Skip to main content

Help us improve the Digital Marketplace - send your feedback

XMA LIMITED

Concentric AI Semantic Intelligence™️Platform

Concentric AI is a cloud-native SaaS data security platform that discovers, categorizes and classifies sensitive and business-critical data across cloud and on‑prem repositories. It provides visibility into where data is, who can access it, and associated risks, with reporting and remediation workflows to support compliance, DLP enablement and GenAI security.

Features

  • AI-driven semantic data categorization across all repositories.
  • Agentless scanning for cloud and on‑prem data sources.
  • Automatic PII and PCI detection using contextual AI models.
  • Data discovery and clustering for structured and unstructured content.
  • Secure document embeddings for accurate classification without storing content.
  • Oversharing and risky-permission detection across the enterprise.
  • Automated remediation to delete, move, classify, or quarantine data.
  • SaaS architecture with isolated tenants and encrypted metadata.
  • Copilot data access monitoring with activity analytics.
  • Works out-of-the-box without rules, regex, or policy creation.

Benefits

  • Accelerate sensitive data discovery across clouds and on‑premises repositories companywide.
  • Reduce exposure by identifying oversharing and risky permissions automatically everywhere.
  • Automate remediation: delete, move, classify, quarantine sensitive content at scale.
  • Increase compliance readiness with built‑in reporting and DSAR response workflows.
  • Lower storage costs by eliminating duplicates, stale, and mislocated data.
  • Shorten investigations using contextual insights, lineage, and anomaly detection dashboards.
  • Enable safe Copilot rollouts by monitoring access and preventing leakage.
  • Improve accuracy versus rules by applying semantic understanding to content.
  • Streamline audits with centralized evidence, change history, and exportable reports.
  • Save analyst time by automating policy creation, classification, and cleanup.

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@xma.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 9 0 4 1 9 1 9 8 1 4 9 1 0 7

Contact

XMA LIMITED Nancy Clayton-Schofield
Telephone: 0115 846 4000
Email: bidteam@xma.co.uk

About your service

Service categories

Systems Infrastructure Software

Security

  • Governance, risk and compliance

Data security

  • Information protection
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Our service is an extension to Microsoft 365 (SharePoint, OneDrive, Exchange), Azure AD, cloud storage platforms (AWS, Azure, GCP), SIEM/SOAR tools, data catalogues, and enterprise DLP systems.
Cloud deployment model
Public cloud
Service constraints
Concentric AI may be subject to constraints based on customer environment configuration and governance. Automated remediation may be restricted in tightly governed or locked-down environments. Private Scan Manager operates in read-only mode and cannot apply changes to customer data. Customers must provide sufficient permissions for scanning and metadata extraction, and service functionality depends on API availability and limits imposed by cloud providers such as Microsoft Graph. Some environments may restrict write-back operations due to tenant governance rules. On-premises scanning requires customer-managed proxy deployment and appropriate network configuration. Excessively restricted service accounts or logging configurations may limit visibility or risk detection.
System requirements
  • Supported cloud service licences (e.g. M365, AWS)
  • Administrator consent for read-only API access
  • Network connectivity to customer data sources
  • Lightweight proxy for on-premises file server scanning
  • Customer-managed network configuration for proxy deployment
  • Appropriate access roles for cloud storage platforms
  • API availability from supported cloud providers
  • Supported identity provider for authentication and access control

