Concentric AI Semantic Intelligence™️Platform
Concentric AI is a cloud-native SaaS data security platform that discovers, categorizes and classifies sensitive and business-critical data across cloud and on‑prem repositories. It provides visibility into where data is, who can access it, and associated risks, with reporting and remediation workflows to support compliance, DLP enablement and GenAI security.
Features
- AI-driven semantic data categorization across all repositories.
- Agentless scanning for cloud and on‑prem data sources.
- Automatic PII and PCI detection using contextual AI models.
- Data discovery and clustering for structured and unstructured content.
- Secure document embeddings for accurate classification without storing content.
- Oversharing and risky-permission detection across the enterprise.
- Automated remediation to delete, move, classify, or quarantine data.
- SaaS architecture with isolated tenants and encrypted metadata.
- Copilot data access monitoring with activity analytics.
- Works out-of-the-box without rules, regex, or policy creation.
Benefits
- Accelerate sensitive data discovery across clouds and on‑premises repositories companywide.
- Reduce exposure by identifying oversharing and risky permissions automatically everywhere.
- Automate remediation: delete, move, classify, quarantine sensitive content at scale.
- Increase compliance readiness with built‑in reporting and DSAR response workflows.
- Lower storage costs by eliminating duplicates, stale, and mislocated data.
- Shorten investigations using contextual insights, lineage, and anomaly detection dashboards.
- Enable safe Copilot rollouts by monitoring access and preventing leakage.
- Improve accuracy versus rules by applying semantic understanding to content.
- Streamline audits with centralized evidence, change history, and exportable reports.
- Save analyst time by automating policy creation, classification, and cleanup.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 9 0 4 1 9 1 9 8 1 4 9 1 0 7
Contact
XMA LIMITED
Nancy Clayton-Schofield
Telephone: 0115 846 4000
Email: bidteam@xma.co.uk
About your service
- Service categories
-
Systems Infrastructure Software
Security
- Governance, risk and compliance
Data security
- Information protection
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Our service is an extension to Microsoft 365 (SharePoint, OneDrive, Exchange), Azure AD, cloud storage platforms (AWS, Azure, GCP), SIEM/SOAR tools, data catalogues, and enterprise DLP systems.
- Cloud deployment model
- Public cloud
- Service constraints
- Concentric AI may be subject to constraints based on customer environment configuration and governance. Automated remediation may be restricted in tightly governed or locked-down environments. Private Scan Manager operates in read-only mode and cannot apply changes to customer data. Customers must provide sufficient permissions for scanning and metadata extraction, and service functionality depends on API availability and limits imposed by cloud providers such as Microsoft Graph. Some environments may restrict write-back operations due to tenant governance rules. On-premises scanning requires customer-managed proxy deployment and appropriate network configuration. Excessively restricted service accounts or logging configurations may limit visibility or risk detection.
- System requirements
-
- Supported cloud service licences (e.g. M365, AWS)
- Administrator consent for read-only API access
- Network connectivity to customer data sources
- Lightweight proxy for on-premises file server scanning
- Customer-managed network configuration for proxy deployment
- Appropriate access roles for cloud storage platforms
- API availability from supported cloud providers
- Supported identity provider for authentication and access control
User support
- Email or online ticketing support
- Yes
- Support response times
-
We provide tiered response times depending on priority.
– Priority 1 issues (service unavailable or security incidents) receive an initial response within 30 minutes.
– Priority 2 issues receive a response within 2 hours.
– Priority 3 by the next business day.
– Priority 4 within two business days.
Status updates are provided according to SLA, and urgent cases receive continuous follow‑up. Response times during weekends or holidays follow the same SLA for critical issues. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Concentric AI provides support in line with defined SLAs covering availability, response times, and escalation. The service is delivered as a fully managed SaaS platform with 24/7 operational monitoring. Error response times follow a tiered model: Priority 1 issues (service unavailable or security incident) receive an initial response within 30 minutes, Priority 2 within 2 hours, Priority 3 by the next business day, and Priority 4 within two business days. Status updates and target resolutions are provided according to the SLA.
Customers receive support through email and online ticketing, with managed services including access to a Customer Success Manager, Solutions Engineer, and Account Manager. Regular cadence meetings and dedicated shared communication channels (such as Teams) are used for ongoing support. Onsite support is available when required and may incur additional cost.
