Skip to main content

Help us improve the Digital Marketplace - send your feedback

MICROLINK PC (UK) LIMITED

Explainable AI Engine

A cloud-based AI transparency platform that provides explainability and interpretability for machine learning models. Enables organisations to understand AI decision-making through visual explanations, feature importance analysis, and model auditability, ensuring compliance with AI governance requirements and building trust in automated systems.

Features

  • Real-time explanations with interactive visualisations and feature importance rankings
  • Automated bias detection across protected demographics with fairness metrics
  • Transparent clinical AI reasoning enabling validation of diagnostic recommendations
  • HL7 FHIR integration for seamless NHS electronic health record connectivity
  • Counterfactual analysis showing alternative outcomes from changed clinical parameters
  • Audit trails tracking all AI decisions for regulatory compliance
  • Multi-user dashboard with role-based access for clinical governance teams
  • Medical imaging explanation support including attention heatmaps for radiology

Benefits

  • Build trust through transparent AI reasoning and clear clinical pathways
  • Reduce compliance risk by demonstrating adherence to healthcare AI regulations
  • Accelerate deployment by identifying and resolving bias issues early
  • Empower clinicians to validate AI recommendations without technical expertise
  • Improve diagnostic accuracy through detailed clinical feature contribution insights
  • Support patient safety by aligning AI with medical ethics standards
  • Streamline regulatory submissions with automated MHRA and NICE compliance documentation
  • Reduce litigation risk through comprehensive audit trails of AI decisions
  • Enable non-technical staff to understand AI predictions through intuitive visualisations
  • Facilitate clinical governance with role-based dashboards for multidisciplinary oversight

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sam@microlinkpc.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 5 0 2 6 4 7 0 3 4 7 7 6 3 4

Contact

MICROLINK PC (UK) LIMITED Hazel Knights
Telephone: 02380240300
Email: sam@microlinkpc.com

About your service

Service categories

Application Development and Deployment

AI platforms

AI life cycle

  • AI Build Software
  • Trustworthy AI Software

AI software services

  • Conversational AI Software Services
  • Computer Vision AI Software Services
  • Generative AI Software Services
  • Document AI Software Services
  • Anomaly Detection AI Software Services
  • Personalize AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
Requires minimum dataset size of 1,000 patient records for effective bias detection.
Scheduled maintenance windows occur monthly during off-peak hours with 48-hour advance notice. Initial model integration requires 2-4 weeks for healthcare-specific configuration and validation. HIPAA compliance requires dedicated encryption keys and secure data handling protocols throughout implementation.
System requirements
  • Compatible with Python 3.8+
  • Minimum 16GB RAM for real-time explanation generation
  • Secure API integration supporting RESTful and SOAP protocols
  • Healthcare data must be HIPAA-compliant
  • Network latency under 100ms for optimal performance
  • Audit logging infrastructure for compliance and tracking purposes
  • TLS 1.2+ encryption for all data transmissions

