Skip to main content

Help us improve the Digital Marketplace - send your feedback

INSIGHT DIRECT (UK) LTD

Bespoke development for Applications, Data & AI

Insight AI delivers bespoke application, data, and AI solutions through flexible extended delivery teams, acting as a strategic partner to public sector organisations. Their model ensures scalability, agility, and cost-efficiency, enabling innovation, modernisation, and secure digital transformation while improving service delivery, optimising resources, and enhancing citizen outcomes.

Features

  • Scales from single developers to full departments fully-integrated with organisations.
  • Delivers capabilities across development, cloud, QA, data, AI, and mobile.
  • Provides strategy, science, machine learning, integration, management, and analytics expertise.
  • Hybrid model ensures continuous maintenance and improvement of bespoke applications.
  • Guides best practices, digital transformation, and value‑driven technology delivery.
  • Drives business outcomes through structured discovery, design, and delivery processes.
  • Governance and proven processes reduce delivery risks and ensure compliance.
  • Agile approach enabling rapid adaptation to changing requirement
  • Nearshore/onshore delivery model optimising resources and reducing costs.
  • Builds long‑term collaboration grounded in trust, alignment, and shared success.

Benefits

  • Scales teams from individuals to departments based on project complexity.
  • Hybrid delivery model ensures agility cultural alignment for public sector.
  • Nearshore economics reduce delivery costs without compromising service quality.
  • Governance and delivery frameworks minimise risks and maintain regulatory compliance.
  • Provides cross‑domain skills across development, cloud, data, AI, cybersecurity.
  • Agile methods and extended teams speed time‑to‑market for critical applications.
  • Managed services ensure ongoing optimisation and enhancement of bespoke systems.
  • Consultative approach aligns technology with organisational goals and sector priorities.
  • Delivers strategy, analytics, and AI innovation to strengthen data‑driven decisions.
  • Modernises systems to optimise resources and improve outcomes for citizens.

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at pstenderteam@insight.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 7 5 4 3 5 1 7 9 9 5 2 7 9 4

Contact

INSIGHT DIRECT (UK) LTD Public Sector Tender Team
Telephone: 0344 846 3333
Email: pstenderteam@insight.com

About your service

Service categories

Application Development and Deployment

Application development

  • Development languages, environments and tools
  • Software construction components
  • Business rules management

Modelling and architecture

  • Object Modelling Tools
  • Enterprise Architecture Tools
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
No
System requirements
No particular system requirements

User support

Email or online ticketing support
Yes
Support response times
Insight aims to provide prompt ticket responses based on agreed SLAs. For weekdays, initial replies are typically within 1–4 hours, ensuring issues are acknowledged quickly. Weekend support is available for critical incidents, though response times may vary depending on priority and contractual terms. For clients with 24-hour support agreements, Insight offers round-the-clock coverage, ensuring urgent tickets are addressed promptly regardless of time or day. While exact timings depend on the specific SLA, Insights governance model prioritises timely communication, escalation, and resolution to maintain service continuity and meet public sector expectations for reliability and responsiveness.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
N/A
Onsite support
Yes
Support levels
N/A
Support available to third parties
No
AI chatbot
No

Onboarding and offboarding

Getting started
Insight follows a structured onboarding process designed to ensure smooth integration for both customers and their dedicated delivery teams. The process begins with a Discovery Phase, where Insight collaborates with the client to understand objectives, technical environments, governance requirements, and success criteria. This information is captured in an Onboarding Manifest, which includes project scope, communication plans, and escalation paths.
Next, Insight assigns a dedicated resource or team, carefully selected based on skills, experience, and cultural alignment. These resources undergo a detailed induction covering client systems, security protocols, and working practices. Insight uses standardised templates and health checks to validate readiness and ensure compliance with contractual and regulatory requirements.
Documentation and artefacts are shared via secure platforms such as Microsoft Teams and client portals, ensuring accessibility and transparency. Regular onboarding reviews and checkpoints are conducted to monitor progress and address any gaps promptly.
This structured approach guarantees that customers receive a fully integrated team equipped with the right tools, knowledge, and governance, enabling rapid mobilisation and reducing delivery risks. Insights onboarding process prioritises clarity, collaboration, and continuity, setting the foundation for successful long-term partnerships.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
N/A
End-of-contract process
At the conclusion of a contract, Insight follows a structured and transparent handover process to ensure all applications and intellectual property (IP) are transferred securely and completely. This process begins with a handover plan, agreed upon with the client, detailing timelines, responsibilities, and deliverables. All source code, documentation, configuration files, and related artefacts are compiled and validated against contractual obligations.
Insight ensures that IP ownership is clearly transferred by delivering all assets in agreed formats, typically via secure repositories or encrypted file transfers. Comprehensive documentation, including architecture diagrams, deployment guides, and operational manuals, is provided to enable seamless continuity. Where applicable, Insight conducts knowledge transfer sessions with client teams, covering system functionality, maintenance procedures, and best practices.
For cloud-based or managed environments, Insight ensures credentials, access rights, and licences are handed over securely, with audit trails to confirm compliance. The process also includes final quality checks and sign-off from both parties to guarantee completeness and accuracy.
This structured approach minimises risk, ensures compliance, and empowers clients with full control over their applications and IP, supporting a smooth transition post-engagement.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
No
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
WCAG 2.2 AAA
API
No
Customisation available
No

