CIIM Software as a Service (SaaS)
CIIM is a suite of open-source (AGPL v3) middleware and API components. Created in 2009, it is utilised at a wide range of museums, galleries, libraries and archives worldwide. Highly scalable (millions of rich records/ media) and fully automated, it seamlessly integrates with 30+ collection, archive, library and DAMS systems.
Features
- Highly scalable both horizontally and vertically
- Automated, API/file format agnostic integrations, cross-system auditing/reporting
- Schemaless data model with internal graph representation
- Flexible processing workflows with field-level enrichment, validation and privacy
- Enterprise / semantic search/RAG AI and flexible LLM/AI service integration
- Codeless API building framework (including IIIF, LinkedArt, LIDO, EDM, Marc)
- Analytics integration with data, to help drive 'insight led' planning
- Flexible and extensible AI integrations/data enrichment
- Role-based, cross-system data visualisation via flexible, accessible interface
- Graduated APIs for records, fields and media (including dimension control)
Benefits
- Eliminates technical integration debt/replacing inefficient point to point integrations
- Utilises modern microservice and cloud oriented architectures
- Automates and audits previously manual data integrations
- Provides built-in IIIF for image delivery and metadata presentation
- Synchronises your data ensuring the correct SSOT per information unit
- Delivers an integrated media analysis/publication framework
- Provide a coherent enterprise/semantic search strategy (including Elasticsearch, SOLR)
- Simplified AI strategy (RAG, LLM, image analysis, audio to text)
- Puts you in control of your delivery/search/syndication requirements
- Simplifies your end-user/user-interface integrations
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 8 6 2 6 8 7 3 3 4 1 5 0 2 1
Contact
KNOWLEDGE INTEGRATION LTD
Rob Tice
Telephone: 01142738271
Email: tenders@k-int.co.uk
About your service
- Service categories
-
Application Development and Deployment
Data management
Database administration and development
- Data Modelling
- Database Development and Optimization
Data integration and intelligence
- Data Ingestion and Transformation Software
- Data Quality Software
- Data Access Infrastructure Software
- Composite Data Framework Software
- Master Data Intelligence Software
- Metadata Management Software
- Data Archiving and Information LifD-Cycle Management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- Support SLA covers business hours of 09:00-17:00 weekdays and excludes weekends and bank holidays. Support requested can be raised as tickets via the Zendesk outside of these hours and will be picked up when working hours resume.
- System requirements
-
- Must have stable internet access
- Must have latest version of popular browsers
- API key / token if automatic system integration is required
User support
- Email or online ticketing support
- Yes
- Support response times
-
Calls logged on the helpdesk are triaged and initial reply sent within two working hours.
Further responses are dependent on nature and Tier of the now triaged call, with Critical Tier 1 tickets taking priority
Support SLA covers business hours of 09:00-17:00 weekdays and excludes weekends and bank holidays - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
First, second and third line corporate support is provided in house by our teams of application specialists, developers and consultants
Support starts at £12K pa for National Institutions, £7.5K for Non-National
Account management is provided on all levels - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We initially liaise with the users to decide which integrations they require, how much data/media they have and what the likely external consumption of the APIs and data will be, in order to allocate an initial CIIM. These integrations are then configured and auto-deployed in a 'vanilla state' (without customisations). Data is then populated and templates are set up to view the data. At that point any required customisations are defined and implemented (which) depending on complexity may use configuration or require the deployment of bespoke code plugins/configuration. Initial training is provided for all classes of user and specific targeted training (e.g. for internal developers. admin users) can be also included within the package. Initial training is always online but on-site training can be provided at extra cost. Detailed online end-user documentation is provided which includes tutorials, glossary and 'click through' videos. There is also additional online developer documentation for the transformation and dissemination frameworks.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- At the end of the contract the service is turned off and ceases to be publicly available. Data export functionality is available at any time during the contract so users can prepare for end of contract in a controlled manner. For a period of 1 month following shutdown, the service can be reinstated for data export (for example if any problems were discovered with the end of service data exports). There is no charge for data exports even during the month post contract end.
- End-of-contract process
- Users are contacted in writing 2 months before contract ends, with a quote to clarify the terms of the continuation (e.g. any RPI price increases). If any material changes to the service are required in response to this quote, these are costed and a revised quote issued. When this is accepted then the service simply rolls over and continues.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- The service interface provides a role-based view across all of your data and syndication endpoints. It enables viewing of performance metrics, system activity, auditing and facilitates the management, configuration and scheduling of data integrations. The interface can integrate with an organisations centralised identity management systems and provide access levels based on memberships set within that system. It has configurable search access points and data partitioning which can be set per-user or cross organisation and user-customisable filtering which can be set at the same granularity. Simple searching and targeted searching using Lucene syntax is also supported.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- None
- API
- Yes
- What users can and can't do using the API
- All of the features of the system are accessible via API which is role-based. The service has multiple APIs for data delivery, extraction, submission and configuration. All of these APIs can be used to both setup/configure the service and to customise delivery frameworks and data processing pipelines. The mechanisms for configuring the service are split between APIs which are used to setup and configure integrations, schedules, timings and allocated system processing power, and configuration which is used to drive pipeline transformations, publication endpoint configuration, syndications and dissemination formats. As this type of configuration needs to be tracked to avoid introducing errors, it is managed via a tailored CI/CD pipeline which both monitors your configuration and tests/deploys changes to using the Argo API into Kubernetes. The common API tasks are also surfaced via the user interface and this can also be used to schedule, suspend, run on demand and search/filter across all content. This also extends to UI customisations for filters, search access points and data display templates.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- The service offering can be customised via the user interface and also via our flexible data manipulation language (Proteus) - this allows buyers to configure their own data delivery formats and standards, data transformations, validation rules and processing pipelines. Via the user-interface end users can set up their own data display templates, search access points and data partitioning. These customisations can be for a specific user only or application wide. Anaytics service integrations can also be customised.
