Skip to main content

Help us improve the Digital Marketplace - send your feedback

ARVATO LIMITED

Process Intelligence - ArvatoConnect's Discovery Engine (ADE)

ADE is an AI-powered process intelligence platform designed to analyse and optimize business workflows. It collects operational data from enterprise systems, applies machine learning to identify inefficiencies, and provides actionable insights for automation and cost reduction. The service focuses on transparency, compliance, and measurable ROI for digital transformation initiatives.

Features

  • Continuously collects human-machine interactions without user disruption.
  • Real-time process mining and analytics
  • Translates daily digital tasks into actionable process insights.
  • Prebuilt dashboards deliver live operational visibility and insights.
  • Integration with ERP, CRM, and productivity tools
  • Compliance dashboards for GDPR and EU AI Act
  • AI pinpoints high‑value automation potential and calculates ROI.
  • Role-based access control and audit logging
  • Tracks improvements, measures impact, and supports ongoing refinement.
  • Detects process variants and compliance deviations across workflows.

Benefits

  • Automated End‑to‑End Data Capture
  • Provides instant visibility into workflows, bottlenecks, and performance metrics.
  • Discovers inefficiencies and compliance gaps across digital workflows automatically.
  • Identifies high-value automation tasks with ROI-based recommendations.
  • Offers tailored insights for individuals and teams to boost efficiency.
  • No interface is required, ADE is installed on users device.
  • Tracks implemented changes and measures impact for ongoing optimisation.
  • Delivers holistic insights across people, processes, and technology layers.
  • Enhances compliance with regulatory frameworks
  • Runs unobtrusively without manual input or workflow interruptions.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at richard.husband@arvatoconnect.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 5 5 9 6 9 7 8 4 0 2 5 6 9 3

Contact

ARVATO LIMITED Richard Husband
Telephone: 07867464428
Email: richard.husband@arvatoconnect.co.uk

About your service

Service categories

Application Development and Deployment

Analytics and business intelligence

  • Business Intelligence
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Hybrid cloud
Service constraints
Delivered primarily as public‑cloud SaaS with optional hybrid connectivity. Buyers must ensure lawful processing (GDPR), complete DPIAs where appropriate, and enforce SSO/MFA with role‑based access. Data capture focuses on interaction metadata; configure scopes, redaction, and residency (UK/EU) as required—which may extend timelines. Stable networks, whitelisted endpoints, and permissions are necessary. Native connectors exist (e.g., SAP Signavio, UiPath, Microsoft); non‑standard systems may need API work or lightweight agents.
System requirements
  • Windows 10+, macOS, or supported Linux distribution.
  • Dual-core CPU, 2.0 GHz or faster recommended.
  • Minimum 4 GB RAM; 8 GB recommended for performance.
  • SSO capability via supported identity providers (e.g., Azure AD).
  • Enable TLS 1.3+ and corporate firewall whitelisting.
  • SSO capability via supported identity providers (e.g., Azure AD).
  • Compatible with virtual desktops and hybrid cloud architectures.
  • Modern browser (Chrome, Edge, Firefox) for web access

User support

Email or online ticketing support
Yes
Support response times
Critical (P1): Initial response within 1 hour; resolution target 4–8 hours.
High (P2): Response within 4 hours; resolution within 1 business day.
Medium (P3): Response within 1 business day; resolution in 3–5 days.
Low (P4): Response within 2 business days; resolution in 5–10 days.

Under the standard SLA, support is available Monday–Friday, 08:00–18:00 UK time, excluding public holidays.

Enhanced Support option, which provides 24×7 coverage for P1 incidents (critical outages/security issues) comes at an additional cost.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
The Enhanced Support option is an add-on service that provides:

24×7×365 coverage for P1 (Critical) incidents instead of standard business hours.
Priority handling and faster escalation for major issues.
Dedicated Technical Account Manager (TAM) for proactive support and service reviews.
Optional proactive monitoring and quarterly health checks.
Custom SLAs for response and resolution times beyond the standard agreement.

This option is typically offered at an additional cost and is ideal for organisations requiring continuous availability and rapid incident response.
Support available to third parties
No

Onboarding and offboarding

Getting started
ADE offers a comprehensive online knowledge base through its Document360-powered portal. This includes:

Getting Started Guides: Step-by-step instructions for initial setup and navigation.
Deployment & Configuration Guides: Detailed technical documentation for installing and configuring the ADE Connect App.
Best Practices and FAQs: Covering compliance, security, and platform usage.
Release Notes and Changelog: Keeping users updated on new features and improvements.

