Process Intelligence - ArvatoConnect's Discovery Engine (ADE)
ADE is an AI-powered process intelligence platform designed to analyse and optimize business workflows. It collects operational data from enterprise systems, applies machine learning to identify inefficiencies, and provides actionable insights for automation and cost reduction. The service focuses on transparency, compliance, and measurable ROI for digital transformation initiatives.
Features
- Continuously collects human-machine interactions without user disruption.
- Real-time process mining and analytics
- Translates daily digital tasks into actionable process insights.
- Prebuilt dashboards deliver live operational visibility and insights.
- Integration with ERP, CRM, and productivity tools
- Compliance dashboards for GDPR and EU AI Act
- AI pinpoints high‑value automation potential and calculates ROI.
- Role-based access control and audit logging
- Tracks improvements, measures impact, and supports ongoing refinement.
- Detects process variants and compliance deviations across workflows.
Benefits
- Automated End‑to‑End Data Capture
- Provides instant visibility into workflows, bottlenecks, and performance metrics.
- Discovers inefficiencies and compliance gaps across digital workflows automatically.
- Identifies high-value automation tasks with ROI-based recommendations.
- Offers tailored insights for individuals and teams to boost efficiency.
- No interface is required, ADE is installed on users device.
- Tracks implemented changes and measures impact for ongoing optimisation.
- Delivers holistic insights across people, processes, and technology layers.
- Enhances compliance with regulatory frameworks
- Runs unobtrusively without manual input or workflow interruptions.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 5 5 9 6 9 7 8 4 0 2 5 6 9 3
Contact
ARVATO LIMITED
Richard Husband
Telephone: 07867464428
Email: richard.husband@arvatoconnect.co.uk
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
- Delivered primarily as public‑cloud SaaS with optional hybrid connectivity. Buyers must ensure lawful processing (GDPR), complete DPIAs where appropriate, and enforce SSO/MFA with role‑based access. Data capture focuses on interaction metadata; configure scopes, redaction, and residency (UK/EU) as required—which may extend timelines. Stable networks, whitelisted endpoints, and permissions are necessary. Native connectors exist (e.g., SAP Signavio, UiPath, Microsoft); non‑standard systems may need API work or lightweight agents.
- System requirements
-
- Windows 10+, macOS, or supported Linux distribution.
- Dual-core CPU, 2.0 GHz or faster recommended.
- Minimum 4 GB RAM; 8 GB recommended for performance.
- SSO capability via supported identity providers (e.g., Azure AD).
- Enable TLS 1.3+ and corporate firewall whitelisting.
- SSO capability via supported identity providers (e.g., Azure AD).
- Compatible with virtual desktops and hybrid cloud architectures.
- Modern browser (Chrome, Edge, Firefox) for web access
User support
- Email or online ticketing support
- Yes
- Support response times
-
Critical (P1): Initial response within 1 hour; resolution target 4–8 hours.
High (P2): Response within 4 hours; resolution within 1 business day.
Medium (P3): Response within 1 business day; resolution in 3–5 days.
Low (P4): Response within 2 business days; resolution in 5–10 days.
Under the standard SLA, support is available Monday–Friday, 08:00–18:00 UK time, excluding public holidays.
Enhanced Support option, which provides 24×7 coverage for P1 incidents (critical outages/security issues) comes at an additional cost. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
The Enhanced Support option is an add-on service that provides:
24×7×365 coverage for P1 (Critical) incidents instead of standard business hours.
Priority handling and faster escalation for major issues.
Dedicated Technical Account Manager (TAM) for proactive support and service reviews.
Optional proactive monitoring and quarterly health checks.
Custom SLAs for response and resolution times beyond the standard agreement.
This option is typically offered at an additional cost and is ideal for organisations requiring continuous availability and rapid incident response. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
ADE offers a comprehensive online knowledge base through its Document360-powered portal. This includes:
Getting Started Guides: Step-by-step instructions for initial setup and navigation.
Deployment & Configuration Guides: Detailed technical documentation for installing and configuring the ADE Connect App.
Best Practices and FAQs: Covering compliance, security, and platform usage.
Release Notes and Changelog: Keeping users updated on new features and improvements.
We can also provide:
Online Training Resources: Through its Knowledge Base and Academy section, offering tutorials and best practices. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
ADE ensures that customers can securely extract their data at the end of a contract through a structured and compliant process. Organisations have multiple options, including using the Integrated Database add-on for exporting all captured data in structured formats such as CSV, Excel, or JSON, or leveraging API connectors for automated synchronisation with internal systems. For advanced requirements, clients may implement Robotic Process Automation (RPA) to transfer data from ADE dashboards into their own analytics platforms.