User support

Email or online ticketing support
Yes
Support response times
We provide tiered response times depending on priority.
– Priority 1 issues (service unavailable or security incidents) receive an initial response within 30 minutes.
– Priority 2 issues receive a response within 2 hours.
– Priority 3 by the next business day.
– Priority 4 within two business days.
Status updates are provided according to SLA, and urgent cases receive continuous follow‑up. Response times during weekends or holidays follow the same SLA for critical issues.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Concentric AI provides support in line with defined SLAs covering availability, response times, and escalation. The service is delivered as a fully managed SaaS platform with 24/7 operational monitoring. Error response times follow a tiered model: Priority 1 issues (service unavailable or security incident) receive an initial response within 30 minutes, Priority 2 within 2 hours, Priority 3 by the next business day, and Priority 4 within two business days. Status updates and target resolutions are provided according to the SLA.
Customers receive support through email and online ticketing, with managed services including access to a Customer Success Manager, Solutions Engineer, and Account Manager. Regular cadence meetings and dedicated shared communication channels (such as Teams) are used for ongoing support. Onsite support is available when required and may incur additional cost.
The platform maintains high availability through a multi‑tenant AWS architecture with isolated tenant environments. If service availability or SLA response obligations are not met, service credits are provided as defined in the Support Agreement.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Concentric AI onboards customers through a structured Customer Success-led process. After order confirmation, a dedicated Customer Success Manager is assigned and the customer tenant is provisioned in the Concentric AI cloud, with initial credentials created. A welcome email is issued to the customer (and partner where applicable) including login details, setup documentation for key integrations (eg. Exchange, OneDrive, SharePoint) and a project plan template with estimated timelines. We run an initial kickoff/scoping session to confirm use cases and in-scope repositories, then guide customers to connect data sources using our agentless connectors (eg. M365 via admin consent; on‑prem sources via a proxy). We provide onboarding guides (eg. LDAP/SQL onboarding, proxy/VM prerequisites), and RBAC/SSO configuration guidance. Customers receive regular working sessions (eg. bi‑weekly) during deployment, plus ongoing check-ins/QBRs as required.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
Video tutorials
End-of-contract data extraction
Users can extract their data by requesting an export from Concentric AI at contract end. Upon written request, Concentric provides a copy of the customer’s data (eg. metadata, reports, and other materials generated by or obtained through the service) within the timeframe set out in the applicable agreement and in a format reasonably acceptable to the customer (eg. relational database export, flat file, or other cloud‑native storage format). Customers may also retain copies of reports and other outputs generated through the service for their own recordkeeping, audit, or compliance needs. After termination, Concentric AI deletes or destroys the customer’s proprietary information within the contractual period (eg. 60 days), unless retention is legally required.
End-of-contract process
At contract end (expiration or termination), customer access to the Concentric AI service is disabled in line with the agreement. On written request, Concentric makes the customer’s proprietary information/customer data available for export or download for a limited period (eg. 30 days) and/or provides a copy of customer data in a format reasonably acceptable to the customer (eg. relational database export, flat file, or other cloud‑native format). Customers may retain copies of data, reports, and other materials generated by or obtained through the service as required for recordkeeping, audit, or compliance. After the export window, Concentric AI deletes or destroys the customer’s proprietary information within the contractual timeframe (eg. 60 days) and can provide written certification of destruction on request. Where an MSA/termination agreement requires it, customer data may be archived for the agreed retention period before deletion.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Concentric AI does not currently claim formal compliance with a specific accessibility standard for its documentation. However, onboarding and offboarding documentation is provided in accessible digital formats and designed to be usable by a wide range of users. Documentation is delivered electronically, structured with clear headings, logical sections, and plain language to support readability and compatibility with common assistive technologies such as screen readers.

Documents avoid unnecessary visual complexity and allow text resizing, copying, and searching. Where diagrams or visual elements are included, accompanying explanatory text is provided. Customers who require clarification, assistance, or alternative formats can request support through Concentric AI’s standard support channels. Offboarding documentation clearly describes service exit and data deletion steps in written form to ensure accessibility without reliance on proprietary tools or inaccessible media.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service is accessed through the Concentric AI Management Portal, a secure web‑based interface available via a tenant‑specific URL. Users authenticate through the customer’s identity provider using SSO with role‑based access control. The portal provides dashboards, data discovery results, risk insights, compliance reporting, and configuration options. All sensitive content is redacted, with only metadata and classification outcomes shown. The interface supports reviewing permissions, monitoring remediation tasks, and managing connected data sources. An API interface also exists for integration and automation, supported through engineering‑assisted processes.
Accessibility standards
EN 301 549
Accessibility testing
An accessibility audit was completed for the Concentric AI VPAT (May 2023) on representative pages and user journeys using the WCAG-EM methodology. Testing included manual accessibility checks, automated accessibility tools, and testing with assistive technology across multiple platforms and browsers. We do not have documented evidence of separate usability testing sessions specifically with end users who rely on assistive technology beyond this audit.
API
Yes
What users can and can't do using the API
Concentric provides REST + GraphQL interfaces. Where API access is enabled for a customer, users set-up API access by authenticating via a REST login endpoint (api/v1/login) using Basic credentials/client credentials plus the tenant domain header, then using the returned token/context cookie for subsequent GraphQL queries. Users can query discovered content inventories (e.g., allContents), apply filters/pagination, run aggregations (e.g., group counts by category/risk), and retrieve analytics such as word clouds/similar content where available.

