Skip to main content

Help us improve the Digital Marketplace - send your feedback

North27 Limited

Byte

Byte is a cloud-based cashless catering and meal management platform for schools. Parents and pupils use mobile and web apps for registration, online top-ups, balance tracking and pre-ordering. Staff use web tools for menu setup, kitchen workflows and reporting, plus an EPOS/till app with offline mode and backup web EPOS.

Features

  • pre-ordering
  • top-ups
  • Balances
  • EPOS
  • Offline-mode
  • Reporting
  • Menus
  • Allergens
  • Permissions
  • Integrations

Benefits

  • Faster-service
  • Shorter-queues
  • Fewer-errors
  • Better-compliance
  • Reduced-cash
  • Higher-uptake
  • Improved-insights
  • Easier-admin
  • Reliable-operations
  • Happier-users

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at kate.fox@north27.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 8 7 4 4 2 3 0 4 9 2 2 4 5 9

Contact

North27 Limited Kate Fox
Telephone: 07974179058
Email: kate.fox@north27.co.uk

About your service

Service categories

Applications

Production and operations

  • Other operations

Service industry and public sector operations

  • Education
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Byte is a standalone cashless catering platform that can integrate with school systems such as SIMS/Arbor MIS, iSAMS and payment providers. It can also integrate with North27 Fusion for identity, sync and automation where required. It does not require ParentPay/ArborPay to operate.
Cloud deployment model
Public cloud
Service constraints
Byte is delivered as a cloud-hosted SaaS and normally requires an internet connection for administration, reporting, payments and synchronisation. Service point operation can continue during temporary connectivity issues using the EPOS offline mode, with transactions queued and synchronised when connectivity returns; a backup web EPOS option is available. Integrations with MIS and directory systems depend on customer data quality and access to required APIs. Online payments depend on third-party payment services and customer network policies (for example firewall allow-listing). Hardware peripherals (if used) must meet supported specifications and be maintained in line with vendor guidance.
System requirements
  • Modern-browser
  • Internet-access
  • IOS/Anroid device
  • Email-account
  • Supported EPOS hardware
  • School MIS access
  • Barcode/QR scanner
  • Reciept printer
  • Card terminal

User support

Email or online ticketing support
Yes
Support response times
“We acknowledge support tickets within 1 business day (priority incidents faster, typically within 1 hour for critical issues during business hours).”
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We have not yet carried out formal user testing of our web chat with assistive-technology users. We aim to ensure support remains accessible by providing alternative channels (Freshdesk email/ticketing and phone support) and by testing key chat journeys (starting a chat, sending messages, file links) using standard browser accessibility tools (keyboard-only navigation, screen reader checks where available).
Onsite support
Yes
Support levels
Support levels are:

Standard Support (included): business-hours support with ticketing/email and phone; onboarding guidance and access to documentation.

Enhanced Support (optional, additional cost): faster response targets, scheduled check-ins, and additional onboarding/training sessions.

Out-of-hours incident support (optional, additional cost): for critical incidents only, agreed per customer.

Support costs depend on organisation size, modules, and required service hours, and are provided in the Pricing Document. A named Technical Account Manager can be provided as part of Enhanced Support (or assigned Cloud Support Engineer where required for integration/onboarding work).
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
We help users get started through a guided onboarding process, including initial setup and configuration, data import/integration support where needed, and role-based training for administrators, catering teams and school staff. Training can be delivered online and onsite where required. We provide user documentation, plus ongoing support through ticketing/email and phone.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Byte provides this detail as an export.
End-of-contract process
At the end of the contract we agree an exit plan and timetable with the customer. We provide an export of the customer’s data and reports in standard formats (for example CSV/Excel) and support validation during the transition. Service access continues until the agreed end date. After contract end, we securely delete customer data in line with agreed retention periods and provide confirmation on request.

