Skip to main content

Help us improve the Digital Marketplace - send your feedback

NATQUEST LIMITED

Intelligent Procurement Tender Management Platform

NatQuest offers Opentender AI, a cloud-based procurement tender management platform for drafting, reviewing and evaluating tenders. The platform is intelligent and compliant with best practices in public procurement tender management.

Features

  • AI-Powered Tender Document Analysis and Requirement Extraction
  • Automated Response Generation from Secure Private Knowledge Base
  • Real-Time Streaming Progress Updates During Document Processin
  • Multi-Format Document Processing with OCR for Scanned PDFs
  • Automated Evaluation and Scoring Against Weighted Tender Criteria
  • Private Tender Bank with Intelligent Semantic Search Retrieval
  • Built-In Review Checkpoints for Human Oversight and Approval
  • Role-Based Access Control with Comprehensive Audit Trail Logging
  • Enterprise-Grade Encryption for Data at Rest and in Transit
  • Customisable AI Outputs Matching Organisation Tone and Style

Benefits

  • Reduce Tender Response and Evaluation Time by Up to 70%
  • Automatically Extract Requirements from Complex Tender Documents
  • Ensure Consistent Quality and Tone Across All Tender Submissions
  • Reuse Proven Tender Responses from Your Secure Knowledge Bank
  • Score and Evaluate Tender Submissions Against Predefined Weighted Criteria
  • Free Procurement Teams to Focus on Strategic Decision-Making
  • Make Defensible Evaluation Decisions Backed by Transparent Scoring Evidence
  • Meet Governance and Compliance Requirements with Automatic Audit Records
  • Reduce Risk of Missed Requirements or Evaluation Criteria
  • Maintain Full Human Control Over Every AI-Assisted Output

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at admin@nat-quest.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 2 3 9 8 3 4 0 6 9 5 8 3 7 7

Contact

NATQUEST LIMITED Salisu Uba
Telephone: 07459757051
Email: admin@nat-quest.com

About your service

Service categories

Application Development and Deployment

AI platforms

  • Search and knowledge discovery

AI software services

  • Conversational AI Software Services
  • Generative AI Software Services
  • Document AI Software Services
  • Personalize AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Hybrid cloud
Service constraints
Scheduled maintenance is performed during off-peak hours (weekends or evenings UK time) with a minimum of 48 hours’ advance notice to users. The service requires a modern web browser (Chrome, Firefox, or Edge, latest two versions) and a stable broadband internet connection. Document uploads are supported in PDF, DOCX, and TXT formats, with a maximum file size of 100MB per document. AI-powered analysis features require active internet connectivity and are subject to the availability of underlying AI model providers. The service operates in English only. Private cloud deployments may require additional configuration lead time.
System requirements
  • Modern Web Browser: Chrome, Firefox, or Edge (latest versions)
  • Stable Broadband Internet Connection with Minimum 5 Mbps Speed
  • No Additional Software Installation or Client-Side Licensing Required
  • Valid Email Address Required for Account Registration and Notifications
  • Screen Resolution of 1280×720 Pixels Minimum Recommended
  • No Specific Antivirus or Firewall Configuration Changes Needed
  • TLS 1.2 or Higher Supported by User's Network