User support

Email or online ticketing support
Yes
Support response times
We provide tiered response times based on priority levels. Critical issues (P1 - system down, patient safety risk): 1 hour response, 4-hour resolution target. High priority (P2 - degraded service): 4-hour response, 24-hour resolution target. Medium priority (P3 - minor issues): 8-hour response, 72-hour resolution target. Low priority (P4 - questions, requests): 24-hour response. Weekend and bank holiday response times are 50% longer for non-critical issues. All times are measured during business hours (Monday-Friday 8am-6pm GMT).
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Our web chat interface has undergone comprehensive accessibility testing with both automated tools and real users. We conducted testing with JAWS, NVDA, and VoiceOver screen readers to ensure full compatibility. User testing included participants with visual impairments, motor disabilities, and cognitive differences. All interactive elements support keyboard-only navigation with visible focus indicators. The chat interface maintains ARIA labels for dynamic content updates, ensuring screen readers announce new messages appropriately. We tested colour contrast ratios (minimum 4.5:1 for normal text, 3:1 for large text) and verified functionality at 200% zoom without horizontal scrolling. Testing confirmed compatibility with speech recognition software including Dragon NaturallySpeaking. The chat widget can be operated entirely via keyboard (Tab, Enter, Escape keys) without requiring mouse interaction. We validated that error messages and system notifications are announced to assistive technologies and that file upload features include appropriate accessible labels and status updates.
Onsite support
Yes
Support levels
There is no onsite support required for this type of work, as it is delivered through AI. However, if any travel is needed, we can accommodate this at the same rate.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
We provide comprehensive onboarding including a dedicated Clinical AI Implementation Manager and Information Governance Specialist for 90 days. Onsite training is available (included in Enterprise support, charged separately for other tiers) covering platform fundamentals, clinical explainability techniques, and NHS compliance requirements. Online training includes live webinars for different healthcare roles (clinicians, radiologists, informaticians, IT teams) and on-demand video tutorials. User documentation comprises implementation guides, API reference manuals, clinical use case libraries, and compliance checklists. Onboarding process includes initial clinical safety assessment, information governance review, secure integration with EPR/EHR systems and PACS, Data Protection Impact Assessment support, and clinical validation workshops. We provide HL7 FHIR integration guides, hands-on sandbox environment access for testing without affecting production systems, and role-based training for clinical, technical, and administrative staff. Healthcare-specific training covers MHRA compliance, NHS AI Lab assessment framework, and clinical risk management (DCB0129/DCB0160). Ongoing support includes quarterly check-ins, knowledge base access, community forums, and regular updates on new features and regulatory changes.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Upon contract termination, NHS trusts retain full ownership of all data. We provide up to 90 days continued read-only access (extendable to 12 months for clinical continuity). Data export includes trained clinical models, anonymised training datasets, patient explanation outputs, clinical validation reports, configuration files, and comprehensive audit logs in healthcare-standard formats: HL7 FHIR JSON, CSV, ONNX, PMML, DICOM (for imaging models), and HDF5. Patient-identifiable data exports use NHS-approved secure channels including N3/HSCN SFTP, encrypted cloud storage, or encrypted physical media via secure courier. We provide HL7 FHIR transformation support, format conversion preserving clinical metadata, and technical consultation on maintaining explainability in new systems. Clinical model validation documentation and safety case reports support continued use or re-validation. Self-service export via dashboard or API available. Large dataset exports coordinated with dedicated support engineer. All exports include data dictionaries and schema documentation for seamless migration.
End-of-contract process
Contract end process begins 90 days before termination with transition planning meeting. Included in contract price: full data extraction in standard formats, 90 days read-only system access, migration documentation, knowledge transfer sessions, and certified data deletion certificate. Additional costs may apply for: extended access beyond 90 days, onsite migration support, custom format conversions, and migration to competitor platforms requiring specialised integration (quoted on request). Process includes clinical governance sign-off, information governance verification, and handover documentation for incoming suppliers. All patient data permanently deleted from our systems within 90 days following NHS Digital standards and Caldicott principles, with verifiable certificate of destruction. Earlier deletion available upon request with appropriate governance approvals. For research data, we support transfer to NHS-approved trusted research environments. No cancellation fees. No lock-in clauses. Customers can request early termination with 30 days’ notice. Final invoice prorated to actual usage. Unused prepaid amounts refunded within 30 days.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile version provides responsive design optimised for tablets and smartphones with touch-friendly interfaces. Full dashboard functionality available including real-time explanation viewing, model performance monitoring, and bias detection alerts. Complex visualisations like 3D model exploration are simplified on mobile, with options to email detailed reports for desktop review. Mobile supports offline viewing of previously generated explanations with automatic sync when connectivity resumes. Clinical decision support notifications are push-enabled for urgent alerts. Healthcare professionals can securely access patient-level AI explanations on mobile during ward rounds or consultations, ensuring point-of-care decision support accessibility.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service provides two primary interfaces: a web-based dashboard and a RESTful API. The dashboard offers interactive visualisations for AI model explanations, bias detection results, feature importance rankings, and compliance reporting. Users configure explanation parameters, manage models, view audit trails, and generate reports through intuitive navigation. The RESTful API enables programmatic access with OpenAPI 3.0 specification, supporting JSON formats and webhooks for asynchronous notifications. HL7 FHIR R4 endpoints facilitate NHS electronic health record integration. Both interfaces support role-based access control aligned to clinical and administrative roles, with full audit logging for compliance.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We conducted comprehensive accessibility testing with healthcare professionals using JAWS, NVDA, and VoiceOver screen readers, keyboard-only navigation, and switch controls. Testing validated that all dashboard features including AI explanations, model configuration, and reporting are fully keyboard accessible with visible focus indicators. Screen reader testing confirmed dynamic content updates are announced via ARIA live regions. Data tables and charts include alternative text descriptions for clinical information. Colour-blind testing verified status indicators use patterns and icons, not just colour. High contrast mode and 200% zoom tested successfully. Speech recognition software (Dragon NaturallySpeaking) compatibility validated. User feedback from staff with visual impairments, motor disabilities, and cognitive differences led to improvements including enhanced heading structures, expanded touch targets, and customisable text sizing without functionality loss.
API
Yes
What users can and can't do using the API
Users can configure AI models, set explanation algorithms (SHAP, LIME), define bias thresholds, submit predictions with automatic explanations, retrieve historical results, manage permissions, and export compliance reports via RESTful API. Supports HL7 FHIR integration for NHS systems. Users can modify model metadata, explanation parameters, and dashboard layouts. Limitations: clinical safety-critical settings require web interface approval for NHS Digital DCB0129 compliance. Patient data deletion requires multi-factor authentication. Rate limits: 1,000 requests/hour (standard), 10,000 (enterprise). Production model deployment requires clinical validation sign-off.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users customise via web interface or API: select explanation algorithms (SHAP, LIME, attention) with configurable parameters; define feature importance thresholds and visualisation templates; configure bias detection metrics and alert rules; white-label dashboards with organisational branding; create custom report templates; integrate proprietary algorithms via plugin architecture (requires security review). Healthcare-specific options include SNOMED CT terminology configuration and specialty-specific explanation templates. Enterprise customers access dedicated environments with custom data residency. Limitations: core security controls, audit logging, and encryption standards cannot be modified for regulatory compliance. Custom algorithms require clinical safety evaluation.

