Erisna Platform
The Erisna Platform helps teams understand their data, monitor and fix data quality issues, and use their data with confidence - while moving faster and staying compliant.
Features include data governance, data cataloguing, data observability, data quality checks, data lineage, compliance tagging, data stewardship, business rules and business glossary.
Features
- Data Catalogue
- Data Validation & Cleansing Reports
- Business Rules
- Data Observability
- Data Lineage and Mapping
- Compliance Tagging
- Data Ownership and Stewardship Tagging
- PII Detection
- Database Integrations
- Developer API
Benefits
- Find trusted datasets quickly with searchable, curated data catalogue
- Improve reporting accuracy using automated validation and cleansing insights
- Standardise governance by enforcing consistent business rules across teams
- Detect data issues early and resolve incidents faster
- Understand impacts of change with end-to-end lineage mapping
- Prove compliance faster with policy-based tagging and audit trails
- Assign clear owners and stewards to improve accountability
- Reduce privacy risk by identifying and classifying PII automatically
- Connect existing databases quickly without disrupting live services
- Integrate and automate workflows using secure, well-documented developer APIs
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 5 6 9 8 3 9 2 9 5 5 9 2 1 5
Contact
Erisna
Ebube Abara
Telephone: 07871083818
Email: ebube.abara@erisna.com
About your service
- Service categories
-
Application Development and Deployment
Data management
Database administration and development
- Data Modelling
Data integration and intelligence
- Data Ingestion and Transformation Software
- Data Quality Software
- Metadata Management Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Databricks, Snowflake, Microsoft Fabric, Google Cloud BigQuery, Amazon (AWS) Redshift, SQL Server, PostgreSQL, Oracle DB, Azure SQL, Azure Cosmos DB, MongoDB, SAP HANA, Azure Synapse Analytics, Microsoft Excel, Microsoft Teams and Slack.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- Planned maintenance for the Public Cloud version of the Erisna Platform typically occurs on weekends (i.e. Saturdays or Sundays).
- System requirements
-
- Erisna Data Catalogue software licence
- Erisna Data Observability software licence
- Erisna Business Glossary software licence
- Erisna Developer API software licence and API key
- Erisna Platform Full Suite software licence
- Memory >= 8 GB RAM (Private Cloud VM)
- Storage >= 64 GB (Private Cloud VM)
- CPU Cores >= 1 physical / 2vCPUs (Private Cloud VM)
- SSL certificate for secure https:// connections (Private Cloud VM)
- OS: Windows Server, Linux (Ubuntu, CentOS, Fedora, Debian)
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 24 hours in working hours (9h to 17h) and days (Monday to Friday). Response times differ on weekends and bank holidays.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
BASIC SUPPORT: email only (£0).
STANDARD SUPPORT: basic support + ticket support + phone + chat (from £25/user/month, minimum £2,500/month).
ENHANCED SUPPORT: standard support + shared support team + agreed SLA + reporting (no named Technical Account Manager / Cloud Support Engineer) (£4,500/month).
DEDICATED SUPPORT: enhanced support + dedicated technical account manager + fractional cloud support engineer (£14,000/month).
MISSION-CRITICAL SUPPORT: dedicated support + dedicated cloud support engineer + higher response-time commitments + extended-hours/rota + greater reserved engineering time (£32,500/month). - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We help users get started with the service through a structured onboarding and enablement approach. We provide a getting-started guide and user documentation to support initial setup, configuration, and day-to-day use. We deliver virtual training sessions for administrators and end users, covering core workflows, governance and permissions, integrations, and operational best practices.
Where required, we offer on-site training (chargeable) tailored to the buyer’s operating model and team roles. Training can be delivered as role-based sessions (for example: platform administrators, data owners/stewards, engineering teams, and service managers) and is supported with practical walkthroughs and Q&A.
During onboarding, we also provide implementation support to help buyers connect priority systems, validate configuration, and confirm the service is working as expected before wider rollout. Buyers can access ongoing guidance through our support channels, and we can run follow-up sessions after go-live to reinforce adoption and introduce advanced capabilities. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Users can extract their data at the end of the contract by requesting an export from Erisna Support. Data exports are provided as a secure, encrypted package and delivered via buyer-approved secure transfer; any passwords/keys are shared out-of-band. The export contains machine-readable files in commonly used formats such as CSV and JSON (Excel and Parquet where appropriate), together with supporting metadata needed to interpret the export (for example: schemas/field definitions and timestamps).