The platform maintains high availability through a multi‑tenant AWS architecture with isolated tenant environments. If service availability or SLA response obligations are not met, service credits are provided as defined in the Support Agreement. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Concentric AI onboards customers through a structured Customer Success-led process. After order confirmation, a dedicated Customer Success Manager is assigned and the customer tenant is provisioned in the Concentric AI cloud, with initial credentials created. A welcome email is issued to the customer (and partner where applicable) including login details, setup documentation for key integrations (eg. Exchange, OneDrive, SharePoint) and a project plan template with estimated timelines. We run an initial kickoff/scoping session to confirm use cases and in-scope repositories, then guide customers to connect data sources using our agentless connectors (eg. M365 via admin consent; on‑prem sources via a proxy). We provide onboarding guides (eg. LDAP/SQL onboarding, proxy/VM prerequisites), and RBAC/SSO configuration guidance. Customers receive regular working sessions (eg. bi‑weekly) during deployment, plus ongoing check-ins/QBRs as required.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Video tutorials
- End-of-contract data extraction
- Users can extract their data by requesting an export from Concentric AI at contract end. Upon written request, Concentric provides a copy of the customer’s data (eg. metadata, reports, and other materials generated by or obtained through the service) within the timeframe set out in the applicable agreement and in a format reasonably acceptable to the customer (eg. relational database export, flat file, or other cloud‑native storage format). Customers may also retain copies of reports and other outputs generated through the service for their own recordkeeping, audit, or compliance needs. After termination, Concentric AI deletes or destroys the customer’s proprietary information within the contractual period (eg. 60 days), unless retention is legally required.
- End-of-contract process
- At contract end (expiration or termination), customer access to the Concentric AI service is disabled in line with the agreement. On written request, Concentric makes the customer’s proprietary information/customer data available for export or download for a limited period (eg. 30 days) and/or provides a copy of customer data in a format reasonably acceptable to the customer (eg. relational database export, flat file, or other cloud‑native format). Customers may retain copies of data, reports, and other materials generated by or obtained through the service as required for recordkeeping, audit, or compliance. After the export window, Concentric AI deletes or destroys the customer’s proprietary information within the contractual timeframe (eg. 60 days) and can provide written certification of destruction on request. Where an MSA/termination agreement requires it, customer data may be archived for the agreed retention period before deletion.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Concentric AI does not currently claim formal compliance with a specific accessibility standard for its documentation. However, onboarding and offboarding documentation is provided in accessible digital formats and designed to be usable by a wide range of users. Documentation is delivered electronically, structured with clear headings, logical sections, and plain language to support readability and compatibility with common assistive technologies such as screen readers.
Documents avoid unnecessary visual complexity and allow text resizing, copying, and searching. Where diagrams or visual elements are included, accompanying explanatory text is provided. Customers who require clarification, assistance, or alternative formats can request support through Concentric AI’s standard support channels. Offboarding documentation clearly describes service exit and data deletion steps in written form to ensure accessibility without reliance on proprietary tools or inaccessible media.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is accessed through the Concentric AI Management Portal, a secure web‑based interface available via a tenant‑specific URL. Users authenticate through the customer’s identity provider using SSO with role‑based access control. The portal provides dashboards, data discovery results, risk insights, compliance reporting, and configuration options. All sensitive content is redacted, with only metadata and classification outcomes shown. The interface supports reviewing permissions, monitoring remediation tasks, and managing connected data sources. An API interface also exists for integration and automation, supported through engineering‑assisted processes.
- Accessibility standards
- EN 301 549
- Accessibility testing
- An accessibility audit was completed for the Concentric AI VPAT (May 2023) on representative pages and user journeys using the WCAG-EM methodology. Testing included manual accessibility checks, automated accessibility tools, and testing with assistive technology across multiple platforms and browsers. We do not have documented evidence of separate usability testing sessions specifically with end users who rely on assistive technology beyond this audit.
- API
- Yes
- What users can and can't do using the API
-
Concentric provides REST + GraphQL interfaces. Where API access is enabled for a customer, users set-up API access by authenticating via a REST login endpoint (api/v1/login) using Basic credentials/client credentials plus the tenant domain header, then using the returned token/context cookie for subsequent GraphQL queries. Users can query discovered content inventories (e.g., allContents), apply filters/pagination, run aggregations (e.g., group counts by category/risk), and retrieve analytics such as word clouds/similar content where available.