Before extraction, ADE applies robust anonymisation and masking techniques to protect sensitive information and maintain compliance with GDPR and SOC 2 standards. This includes encryption, hashing, and RegEx-based detection of personal identifiers. Once data is successfully transferred, ADE follows secure destruction protocols aligned with NIST SP 800-88 Rev.1, ensuring cryptographic erasure and logical purge of all residual data. AWS-certified physical media destruction is used for hardware-level compliance.
Customers are responsible for requesting data extraction prior to contract termination and confirming preferred formats. ADE provides full support throughout the process, ensuring transparency, security, and compliance. This approach guarantees that organisations retain control of their data while meeting regulatory and contractual obligations. - End-of-contract process
-
At the end of a KYP.ai contract, a secure and transparent offboarding process ensures customers retain full control of their data while meeting compliance obligations. Organisations can request data extraction prior to termination, choosing from multiple options such as structured exports in CSV, Excel, or JSON formats, or automated transfer via API connectors. For advanced needs, Robotic Process Automation (RPA) can be used to migrate data from KYP.ai dashboards into internal analytics platforms.
Before any data is handed over, KYP.ai applies strict anonymisation and masking protocols to protect sensitive information and comply with GDPR and SOC 2 standards. This includes encryption, hashing, and pattern-based detection of personal identifiers. Once extraction is complete, KYP.ai performs secure data destruction following NIST SP 800-88 Rev.1 guidelines, which include cryptographic erasure and logical purge of all residual data. For hardware-level compliance, AWS-certified physical media destruction is used.
Customers are responsible for confirming the scope and preferred format of data extraction. Throughout the process, KYP.ai provides full support and documentation to ensure clarity, security, and compliance. This approach guarantees that organisations can transition smoothly while safeguarding data integrity and meeting regulatory requirements. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
ADE uses Document360 as its primary platform for hosting onboarding and offboarding documentation.
This portal provides web-based articles, FAQs, and step-by-step guides for:
Onboarding: Account setup, deployment instructions, and initial configuration.
Offboarding: Data removal, compliance steps, and deactivation processes.
Access is granted to customers and prospects (subject to NDA) and is integrated with KYP.ai’s website for quick navigation.
Detailed technical documentation is available in PDF format, including:
KYP.ai_Architecture - 25Q1 v1.0 – Covers platform architecture and deployment models (cloud, hybrid, on-premise).
KYP.ai_Deployment - 25Q1 v1.0 – Provides installation methods for the KYP.ai Connect App (manual, Intune, SCCM, silent mode).
Compliance and security documentation, such as KYP.ai SOC 2 Type 2 Report 06.30.2025, outlines commitments and processes for onboarding/offboarding in line with GDPR and SOC 2 standards.
Accessibility Features:
Cloud-based access: Documentation is hosted online, ensuring availability from any location.
Role-based permissions: Access is controlled to protect sensitive information, with restrictions based on user roles.
Multiple formats:
PDFs for architecture, deployment, and compliance.
PowerPoint (.pptx) for roadmap and pilot overview presentations.
Web articles for quick reference and FAQs.
Integration with HR and IT systems: For internal onboarding/offboarding, documentation links are embedded in workflow tools and shared via Teams and email.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Yes, ADE provides a service interface in the form of a secure web portal. This is where users access dashboards, analytics, and insights. The interface is browser-based and supports major browsers (Chrome, Edge, Firefox). It also includes role-based access controls, SSO integration, and conversational AI features for querying operational data.
- Accessibility standards
- None or don’t know
- Description of accessibility
- ADE is accessed via a secure, browser-based portal compatible with Chrome, Edge, and Firefox. The interface uses responsive design for different screen sizes and supports role-based access controls, SSO, and MFA for secure login. Dashboards and conversational AI features are structured for intuitive navigation and clear data visualisation. Mobile browsers allow read-only access to insights, though data capture remains desktop-only. Accessibility features include keyboard navigation, high-contrast modes, and screen-reader compatibility.
- Accessibility testing
-
We’re committed to making our service usable by as many people as possible and to meeting UK public‑sector accessibility regulations.
