Gen AI Bots for E-Government Services
Tovie Platform is a cloud-based conversational and generative AI service that enables public sector organisations to deliver automated chat and voice services for citizens and staff. It supports self-service, assessments, outreach, and internal assistance through low-code configuration, omni-channel delivery, secure access controls, real-time analytics, and accessibility-compliant interfaces.
Features
- Real-time analytics with exportable dashboards and interaction data.
- Multilingual, multi-device access with responsive, accessible interfaces.
- Flexible integration with REST, SOAP, and internal APIs.
- Project versioning with import/export tools for AI models.
- Supports major LLMs and Microsoft Cognitive Services.
- Low/no-code workflow builder with AI-assisted orchestration.
- Omni-channel support including web, voice, and social messaging.
- Robust, documented API for full platform feature access.
- Granular user roles with RBAC for operational security.
- Compliant with WCAG 2.1 AA and EN 301 549.
Benefits
- Enable residents to access services 24/7 via automation.
- Reduce staff workload by automating frequent enquiries.
- Reach diverse communities with multilingual & empathetic tuning
- Escalate complex cases smoothly to human advisors as needed.
- Integrate seamlessly with existing CMS, CRM, and case systems.
- Maintain compliance with audit trails and data protection policies.
- Monitor service performance with real-time usage insights.
- Apply council branding consistently across all resident touchpoints.
- Ensure secure data handling with UK-based cloud hosting.
- Scale capacity during peak periods without service disruption.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 3 3 1 7 4 3 4 5 1 4 4 0 6 2
Contact
TOVIE AI LIMITED
Joshua Kaiser
Telephone: 0204 577 1007
Email: bd@tovie.ai
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI software services
- Conversational AI Software Services
- Generative AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
The service requires a stable internet connection and access to a supported modern web browser.
Availability, support levels, and planned maintenance are defined in the service level agreement (SLA). Maintenance is normally carried out during off-peak hours.
Integration with third-party systems depends on the availability and stability of those external services.
Custom functionality beyond standard configuration may require additional delivery time and commercial agreement. - System requirements
-
- Latest supported versions of Chrome, Firefox, Safari, or Edge recommended.
- API access required for integrations.
- Active internet connection required.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support requests submitted via email receive an initial response within the same working day, Monday to Friday.
Emails received at weekends or on public holidays are responded to on the next working day.
Support requests are logged and tracked internally to ensure visibility and resolution. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Core Support
Provided as standard with all licences. Core Support gives customers access to Tovie AI support by email during UK business hours. Response and resolution targets are managed in line with the SLA. Support outside these hours is prioritised based on issue severity.
Enhanced Support
Enhanced Support is designed for customers with on-premise deployments or specific information governance, security, or operational policy requirements. This option provides closer operational support, faster response targets, priority handling, and access to a named Tovie technical contact. Support processes and communication methods can be aligned with the customer’s internal governance and assurance frameworks.
Onsite Support
Onsite support is available as an additional service. This provides in-person assistance for delivery, configuration, troubleshooting, training, or service review activities. Scope, duration, and cost are agreed in advance based on project requirements. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Tovie AI supports users through a structured onboarding process designed to enable rapid and confident service adoption. Support includes guided setup, initial configuration assistance, and access to user documentation covering platform features, configuration, and best practice.
Training can be provided remotely through online sessions, and onsite training is available where required as an additional service. Ongoing guidance is available to project owners and authorised project collaborators to support continued service use and improvement.
This approach allows organisations to adopt the service in line with their delivery model, technical capability, and governance requirements. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, users can export their data directly from the platform in commonly used, non-proprietary formats. Where required, users may also request Tovie AI to provide a managed data export.
Data extraction can include configuration data, conversation logs, and reporting outputs.
Users may also request secure deletion of their data following successful extraction, in line with agreed retention policies and regulatory obligations. - End-of-contract process
-
At the end of the contract, buyer access to the service is closed in line with agreed security procedures. Users may export their data directly from the platform or request a managed export from Tovie AI. Following confirmation of successful extraction, data is securely deleted in accordance with the buyer’s instructions, retention policies, and regulatory requirements.
The contract price includes standard offboarding activities, including access termination, self-service data export, and secure data deletion.
Additional support, such as managed data extraction, format transformation, migration assistance, or extended transition support, is available as an optional, chargeable service where required.
This approach ensures buyers can exit the service in a controlled, secure, and transparent manner. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The service is designed using a responsive, mobile-first approach and is fully usable on smartphones, tablets, and desktop devices through modern web browsers.
On mobile devices, the interface is optimised for smaller screens, with simplified navigation, touch-friendly controls and vertically stacked content to support ease of use and accessibility. On desktop the same functionality is available with wider layout, additional on-screen context and faster navigation between sections.
There is no functional loss between mobile and desktop. All core features, data, and user journeys are available across both environments. Layout and interaction patterns adjusted to suit screen size and input method. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
The service is delivered through a secure, web-based conversational interface, including an integrated webchat experience accessible via modern browsers on mobile, tablet, and desktop devices. In addition, the service supports optional omni-channel access through platforms such as WhatsApp and other digital messaging channels, depending on customer configuration.
