Hardware procurement and disposal is managed through certified third-party providers rather than directly under our ISO 27001 scope.

All core platform security, development practices, and service delivery functions required for G-Cloud services are fully covered within our certification scope.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation ISO Certification Limited
ISO 9001 accreditation date
Friday 26 September 2025
What the ISO 9001 doesn’t cover
Our ISO 9001 certification covers all core quality management processes for Xefr's design, development, delivery and support. The certification encompasses our complete software development lifecycle, AI/ML model training processes, and consultancy service delivery.

Exclusions from the ISO 9001 scope include third-party infrastructure operations (Azure and MongoDB Atlas maintain independent quality certifications), manufacturing or hardware production (not applicable to our SaaS model), on-site installation services where performed by third-party partners, and customer-specific customisations delivered outside our standard service framework.

Quality management for subcontracted services relies on vendor management processes and service level agreements rather than direct ISO 9001 certification. Customer-managed deployments and self-hosted installations fall under shared responsibility models with quality assurance guidance provided through documentation.

The certification applies to UK operations. Marketing activities, financial management, and HR processes, whilst following quality principles, are managed through separate governance frameworks rather than ISO 9001.

All software development, service delivery, customer support, and consultancy activities essential to G-Cloud service provision are fully covered. Our certification ensures consistent quality in platform development, deployment processes, service management, and customer deliverables. Regular surveillance audits confirm ongoing compliance and continuous improvement across all certified processes.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
35ad8a93-1e97-45ff-b819-7d59308a20d7
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at admin@xerini.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.