Data export and standard offboarding support are included in the contract price. Additional costs may apply for bespoke exports, accelerated timescales, complex migration support, or onsite assistance, where requested.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Mobile (iOS/Android) is designed for parents/pupils - registration, top-ups, balance checking, pre-ordering and notifications. Desktop/browser access provides the full admin and catering staff functionality - configuration, menu and pricing setup, kitchen workflows, reporting and exports, plus back-office management. EPOS/till operation is provided through the dedicated till application (and backup web EPOS where enabled).
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Byte is accessed through role-based interfaces. Parents and pupils use mobile apps and a web portal for registration, online payments, balance management, pre-ordering and notifications. School and catering staff use secure web dashboards for user management, menus and pricing, allergen/dietary settings, kitchen workflows, reporting and exports. Point-of-service transactions are handled through the Byte EPOS/till interface, with offline capability and optional backup web EPOS.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have not yet completed formal usability testing of the Byte interfaces with assistive-technology users. We carry out accessibility checks during development and release using automated testing and manual verification of key user journeys (keyboard-only navigation, focus order, labels and contrast) and we review issues raised by users. Where required, we provide alternative support channels (phone and ticketing) and prioritise accessibility improvements identified through customer feedback.
API
Yes
What users can and can't do using the API
Byte provides an OpenAPI-documented REST API for integration and automation. Users can use the API to import and update data (for example users and account records), synchronise reference data, and export operational/reporting data. Some initial configuration (organisation settings, modules, menus/pricing and permissions) is completed in the admin portal rather than via API. API access is authenticated, rate limited and audited.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customise Byte’s look and feel (branding, logos and messaging) and configure workflows such as menus, pricing, meal rules, pre-ordering and kitchen/EPOS processes. Customisation is done through the admin web interface (no code). Only authorised administrators (trust/council and school/catering admins) can make changes.

Scaling

Independence of resources
All core components of Byte are independently scalable. We monitor capacity and performance and scale resources to handle peak demand. Resource limits and throttling are used where needed to prevent any single customer workload impacting other users.

Analytics

Service usage metrics
Yes
Metrics types
This is integral to Byte's AI assisted reports.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
NCSC approved service provider
Protecting data at rest
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Through Byte's extensive AI assisted reports module.
Data export formats
  • CSV
  • ODF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Availability is agreed on a customer-by-customer basis and set out in the individual contract/SLA, including how uptime is measured, planned maintenance windows and exclusions. If agreed availability targets are not met, remedies are handled in line with the customer’s SLA - typically service credits or other contractual remedies, applied to the next billing period where applicable.
Approach to resilience
Byte is designed for resilience using scalable cloud infrastructure with monitored core components and redundancy at service and data layers. We use regular backups and tested restore procedures, and we monitor availability and performance to detect and respond to issues quickly. The service supports operational continuity at the point of service through EPOS offline mode, with queued transactions synchronised when connectivity is restored, and a backup web EPOS option where enabled. Detailed datacentre/region design is available to buyers on request.
Outage reporting
We monitor availability using updown.io. Customers can subscribe to updown.io notifications for status updates and receive alerts during incidents.

Identity and authentication

User authentication needed
Yes
User authentication
Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using role-based access control (RBAC). Only authorised users can access administrative functions, and permissions are granted on a least-privilege basis. Administrative access is limited to approved accounts, with access reviewed and removed promptly when no longer required.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Security governance is led by senior management with clear accountability for service security. We maintain documented security policies and risk management processes, review security risks and incidents regularly, and ensure changes are assessed for security impact. We hold Cyber Essentials Plus certification and use role-based access controls, audit logging and monitoring. We commission security testing (including penetration testing where appropriate) and track remediation through to completion.
Information security policies and processes
We follow documented information security policies covering access control, encryption, incident management, vulnerability management, secure development, supplier management, and backup and recovery. A named senior owner is accountable for information security, with day-to-day responsibility assigned to designated leads.

We ensure policies are followed through role-based access controls, staff onboarding/offboarding, security awareness training, and regular reviews of user access and system changes. Security risks and incidents are logged, escalated and reviewed by senior management, with corrective actions tracked to completion.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Describe your configuration and change management processes.
Include details of how:

the components of your services are tracked through their lifetime
changes are assessed for potential security impact.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We assess threats through automated vulnerability scanning, dependency monitoring and security reviews. Alerts are triaged by severity and exposure. Critical patches are prioritised and deployed as soon as practicable (often within days), with lower-severity fixes scheduled into normal release cycles. We track advisories from tooling and vendor feeds (for example security advisories from vendors and maintainers, and cloud provider notices).
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use logging and monitoring across key service components to detect unusual activity, errors and access patterns that could indicate compromise. Alerts are triaged by severity and investigated by authorised staff. When a potential compromise is suspected we contain access (e.g. revoke credentials, isolate affected components), assess impact, remediate, and communicate updates to nominated contacts. We respond to critical security incidents as soon as identified and prioritise immediate containment and service stabilisation.
Incident management type
Supplier-defined controls
Incident management approach
We have documented incident processes, including predefined runbooks for common events (service outage, performance degradation, security incidents and payment issues). Users report incidents through our ticketing/email and phone support channels. We triage by severity, assign an incident owner, and provide updates to nominated contacts until resolution. After closure we provide an incident report on request, covering timeline, impact, root cause, corrective actions and any preventative changes.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
8d730adf-a264-4f79-ba73-f1913961276b
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Cca3370e-3989-4e3d-b34b-22b6a4eb21db
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at kate.fox@north27.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.