We can also provide:

Online Training Resources: Through its Knowledge Base and Academy section, offering tutorials and best practices.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
ADE ensures that customers can securely extract their data at the end of a contract through a structured and compliant process. Organisations have multiple options, including using the Integrated Database add-on for exporting all captured data in structured formats such as CSV, Excel, or JSON, or leveraging API connectors for automated synchronisation with internal systems. For advanced requirements, clients may implement Robotic Process Automation (RPA) to transfer data from ADE dashboards into their own analytics platforms.
Before extraction, ADE applies robust anonymisation and masking techniques to protect sensitive information and maintain compliance with GDPR and SOC 2 standards. This includes encryption, hashing, and RegEx-based detection of personal identifiers. Once data is successfully transferred, ADE follows secure destruction protocols aligned with NIST SP 800-88 Rev.1, ensuring cryptographic erasure and logical purge of all residual data. AWS-certified physical media destruction is used for hardware-level compliance.
Customers are responsible for requesting data extraction prior to contract termination and confirming preferred formats. ADE provides full support throughout the process, ensuring transparency, security, and compliance. This approach guarantees that organisations retain control of their data while meeting regulatory and contractual obligations.
End-of-contract process
At the end of a KYP.ai contract, a secure and transparent offboarding process ensures customers retain full control of their data while meeting compliance obligations. Organisations can request data extraction prior to termination, choosing from multiple options such as structured exports in CSV, Excel, or JSON formats, or automated transfer via API connectors. For advanced needs, Robotic Process Automation (RPA) can be used to migrate data from KYP.ai dashboards into internal analytics platforms.
Before any data is handed over, KYP.ai applies strict anonymisation and masking protocols to protect sensitive information and comply with GDPR and SOC 2 standards. This includes encryption, hashing, and pattern-based detection of personal identifiers. Once extraction is complete, KYP.ai performs secure data destruction following NIST SP 800-88 Rev.1 guidelines, which include cryptographic erasure and logical purge of all residual data. For hardware-level compliance, AWS-certified physical media destruction is used.
Customers are responsible for confirming the scope and preferred format of data extraction. Throughout the process, KYP.ai provides full support and documentation to ensure clarity, security, and compliance. This approach guarantees that organisations can transition smoothly while safeguarding data integrity and meeting regulatory requirements.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
ADE uses Document360 as its primary platform for hosting onboarding and offboarding documentation.

This portal provides web-based articles, FAQs, and step-by-step guides for:

Onboarding: Account setup, deployment instructions, and initial configuration.

Offboarding: Data removal, compliance steps, and deactivation processes.

Access is granted to customers and prospects (subject to NDA) and is integrated with KYP.ai’s website for quick navigation.

Detailed technical documentation is available in PDF format, including:
KYP.ai_Architecture - 25Q1 v1.0 – Covers platform architecture and deployment models (cloud, hybrid, on-premise).
KYP.ai_Deployment - 25Q1 v1.0 – Provides installation methods for the KYP.ai Connect App (manual, Intune, SCCM, silent mode).

Compliance and security documentation, such as KYP.ai SOC 2 Type 2 Report 06.30.2025, outlines commitments and processes for onboarding/offboarding in line with GDPR and SOC 2 standards.

Accessibility Features:

Cloud-based access: Documentation is hosted online, ensuring availability from any location.
Role-based permissions: Access is controlled to protect sensitive information, with restrictions based on user roles.
Multiple formats:

PDFs for architecture, deployment, and compliance.
PowerPoint (.pptx) for roadmap and pilot overview presentations.
Web articles for quick reference and FAQs.

Integration with HR and IT systems: For internal onboarding/offboarding, documentation links are embedded in workflow tools and shared via Teams and email.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Linux or Unix
  • MacOS
  • Windows
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Yes, ADE provides a service interface in the form of a secure web portal. This is where users access dashboards, analytics, and insights. The interface is browser-based and supports major browsers (Chrome, Edge, Firefox). It also includes role-based access controls, SSO integration, and conversational AI features for querying operational data.
Accessibility standards
None or don’t know
Description of accessibility
ADE is accessed via a secure, browser-based portal compatible with Chrome, Edge, and Firefox. The interface uses responsive design for different screen sizes and supports role-based access controls, SSO, and MFA for secure login. Dashboards and conversational AI features are structured for intuitive navigation and clear data visualisation. Mobile browsers allow read-only access to insights, though data capture remains desktop-only. Accessibility features include keyboard navigation, high-contrast modes, and screen-reader compatibility.
Accessibility testing
We’re committed to making our service usable by as many people as possible and to meeting UK public‑sector accessibility regulations.