Users cannot use the API to perform service setup or make operational changes such as creating/updating policies, configuring connectors, managing scans, modifying permissions, applying labels, or executing remediation actions; these changes are performed through the Concentric UI/workflows. API access is not currently offered as a generally available, officially supported public customer API; it has been provided only in controlled cases for specific use-cases, with expectations to limit load/usage and typically to keep operations read-only.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Users customise Concentric AI through the web UI (and API, where enabled). Admin users can scope and schedule scans (eg. by repository and folder paths), configure classification and labelling policies, and set thresholds and patterns (including optional regex) to support sensitive data detection. They can define alerting rules and remediation workflows (eg. notifications and ticket creation), map categories to downstream controls (DLP/label frameworks), and tailor dashboards and reports (including exported reports). Access and what each user can see/do is configurable using role-based access control (e.g., Admin, Readonly, Users, Manager, Department, Security, Database).

Scaling

Independence of resources
Concentric AI limits impact through a multi-tenant architecture with strict tenant isolation. Each tenant’s metadata is stored in a separate database/index, and scanning/processing runs as separate workflow jobs per tenant (even though some common services eg. authentication are shared). Workloads are hosted as microservices on Kubernetes (AWS EKS), and the underlying AWS environment provides redundant infrastructure to reduce single points of failure. Customers also control scan scope (eg. specific folders/paths), which helps manage workload and performance.

Analytics

Service usage metrics
Yes
Metrics types
Concentric AI provides service usage and operational metrics via dashboards and exportable reports, eg. total data scanned/processed (TB and file/record counts), scan progress and connector coverage, classification coverage (classified vs unclassified), sensitive data findings (eg. PII/PCI/PHI counts), risk and exposure metrics (eg. oversharing, external links, excessive permissions), stale/duplicate data volumes, and user activity/audit metrics (eg. access events, directory events, policy violations and remediation actions). Concentric AI also maintains per‑tenant telemetry comparing raw data processed vs metadata/embeddings retained (available on request).
Reporting types
Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Concentric AI