Users cannot use the API to perform service setup or make operational changes such as creating/updating policies, configuring connectors, managing scans, modifying permissions, applying labels, or executing remediation actions; these changes are performed through the Concentric UI/workflows. API access is not currently offered as a generally available, officially supported public customer API; it has been provided only in controlled cases for specific use-cases, with expectations to limit load/usage and typically to keep operations read-only. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Users customise Concentric AI through the web UI (and API, where enabled). Admin users can scope and schedule scans (eg. by repository and folder paths), configure classification and labelling policies, and set thresholds and patterns (including optional regex) to support sensitive data detection. They can define alerting rules and remediation workflows (eg. notifications and ticket creation), map categories to downstream controls (DLP/label frameworks), and tailor dashboards and reports (including exported reports). Access and what each user can see/do is configurable using role-based access control (e.g., Admin, Readonly, Users, Manager, Department, Security, Database).
Scaling
- Independence of resources
- Concentric AI limits impact through a multi-tenant architecture with strict tenant isolation. Each tenant’s metadata is stored in a separate database/index, and scanning/processing runs as separate workflow jobs per tenant (even though some common services eg. authentication are shared). Workloads are hosted as microservices on Kubernetes (AWS EKS), and the underlying AWS environment provides redundant infrastructure to reduce single points of failure. Customers also control scan scope (eg. specific folders/paths), which helps manage workload and performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Concentric AI provides service usage and operational metrics via dashboards and exportable reports, eg. total data scanned/processed (TB and file/record counts), scan progress and connector coverage, classification coverage (classified vs unclassified), sensitive data findings (eg. PII/PCI/PHI counts), risk and exposure metrics (eg. oversharing, external links, excessive permissions), stale/duplicate data volumes, and user activity/audit metrics (eg. access events, directory events, policy violations and remediation actions). Concentric AI also maintains per‑tenant telemetry comparing raw data processed vs metadata/embeddings retained (available on request).
- Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Concentric AI
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users export data from the Concentric AI console by generating report exports (eg. content, directory, user/activity, owner and risk reports). Exports are typically delivered as CSV files via a secure download link that expires after a defined period.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Concentric AI is designed to be highly available and is hosted on Amazon Web Services (AWS), leveraging resilient cloud infrastructure across multiple availability zones. The platform is monitored continuously and designed to minimise single points of failure. Service availability commitments are defined contractually. Where service level agreements (SLAs) are agreed, Concentric AI provides availability targets aligned to the underlying AWS service availability and best-practice cloud architecture. Planned maintenance is communicated in advance wherever possible and scheduled to minimise customer impact. If Concentric AI fails to meet agreed availability levels, service credits or other remedies may be provided in accordance with the terms set out in the customer contract or order form. AWS separately provides availability commitments for its underlying infrastructure under its own published SLAs.
- Approach to resilience
- Concentric AI is designed for resilience using cloud-native architecture hosted on Amazon Web Services (AWS). The service is deployed across multiple AWS availability zones to reduce the risk of single points of failure and to maintain service continuity in the event of infrastructure issues. The platform uses managed AWS services that provide built-in redundancy, automated failover, and high availability. Data is stored on resilient storage services with regular backups and recovery mechanisms in place to support service restoration if required. System health and availability are continuously monitored, with alerts and operational procedures to respond to incidents. Resilience of the underlying datacentre infrastructure, including power, cooling, networking, and physical security, is provided by AWS and independently assured through recognised standards and certifications. Further details on architectural resilience and recovery capabilities can be provided to customers on request.
- Outage reporting
-
Concentric AI communicates service outages and incidents through direct customer notifications and agreed support channels. Customers are notified of service-impacting incidents via email alerts, providing updates on incident status, impact, and progress toward resolution.
Operational monitoring and alerting are in place to detect availability issues, allowing incidents to be identified and addressed promptly. Where incidents are linked to underlying cloud infrastructure, Concentric AI also monitors relevant Amazon Web Services (AWS) service health notifications. Concentric AI does not currently provide a public service status dashboard or outage reporting API. Incident updates and post-incident communications are provided directly to affected customers through established support and account management channels.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to Concentric AI management interfaces is restricted to authorised personnel using role-based access control and the principle of least privilege. Administrative access is limited to approved roles and protected through authenticated user accounts, with access reviewed regularly.