We design for perceivable, operable, understandable and robust content, including keyboard access, screen‑reader compatibility (JAWS, NVDA, VoiceOver), sufficient colour contrast, and responsive layouts. - API
- Yes
- What users can and can't do using the API
-
ADE exposes a REST API for integration and data automation. It offers:
Projects: list, retrieve, create, update, delete projects
Project Analytics: fetch analytics/statistics for specific projects
Activities & Phases: manage project activities and phases programmatically
Users: retrieve and manage project user assignments
Post-its: add, update, delete post-it notes within activities
REST hooks: configure webhooks for event-driven automation
BIM endpoints: upload and manage BIM models related to projects
Rate limiting: enforced per user token, HTTP 429 responses for excess requests.
This API enables integration with external systems and automation pipelines, supporting scalable, developer-driven workflows.
Users can extract process data, push configuration updates, and integrate dashboards - Integration Database. They cannot modify core data and core AI models or access internal system logs. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
ADE can be customized in several ways:
Dashboards & Reports: Configure KPIs, filters, and views to match organizational needs.
Data Capture Scope: Define which applications, processes, or user groups are monitored.
Integrations: Connect with ERP, CRM, RPA tools via APIs or connectors.
Role-Based Access: Tailor permissions and visibility for different user roles.
Automation Recommendations: Adjust prioritization logic and ROI thresholds.
Conversational AI: Customize query responses and integrate with internal knowledge bases.
Scaling
- Independence of resources
-
ADE is designed as a scalable, cloud‑based, multi‑tenant platform that prevents one customer’s usage (“noisy neighbour's”) from impacting another’s performance.
ADE continuously collects and processes data across user machines and cloud infrastructure, distributing workloads to avoid bottlenecks and maintain responsiveness even under heavy load.
The platform provides real‑time dashboards and insights, which depend on scalable compute and storage layers capable of expanding with demand to sustain performance for all tenants.
Industry‑standard patterns for multi‑tenant AI systems emphasise tenant isolation, scalable resource allocation, and predictable performance, ensuring one organisation’s workload cannot degrade another’s service quality.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
ADE delivers detailed, real‑time usage and operational metrics across people, processes, and technology.
ADE explicitly includes Tool / App Usage Tracking as a platform capability. This confirms that the platform records detailed usage insights for applications and digital interactions.
ADE continuously captures digital interaction data such as; what applications users use, how long they interact with them, sequence of activities, process steps and workflows. The platform also provides hardware and software metrics, which contribute to usage monitoring.
ADE has dashboards that expose usage, productivity patterns, process variants, and operational efficiency. - Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- KYP.ai
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Appropriately permissioned users can export log and process data via Secure Remote Desktop connection to the platform.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- Private network or public sector network
- Data protection within supplier network
- Other
- Other protection within supplier network
- ADE protects data inside a customer’s own network through a combination of local processing, strict data‑collection controls, encryption, and customer‑defined privacy boundaries.
Availability and resilience
- Guaranteed availability
-
ADE will be available to Customer for normal use no less than 99.5% of the Scheduled Uptime.
Calculation: a. (Actual Uptime / Scheduled Uptime) * 100 = Percentage Uptime (as calculated by rounding to the second decimal point) - Approach to resilience
-
ADE is delivered as a cloud‑hosted SaaS with data stored and processed in customer‑agreed regions, supporting fault isolation and regional deployment choices. The KYP Connect App performs local pre-processing on user devices and, if connectivity is interrupted, securely buffers data in an embedded store and forwards it once the connection is restored—reducing dependency on constant network availability and preventing data loss during transient outages. All data is encrypted at rest and in transit using strong cryptography (e.g., AWS KMS for key management)
Operationally, ADE provides continuous collection and real‑time dashboards, which implies elastic, scalable ingestion and analytics to sustain service under load. For organisations requiring full sovereignty, an on‑premises option keeps processing within the customer’s environment.
Datacentre / Hosting Resilience: Specific details (e.g., multi‑AZ/region topology, backup cadence, RTO/RPO, DR test frequency) are not published publicly. These artefacts—including architecture diagrams and BC/DR procedures—are available on request. - Outage reporting
- As a SaaS provider operating in customer‑selected cloud regions, incidents would typically be communicated through standard vendor channels such as support, account management, or agreed escalation paths. Detailed outage‑communication processes—including notification channels, severity classifications, and reporting timelines—are available on request from ADE as they are not included in the publicly available Security & Compliance documentation.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- Microsoft Account (SSO) Authentication
- Access restrictions in management interfaces and support channels
- ADE restricts access to management interfaces and support channels through its Unified Login system, requiring authentication via Microsoft SSO or an approved‑domain username/password account. Registration is limited to whitelisted email domains, preventing unauthorised access. Permissions across administrative areas are controlled using role‑based access control (RBAC), ensuring users only access data and functions relevant to their responsibilities. Access to some systems requires additional manual approval after registration, providing a further safeguard. The Support Portal also requires authenticated access, ensuring only authorised customer personnel can submit or view support cases.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- Microsoft Account (SSO) Authentication
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
ADE provides a detailed overview of its security and compliance practices through its Security & Compliance FAQ.
