360 feedback system
Highly customisable online 360 feedback questionnaire, for participants and their nominated reviewers. Automated individual reports with benchmarks, plus organisational aggregate outputs. Use your behavioural content or GatenbySanderson’s proprietary Altitude leadership model for public sector leaders / executives. Use for individual or group leadership development/ audit, talent management, performance appraisal, coaching.
Features
- Bespoke fully managed 360 platform assessing your behaviours, values, competencies
- Or use our extensively researched public sector leadership excellence model
- Exceptionally flexible and customisable content, reporting and functionality
- Multi-rater feedback 24/7: manager, reports, peers, external stakeholders, others
- Contributors pre-set and uploaded, or nominated by the reviewee
- Real-time organisational and individual reports featuring benchmarks
- Branding options available with video content where required
- Fully managed UK-based service with automated email invitations and reminders
- High browser compatibility: desktop, tablet and mobile responsive/optimised
- Specialist support via account manager, email / telephone helpdesk
Benefits
- Enhance leadership capability audits, coaching, talent/ development/ succession planning
- Grounded in extensive, continuous research benchmarking public sector leadership success
- Exceptional capacity to customise, tailored to your requirements cost-effectively
- No licence fee: fully managed service with clear pricing
- Drives behavioural change through self-awareness and understanding strengths and weaknesses
- Tailored aggregate reporting supports strategic organisational / HR planning needs
- Guaranteed anonymity of responses supports open feedback, enhances developmental outcomes
- Enhanced completion rates: 24 hour remote access, mobile optimised/ compatible
- Convenient, rapid access to reports; unique, secure GDPR compliant delivery
- Optional psychologist support designing content or facilitating feedback / coaching
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 8 3 5 5 7 3 0 3 3 9 6 5 2 0
Contact
GATENBYSANDERSON LIMITED
Charlotte Jourdon
Telephone: 07530 578920
Email: tenders@gatenbysanderson.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- We keep service down-time to a minimum. For scheduled server maintenance, we display a prominent banner on all our websites, advising of maintenance for a minimum of 24 hours prior, and schedule maintenance for out-of-hours (generally after 11pm). We plan ahead to ensure we identify maintenance windows and timeframes that avoid or minimise client or user disruption.
- System requirements
-
- A modern web browser
- Javascript enabled
User support
- Email or online ticketing support
- Yes
- Support response times
- 9 to 5.30 (UK time), Monday to Friday, typically within 24 hours.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We can offer a varied level of support depending upon the client requirements. This could relate to configuration options, customisation requirements or assistance relating to execution of activity. We provide a technical account manager and prices over and above our standard offering will be a cost per hour basis, dependent upon the seniority of personnel required. Many aspects of support are included in our standard fees, as outlined in our pricing document.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- An account manager and project coordinator are assigned to each new client project. The project plan will include the process for launch, and we will work with you to ensure that all communications from both us and you are aligned. Configuration requires limited input from the client; your account manager will discuss configuration options with you and provide a test link for your approval once set up. The platform is intuitive and no training is required for those completing the 360. Telephone / online helpesk support is available to all completing the 360. If required, at additional cost, we can run sessions to meet your needs, such as: training your internal team in feedback of 360; orientating individuals to the reports and how to make best use of them; or our psychologists / coaches can facilitate 360 feedback sessions for you. Post launch, the account team are available to answer any questions or provide support to ensure successful implementation of the system.
- Service documentation
- No
- End-of-contract data extraction
- At the end of any contract, we can provide CSV files of relevant data. Individuals can request copies of personal reports for tools where that is applicable. Where individual data is required to be deleted, we retain anonymous, aggregate data for benchmarking and reporting purposes.
- End-of-contract process
- At the end of the contract, we remove user access to the system and can provide CSV data as required, as well as a copy of any website content. There is no charge for this service. Individual users can still access their dashboards (and any personal reports delivered there) but will not be able to access the 360.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Uses a responsive-html design that scales and re-layouts the design for mobile and tablet users.
- Service interface
- No
- User support accessibility
- WCAG 2.2 A
- API
- No
- Customisation available
- Yes
- Description of customisation
-
We offer a wide range of customisation options.
Our white label product comes with our own set of standard 'Altitude' questions, with many customisation options as standard. We will discuss your requirements at project set-up and implement changes.
Options include; selection of question levels/competencies from the Altitude model; creation of bespoke 360 using your own question content; mapping of your behavioural/values frameworks to Altitude; email content; all wording throughout; client logo/branding; labels for/addition of contributor categories; setting minimum contributor numbers; adding cohort benchmark on reports; rating scales and descriptions; timing/schedule for reminder emails; customisation of reports; add organisation-specific 'biodata' questions to track organisational patterns on the factors that matter to you (i.e. grade / department etc).
Many customisation options are included as standard. Please see pricing document for more details.