User support

Email or online ticketing support
Yes
Support response times
Standard Support Hours:
Monday to Friday, 9:00 AM – 5:30 PM GMT/BST
Response Times by Priority:
Critical (service unavailable): Within 4 hours during business hours
High (major feature impaired): Within 8 business hours
Medium (minor issue, workaround available): Within 1 business day
Low (general enquiry or feature request): Within 2 business days
Additional Information:
Weekend and bank holiday support is not included as standard but can be arranged under a separate agreement. Support is provided via email and the online ticketing portal.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
No
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Our web chat interface is built using established third-party chat technology and conforms to WCAG 2.2 AA standards. Key accessibility features include:
Keyboard-only navigation: Users can open, type, send messages, and close the chat without a mouse.
Screen reader compatibility: All interactive elements include proper ARIA labels and roles.
Assistive technology testing:
Screen readers: NVDA and VoiceOver on desktop browsers
Keyboard navigation: Full tab order and focus management
Browser zoom: Usable at 200% magnification
High contrast mode: Windows High Contrast and forced-colours CSS
Focus and visual indicators: Logical focus order, announcements for incoming messages, and visible focus indicators on all controls.
Font and color standards: Font sizes and contrast ratios meet AA thresholds (minimum 4.5:1 for body text).
We perform periodic accessibility reviews when updating the chat platform and prioritize reported accessibility issues. User feedback from assistive technology users is actively welcomed to continuously improve the experience.
Onsite support
Yes, at extra cost
Support levels
Support Options
1. Standard Support (Included)
Channels: Email, web chat, phone, and ticketing during business hours (Monday–Friday, 9:00 AM – 5:30 PM GMT/BST)
Response times: 4 hours (critical) to 2 business days (low)
Access to online documentation, knowledge base, and AI-powered self-service chatbot
2. Enhanced Support (Extra Cost)
Extended support hours, including evenings and weekends
Dedicated Technical Account Manager as a single point of contact
Monthly service reviews, proactive usage reporting, and priority escalation paths
Recommended for large deployments or organisations with complex integration needs
3. Premium Support (Extra Cost)
Includes all Enhanced features plus:
Onsite support visits
Bespoke training workshops
Dedicated Cloud Support Engineer for hybrid and private cloud deployments
Quarterly strategic reviews and custom integration assistance
Guaranteed 2-hour response for critical issues
Additional Notes:
Technical Account Manager: Available in Enhanced and Premium tiers, providing continuity, proactive guidance, and coordination across support requests
Cloud Support Engineer: Available in Premium tier for hands-on assistance with infrastructure, deployment, and integration
All tiers include access to platform updates and security patches at no extra cost
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Training and Support
Online Training:
Structured onboarding modules covering platform navigation, document upload, evaluation configuration, and AI-assisted response generation
Video tutorials and step-by-step guides available on demand for self-paced learning
Live webinar sessions held regularly for new users, with recordings accessible afterwards
User Documentation:
Comprehensive online documentation covering all platform features
Includes quick-start guides, detailed feature guides, API reference, and FAQ section
Searchable knowledge base provides answers to common questions
Documentation updated with each platform release
In-Application Support:
Contextual help embedded within the interface to provide guidance relevant to the user’s task
AI-powered support chatbot assists with common queries and directs users to relevant documentation
Onsite Training (Extra Cost):
Tailored workshops delivered at the buyer’s premises for hands-on training
Sessions customised to the buyer’s specific procurement workflows and use cases
Recommended for large deployments or organisations transitioning from manual tendering processes
Dedicated Onboarding Manager:
Available in Enhanced and Premium support tiers
Guides initial setup and configuration to ensure smooth onboarding
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data Export and Migration
Self-Service Export:
Users can export data at any time through the web interface, including during and after the contract period
Export options include tender documents, evaluation results, scoring data, audit trails, and user activity logs
Data is available in standard open formats such as CSV, JSON, and PDF to ensure compatibility with other systems
API Export:
All interface-accessible data can be extracted programmatically via the API
Supports bulk data retrieval with pagination for large datasets
Enables buyers to automate migration to replacement systems
Assisted Migration:
Technical team can provide a complete data export package upon request
Includes:
Tender bank documents in original file formats
Evaluation data in CSV/JSON
System configuration settings for reference
Timelines and Access:
Buyers receive 90 days’ notice before contract end
Data remains accessible for a minimum of 30 days after contract termination for complete extraction
Data is permanently and securely deleted from all systems, including backups, within 60 days of contract end, unless otherwise agreed in writing
End-of-contract process
The contract provides buyers with a 90-day written notice before the end date, ensuring sufficient time to plan for transition. Full platform access is maintained until the final day, with self-service data export available through the web interface and API during the contract and wind-down period. Buyers retain 30 days of post-contract access solely for data extraction, after which all data, including backups, is securely deleted within 60 days, with written confirmation of destruction provided. Guidance documentation outlines the exit process and supported data formats.