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users export data from the Concentric AI console by generating report exports (eg. content, directory, user/activity, owner and risk reports). Exports are typically delivered as CSV files via a secure download link that expires after a defined period.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Concentric AI is designed to be highly available and is hosted on Amazon Web Services (AWS), leveraging resilient cloud infrastructure across multiple availability zones. The platform is monitored continuously and designed to minimise single points of failure. Service availability commitments are defined contractually. Where service level agreements (SLAs) are agreed, Concentric AI provides availability targets aligned to the underlying AWS service availability and best-practice cloud architecture. Planned maintenance is communicated in advance wherever possible and scheduled to minimise customer impact. If Concentric AI fails to meet agreed availability levels, service credits or other remedies may be provided in accordance with the terms set out in the customer contract or order form. AWS separately provides availability commitments for its underlying infrastructure under its own published SLAs.
Approach to resilience
Concentric AI is designed for resilience using cloud-native architecture hosted on Amazon Web Services (AWS). The service is deployed across multiple AWS availability zones to reduce the risk of single points of failure and to maintain service continuity in the event of infrastructure issues. The platform uses managed AWS services that provide built-in redundancy, automated failover, and high availability. Data is stored on resilient storage services with regular backups and recovery mechanisms in place to support service restoration if required. System health and availability are continuously monitored, with alerts and operational procedures to respond to incidents. Resilience of the underlying datacentre infrastructure, including power, cooling, networking, and physical security, is provided by AWS and independently assured through recognised standards and certifications. Further details on architectural resilience and recovery capabilities can be provided to customers on request.
Outage reporting
Concentric AI communicates service outages and incidents through direct customer notifications and agreed support channels. Customers are notified of service-impacting incidents via email alerts, providing updates on incident status, impact, and progress toward resolution.
Operational monitoring and alerting are in place to detect availability issues, allowing incidents to be identified and addressed promptly. Where incidents are linked to underlying cloud infrastructure, Concentric AI also monitors relevant Amazon Web Services (AWS) service health notifications. Concentric AI does not currently provide a public service status dashboard or outage reporting API. Incident updates and post-incident communications are provided directly to affected customers through established support and account management channels.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to Concentric AI management interfaces is restricted to authorised personnel using role-based access control and the principle of least privilege. Administrative access is limited to approved roles and protected through authenticated user accounts, with access reviewed regularly.
Support channels are restricted to authorised customer contacts and Concentric AI support staff. Requests involving customer data or configuration changes are verified before action is taken. All access to management functions and support activities is logged and monitored to support auditability and incident investigation.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Concentric AI follows a defined set of information security policies and processes aligned to ISO/IEC 27001 principles. These include policies covering information security management, access control, data protection, incident management, risk management, secure development, and supplier security. Security governance is overseen by senior management, with clear ownership and reporting lines for information security. Risks, incidents, and compliance matters are escalated through defined reporting structures and reviewed regularly to ensure appropriate oversight and accountability. Policies are communicated to relevant staff and supported by mandatory security awareness training. Compliance is reinforced through technical controls, monitoring, and periodic reviews of access and security practices. Where services are delivered using Amazon Web Services (AWS), infrastructure-level security policies and controls are provided by AWS under the shared responsibility model and are independently assured against recognised standards.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Concentric AI operates a formal configuration and change management process covering application code and production infrastructure. All incidents, bugs, and change requests are logged and tracked in a change-management ticketing system. Service components are version-controlled and tracked throughout their lifecycle. Changes follow a defined development methodology, including risk assessment, approval, testing, and secure deployment controls to assess potential security impact. Concentric AI uses a CI/CD delivery model to deploy new features and security patches regularly. The service is hosted on AWS under a shared responsibility model, with Concentric AI managing application-level configuration and releases.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Concentric AI assesses potential threats through a combination of ongoing security monitoring, vulnerability scanning, independent penetration testing, and review of security advisories. Vulnerabilities are risk-assessed based on severity and potential impact to the service. Patches and mitigations are prioritised accordingly and deployed in a timely manner through controlled change management processes, with urgent security fixes applied as soon as practicable. Information about emerging threats is obtained from trusted sources including AWS security notifications, vendor advisories, industry best practice guidance, and third-party security testing reports.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Concentric AI uses security monitoring and alerting to identify potential compromises, including anomalous behaviour, unauthorised access attempts, and service integrity issues. Monitoring outputs are reviewed to detect and assess potential security events. When a potential compromise is identified, defined incident response procedures are followed to investigate, contain, and remediate the issue. Incidents are prioritised based on severity and potential impact, with urgent issues addressed as soon as practicable. Infrastructure-level monitoring and incident detection are provided by Amazon Web Services (AWS) under the shared responsibility model.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Concentric AI has defined incident management processes with pre-defined response procedures for common security and service events. Incidents are logged, assessed, prioritised, and managed based on severity and potential impact. Users can report incidents via agreed support channels, including email and customer support contacts. Incidents are investigated and managed through to resolution, with escalation where required. Incident reports and updates are provided to affected customers through direct communication, including details of impact, actions taken, and remediation outcomes. Infrastructure-level incidents are managed in coordination with Amazon Web Services (AWS) under the shared responsibility model.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Concentric AI provides a time-limited Proof of Value (PoV). The PoV includes analysis of up to 100,000 files or records using up to two standard data connectors over a typical 2–3 week period. It excludes full production deployment, ongoing monitoring, and remediation.
Link to free trial
The free Proof of Value (PoV) is provided through engagement with a Concentric AI representative. There is no publicly accessible self-service link.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
LRQA Limited
ISO/IEC 27001 accreditation date
Thursday 27 November 2025
What the ISO/IEC 27001 doesn’t cover
The certificate scope covers the full company business operations, across all business locations, applicable and relevant to the delivery, deployment and management of IT solutions, support and services in accordance with Statement of Applicability Version 4, and is audit against the new 2022 standard.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
LRQA Limited
ISO 9001 accreditation date
Monday 17 February 2025
What the ISO 9001 doesn’t cover
The certificate scope covers the full company business operations, across all business locations, applicable and relevant to the Delivery, Deployment and Management of IT Solutions, Support and Services.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Barclaycard
PCI DSS accreditation date
Thursday 9 January 2025
What the PCI DSS doesn’t cover
Our PCI DSS certification applies exclusively to payment processing systems and hosted payment gateways and does not extend to non‑payment systems, corporate IT infrastructure, or business applications outside the cardholder data environment.
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
B5f066ef-ff99-48a9-94b0-23f1f0ee595b
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
2d75659c-9df3-4d75-9406-9052a6e68c4b
Other security certifications
Yes
Any other security certifications
IASME CYBER ASSURANCE LEVEL ONE

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@xma.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.