All channels connect to the same underlying service logic and data model, ensuring consistent user journeys, responses, and outcomes. Council administrators access a separate secure management interface for configuration, content management, reporting, and service oversight. No local installation is required. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
The interface has been tested using common assistive technologies including screen readers, keyboard-only navigation, browser zoom, and high-contrast display settings across mobile and desktop devices. Testing focused on reading order, form labelling, focus management, error messaging, and conversational flow within the webchat interface.
Feedback from accessibility checks and user interactions has been used to improve wording, layout, and navigation. Accessibility testing is repeated as part of ongoing service improvement and release review processes. - API
- Yes
- What users can and can't do using the API
-
The Tovie Platform provides a secure, REST-based API that enables customers to integrate, configure, and operate conversational bots within their digital environments.
Using the API, customers can create and manage bots, configure digital channels (such as webchat and messaging platforms), send and receive conversational messages, and retrieve conversation history and analytics data. The Chat Adapter APIs support connection to multiple communication channels while maintaining consistent conversation logic.
Through the NLU APIs, customers can create, update, import, and manage intents, entities, and training data to continuously improve language understanding. Configuration APIs allow updates to content structures, routing rules, and operational parameters.
Live-agent handover APIs enable conversations to be transferred to human operators with full context and event tracking.
Core platform logic, security controls, and governance settings are configured through the Tovie Platform’s no-code / low-code management interface rather than directly through the API, ensuring controlled change management while still allowing rapid service configuration.
Rate limits, access controls, and versioned endpoints protect performance and data integrity. Documentation and onboarding support are provided. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The Tovie Platform can be customised by project owners and authorised project collaborators to meet organisational and service delivery requirements.
What can be customised
Project owners and authorised project collaborators can customise:
Conversation flows, questions, and responses
Language understanding models (intents and entities)
Digital channels and user journeys
Front-end presentation through custom webchat or embedded interfaces
Logging, monitoring, and reporting outputs
Integration connections to external systems and data sources
AI and large language model providers
How users can customise
Customisation is carried out through the Tovie Platform’s no-code and low-code management interface. Where required, integrations and extensions can be configured using standard API connections.
Who can customise
Customisation can be performed by:
Project owners
Authorised project collaborators
This approach supports flexible configuration while maintaining governance, security, and service stability.
Scaling
- Independence of resources
-
The service is designed to isolate customer workloads so one customer’s usage does not affect another’s service performance.
For Tovie-hosted cloud deployments, logical separation, resource controls, and traffic management ensure consistent performance across tenants. Capacity is monitored and scaled to maintain agreed service levels.
For customer-managed deployments on the buyer’s own infrastructure, resources are fully dedicated to the buyer’s environment. This provides complete isolation and allows control over capacity, scaling, and performance in line with governance policies.
In both deployment models, performance is monitored to maintain reliability during periods of high activity.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides usage and performance metrics including conversation volumes, user engagement, channel usage, response times, completion rates, and error or fallback events. Metrics can be viewed at project, bot, channel, and session level. Users can drill into individual conversations and time periods to support operational monitoring, service improvement, and reporting.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
-
The service protects data at rest in line with UK NCSC cloud security principles for asset protection and resilience.
Data is stored on encrypted storage using industry-standard encryption. Encryption is applied to primary storage and backups. Stored data access is controlled using role-based access controls and audited administrative access.
Customer data is logically segregated to prevent unauthorised access between tenants. Backup data is protected using the same encryption and access controls as production data.
For customer-managed deployments in the buyer’s own environment, data protection controls are applied in accordance with the buyer’s governance policies and NCSC-aligned security requirements. - Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Users can export their data directly through the Tovie Platform using built-in export tools. Data can be exported at project level or for specific datasets, such as conversation sessions, configuration content, and reporting outputs.
Exports are provided in commonly used, non-proprietary formats to support reuse, analysis, or migration to other systems. Where required, users can also request a managed export from Tovie AI.
This approach ensures buyers retain full access to their data throughout and at the end of the contract. - Data export formats
-
- CSV
- Other
- Other data export formats
- ZIP (containing other non-proprietary formats)
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- ZIP (containing other non-proprietary formats)
- Any other format uploaded by the buyer into their project.
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Tovie AI guarantees 99% availability for dialogue (bot) services in line with the service level agreement (SLA).
Availability is measured across production service components and excludes planned maintenance periods, which are communicated in advance and normally scheduled during off-peak hours.
Service performance and availability are continuously monitored and reported through the platform and service reporting processes.
If the guaranteed availability level is not met, buyers are entitled to service credits as defined in the SLA. The calculation method and thresholds are set out in the SLA.
Availability targets and service arrangements can be adjusted by agreement to meet specific buyer operational or governance requirements. - Approach to resilience
-
The Tovie Platform is designed in line with the UK National Cyber Security Centre (NCSC) cloud security principles for asset protection and resilience.