Scaling
- Independence of resources
- We review each project to gauge expected load and determine whether separate server(s) are required or whether a shared server is more cost effective for the client. We routinely monitor the performance of server(s) and take appropriate action to negate any potential disruption.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Our managed service and dedicated account team can provide real-time information on completion rates for both participants and their reviewers (not started / started / completed) and nomination rates (i.e where individuals are expected to nominate their own reviewers, whether they have done so and whether they have met any agreed minimums set).
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Approach Data submitted by participants and contributors can only be accessed and/or modified by themselves or within our administration system (requiring a username and password). Passwords are encrypted with bcrypt hashing; Other data is not encrypted due to reporting and analytics requirements. The RDS is encrypted at rest
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Individuals have access to their own report via a password-protected dashboard. Here they can choose to read or download a pdf of their report. Clients can request data downloads in csv/excel format.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Our service commitment is 99.9% during office hours. If we fail to reach this level, we would consider the impact upon the client business and agree a level of compensation based upon refunding monthly subscription charges
- Approach to resilience
- Daily backups of the RDS are taken daily and retained for 30 days. Our deployment process is also automated so in the event of failure we are able to restore environments in a short period of time. Our service is also monitored to detect any suspicious activity or high traffic volumes.
- Outage reporting
-
For any outages, we would promptly contact affected clients by telephone or email (depending on time and severity). Public notification would be via our twitter account, and if possible our website(s).
Once an outage has been resolved we will investigate the cause and provide an explanation of what happened, with a timeline, and what changes we will be making to avoid a similar outage in future.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- We have a separate internal administration system which uses single sign-on with Microsoft 365.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
Cyber Essentials + Certified
ISO27001 and ISO27701 - Information security policies and processes
-
We have Data Protection and Data Security Policies that form part of each employee's formal induction process as well as maintaining an ongoing risk register. We formally record when induction modules are complete. Additionally, we communicate any ongoing requirements to protect ourselves from vulnerabilities. This includes reminders about the use and care of laptops and mobiles also the importance of password security.
More formally, colleagues are warned of the potential disciplinary action of failing to adhere to these policies and procedures which could result in the termination of employment. As soon as colleagues leave the business, we terminate access rights and delete accounts.
All admin pages and logins are via HTTPS and we use HSTS and public-key-pinning to protect and warn users against attempted man-in-the-middle attacks/insecure internet connections.
Our policies include:
Cyber security and Data Protection Policy
IT Security Standard
Acceptable Use Standard
Physical Security Standard
Data Security Standard
Risk Management Standard
Incident Management Standard
3rd Party Supplier Due Diligence
Joiner, Mover, Leaver Process - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Change requests and bug reports are directed to defined product owners who evaluate, prioritise and document changes adding them to product backlogs, which are then scheduled into the development cycle.
Code is versioned and branched in a git repository, following the Git-Flow practice of feature branches pull-requested into a develop branch, and releases performed on the master branch. Merges into develop and master branches (and deployment to servers) are restricted to the head of development. Testing is performed on the developers' own machines (using virtual machines) and on a staging server before deployment to live servers. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We pro-actively gather information on potential threats from email subscriptions to http://cve.mitre.org & https://www.us-cert.gov/ncas/alerts , along with regular checks of https://www.reddit.com/r/netsec.
New alerts are assessed for whether they affect us, For deployment we automatically apply patches to servers on a regular basis to resolve any exploits. If there is a way of mitigating against them (eg rewrite-rules, config changes) we will apply protection to the servers ourselves asap. We will then audit servers to confirm that the exploit had not been used against us. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
In terms of our web server, AWS provide us with the monitoring capabilities to monitor access to the servers and inform us immediately if they see any suspicious behaviour. We routinely audit server logins and server errors to identify suspicious behaviour.
We are registered with relevant news sites/forums that quickly identify vulnerabilities. We have a fast action response where the Head of Development will allocate and oversee resource to close off any vulnerabilities. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Users report incidents via phone and email, and these are forwarded directly to the Development team. We deploy the Development team to investigate incidents, exploits or areas of vulnerability and whether a breach as occurred. Vulnerabilities are closed. We have a central breach register, which documents a formal communications plan to inform individuals, organisations and regulators of the potential compromise.
Breaches of security are formally reported at Board Level and documented in monthly board reports. Remedial action required is agreed and executed within specific timeframes. Learnings are documented and any change to best practice implemented. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12.5%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Sunday 24 August 2025
- What the ISO/IEC 27001 doesn’t cover
- Outsourced Development (A.14.2.7) as GatenbySanderson do not outsource any development activity or outsource system development.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- D54eea72-0a07-4ec0-b1b7-fb12c8f342b9
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- F9044cc1-ccf6-4a9d-837b-b6d7f908df2f
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
-