Skip to main content

Help us improve the Digital Marketplace - send your feedback

CTMS SERVICE MANAGEMENT LTD

Ivanti Neurons for ITSM (SaaS) - supplied by CTMS - authorised Ivanti partner

Ivanti Neurons for ITSM is a cloud-hosted IT and Enterprise Wide Service Management Platform. The platform is cloud hosted by Ivanti and the licence subscription is supplied by CTMS Service Management as an authorised reseller and certified solution partner of Ivanti. See Lot 3 for CTMS Ivanti technical services.

Features

  • AI Powered ITSM IT Service Management Platform
  • Agentic AI Bot for Incidents, Service Requests plus more
  • PinkVerified to 13 Processes
  • Over 80 prebuilt service templates for IT, Facilities and HR
  • Request, Incident, Problem and Change Management processes and more!
  • iPaaS orchestration connectivity with over 1000 low code connectors
  • ESM Platform includes Facilities, HR, SecOps, Project Mgt, GRC
  • Full Asset and Configuration (CMDB) Lifecycle Management
  • Asset Request, Procurement, Identification, Contracts, Vendor and Bar Code Tracking
  • Intuitive Dashboards, Xtraction Reporting and Notifications for business insights

Benefits

  • Ivanti Agentic AI revolutionizes IT operations delivering intelligent conversational automation
  • High availability integrated SaaS Based Service and Asset management solution
  • Remote access for End User Service Catalogue, Analysts and Administrators
  • Provides end-user portal for self service request management
  • Enterprise Service Management solution beyond IT for HR, Facilities, etc.
  • Robust automation and integration with business applications over 1000 connectors
  • Codeless design facilitates fast time to value
  • Know your Assets, where they are and their full costs
  • Ability to proactively forecast and plan for future needs
  • Integral reporting to improve efficiency and decision making

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at david.keen@ctms-itsm.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 1 9 2 2 9 1 6 7 0 3 7 2 7 6

Contact

CTMS SERVICE MANAGEMENT LTD David Keen
Telephone: 01189338070
Email: david.keen@ctms-itsm.com

About your service

Service categories

Systems Infrastructure Software

System and service management

  • IT operations management
  • IT service management
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Digital Assistant - AI/Chatbot functionality Ivanti Service Mapping Ivanti Security Controls (Patching) Ivanti Environment Manager (profile management) Ivanti Unified Endpoint Management Ivanti MDM Ivanti Application Control (application whitelisting & privilege management) Ivanti Neurons Platform (Self Heal, realtime analysis,Remote Control, Discovery) Ivanti Risk Based Vulnerability Management Ivanti External Attack Surface Management
Cloud deployment model
Public cloud
Service constraints
Upgrades are performed automatically by Ivanti Software where you will have access to upgraded functionality. Upgrades as part of the new version will not affect any configuration changes done within your environment and you will have the option of turning on or keeping the product enhancement features off as part of the new release. Versions are in-line with Year with quarterly upgrades. Notifications are issued well in advance by email and issued on user login to the Ivanti platform of any major release as part of the standard agreement.
System requirements
  • Ivanti Neurons for ITSM is delivered over the internet
  • Ivanti Neurons for ITSM and Asset Manager are browser based
  • Native Mobile Apps require iOS /Android, others use browser app
  • All modern mainstream browsers supported(IE, Edge, Chrome, FireFox, Safari)

User support

Email or online ticketing support
Yes
Support response times
Support response times
Please refer to our online support terms for a current view (Clause V) - https://www.ivanti.co.uk/company/legal/support-terms
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support provided by Ivanti as part of the licence subscription: Please refer to our online support terms for a current view (Clause V) - https://www.ivanti.co.uk/company/legal/support-terms As standard, all our license subscription include support, with three levels of support available; standard, enhanced and premium. Clause II of the online terms (link above) provides full details. All levels include access to the Cloud Care Team, which includes a team of technical engineers, online assistance, and phone help. Other support functions include: Ivanti Community - Troubleshoot, search knowledge base articles, access white papers, and join our discussion forums. Product Advice - The Advice Center provides a centralized search through knowledge base articles, forums, and product documentation. Manuals, installation guides, and support documents can be found on all Ivanti solutions. Ivanti products are constantly updated to meet the needs of rapidly changing IT environments. As new products are released, previous versions are supported and maintained for a certain amount of time, then retired. Many of the principles of WCAG are supported.