We design for perceivable, operable, understandable and robust content, including keyboard access, screen‑reader compatibility (JAWS, NVDA, VoiceOver), sufficient colour contrast, and responsive layouts.
API
Yes
What users can and can't do using the API
ADE exposes a REST API for integration and data automation. It offers:
Projects: list, retrieve, create, update, delete projects
Project Analytics: fetch analytics/statistics for specific projects
Activities & Phases: manage project activities and phases programmatically
Users: retrieve and manage project user assignments
Post-its: add, update, delete post-it notes within activities
REST hooks: configure webhooks for event-driven automation
BIM endpoints: upload and manage BIM models related to projects
Rate limiting: enforced per user token, HTTP 429 responses for excess requests.

This API enables integration with external systems and automation pipelines, supporting scalable, developer-driven workflows.

Users can extract process data, push configuration updates, and integrate dashboards - Integration Database. They cannot modify core data and core AI models or access internal system logs.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
ADE can be customized in several ways:

Dashboards & Reports: Configure KPIs, filters, and views to match organizational needs.
Data Capture Scope: Define which applications, processes, or user groups are monitored.
Integrations: Connect with ERP, CRM, RPA tools via APIs or connectors.
Role-Based Access: Tailor permissions and visibility for different user roles.
Automation Recommendations: Adjust prioritization logic and ROI thresholds.
Conversational AI: Customize query responses and integrate with internal knowledge bases.

Scaling

Independence of resources
ADE is designed as a scalable, cloud‑based, multi‑tenant platform that prevents one customer’s usage (“noisy neighbour's”) from impacting another’s performance.

ADE continuously collects and processes data across user machines and cloud infrastructure, distributing workloads to avoid bottlenecks and maintain responsiveness even under heavy load.

The platform provides real‑time dashboards and insights, which depend on scalable compute and storage layers capable of expanding with demand to sustain performance for all tenants.

Industry‑standard patterns for multi‑tenant AI systems emphasise tenant isolation, scalable resource allocation, and predictable performance, ensuring one organisation’s workload cannot degrade another’s service quality.

Analytics

Service usage metrics
Yes
Metrics types
ADE delivers detailed, real‑time usage and operational metrics across people, processes, and technology.

ADE explicitly includes Tool / App Usage Tracking as a platform capability. This confirms that the platform records detailed usage insights for applications and digital interactions.

ADE continuously captures digital interaction data such as; what applications users use, how long they interact with them, sequence of activities, process steps and workflows. The platform also provides hardware and software metrics, which contribute to usage monitoring.

ADE has dashboards that expose usage, productivity patterns, process variants, and operational efficiency.
Reporting types
Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
KYP.ai

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
No
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
Appropriately permissioned users can export log and process data via Secure Remote Desktop connection to the platform.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
Private network or public sector network
Data protection within supplier network
Other
Other protection within supplier network
ADE protects data inside a customer’s own network through a combination of local processing, strict data‑collection controls, encryption, and customer‑defined privacy boundaries.

Availability and resilience

Guaranteed availability
ADE will be available to Customer for normal use no less than 99.5% of the Scheduled Uptime.

Calculation: a. (Actual Uptime / Scheduled Uptime) * 100 = Percentage Uptime (as calculated by rounding to the second decimal point)
Approach to resilience
ADE is delivered as a cloud‑hosted SaaS with data stored and processed in customer‑agreed regions, supporting fault isolation and regional deployment choices. The KYP Connect App performs local pre-processing on user devices and, if connectivity is interrupted, securely buffers data in an embedded store and forwards it once the connection is restored—reducing dependency on constant network availability and preventing data loss during transient outages. All data is encrypted at rest and in transit using strong cryptography (e.g., AWS KMS for key management)

Operationally, ADE provides continuous collection and real‑time dashboards, which implies elastic, scalable ingestion and analytics to sustain service under load. For organisations requiring full sovereignty, an on‑premises option keeps processing within the customer’s environment.

Datacentre / Hosting Resilience: Specific details (e.g., multi‑AZ/region topology, backup cadence, RTO/RPO, DR test frequency) are not published publicly. These artefacts—including architecture diagrams and BC/DR procedures—are available on request.
Outage reporting
As a SaaS provider operating in customer‑selected cloud regions, incidents would typically be communicated through standard vendor channels such as support, account management, or agreed escalation paths. Detailed outage‑communication processes—including notification channels, severity classifications, and reporting timelines—are available on request from ADE as they are not included in the publicly available Security & Compliance documentation.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Other user authentication
Microsoft Account (SSO) Authentication
Access restrictions in management interfaces and support channels
ADE restricts access to management interfaces and support channels through its Unified Login system, requiring authentication via Microsoft SSO or an approved‑domain username/password account. Registration is limited to whitelisted email domains, preventing unauthorised access. Permissions across administrative areas are controlled using role‑based access control (RBAC), ensuring users only access data and functions relevant to their responsibilities. Access to some systems requires additional manual approval after registration, providing a further safeguard. The Support Portal also requires authenticated access, ensuring only authorised customer personnel can submit or view support cases.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Description of management access authentication
Microsoft Account (SSO) Authentication

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
ADE provides a detailed overview of its security and compliance practices through its Security & Compliance FAQ.