Scaling
- Independence of resources
- When the systems are configured (as part of the onboarding), limits are placed on the amount of resource each tenant can utilise. This guarantees that even under heavy load there is no cross instance performance degradation. The overall architecture always has headroom to allow it to be temporarily 'burstable' to deal with transient heavy load and there are multiple API caches (including cloudflare optionally) to also balance system throughput. If an ongoing resource increase is required for a specific tenant this can be configured and redeployed automatically.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Integration and data throughput and API usage metrics. We integrate with multiple analytics services so that any downstream services which use the platform can have their analytics integrated into the data for insight-led planning.
Helpdesk response times, service availability and resource usage are also provided - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Built in User driven export functionality provides format options
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Json
- Xml
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Json
- Xml
- RDF/TTL
- SQL
- Excel
- Shapefile
- Images (JPEG. TIF etc)
- Documents (HTML, PDF, DOCX etc)
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Other
- Other protection between networks
- Secure SSH tunnels can be configured if options above are not available
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
-
"We guarantee 99.9% uptime for any public facing services. This excludes agreed scheduled downtime and any outages which are the result of issues caused by the underlying cloud provider platform being unavailable.
Uptime is monitored and reviewed as part of service renewal, any failure to hit the agreed availability will be considered and offset against any annual increase in renewal costs" - Approach to resilience
- Our services can be delivered via all the common cloud platforms and are deployed on Kubernetes, typically using Amazon EKS. We specify the numbers of 'replicas' of service components via our automatic configuration management and this replica provides the underlying resilience and auto scaling for handling of burstable demand increases, as well as replacing unhealthy services with new healthy replicas. Where cloud platforms are used, their service guarantees cover the uptime of the Kubernetes Platform.
- Outage reporting
-
"Our services are deployed within a Kubernetes cluster, with cluster management via Argo and service management via our own internal monitoring system (Harvey).In addition our automated monitoring system automatically raises a support ticket when any system anomalies are detected. These anomalies are not limited to actual problems and can be used to pre-empt issues arising. This can include performance slowdowns, processing bottlenecks and API response times. Because these are raised as support tickets they are also visible to the customer when they log in to their support portal.
External monitoring tools are also configured to probe aliveness of deployed applications. "
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is restricted in management interfaces and support channels by a minimum of 2fa. It can be additionally restricted by IP. In terms of the management authentication, it can also be integrated with an organisation's identity management system, so that additional account information is not required. In this case access (and therefore by definition) the restrictions (in addition to 2FA) are based on the individual organisational identity management policy, however we can additionally disable accounts directly via our interfaces
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
We have internally allocated information security responsibilities with a regular review process.
Entry controls to restrict access to premises, equipment and data.
We ensure the security of home working and mobile devices.
We configure new and existing hardware to reduce vulnerabilities.
We assign user accounts to authorised individuals, and manage user accounts to provide the minimum access to information.
We have password security procedures and network 'rules' for access to information systems.
We have anti-malware defences to protect computers from malware infection (including at firewall level).
We have boundary firewalls (Fortigate) to protect from external attack and exploitation and help prevent data breaches.
Breaches or misuse are reported and escalated to Heads of Department and then Directors - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our core components, implementation code and configuration are managed/ tested within our CI/CD pipeline for all commits, with weekly large scale integration tests as part of this framework to allow us to capture any potential issues which only surface for large data sets. The potential security impact of any change is always reviewed in terms of changing the threat landscape, attack surface and whether our existing controls mitigate the change. If there is deemed an impact on security, then these threats are documented and mitigation is put in place. This is always validated by vulnerability and/or penetration testing as required.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We utilise OWASP dependency Check within our CI/CD build pipeline. Scanning of new and existing components happens at verify time as part of the build process. We utilise a central database, updating from the NVD database daily and all our builds use this database. We utilise Intruder.io to check external vulnerabilities daily and to email a report and these are also responded to within a 48 hour window. Both of these services monitor daily CVE updates to provide their analysis. For third party components, we utilise OpenVAS checking against an internal version registry to produce alerts.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Potential compromises are identified through technical controls and human input. Access and authentication logs are monitored for unusual activity such as repeated failed logins, privilege escalation, or abnormal access patterns. Tools such as OSSEC and Fail2ban are used to detect and automatically alert administrators to high-risk events and mitigate intrusive activity.
Security incidents are treated as a critical priority. Initial triage begins as soon as a potential threat is identified, with immediate action taken to confirm and contain the incident to minimise impact. Following containment, incidents are investigated, remediated, and affected customers are notified with relevant findings and actions taken. - Incident management type
- Supplier-defined controls
- Incident management approach
- Incident management covers security compromises, service outages or degradation, data access breaches, and account or access misuse. Incidents are categorised by type and severity and follow a clear workflow of containment, investigation, resolution, and review. After resolution, reports are provided to affected customers summarising the cause, impact, and actions taken, including preventive measures, to ensure transparency, accountability, and continual improvement. Users can report incidents via our support ticketing system, Zendesk, ensuring prompt visibility of incidents, triage and escalation of high-priority events.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 17.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 080561af-3109-4d58-8c86-ce86c20d6017
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-