Support provided by CTMS Service Management: CTMS will provide first line support and provide initial troubleshooting and technical advice. Buyers can also contact Ivanti support directly as an additional support channel.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
The Ivanti Global Training Academy subscription is the most common approach to training, although classroom and on-site training is also available. The Academy marries training content and services to provide a more effective and engaging learning experience. Live Online Training = Short (30- to 120-minute) courses taught by one of our certified instructors via WebEx Training Centre. They’re scheduled repeatedly throughout the week so you can fit the ones you’d like to attend into your schedule. eLearning Modules = Short, concise, and interactive computer-based training modules. They focus on the content necessary to achieve a specific set of learning objectives. Informational Videos = View commentary or watch a feature demo from within an eLearning Module. Reference Materials = Further explore the topic at hand via a convenient link. Downloadable Content = Student guides and lab guides for each of the Live Online Training courses, quick reference guides, course brochures, and more. Please access the Ivanti Global Academy to see full list of courses https://advantagelearning.ivanti.com/ Note - User documentation is also available via online Help along with in app guided help videos on our integrated Neurons platform.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract the customer is given an extract of their database containing their data. Once the customer has confirmed receipt of data and successful restore then all data is removed from our system.
End-of-contract process
A Database extract is included fully in the cost of the contract.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
No functional differences, apart from mobile interfaces can be configured suitably for tablet and smartphone interfaces.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
End User Self Service is available upon desktop and mobile interfaces. Mobile Self Service is available over dedicated apps for iOS and Android and browser based apps for all other devices. Desktop Service access is available for analysts and managers through browser only platforms. Mobile apps are also available for analysts
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Independent accessibility tools have been used internally among the Ivanti engineering team as part of the accessibility testing of the solution. As it resides fully within the browser page, Zoom in/out is supported and all text labels and content convert consistently from text to speech. Contrasting colours are supported throughout and these can be altered for all or purposely for visually impaired personnel. Low alternate Flash indication can draw attention. 'As you type' suggested content is provided to the user on search fields and extensive use of validated fields are utilised. In our latest release in December 2025 , new controls in the Analyst interface have been added to the accessibility list to ensure on-screen elements have alternative text in order to be read by assistant technologies. Some of the important controls are mentioned below: •Change Role •User panel •Home screen Side Nav •View/Edit forms •Date time control •Search and others Further ongoing improvements to support improved accessibility measures are planned throughout 2026.
API
Yes
What users can and can't do using the API
What users can and can't do using the API
The Ivanti Neurons for ITSM(IN4ITSM) API can be adopted to CREATE/UPDATE and DELETE tickets across all business objects/ITSM processes (Incidents/Requests/Problem etc.). Actions can also be called to automate activity/instruction such as issuing emails or updates. The API can obtain information out of IN4ITSM into third party solutions such as to feed web sites of User/Ticket History/Asset details.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Ivanti Neurons for ITSM(IN4ITSM) and Asset Manager inherit a codeless development platform. New Business Objects(Tables), Forms, Fields, Reports and automated actions can be configured. All configurations are supported. Configurations can be recorded onto packages and exported/Imported from Development/Test to Production environments to mitigate risk of manual development steps. IN4ITSM utilises a Role based access model. Templates, Quick actions(automations) and dashboard development can be carried out by "Super users" whilst Administrators are able to reconfigure business objects and/or create new objects. In the very latest version AI can be leveraged to generate new dashboards.