Exports can be scoped to the buyer’s requirements (for example: all datasets, metadata catalogue entries, lineage, validation results, tags, users/roles and audit logs). We agree on the scope and delivery method with the buyer, then deliver the export securely (e.g., via an encrypted download link or a buyer-approved secure file transfer).
Where requested, we can also provide a short handover note describing the export contents and how to import them into another system. - End-of-contract process
-
At the end of the contract, we follow a controlled offboarding process agreed with the buyer. We will:
1. Confirm the contract end date and offboarding plan (including export scope, delivery method and timelines).
2. Provide an end-of-contract data export (as requested) and validate successful delivery.
3. Revoke user access and disable integrations/tokens after the agreed final service date.
4. Decommission the buyer’s tenancy/environment and securely delete customer data in line with the contract and any agreed retention period.
5. Provide confirmation of decommissioning/deletion on request.
Included in the contract price:
- Standard offboarding support and coordination.
- One end-of-contract data export in common machine-readable formats (e.g., CSV/JSON; Excel where appropriate) delivered securely.
- Access removal and environment decommissioning.
Additional cost (if required):
- Multiple or repeated exports, bespoke export formats, or complex data transformation/mapping.
- Extended data retention beyond the contracted retention period.
- Migration/implementation services into a new platform, bespoke integrations, or onsite support.
- Standard/enhanced/dedicated/mission-critical dedicated support outside the contracted service scope or after the contract end date. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The Erisna Platform's service interface is a web-based UI / portal, and an API.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
We have not yet carried out formal usability testing sessions with users who rely on assistive technologies.
Accessibility testing is currently carried out through a combination of automated testing tools and internal manual checks aligned to WCAG 2.2 AA. This includes keyboard-only navigation testing, colour contrast checks, and semantic HTML validation.
Accessibility is considered throughout design and development, and issues identified through customer feedback or internal review are prioritised for remediation. We are committed to involving users of assistive technologies in future testing cycles as part of our ongoing accessibility improvements. - API
- Yes
- What users can and can't do using the API
-
Users can programmatically configure, read from and populate the Erisna Platform by creating and managing core governance objects and relationships exposed by the API reference.
Users call the API using the published base URL and include an API key in the X-Api-Key header.
Users cannot perform actions that are not exposed in the API recernce section.
Users cannot access or change anything that they are not authorised to access with their API key. - API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise the Erisna Platform service to fit their environment, integrations, and governance requirements. We tailor deployments for cloud, hybrid, or on-prem, including environment provisioning, authentication, and configuration.
What can be customised: deployment topology; SSO/authentication and role-based access controls; API token provisioning; audit logging/monitoring; data sensitivity tagging and encryption guidance; and platform integrations with the buyer’s data stores and tools (e.g., warehouses/lakehouses, relational/document databases, ETL/ELT, BI, communications, and security).
How users can customise: buyers can configure environments and governance settings and enable integrations during implementation. Where requirements are bespoke, we build custom workflows and automations, including custom ingestion pipelines, webhook/event triggers, API-based orchestration with internal systems, and automated policy enforcement.
Who can customise: the buyer’s nominated administrators/data engineering team can manage configuration and governance settings; Erisna’s Implementation & Integration specialists can deliver and maintain bespoke integrations, workflows, and security/governance setup in collaboration with the buyer.
Scaling
- Independence of resources
- We protect buyers from “noisy neighbour” effects through tenancy isolation and capacity controls. Each buyer’s data and workloads are logically segregated, with per-tenant quotas and rate limits on APIs and background processing, so that no tenant can consume disproportionate resources. We monitor performance and availability (for example latency, error rates, and processing backlogs) with alerting and operational procedures to manage spikes in demand, including throttling and prioritisation where appropriate. Where additional isolation is required, we can provide a dedicated environment for the buyer to separate resources from other tenants.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide standard service usage metrics via exportable reports (CSV/JSON) to support operational management and audit needs. Metrics include: active users and logins; feature usage and adoption by team/role; catalogue activity (assets registered, views); data quality/observability activity (rules executed, pass/fail rates); integration and job health (connector status, last run, success/failure counts); API usage (requests, errors, latency); and support metrics (ticket volumes, response/resolution times by severity). Metrics can be filtered by date range, environment and user group.
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data in the Erisna Platform in CSV format. Alternatively, users can export their data by contacting Erisna Support. Data exports are provided as a secure, encrypted package and delivered via buyer-approved secure transfer; any passwords/keys are shared out-of-band.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- EXCEL
- PARQUET
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
1. The service is not available and there is no alternative for users to carry out the activities. (Diagnosis Deadline: 1 hour / Solution Timeframe: 6 hours).