For Tovie-hosted deployments, the service is operated on resilient UK-based cloud infrastructure. Unless requested otherwise by the buyer, services are deployed across UK South and UK West regions to support regional redundancy and service continuity. Data and services are replicated across availability zones, with automated recovery mechanisms to reduce the risk of single-point failure.
For customer-managed deployments on the buyer’s own cloud infrastructure, resilience is implemented in line with the buyer’s chosen architecture and governance requirements.
The platform supports automated backups, monitored health checks, and documented recovery procedures. Disaster recovery processes are tested as part of operational governance.
Tovie AI is Cyber Essentials Plus certified and operates security controls aligned with SOC 2 principles, supporting secure and resilient service operation.
Further architectural and resilience details can be provided to buyers on request. - Outage reporting
-
Service availability is monitored continuously using Tovie AI’s internal logging and monitoring systems, including security and operational monitoring.
Outages and service issues are reported through:
Email alerts sent to nominated project owners and authorised project collaborators.
API responses, where service endpoints return appropriate error codes (for example, service unavailable) during an outage.
Custom logging and monitoring integration, allowing customers to forward service events into their own monitoring, security, or information governance platforms.
Internal logs and alerts are reviewed by Tovie AI operations teams to support rapid detection, investigation, and resolution of service issues.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
-
Authentication requirements depend on user role.
End users interacting with chatbots do not require authentication unless configured by the buyer.
Platform users (project owners and authorised project collaborators) must authenticate using username and password with enforced minimum password length of 12 characters, complexity controls, and account protection measures.
Access is role-based and aligned with buyer governance requirements. - Access restrictions in management interfaces and support channels
-
Access to management interfaces is restricted to authenticated platform users with role-based permissions. Project owners control user access, roles, and privileges. Access is granted on a least-privilege basis and reviewed regularly.
Support channels are restricted to authorised project owners and authorised project collaborators. Requests are verified against registered contact details before being actioned.
Administrative actions are logged and monitored. Access is revoked immediately when users change role or leave a project. These controls ensure that only approved users can manage services or raise support requests. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- Management access is authenticated using unique user accounts with enforced minimum 12-character passwords, complexity controls, account lockout protection, and role-based access controls. Access is logged and monitored in line with security governance requirements.
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
Tovie AI operates a formal information security management framework aligned with ISO/IEC 27001 and Cyber Essentials Plus requirements.
Information security policies cover access control, data protection, incident management, risk management, supplier assurance, business continuity, and secure development. Policies are reviewed regularly and approved by senior management.
Security governance is overseen by the leadership team, with defined responsibility for information security management, risk ownership, and compliance monitoring. Operational teams follow documented procedures and receive security awareness training.
Compliance is supported through access controls, logging and monitoring, internal reviews, and external assurance activities. Security incidents and risks are formally recorded, reviewed, and escalated in line with defined reporting and response processes.
This approach ensures consistent application of security controls across all service operations. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Tovie AI uses formal configuration and change management processes to protect service stability and security. Service components are tracked throughout their lifecycle using a centralised configuration and change register, supported by audit logs.
All changes are reviewed and approved by a cross-functional team. Each change is assessed for security, data protection, and operational impact before approval. Approved changes are tested in controlled environments prior to deployment.
Deployment activities are documented, and post-change checks confirm successful implementation. Records are retained for audit, governance, and continuous improvement purposes. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Tovie AI operates a formal vulnerability management process to protect services from known and emerging threats.
Potential threats are identified through automated vulnerability scanning, security monitoring, and review of trusted threat intelligence sources. Information is sourced from the Microsoft Security Response Centre (MSRC), vendor advisories, and security community alerts.
Vulnerabilities are assessed for severity and potential service impact. Security updates and patches are deployed using integrated deployment systems, with critical patches prioritised for rapid deployment.
Patch timelines are managed according to risk level, with testing performed before release to maintain service stability. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Tovie AI uses centralised logging, automated alerting, and security monitoring tools to identify potential compromises, including unusual access patterns, failed authentication attempts, privilege changes, and abnormal system behaviour.
When a potential compromise is detected, alerts are reviewed by operational and security personnel. Incidents are investigated, contained, and escalated through defined incident response procedures, including evidence collection and impact assessment.
Critical security incidents are responded to immediately, with investigation and containment initiated as soon as alerts are confirmed. Response times are prioritised based on incident severity in line with documented incident management processes. - Incident management type
- Supplier-defined controls
- Incident management approach
- We maintain documented incident management procedures for common security and privacy events, including phishing, data breaches, unauthorised access, and device loss. Users report incidents immediately to their manager and the Information Security team via a dedicated security email or approved reporting tools. All incidents are triaged, contained, investigated, and remediated by the security team. Incidents are logged, reviewed, and corrective actions tracked. Incident reports are provided to internal stakeholders and, where required, to customers or data controllers without undue delay.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We provide a free license for POCs with prospective customers for 3 months.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 6768040c-b80d-4eae-80de-b1630afdb3a7
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 4fad4942-e540-4c77-9815-d34134dca2ac
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-