Aiimi Workplace AI for Operationalising AI
Aiimi Workplace AI connects your chosen LLM(s) to all of your corporate information sources. Deploy retrieval augmented generation solutions taking advantage of your organisation's complete data picture. The solution provides a built in UI for chatbots and deep research flows as well as providing integrations to enhance existing AI assistants.
Features
- Enterprise Search, Generative AI and Retrieval Augmented Generation (RAG) Support
- Suite of connectors for indexing muiltiple corporate data sources
- Central searchable index of corporate structured and unstructured data
- Structured data ingestion and preparation for use with LLMs
- MCP Service Support for integrating with ecosystem copilots
- Built in Chatbot and AI Assistant
- Classification engine so AI only uses golden records
- Extensive support for citation and on-demand deep research
- Integrations with MS CoPilot, Claude Desktop and Databricks Genie
Benefits
- Rapid deployment of custom LLM powered chat experiences
- Secure use of corporate data in LLM solutions
- Classification of data and reduction in hallucination
- More complete answers from AI solutions with full corporate data
- Multi LLM support (OpenAI, Llama, Claude Sonnet, Mistral and more)
- Orchestrate the feed of curated data to your chosen front-end
- Enable rapid experimentation against select datasets
- Automatically assess information risk and exclude sensitive data from LLMs
- Automated search for cited information within the source document preview(s)
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 3 7 9 6 3 8 8 9 1 8 5 1 0 1
Contact
AIIMI LIMITED
Matt Eustace
Telephone: +447919330081
Email: tenders@aiimi.com
About your service
- Service categories
-
Application Development and Deployment
AI platforms
- Search and knowledge discovery
AI life cycle
- Data Labeling Software
- Trustworthy AI Software
AI software services
- Conversational AI Software Services
- Generative AI Software Services
- Document AI Software Services
- Personalize AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- The solution can be installed on Docker (Kubernetes) on Azure, or on Windows or Linux operating systems on other cloud providers or in a hybrid environment.
- System requirements
-
- Windows 2016 Server or later
- Red Hat or Alma Linux 8 or 9
- SSL Certificates to be provided by client
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 30 minutes during UK Business Hours (9AM to 17.30PM) on working days. Premium support outside of these hours is available subject to contract.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
- Standard support is available at 20% of the annual subscription fee and includes 4 upgrades per year and access to a Solutions Architect aligned to your account.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Aiimi can provide a fully managed service if required, assistance up to an including platform set-up and hosting, integration with your cloud and on-premises data sources, configuration of enrichment, user experience, branding and training. The solution has on-line help and a nominated DevOps consultant will be available to support throughout the duration of your contract.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- The service stores information in an Elasticsearch index, which may be enriched with metadata by Workplace AI , or by users of the software. The index will hold audit information, disclosure information and discovered metadata and text from source documents and data. This information can be provided at the end of the service term in CSV or JSON format as part of the service close down. There is no charge for provision of this information.
- End-of-contract process
-
Included in the price of the contract:
At the end of the contract, Workplace AI components and Elasticsearch will be uninstalled and all access to applications revoked.
Elasticsearch components will be removed from the instance:
The Elasticsearch instance will be closed down and the data held will be deleted.
Customer can retain all main indices within Elasticsearch in CSV format. These exports contain the indices, the data outputs from the crawling and enrichment, text content and specify any classification applied to documents.
Data can be exported using a CSV export utility that will output the attributes of documents enabling the administrator to select what attributes to be exported :
Elasticsearch nodes will be closed down and removed from any servers that they are installed on.
Elasticsearch service will be closed down.
Kibana service will be closed down.
The Aiimi Workplace AI (AIE) components that will be removed include:
Aiimi Workplace AI Logs:
Log production will cease.
Historic Aiimi Workplace AI logs will be deleted.
Aiimi Workplace AI services that will be uninstalled:
Source Agent.
Enrichment Agent.
Security Agent.
Content Agent.
Applications that will be made inaccessible:
AIE.
Kibana. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is responsively designed, so will refactor the display according to the device and screen size available. This means more or less information is available at a time without scrolling.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
- The API provides access to the Middleware using REST and can carry out all of the application's functions. The solution can generate an API key which is then used when accessing the API. MCP services are also available as is an OData API.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Branding, sources connected to, enrichment carried out and the filters, search flows, LLMs and CoPilots that the solution connects to are all configurable by an administrator. The solution provides classification services (schemas and classes) using AI and rules based classification which is configurable by an Information Manager. End users can configure the prioritisation of information returned by boosting sources in search results and can set up saved searches and custom notifications for their interests.