Support channels are restricted to authorised customer contacts and Concentric AI support staff. Requests involving customer data or configuration changes are verified before action is taken. All access to management functions and support activities is logged and monitored to support auditability and incident investigation. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Concentric AI follows a defined set of information security policies and processes aligned to ISO/IEC 27001 principles. These include policies covering information security management, access control, data protection, incident management, risk management, secure development, and supplier security. Security governance is overseen by senior management, with clear ownership and reporting lines for information security. Risks, incidents, and compliance matters are escalated through defined reporting structures and reviewed regularly to ensure appropriate oversight and accountability. Policies are communicated to relevant staff and supported by mandatory security awareness training. Compliance is reinforced through technical controls, monitoring, and periodic reviews of access and security practices. Where services are delivered using Amazon Web Services (AWS), infrastructure-level security policies and controls are provided by AWS under the shared responsibility model and are independently assured against recognised standards.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Concentric AI operates a formal configuration and change management process covering application code and production infrastructure. All incidents, bugs, and change requests are logged and tracked in a change-management ticketing system. Service components are version-controlled and tracked throughout their lifecycle. Changes follow a defined development methodology, including risk assessment, approval, testing, and secure deployment controls to assess potential security impact. Concentric AI uses a CI/CD delivery model to deploy new features and security patches regularly. The service is hosted on AWS under a shared responsibility model, with Concentric AI managing application-level configuration and releases.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Concentric AI assesses potential threats through a combination of ongoing security monitoring, vulnerability scanning, independent penetration testing, and review of security advisories. Vulnerabilities are risk-assessed based on severity and potential impact to the service. Patches and mitigations are prioritised accordingly and deployed in a timely manner through controlled change management processes, with urgent security fixes applied as soon as practicable. Information about emerging threats is obtained from trusted sources including AWS security notifications, vendor advisories, industry best practice guidance, and third-party security testing reports.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Concentric AI uses security monitoring and alerting to identify potential compromises, including anomalous behaviour, unauthorised access attempts, and service integrity issues. Monitoring outputs are reviewed to detect and assess potential security events. When a potential compromise is identified, defined incident response procedures are followed to investigate, contain, and remediate the issue. Incidents are prioritised based on severity and potential impact, with urgent issues addressed as soon as practicable. Infrastructure-level monitoring and incident detection are provided by Amazon Web Services (AWS) under the shared responsibility model.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Concentric AI has defined incident management processes with pre-defined response procedures for common security and service events. Incidents are logged, assessed, prioritised, and managed based on severity and potential impact. Users can report incidents via agreed support channels, including email and customer support contacts. Incidents are investigated and managed through to resolution, with escalation where required. Incident reports and updates are provided to affected customers through direct communication, including details of impact, actions taken, and remediation outcomes. Infrastructure-level incidents are managed in coordination with Amazon Web Services (AWS) under the shared responsibility model.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Concentric AI provides a time-limited Proof of Value (PoV). The PoV includes analysis of up to 100,000 files or records using up to two standard data connectors over a typical 2–3 week period. It excludes full production deployment, ongoing monitoring, and remediation.
- Link to free trial
- The free Proof of Value (PoV) is provided through engagement with a Concentric AI representative. There is no publicly accessible self-service link.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA Limited
- ISO/IEC 27001 accreditation date
- Thursday 27 November 2025
- What the ISO/IEC 27001 doesn’t cover
- The certificate scope covers the full company business operations, across all business locations, applicable and relevant to the delivery, deployment and management of IT solutions, support and services in accordance with Statement of Applicability Version 4, and is audit against the new 2022 standard.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA Limited
- ISO 9001 accreditation date
- Monday 17 February 2025
- What the ISO 9001 doesn’t cover
- The certificate scope covers the full company business operations, across all business locations, applicable and relevant to the Delivery, Deployment and Management of IT Solutions, Support and Services.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Barclaycard
- PCI DSS accreditation date
- Thursday 9 January 2025
- What the PCI DSS doesn’t cover
- Our PCI DSS certification applies exclusively to payment processing systems and hosted payment gateways and does not extend to non‑payment systems, corporate IT infrastructure, or business applications outside the cardholder data environment.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B5f066ef-ff99-48a9-94b0-23f1f0ee595b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 2d75659c-9df3-4d75-9406-9052a6e68c4b
- Other security certifications
- Yes
- Any other security certifications
- IASME CYBER ASSURANCE LEVEL ONE
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-