Additional services are available at extra cost, including assisted migration to replacement systems with data mapping and format conversion, extended post-contract access, onsite transition workshops, and custom data export packages tailored to successor systems. Technical consultation can support detailed transition planning.
A dedicated point of contact manages the transition, coordinating with the buyer to establish an exit plan covering timelines, data requirements, and any additional services. Regular progress updates are provided throughout the wind-down period, ensuring a smooth and well-documented handover while minimising disruption to operations.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The full OpenTender AI service is accessible via mobile browsers with a responsive interface. Core functionality, including tender review, evaluation tracking, and approval workflows, is fully available on mobile devices.
Desktop Use:
Recommended for document uploads, detailed evaluation scoring, and extended content editing
Optimised for complex data tables and side-by-side document comparisons
Mobile Use:
Ideal for reviewing summaries, checking progress, approving evaluations, and managing support tickets
All data synchronises in real time across devices
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
OpenTender AI provides a web-based management interface accessible through standard browsers. Key features include:
Dashboard: Displays active tenders, evaluation progress, and recent activity
User & Role Management: Administrators can manage users, assign roles, and configure access permissions
Tender Bank: Upload, organise, and search tender documents efficiently
Evaluation Configuration: Set scoring criteria, weightings, and approval workflows
Real-Time Progress Tracking: Monitor each stage of AI-assisted analysis with human review checkpoints
Audit Trail: Records all user actions to support governance and compliance
Unified Access: All settings and data are available from a single portal
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Accessibility Compliance
Our service interface is developed following WCAG 2.2 AA guidelines, with accessibility considered throughout the design and development process. The React-based frontend uses semantic HTML elements, ARIA landmarks, and roles to provide meaningful structure for assistive technology users.
Testing Conducted Includes:
Screen Readers:
Tested with NVDA on Windows and VoiceOver on macOS
Navigation menus, form inputs, buttons, and data tables are properly labelled and announced
Dynamic content updates, including real-time analysis progress indicators, use ARIA live regions to notify screen reader users of changes
Keyboard Navigation:
Full keyboard operability verified across all interface sections
Logical tab order maintained throughout workflows
Focus indicators visible on all interactive elements
Modal dialogs trap focus appropriately and return focus on dismissal
Visual Accessibility:
Colour contrast ratios meet AA thresholds (minimum 4.5:1 for text)
Interface remains functional at 200% browser zoom
Content reflows without horizontal scrolling at standard zoom levels
No information is conveyed through colour alone
Motor Accessibility:
Interactive targets meet minimum size guidelines
No time-dependent interactions that cannot be extended
We conduct accessibility reviews with each release and prioritise reported accessibility issues for prompt resolution.
API
Yes
What users can and can't do using the API
Setup through the API:
Users can programmatically create analysis threads, configure evaluation criteria and scoring weightings, upload tender documents, and manage user accounts with role-based permissions.
Organisation settings, including tender bank configuration and workflow preferences, can be established entirely through API calls.
Changes through the API:
Submit documents for AI-powered analysis and trigger evaluation workflows
Retrieve real-time processing status via streaming endpoints
Export results
Update evaluation criteria, scoring parameters, and approval workflows
Modify user roles and permissions
Query audit trail data for compliance reporting
Full CRUD operations supported on tender bank entries
Limitations:
Initial organisation onboarding and billing setup must be completed through the web interface
AI model configuration and selection is managed by the platform and not exposed through the API
Bulk document uploads are limited to 50 files per request
API rate limits apply: 100 requests per minute for standard tier, 500 for enhanced and premium support tiers
Webhook configuration for event notifications requires initial setup through the web interface
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
What Can Be Customised:
Evaluation Frameworks: Scoring criteria, weightings, and pass/fail thresholds
Workflows: Approval stages, review checkpoints, and escalation paths
User Roles & Permissions: Configure levels and access rights
Tender Bank: Categories and document organisation
AI Output Parameters: Response tone, length, and formatting preferences
Reporting & Dashboards: Templates and dashboard views
Hybrid/Private Cloud Deployments: Infrastructure configuration to meet security and data residency requirements
How Users Can Customise:
Most customisation is self-service through the web interface
Administrators access a settings panel to configure evaluation frameworks, workflows, and user permissions
AI output preferences are adjusted via intuitive controls within the application
API-based customisation is available for buyers integrating OpenTender AI into existing procurement systems
Bespoke customisation, such as private cloud deployment or custom integrations, is delivered by our technical team in collaboration with the buyer
Who Can Customise:
Organisation Administrators: Configure all self-service settings
Standard Users: Personalise workspace preferences and AI output settings within administrator-defined boundaries
Technical Team: Handles bespoke customisation requiring platform changes, coordinated through the assigned Technical Account Manager