ADE has continuous alignment with EU GDPR requirements. This includes applying all new regulatory updates across both the organisation and product. This Includes:
Data protection by design and by default
Compliance reviews and external GDPR audits
Use of EU Standard Contractual Clauses (SCCs) for data transfers
Administrators have complete control over which applications are monitored, this supports data minimisation, a core GDPR principle.
ADE uses strong encryption to protect customer data; This ensures confidentiality throughout data collection, transmission, and storage.
ADE provides clear data‑handling rules:
SaaS data stored in customer‑agreed regions
Local processing on devices
Encrypted temporary local buffering
Customers can also choose on‑premises processing.
ADE undergoes regular external GDPR audits by specialist law firms. This provides independent assurance of compliance and risk control maturity.
Our process intelligence security guide highlights strong access governance. Controls cover:
Access rights
Export permissions
Administrative privileges
For analytics, KYP.ai uses: Pseudonymisation, Data masking, Tokenisation. These methods reduce exposure risks while enabling analysis.
ADE maintains internal security processes that include:
The ability to enable logs reviewing collected data
Internal investigations for security-related incidents. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- ADE operates a structured release/change lifecycle with Release Notes, Release Guides, and a Changelog for updates and fixes, ensuring controlled adoption and configuration changes. Administrators govern endpoint configuration via the KYP Connect App—defining monitored applications (Productive/Neutral/Private) to enforce data‑minimisation and prevent unintended collection. Backup location, frequency, and retention are customer‑configurable through platform settings. Security incidents follow an immediate investigation and notification process to affected apps. Detailed internal CM/Change procedures (ITIL mappings, approvals, RACI) are available on request.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- ADE does not publicly document a formal vulnerability‑management programme, patch‑deployment timelines, or threat‑intelligence sources. However, our Security & Compliance FAQ has continuous GDPR‑aligned reviews and regular external audits, which support ongoing identification of security risks. The Information Security Team also immediately investigates incidents, indicating an established process for assessing and responding to potential threats. Encryption, strict data‑collection controls and region‑based hosting further mitigate exposure. Full vulnerability‑management, patching SLAs, and threat‑intelligence processes are available on request.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- ADE provides protective monitoring through continuous GDPR‑aligned compliance reviews and regular external GDPR audits, ensuring ongoing oversight of security and privacy controls. Our Information Security Team immediately investigates any incident and informs affected customers, providing active monitoring and rapid response. Administrators can optionally enable endpoint‑level data logs in the KYP Connect App to support customer‑side monitoring and auditability. While we does not publicly map controls to specific protective‑monitoring standards, detailed monitoring procedures and framework mappings are available on request.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
ADE operates a documented incident process: our Information Security Team immediately investigates every incident and informs affected customers of the type and extent of any impact. ADE also undertakes regular external GDPR audits to provide independent oversight of security and incident‑handling practices.
How users report incidents: Customers raise issues via our Support Portal.
How we provide incident reports: Affected customers receive direct notifications describing what happened and any data affected; further procedural detail is available on request. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Our ADE free trial provides full exploratory access to the platform, enabling users to view real‑time productivity insights, understand 360° operational visibility, and assess improvement opportunities with no obligations or restrictions. It is designed for unrestricted evaluation of ADE's capabilities. Our general trial is 1 month.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Wednesday 7 September 2022
- What the ISO/IEC 27001 doesn’t cover
- While it is not practicable to list exclusions in isolation, our ISO 27001 certification supports all contracted services to ArvatoConnect customers, including contact centre, back-office and IT services.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Monday 16 January 2023
- What the ISO 9001 doesn’t cover
- While it is not practicable to list exclusions in isolation, our ISO 9001 certification supports business process outsourcing, delivering a comprehensive range of front and back office services. This includes customer experience services and administrative services.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Fbb5c636-5561-4d78-b819-3360c25ffe07
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- A774e5a5-9ad4-4cbf-a7a3-e47ea2c0ef05
- Other security certifications
- Yes
- Any other security certifications
-
- Tisax
- ISO 20000-1:2018
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
-