2. Some of the service is seriously affected, taking longer than normal to complete. (Diagnosis Deadline: 2 hours / Solution Timeframe: 8 hours).
3. An entire functionality or part of it is unavailable, affecting some specific End-user process. Alternatives are available to get the job done, although other activities may be affected while waiting for the problem to be resolved. (Diagnosis Deadline: 1 day / Solution Timeframe: 2 days).
4. A functionality is partially working, affecting some business processes, but not compromising the progress of the activities. There are alternatives available to perform the work. (Diagnosis Deadline: 2 days / Solution Timeframe: 5 days). - Approach to resilience
- Information is available on request.
- Outage reporting
- Public dashboard on https://status.erisna.com/.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is restricted using RBAC and least privilege. Administrative functions are limited to authorised buyer administrators and approved Erisna personnel. Authentication is enforced via SSO/MFA where supported, with strong password policies as fallback. Privileged actions are logged and reviewed, and production access is time-bound and approval-based, with elevated permissions required for sensitive operations.
Support channels are controlled through verified user accounts and tenant context for tickets/chat. Phone support uses caller verification and agreed escalation contacts. We only disclose sensitive information after confirming identity and authorisation, and all support interactions are recorded in the ticket history for audit. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Certified
- Information security policies and processes
-
We operate an information security management framework aligned to recognised good practice (for example Cyber Essentials principles) covering: secure configuration, user access control, malware protection, security update management (patch management), firewalls, access control and least privilege; and change management; secure software development; vulnerability management and penetration testing; incident management and breach reporting; logging and monitoring; business continuity and disaster recovery; data classification, retention and secure disposal; supplier/third-party security assurance; and HR security (onboarding/offboarding, acceptable use).
Regarding the reporting structure, overall accountability sits with senior leadership. Day-to-day security is owned by a nominated security lead who reports to the CEO (and escalates material risks/incidents to leadership). Data protection matters are managed with appropriate oversight (for example, via a DPO function).
To ensure policies are followed, policies are documented and reviewed at least annually or following a significant change. Staff complete mandatory security training and regular refreshers. Controls are enforced through role-based access, approvals for privileged actions, audit logging, periodic access reviews, and change controls. Compliance is monitored through internal checks, risk register reviews, and incident post-mortems, with corrective actions tracked to closure. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We use controlled configuration and change management to maintain service integrity. Service components (for example, application releases, infrastructure configuration, integrations and customer-specific settings) are versioned and tracked throughout their lifecycle using source control and change records, with an audit trail of who changed what and when. Changes follow a defined workflow (request, review, test, approve, deploy) and are deployed using repeatable procedures with rollback plans.
Security impact is assessed through risk-based review, including peer review, approval for privileged changes, dependency checks, and pre-release testing. High-risk changes require additional security sign-off and may trigger customer communication. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We use a risk-based vulnerability management process covering application, dependencies and hosting configuration. We assess threats through continuous monitoring, automated scanning, periodic penetration testing and security review of changes. Findings are triaged by severity, then tracked to remediation with ownership and due dates.
Patch deployment is prioritised by severity: critical vulnerabilities are treated as emergency changes and patched as soon as practicable (typically within 24–72 hours), high within days, and medium/low via planned release cycles. Threat intelligence comes from vendor advisories, cloud provider security bulletins, NCSC guidance, and security tooling alerts. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We identify potential compromises by collecting and reviewing security logs (e.g., authentication events, privilege changes, administrative actions, and API activity) and alerting on suspicious patterns, such as unusual login behaviour, repeated failures, or unexpected access to sensitive data.
If a compromise is suspected, we follow an incident response process to confirm and scope the impact, contain the issue (e.g., disable accounts/tokens and isolate affected components), remove the cause, restore service, and complete a post-incident review with corrective actions.
We begin triage within 1 hour for high-severity alerts and provide updates in line with agreed SLAs. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We follow a documented incident management process covering detection, triage, containment, resolution, recovery and post-incident review. We maintain pre-defined runbooks for common events (e.g., service degradation, failed integrations/jobs, access issues, and suspected security incidents) with escalation paths and communications templates.
Users can report incidents via email, support portal/chat, or by phone for high-severity issues. Incidents are prioritised by severity and managed to agreed response and update SLAs, with clear ownership and escalation to engineering where required.
We provide incident reports for significant incidents, including timeline, customer impact, root cause, corrective/preventative actions, and any required follow-up, shared securely with the buyer. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 3%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 8%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 00c6155b-2cd4-485f-b6a2-dfaf5bf1a253
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-