Scaling

Independence of resources
Ivanti cloud architecture that leveraged containerisation and tenant architecture whereupon each user has separate databases of their own to mitigating risks of affecting each other. An offset database can also be provided for reporting purposes again to reduce risk of drawing resource from the production environment. Processes are established to automatically deploy additional Virtual Servers in the event of an increase of requirements.

Analytics

Service usage metrics
Yes
Metrics types
Availability Statistics, i.e. % availability per month. Provision of planned maintenance downtime. Provision of software upgrade and update schedules.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Ivanti

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Export to CSV via the application or through native reporting/dashboarding/list view extracts.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • PNG (image)
Data import formats
  • CSV
  • Other
Other data import formats
  • Excel (XLS/XLSX)
  • XML

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Please refer to section 4.1 of the Ivanti Software as a Service terms and conditions found here; https://www.ivanti.com/company/legal/saas
Approach to resilience
Ivanti resides on the highly resilient cloud platform Microsoft Azure. The Ivanti services architecture adopts production and failover system resident within the UK but can also offer a wider platform in EEC or globally. Azure proactively mitigates potential failures—reducing the failure impact on availability by 50 percent. Using deep fleet telemetry, Microsoft enables failure predictions with machine learning (ML) and ties them to automatic live migration for several types of hardware failure cases, including disk failures, input/output (I/O) latency, and CPU frequency anomalies. As a result, VMs are live migrated off of “at-risk” machines before they ever show signs of failing. This means VMs running on Azure are more reliable than the underlying hardware. Further details can be found here: https://azure.microsoft.com/mediahandler/files/resourcefiles/resilience-in-azure-whitepaper/Resilience%20in%20Azure.pdf Ivanti also complies with many safety frameworks upon its platform including SOC2 and ISO27001
Outage reporting
Ivanti ITSM and Asset Manager solutions do not require systems to be brought offline to perform regular maintenance and system patching. MS Azure's own maintenance and system patching generally do not impact customers.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access is restricted through Roles and Groups within the solution to ensure only those authorised can access the system via management interfaces and support channels
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
  • Other
Other security governance standards
SOC2
Information security policies and processes
Control Objectives for Information and related Technology (COBIT) framework and have effectively integrated the ISO 27001 certifiable framework based on ISO 27002 controls, American Institute of Certified Public Accountants (AICPA) Trust Services Principles, the PCI DSS v2.0, and the National Institute of Standards and Technology (NIST) Publication 800-53 Rev 3 (Recommended Security Controls for Federal Information Systems).
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
MS Azure patches systems supporting the delivery of service to customers, such as the hypervisor and networking services. This is done as required per MS Azure policy and in accordance with ISO 27001, NIST, and PCI requirements. MS Azure Security regularly scans all Internet facing service endpoint IP addresses for vulnerabilities (these scans do not include customer instances). MS Azure Security notifies the appropriate parties to remediate any identified vulnerabilities. In addition, external vulnerability threat assessments are performed regularly by independent security firms. Findings and recommendations resulting from these assessments are categorized and delivered to MS Azure leadership.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
MS Azure's program, processes and procedures to managing antivirus / malicious software is in alignment with ISO 27001 standards. Refer to MS Azure's SOC 2 Type II report provides further details. In addition, refer to ISO 27001 standard, Annex A, domain 10.4 for additional details. MS Azure has been validated and certified by an independent auditor to confirm alignment with ISO 27001 and SOC2 Type 2 certification standards and others.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
MS Azure's program, processes and procedures to managing antivirus / malicious software is in alignment with ISO 27001 standards. Refer to MS Azure's SOC 2 Type II report provides further details. In addition, refer to ISO 27001 standard, Annex A, domain 10.4 for additional details. MS Azure has been validated and certified by an independent auditor to confirm alignment with ISO 27001 and SOC2 Type 2 certification standards and others.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Organisations can try a 30 day free trial of Ivanti Neurons for ITSM. Contact sales@ctms-itsm.com for further information.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at david.keen@ctms-itsm.com. Tell them what format you need. It will help if you say what assistive technology you use.