Scaling

Independence of resources
We implement multi-tenant architecture with strict resource isolation. Each NHS organisation receives dedicated compute quotas, memory allocation, and storage partitions with cryptographic separation at application layer. Auto-scaling provisions additional resources based on individual customer demand without impacting others. Enterprise customers receive dedicated infrastructure ensuring complete isolation. We enforce per-customer rate limiting, connection pooling, and query timeouts preventing resource monopolization. Load balancing distributes requests across geographically separate availability zones. Patient data isolation meets NHS Digital standards with logical separation verified through annual penetration testing. Monitoring alerts trigger automatic resource reallocation maintaining guaranteed performance SLAs.

Analytics

Service usage metrics
Yes
Metrics types
We provide comprehensive usage analytics including API call volumes and response times, explanation generation metrics (requests per model, average processing time), model performance tracking (accuracy, bias scores over time), feature importance trend analysis, user engagement analytics (active users, dashboard sessions, report downloads), audit trail summaries (access patterns, configuration changes), compliance reporting (DSPT requirements, bias detection alerts, clinical safety incidents), system performance metrics (uptime, latency percentiles), and resource utilisation (compute usage, storage consumption). All metrics exportable to CSV, JSON, or via API integration with NHS analytics platforms and Tableau/Power BI dashboards.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Other
Other data at rest protection approach
AES-256 encryption for all patient data at rest using NHS-approved key management with keys stored in UK-based Hardware Security Modules (HSMs). Encryption keys separated from data with role-based access controls. Database-level encryption with transparent data encryption (TDE) and encrypted backups. Field-level encryption for highly sensitive patient identifiers. Encrypted file systems for all storage volumes. Regular key rotation every 90 days. Multi-factor authentication required for key access. Encryption validated through annual NHS Digital security assessments. Compliance with ISO 27799 healthcare security standards and NHS Data Security and Protection Toolkit requirements.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users export data through multiple methods: automated scheduled exports via API, on-demand downloads through the web dashboard, or programmatic extraction using RESTful endpoints. Explanation reports, bias metrics, and audit logs can be exported individually or in bulk. Healthcare administrators access a dedicated export portal with filtering options by date range, model type, or patient cohort. All exports maintain HIPAA compliance with encrypted file transfers and access logging. Users can configure export templates to include specific metrics, visualisations, or documentation formats required for regulatory submissions or internal reporting workflows.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON (for API integrations and programmatic access)
  • PDF (for clinical reports and regulatory documentation)
  • Excel/XLSX (for healthcare analytics teams)
  • HL7 FHIR (for EHR System Integration)
Data import formats
  • CSV
  • Other
Other data import formats
JSON, XML, HL7 FHIR (JSON/XML), Excel (XLSX)

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Internal network segmentation using VLANs isolates patient data processing from management systems. Encrypted network fabric using MACsec (802.1AE) for layer 2 encryption between switches. Zero-trust architecture requires mutual TLS authentication for all internal service communications. Patient-identifiable data transmitted internally uses AES-256 encryption in addition to TLS. Network traffic inspection via NHS-approved intrusion detection systems. Microsegmentation enforces least-privilege access between application tiers. All internal APIs require certificate-based authentication. Encrypted overlay networks (WireGuard) for inter-datacenter replication. Network access control (802.1X) validates device identity before network access.