ADE has continuous alignment with EU GDPR requirements. This includes applying all new regulatory updates across both the organisation and product. This Includes:
Data protection by design and by default
Compliance reviews and external GDPR audits
Use of EU Standard Contractual Clauses (SCCs) for data transfers

Administrators have complete control over which applications are monitored, this supports data minimisation, a core GDPR principle.

ADE uses strong encryption to protect customer data; This ensures confidentiality throughout data collection, transmission, and storage.

ADE provides clear data‑handling rules:
SaaS data stored in customer‑agreed regions
Local processing on devices
Encrypted temporary local buffering
Customers can also choose on‑premises processing.

ADE undergoes regular external GDPR audits by specialist law firms. This provides independent assurance of compliance and risk control maturity.

Our process intelligence security guide highlights strong access governance. Controls cover:
Access rights
Export permissions
Administrative privileges

For analytics, KYP.ai uses: Pseudonymisation, Data masking, Tokenisation. These methods reduce exposure risks while enabling analysis.

ADE maintains internal security processes that include:
The ability to enable logs reviewing collected data
Internal investigations for security-related incidents.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
ADE operates a structured release/change lifecycle with Release Notes, Release Guides, and a Changelog for updates and fixes, ensuring controlled adoption and configuration changes. Administrators govern endpoint configuration via the KYP Connect App—defining monitored applications (Productive/Neutral/Private) to enforce data‑minimisation and prevent unintended collection. Backup location, frequency, and retention are customer‑configurable through platform settings. Security incidents follow an immediate investigation and notification process to affected apps. Detailed internal CM/Change procedures (ITIL mappings, approvals, RACI) are available on request.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
ADE does not publicly document a formal vulnerability‑management programme, patch‑deployment timelines, or threat‑intelligence sources. However, our Security & Compliance FAQ has continuous GDPR‑aligned reviews and regular external audits, which support ongoing identification of security risks. The Information Security Team also immediately investigates incidents, indicating an established process for assessing and responding to potential threats. Encryption, strict data‑collection controls and region‑based hosting further mitigate exposure. Full vulnerability‑management, patching SLAs, and threat‑intelligence processes are available on request.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
ADE provides protective monitoring through continuous GDPR‑aligned compliance reviews and regular external GDPR audits, ensuring ongoing oversight of security and privacy controls. Our Information Security Team immediately investigates any incident and informs affected customers, providing active monitoring and rapid response. Administrators can optionally enable endpoint‑level data logs in the KYP Connect App to support customer‑side monitoring and auditability. While we does not publicly map controls to specific protective‑monitoring standards, detailed monitoring procedures and framework mappings are available on request.
Incident management type
Supplier-defined controls
Incident management approach
ADE operates a documented incident process: our Information Security Team immediately investigates every incident and informs affected customers of the type and extent of any impact. ADE also undertakes regular external GDPR audits to provide independent oversight of security and incident‑handling practices.

How users report incidents: Customers raise issues via our Support Portal.

How we provide incident reports: Affected customers receive direct notifications describing what happened and any data affected; further procedural detail is available on request.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Our ADE free trial provides full exploratory access to the platform, enabling users to view real‑time productivity insights, understand 360° operational visibility, and assess improvement opportunities with no obligations or restrictions. It is designed for unrestricted evaluation of ADE's capabilities. Our general trial is 1 month.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Wednesday 7 September 2022
What the ISO/IEC 27001 doesn’t cover
While it is not practicable to list exclusions in isolation, our ISO 27001 certification supports all contracted services to ArvatoConnect customers, including contact centre, back-office and IT services.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI
ISO 9001 accreditation date
Monday 16 January 2023
What the ISO 9001 doesn’t cover
While it is not practicable to list exclusions in isolation, our ISO 9001 certification supports business process outsourcing, delivering a comprehensive range of front and back office services. This includes customer experience services and administrative services.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Fbb5c636-5561-4d78-b819-3360c25ffe07
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
A774e5a5-9ad4-4cbf-a7a3-e47ea2c0ef05
Other security certifications
Yes
Any other security certifications
  • Tisax
  • ISO 20000-1:2018

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at richard.husband@arvatoconnect.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.