Scaling

Independence of resources
Insight prevents customer impact from competing demands through dedicated resource models, ensuring teams are not shared across projects. The Insight Way Framework provides structured governance, SCRUM-certified delivery leads, and customer success managers for focused attention. Additionally, the Advance Platform manages resource allocation, tracks skills, and mitigates risks through proactive planning and audits, guaranteeing continuity and prioritisation for every client.

Analytics

Service usage metrics
Yes
Metrics types
Insight provides customers with clear, measurable service metrics to ensure transparency and performance accountability. Key metrics include delivery velocity, tracking sprint progress and feature completion; quality indicators, such as defect density and test coverage; and resource utilisation, ensuring optimal team efficiency. We also measure SLA compliance, including response and resolution times, and customer satisfaction scores gathered through regular feedback loops. Additional metrics cover on-time delivery, budget adherence, and change request turnaround. These metrics are reported through dashboards and periodic reviews, enabling clients to monitor progress, validate outcomes, and maintain confidence in service excellence and continuous improvement.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Degaussing
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can export their data through a user-friendly interface that offers multiple options for format selection. The system supports exporting in open formats such as CSV and ODF, alongside other formats including XML, JSON, Excel (XLSX), TXT, SQL, Parquet, Avro, YAML, and HTML. This flexibility ensures that users can easily access and utilize their data in a manner that suits their needs, whether for analysis, reporting, or integration with other systems.
Data export formats
  • CSV
  • ODF
Data import formats
  • CSV
  • ODF

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection between networks
Insight protects data between the buyer’s network and its own using secure, modern protocols. Connections are established over private networks or approved public sector networks, ensuring compliance with security standards. All data in transit is encrypted using TLS version 1.2 or above, and IPsec or TLS VPN gateways provide additional secure tunnelling. Legacy SSL and TLS versions below 1.2 are strictly prohibited, eliminating vulnerabilities from outdated encryption. Other measures include strong authentication, continuous monitoring, and adherence to industry best practices for secure communication. This layered approach guarantees confidentiality, integrity, and resilience for sensitive data exchanges.
Data protection within supplier network
IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Our service guarantees a minimum availability of 99.9% as part of our Service Level Agreement (SLA). This commitment ensures that our clients experience minimal disruption and can rely on our services for their critical operations. In instances where we fail to meet this guaranteed level of availability, we provide a refund to users based on the duration of the outage. Specifically, for each hour of downtime beyond the 99.9% threshold, clients are entitled to a credit against their future billing, proportional to the extent of the service interruption. This guarantees accountability and reinforces our commitment to delivering reliable and resilient services to our public sector clients.
Approach to resilience
Our service is designed with a multi-layered approach to resilience, ensuring continuous availability and minimal downtime. We utilise a robust data centre setup that includes geographically dispersed locations, allowing for redundancy and failover capabilities. Each data centre facility is equipped with redundant power supplies, cooling systems, and high-speed internet connections. This ensures that even in the event of a hardware failure or natural disaster, operations can seamlessly switch to a backup site.

Additionally, our infrastructure employs active-active configurations where applicable, providing real-time data replication and load balancing across multiple sites. Regular disaster recovery drills and maintenance checks are conducted to ensure systems are always prepared for unexpected events.