Scaling

Independence of resources
OpenTender AI uses a multi-tenant architecture with logical data isolation ensuring each buyer's data is completely separate. Resource allocation is managed through AWS ECS Fargate with auto-scaling, automatically provisioning additional compute capacity during demand spikes so no single buyer's usage impacts others. Database queries are isolated per organisation with connection pooling to prevent resource contention. AI processing tasks are queued independently per buyer with dedicated rate limits. Performance monitoring tracks per-tenant resource consumption, triggering automatic scaling before service degradation occurs. Service level targets apply equally to all buyers regardless of overall platform demand.

Analytics

Service usage metrics
Yes
Metrics types
Platform usage metrics include: number of active users and login frequency, tender documents uploaded and processed, evaluations completed and average scoring times, AI-assisted responses generated and edited, API call volumes and response times, storage utilisation across the tender bank, and support ticket volumes by priority and resolution time. Administrative dashboards display organisation-wide activity trends. Per-user activity tracking supports internal governance and licence management. System performance metrics cover platform availability, processing throughput, and error rates. All metrics can be filtered by date range, user, project, and department.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export data through three methods. The web interface provides an export section where users select the data they need — tender documents, evaluation results, scoring data, or audit trails — and download in CSV, JSON, or PDF formats. The API enables programmatic bulk extraction for automated migration to replacement systems. On request, our technical team can prepare a complete data package containing all organisation data in structured, open formats with original documents in their uploaded file formats. All export methods are available throughout the contract at no additional cost.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • JSON
  • PDF
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • PDF
  • PDF/A
  • DOCX
  • XLSX
  • JSON

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Service Level Agreement:
OpenTender AI guarantees 99.9% platform availability, measured monthly excluding planned maintenance windows. This equates to a maximum of approximately 43 minutes unplanned downtime per month.

Planned Maintenance:
Scheduled maintenance is performed during low-usage periods (weekends, 00:00–06:00 GMT/BST) with a minimum of 5 business days' advance notice. Planned maintenance is excluded from availability calculations.

Monitoring:
Platform availability is monitored continuously using automated health checks. Real-time status information is accessible to all users via a public status page. Users are notified promptly of any service disruption through email and the status page.

Service Credits:
If monthly availability falls below the guaranteed level, service credits are applied automatically to the buyer's next invoice:
- 99.0% – 99.9%: 5% service credit
- 95.0% – 99.0%: 10% service credit
- Below 95.0%: 25% service credit

Service credits are calculated as a percentage of the monthly fees for the affected period.
Claims must be submitted within 30 days of the affected month. Service credits are capped at 25% of the monthly fee and represent the sole remedy for availability failures.
Approach to resilience
OpenTender AI is deployed on AWS infrastructure across multiple Availability Zones within the EU-West-2 (London) region, providing resilience against individual datacentre failures.

Compute Resilience: Application containers run on AWS ECS Fargate with auto-scaling across multiple Availability Zones. If one zone becomes unavailable, traffic automatically routes to healthy instances in remaining zones with no manual intervention required.

Data Resilience: MongoDB Atlas provides automated replication across three Availability Zones with automatic failover. Point-in-time recovery enables database restoration to any moment within the retention window. Document storage on AWS S3 provides 99.999999999% (11 nines) durability with automatic cross-zone replication.

Network Resilience: AWS CloudFront CDN distributes static content globally, reducing single points of failure.
Application Load Balancers perform continuous health checks and route traffic only to healthy instances.

Backup and Recovery: Automated daily backups are stored in a separate AWS region for disaster recovery.
Recovery Point Objective (RPO): 24 hours.
Recovery Time Objective (RTO): 4 hours.

Monitoring: Continuous automated monitoring detects failures and triggers self-healing processes including instance replacement and traffic rerouting.

Detailed resilience architecture documentation is available on request under NDA.
Outage reporting
Public Status Dashboard: A publicly accessible status page displays real-time platform health, current service status for all components, and historical uptime data. The dashboard shows active incidents, ongoing maintenance, and past incident timelines with resolution details. No login is required to view the status page.

Email Alerts: Registered users receive automatic email notifications when incidents are detected, updated, and resolved. Administrators can configure notification preferences to control which team members receive alerts. Planned maintenance notifications are sent a minimum of 5 business days in advance. Incident emails include severity level, affected components, estimated resolution time, and updates as the situation progresses.

API: A status API endpoint provides programmatic access to current and historical service status data, enabling buyers to integrate outage information into their own monitoring dashboards and alerting systems. The API returns structured JSON data including component status, active incidents, and scheduled maintenance windows.

Incident Communication: Each outage triggers a documented incident response process. Post-incident reports are published within 5 business days of resolution, detailing root cause, timeline, impact, and preventive measures. Reports are accessible through the status dashboard and provided directly to affected buyers.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Management interfaces are protected by role-based access controls with three tiers: administrators, managers, and standard users.

Administrators control user provisioning, security settings, and system configuration.
Managers oversee evaluations and approve workflows.
Standard users access assigned tenders only. All management access requires multi-factor authentication.