Availability and resilience

Guaranteed availability
We guarantee 99.9% uptime SLA excluding planned maintenance windows, equating to maximum 43 minutes unplanned downtime per month. Planned maintenance limited to 4 hours monthly during designated windows (second Sunday 2AM-6AM GMT) with 7 days advance notice. For clinical decision support systems requiring higher availability, Enterprise tier offers 99.95% SLA (maximum 22 minutes monthly downtime). SLA measured monthly on per-customer basis. Service credits automatically applied for SLA breaches: 10% monthly fee credit for availability between 99.0-99.9%, 25% credit for 95.0-99.0%, 50% credit below 95.0%. Credits capped at 100% monthly service fee. Availability calculated excluding scheduled maintenance and customer-caused incidents. Emergency maintenance for critical security vulnerabilities provided with minimum 48-hour notice where possible, excluded from SLA calculations if completed within 4-hour window. Enterprise customers receive dedicated infrastructure with independent availability guarantees. Real-time uptime monitoring available via status dashboard. Monthly availability reports provided showing actual uptime, incidents, and any credits applied.
Approach to resilience
Our service implements multi-layered resilience architecture. Infrastructure deployed across multiple UK availability zones (London, Manchester) with automatic failover capability achieving sub-30 second switching for patient-critical systems. Active-active configuration ensures continuous operation if one zone fails. Load balancing distributes traffic across geographically separate datacentres with health monitoring and automatic traffic rerouting. Database replication maintains synchronous copies across zones with automated failover for 5-minute Recovery Point Objective. Hot standby systems for all clinical-facing components eliminate single points of failure. Network redundancy via diverse fibre paths and multiple ISP connections. Power resilience through N+1 redundant UPS systems and onsite backup generators. Cooling systems with N+1 redundancy. Storage resilience uses RAID configurations with distributed replication. Application layer implements circuit breakers, retry logic, and graceful degradation. Regular disaster recovery drills conducted bi-annually with clinical stakeholder participation. Datacentres certified to ISO 27001, Tier III+ standards. Detailed resilience architecture documentation available on request under NDA for security-cleared NHS procurement teams.
Outage reporting
We provide multiple channels for outage reporting and status updates. Public status dashboard (status.explainableai.health) displays real-time service health for all major components including API availability, dashboard access, explanation generation service, and authentication systems. Color-coded indicators show operational (green), degraded (amber), or outage (red) status with incident history for 90 days. Dashboard includes RSS feed for automated monitoring integration. API endpoints provide programmatic access to status data for integration with NHS trust monitoring systems. Email alerts sent to registered contacts at incident detection, every 30 minutes during ongoing incidents, and upon resolution. SMS notifications available for critical Priority 1 incidents affecting patient safety. Webhook notifications push real-time status updates to customer systems. Enterprise customers receive direct phone notifications for critical incidents. All incidents documented with timestamps, root cause analysis, and resolution details. Post-incident reviews published within 5 business days for major outages. Status updates published via NHS Digital CareCERT for security incidents. Integration available with ServiceNow, PagerDuty, and other ITSM platforms.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
Access restrictions in management interfaces and support channels
Management interfaces require mandatory multi-factor authentication using hardware security keys (FIDO2/WebAuthn), authenticator apps, or NHS smartcards. Role-based access control enforces least-privilege with separation of duties between clinical, technical, and administrative roles. Administrative access restricted to authorised IP ranges via allowlisting. Jump servers with session recording required for production system access. Time-limited access tokens expire after 8 hours requiring re-authentication. Support staff access patient data only with documented justification and customer approval, logged for audit. Privileged access management enforces just-in-time elevation with approval workflows. All administrative actions logged immutably. Remote access via VPN mandatory.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
ISO 27799 (Health Informatics Security), ISO 27017 (Cloud Security), ISO 27018 (Cloud Privacy), SOC 2 Type II, Cyber Essentials Plus, NHS Data Security and Protection Toolkit (DSPT) Standards Met status.
Information security policies and processes