Scaling
- Independence of resources
- The solution provides a number of mechanisms to isolate it from the demands of other processes or platforms. The solution can index source information and do this on a schedule with threading and timeout controls to ensure it doesn't impact the source platform. It can catch up on indexing during periods of low activity. The platform can be installed on isolated infrastructure scaled the the appropriate degree and works on Kubernetes for auto-scaling. Hosted / SaaS versions of the product are customer isolated at network and infrastructure level and shared services auto-scale with demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Test
- Reporting types
-
- API access
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- The solution has a user interface for exporting information in CSV format. There is also an admin reporting interface accessible on request to extract raw information in JSON or CSV format.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- If hosted in Azure, Google or Amazon datacentres, we provide a 99.99% uptime SLA for the application (agreed maintenance windows excepted). The solutions ability to crawl new source data or to be accessible from the customer network is covered to the perimeter of the Aiimi provided facility, e.g. we do not provide an SLA for customer network connections. Customers receive support service credits when SLAs are not met.
- Approach to resilience
- Workplace AI can be provisioned in Azure, AWS and GCP environments as well as on-premises, each with similar approaches to resilience. An Aiimi implementation will include our best practice resilience measures, including taking advantage of geographical and in-datacentre resilience features provided by the datacentre. Examples include ensuring that multiple machines are used to support the service, each patched and maintained at different times and with independent power, cooling and network connections. The service itself makes use of stateless connections, load balanced web application servers and sharded indexes. Background activities such as source system crawls and metadata enrichment processes can run on any available server, providing resilience for back-end services. The resilience approach appropriate to your chosen infrastructure provided will be discussed prior to implementation.
- Outage reporting
- We routinely monitor the health of our elasticsearch cluster through Kibana Monitoring to ensure that the cluster is in a healthy state and performing as expected. Aiimi will also monitor dashboarding offered by cloud providers e.g. Google Stackdriver Monitoring or Azure Monitor. These dashboards allow us to track the performance of our hardware and software in real time. E-mail alerts are also setup to notify Administrators, should any metrics exceed pre defined thresholds.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Aiimi Workplace AI uses domain independent authorisation for management and support interface access. These logons only allow access to the management interfaces and full audit is recorded for all management actions.
A starters movers, leavers process is used to control and audit who is authorised to access systems and this is provided on a 'need to know' basis rather than access being granted to all support and service staff to all systems. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
Aiimi has an Information Governance Committee which is responsible for generating and reviewing data security and policies. The policies are then reviewed by the board and distributed to staff by our eLearning platform and the HR team. Information governance and data protection clauses are also included in staff contracts and updated with employee data privacy notices on a regular basis in-line with changes in the security policy.
Our policies are in-line with ISO27001 and communicated to staff in a number of ways:
- Monthly all staff briefings for the latest information security concerns
- Regular automated information security tests
- Electronic information security training with assessments. This is focussed on the staff role
- Ad-hoc staff updates related to current concerns
Aiimi has an annually reviewed risk management framework that is agreed with the board, which guides the activities of the information governance committee who implement policy changes to cater for current risks. The IGC meet as a committee once a quarter, or on demand if required.
Incident management is handled by our service desk and a formal procedure governs how incidents are handled. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Instances of Workplace AI hosted by Aiimi will be commissioned on Azure infrastructure in a customer resource group and the change management approach for that instance will be agreed with the customer. Based upon a template that defines the annual maintenance windows, KPIs, SLAs, RPO and RTO for the instance, change management activities will be governed by those requirements. Application releases and code components are managed in GitHub and all releases are penetration tested in-house on QA environments and again when released to a customer environment.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Aiimi deploys two key mechanism for assessing threats to the application. First is a peer code review by developers trained in secure software development. Training is provided by KnowBe4. The second is through the use of AppCheck to perform vulnerability scans on internal deployments of Workplace AI. These are performed monthly and the output reports are fed into the development backlog.
Patches to security issues are immediately prioritised for development and can be released outside the standard release cycle. High risk security patches are applied by our DevOps team within two days of being issued, or according to customer schedule. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is only commissioned by Aiimi where we host the application on our customer's behalf in Microsoft Azure datacentres. We use Microsoft Antimalware for Azure Cloud Services and Virtual Machines to identify compromises. Aiimi responds within 30 minutes to an alert, whether that is a potential compromise or an incident.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
The Aiimi Service Desk processes are determined by the Incident Management tool in use and based on the ITIL V3 framework. Incidents are logged, classified, categorized, prioritized, assigned for investigation and investigated until resolved. Customers log incidents via a dedicated email address, a dedicated landline phone number or an on-line portal.
Routine events are handled through scheduled maintenance windows. Recurring issues are logged as Problem tickets for root cause analysis.
Periodic reports are generated using the Incident Management tool and used by customers and internal teams for trend analysis, performance review and continual service improvement. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Tuesday 25 November 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B91b04ac-62e5-429b-8cda-615a85fd888e
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 97b2e909-2ed4-4551-b2cf-67ebb85fb4ed
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
-