Administrative actions are recorded in tamper-proof audit trails. Support channels verify user identity before processing requests, with sensitive operations requiring additional verification from an authorised administrator. Access reviews are conducted quarterly to remove inactive accounts and validate permissions. The principle of least privilege ensures users only access functionality required for their role.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Our security governance is led by our CTO who holds board-level responsibility for information security across all services. We maintain a documented information security policy reviewed annually, covering access control, data protection, incident response, and secure development practices. We hold Cyber Essentials certification and comply with the Software Security Code of Practice. Security risks are assessed and recorded in a risk register reviewed quarterly. All staff complete security awareness training on joining and annually thereafter. We conduct annual penetration testing through a CREST-accredited provider and maintain an vulnerability disclosure process for responsible reporting.
Information security policies and processes
Policies:
We maintain a suite of information security policies including: Information Security Policy, Acceptable Use Policy, Access Control Policy, Data Protection and Privacy Policy, Incident Response Plan, Business Continuity and Disaster Recovery Plan, Secure Development Policy, and Supplier Management Policy. All policies are approved by the CTO and reviewed annually or following significant incidents.

Reporting Structure:
The CTO holds board-level responsibility for information security and reports directly to the Managing Director. Security incidents are escalated immediately to the CTO, who has authority to mobilise resources and make decisions on containment and remediation. Monthly security reviews are conducted covering risk register updates, policy compliance, and emerging threats.

Ensuring Compliance:
All staff complete mandatory security awareness training during onboarding and annually thereafter. Secure development practices are enforced through code review processes, automated security scanning in our CI/CD pipeline, and dependency vulnerability monitoring. Access to production systems follows the principle of least privilege with multi-factor authentication enforced for all accounts. Annual penetration testing by a CREST-accredited provider validates our security controls. Audit trails record all system access and administrative actions.

Non-compliance with security policies is addressed through our disciplinary process.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All infrastructure and application components are tracked through version-controlled repositories using Git. Every change follows a defined process: code is developed on feature branches, reviewed through pull requests, and tested via automated CI/CD pipelines including security scanning before deployment. Changes are assessed for security impact during code review, with mandatory review for changes affecting authentication, data handling, or access controls.

Production deployments are automated, auditable, and reversible through container-based infrastructure. Infrastructure configuration is managed as code, ensuring environments are reproducible and trackable. A change log records all production deployments with timestamps, authors, and descriptions.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Threat Assessment:
Automated dependency scanning monitors all software libraries for known vulnerabilities. Our CI/CD pipeline runs security checks on every deployment. Annual CREST-accredited penetration testing identifies application-level vulnerabilities. Infrastructure is continuously monitored through AWS security tools including GuardDuty and Inspector.

Patching:
Critical vulnerabilities are patched within 24 hours. High severity within 7 days. Medium and low within 30 days. Emergency patches follow an expedited deployment process outside normal release cycles.

Threat Intelligence Sources:
NCSC advisories, CVE databases, GitHub security alerts, AWS security bulletins, and AI provider security notifications.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Identifying Compromises:
Continuous monitoring through AWS CloudTrail, GuardDuty, and CloudWatch detects suspicious activity including unauthorised access attempts, unusual API patterns, and anomalous network behaviour. Application-level logging tracks all authentication events, permission changes, and data access. Automated alerts trigger when predefined thresholds are breached.

Response:
Security incidents follow a documented response plan: detect, contain, eradicate, recover, and review. The CTO is notified immediately and coordinates response. Affected buyers are informed within 24 hours of confirmed incidents.

Response Times:
Critical incidents: response within 1 hour. High severity: within 4 hours. Post-incident reports published within 5 business days.
Incident management type
Supplier-defined controls
Incident management approach
Pre-defined Processes:
Documented runbooks cover common incidents including service outages, security breaches, data loss, authentication failures, and third-party provider disruptions. Each runbook defines severity classification, escalation paths, containment steps, and communication templates.

Reporting Incidents:
Users report incidents through email, phone, web chat, or the ticketing portal during support hours. The public status page enables users to check for known issues at any time. All reported incidents are acknowledged and assigned a severity level and tracking reference.

Incident Reports:
Post-incident reports are published within 5 business days covering root cause, timeline, impact, and preventive actions.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
4%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
12%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
7920a4dd-1ae6-4170-8917-1b0f7403b8d5
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at admin@nat-quest.com. Tell them what format you need. It will help if you say what assistive technology you use.