We maintain comprehensive information security policies covering access control, encryption, incident management, business continuity, secure development, vendor management, and physical security. Policies align with ISO 27001, ISO 27799, and NHS Digital Data Security and Protection Standards. Access control policy enforces least-privilege principle, mandatory MFA, role-based permissions aligned to NHS workforce roles, and annual access reviews. All staff undergo enhanced DBS checks and sign confidentiality agreements. Information governance training mandatory for all personnel quarterly, with clinical staff receiving additional Caldicott principles training. Secure development lifecycle implements security-by-design, code reviews, static/dynamic analysis, and penetration testing before production deployment. Change management requires security impact assessment and clinical safety evaluation for patient-facing features. Incident response procedures provide 24/7 escalation path with mandatory reporting to NHS Digital CareCERT for healthcare data incidents. Data Protection Officer oversees GDPR compliance and conducts DPIAs for new features. Internal audit team conducts quarterly compliance reviews. Security metrics dashboard tracks policy adherence, training completion, incident response times, and vulnerability remediation. Annual external ISO 27001 surveillance audits verify policy effectiveness. Non-compliance triggers corrective action procedures with Board visibility.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
All infrastructure and application components tracked via configuration management database with automated asset discovery and version control. Changes follow ITIL-based process requiring documented justification, security impact assessment, clinical safety evaluation (for patient-facing features per DCB0129), peer review, and approval gates. Standard changes pre-approved; normal changes require Change Advisory Board review; emergency changes require CISO and Clinical Safety Officer approval. All changes logged with rollback procedures. Configuration baselines maintained with automated compliance scanning. Healthcare-specific changes undergo additional clinical validation. Version control via Git with immutable audit trails. Automated testing in staging mirrors production.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Continuous vulnerability scanning using automated tools (Qualys, Nessus) with daily scans of internet-facing systems and weekly internal scans. Threat intelligence from NCSC, NHS Digital CareCERT, CISA, and vendor security bulletins. Risk-based prioritisation using CVSS scores with healthcare context: critical vulnerabilities (CVSS 9.0+) patched within 24 hours for patient-facing systems, 72 hours for internal systems; high severity within 7 days; medium within 30 days. Emergency patches tested in staging before production deployment. Patient safety assessment for clinical system patches. Penetration testing annually by CHECK/CREST providers. Dependency scanning for third-party libraries. Zero-day vulnerabilities trigger immediate incident response with clinical safety team engagement.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
24/7 Security Operations Centre monitors all systems using SIEM platform aggregating logs from applications, infrastructure, network devices, and security tools. Machine learning-based anomaly detection identifies suspicious patterns including unauthorised access attempts, unusual data access, privilege escalation, and lateral movement. Real-time alerts for high-risk events trigger immediate investigation. Integration with NHS Digital CareCERT provides healthcare-specific threat intelligence. Automated response blocks suspicious IP addresses and isolates compromised systems. Patient data access monitoring flags abnormal queries. Security analysts investigate alerts within 15 minutes for critical incidents. Quarterly threat hunting exercises proactively identify hidden threats.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Structured incident response following ISO 27035 with predefined playbooks for common scenarios (ransomware, data breach, DDoS, insider threat). Users report incidents via 24/7 hotline, email, ticketing system, or automated monitoring alerts. Incidents classified P1-P4 based on patient safety risk, data exposure, and business impact. P1 incidents trigger immediate escalation to CISO, Clinical Safety Officer, and NHS Digital CareCERT notification within 24 hours per GDPR. Incident command structure activates for major incidents. Root cause analysis completed within 5 days. Customers receive incident notifications via email/SMS with detailed post-incident reports including timeline, impact, and remediation.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
Other
Other public sector networks
  • NHS N3 (legacy)
  • HSCN (Health and Social Care Network)
  • NHSmail connectivity

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
30-day free trial includes full platform access with up to 1,000 explanation requests, 2 AI models, basic bias detection, and email support. Excludes: onsite support, dedicated account manager, custom integrations, production deployment, and SLA guarantees. Trial uses isolated sandbox environment with synthetic healthcare data. No credit card required.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
7.5%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
NQA
ISO/IEC 27001 accreditation date
Wednesday 9 July 2025
What the ISO/IEC 27001 doesn’t cover
Due to the nature of the services we provided, data masking or anonymisation is not possible, so it is not covered by our certification. We can provide a redacted version of our SOA for ISO27001 showing all the sections covered.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
NQA
ISO 9001 accreditation date
Monday 18 December 2023
What the ISO 9001 doesn’t cover
Nothing. Everything is covered.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
3646e13c-d7dc-42b3-a7ed-07a5814cc080
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
80f895cd-7070-464a-98f1-307a7c616c2f
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sam@microlinkpc.com. Tell them what format you need. It will help if you say what assistive technology you use.