We also implement comprehensive monitoring tools to proactively identify and address potential issues before they impact service availability. Our approach to resilience is continuously reviewed and updated to incorporate the latest industry best practices and technological advancements. For detailed information about our data centre setup and specific resilience strategies, please contact us directly.
Outage reporting
Our service reports any outages through multiple channels to ensure transparency and timely communication. We provide a public dashboard that displays real-time status updates and historical outage reports, allowing users to monitor service availability. Additionally, we offer an API for integration with client systems, enabling automated tracking of service status and alerts. Users can also subscribe to email alerts that notify them immediately of any service disruptions or maintenance activities. This multi-faceted approach ensures that clients remain informed and can make informed decisions regarding their operations during outages.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Other user authentication
Insight enforces strong authentication measures to protect systems and data. All user access is controlled through role-based permissions and multi-factor authentication (MFA), ensuring identity verification beyond passwords. Authentication protocols include TLS 1.2 or higher for secure connections and integration with VPN gateways for remote access. Password policies mandate complexity, expiry, and encryption at rest and in transit. Legacy authentication methods are disabled to prevent vulnerabilities. Additionally, Insight uses centralised identity management with audit trails for compliance and monitoring. These measures align with public sector security standards, guaranteeing secure, verified access for all users across applications and infrastructure.
Access restrictions in management interfaces and support channels
Insight enforces strict access controls across all management interfaces and support channels to maintain security and compliance. Access is granted on a least privilege basis, ensuring users only have permissions necessary for their role. Multi-factor authentication (MFA) and role-based access control (RBAC) are mandatory for administrative interfaces. Support channels are secured through authenticated sessions, encrypted communications, and identity verification before any action is taken. Legacy protocols are disabled, and all activities are logged for audit and compliance purposes. These measures align with public sector security standards, preventing unauthorised access and safeguarding sensitive systems and data.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Insight operates under a comprehensive security governance framework aligned with ISO 27001, GDPR, and UK public sector standards. Our policies cover key areas such as access control, encryption, vulnerability management, secure development, and incident response. These policies are documented, reviewed regularly, and communicated to all employees through mandatory training and compliance programmes.
The reporting structure includes a Chief Information Security Officer (CISO) who oversees security governance, supported by dedicated security leads embedded within delivery teams. Regular audits, risk assessments, and penetration tests ensure adherence to policies, while automated monitoring tools track compliance in real time.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Our configuration and change management processes involve meticulous tracking of service components throughout their lifecycle using a centralised configuration management database (CMDB). Each component is assigned a unique identifier for easy tracking. Changes are evaluated for potential security impact through a structured change assessment process, which includes security reviews, risk assessments, and stakeholder consultations. This ensures that all modifications are documented, approved, and implemented with minimal disruption while maintaining compliance with security protocols and best practices throughout the service delivery.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Our vulnerability management process includes regular assessments of potential threats through continuous monitoring and threat intelligence feeds. We deploy patches within 24 hours of identifying a critical vulnerability and within 72 hours for high-risk vulnerabilities. We gather information about emerging threats from reputable sources such as the National Cyber Security Centre (NCSC), vendor notifications, and industry-specific advisories to ensure our services remain secure and compliant with best practices.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Our protective monitoring process involves continuous monitoring of system logs and network traffic to identify unusual patterns that may indicate potential compromises. Upon detecting a potential compromise, we initiate an incident response protocol, which includes containment, investigation, and remediation steps. Our response time for critical incidents is within 30 minutes, ensuring swift action to mitigate risks and safeguard sensitive data. Regular reviews and updates of our monitoring tools and processes are conducted to adapt to emerging threats, ensuring a proactive approach to security.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Our incident management process includes predefined workflows for common events, ensuring rapid response and resolution. Users can report incidents through a dedicated support portal, email, or phone, enabling quick logging and tracking. We provide incident reports detailing the nature of the incident, actions taken, and resolution outcomes. These reports are shared with affected users and relevant stakeholders to maintain transparency and facilitate continuous improvement. Our approach aligns with best practices to ensure a structured response that minimises disruption and enhances service reliability.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Atlas
ISO/IEC 27001 accreditation date
Sunday 13 April 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Atlas
ISO 9001 accreditation date
Tuesday 1 April 2025
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Be7ce590-de10-486e-8431-2e10891a8979
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Cd8b1a78-44c7-4bb0-84d6-59a7506f3bba
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at pstenderteam@insight.com. Tell them what format you need. It will help if you say what assistive technology you use.