Skip to main content

Help us improve the Digital Marketplace - send your feedback

Erisna

Erisna Platform

The Erisna Platform helps teams understand their data, monitor and fix data quality issues, and use their data with confidence - while moving faster and staying compliant.

Features include data governance, data cataloguing, data observability, data quality checks, data lineage, compliance tagging, data stewardship, business rules and business glossary.

Features

  • Data Catalogue
  • Data Validation & Cleansing Reports
  • Business Rules
  • Data Observability
  • Data Lineage and Mapping
  • Compliance Tagging
  • Data Ownership and Stewardship Tagging
  • PII Detection
  • Database Integrations
  • Developer API

Benefits

  • Find trusted datasets quickly with searchable, curated data catalogue
  • Improve reporting accuracy using automated validation and cleansing insights
  • Standardise governance by enforcing consistent business rules across teams
  • Detect data issues early and resolve incidents faster
  • Understand impacts of change with end-to-end lineage mapping
  • Prove compliance faster with policy-based tagging and audit trails
  • Assign clear owners and stewards to improve accountability
  • Reduce privacy risk by identifying and classifying PII automatically
  • Connect existing databases quickly without disrupting live services
  • Integrate and automate workflows using secure, well-documented developer APIs

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ebube.abara@erisna.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 5 6 9 8 3 9 2 9 5 5 9 2 1 5

Contact

Erisna Ebube Abara
Telephone: 07871083818
Email: ebube.abara@erisna.com

About your service

Service categories

Application Development and Deployment

Data management

Database administration and development

  • Data Modelling

Data integration and intelligence

  • Data Ingestion and Transformation Software
  • Data Quality Software
  • Metadata Management Software
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Databricks, Snowflake, Microsoft Fabric, Google Cloud BigQuery, Amazon (AWS) Redshift, SQL Server, PostgreSQL, Oracle DB, Azure SQL, Azure Cosmos DB, MongoDB, SAP HANA, Azure Synapse Analytics, Microsoft Excel, Microsoft Teams and Slack.
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
Planned maintenance for the Public Cloud version of the Erisna Platform typically occurs on weekends (i.e. Saturdays or Sundays).
System requirements
  • Erisna Data Catalogue software licence
  • Erisna Data Observability software licence
  • Erisna Business Glossary software licence
  • Erisna Developer API software licence and API key
  • Erisna Platform Full Suite software licence
  • Memory >= 8 GB RAM (Private Cloud VM)
  • Storage >= 64 GB (Private Cloud VM)
  • CPU Cores >= 1 physical / 2vCPUs (Private Cloud VM)
  • SSL certificate for secure https:// connections (Private Cloud VM)
  • OS: Windows Server, Linux (Ubuntu, CentOS, Fedora, Debian)

User support

Email or online ticketing support
Yes
Support response times
Within 24 hours in working hours (9h to 17h) and days (Monday to Friday). Response times differ on weekends and bank holidays.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
BASIC SUPPORT: email only (£0).

STANDARD SUPPORT: basic support + ticket support + phone + chat (from £25/user/month, minimum £2,500/month).

ENHANCED SUPPORT: standard support + shared support team + agreed SLA + reporting (no named Technical Account Manager / Cloud Support Engineer) (£4,500/month).

DEDICATED SUPPORT: enhanced support + dedicated technical account manager + fractional cloud support engineer (£14,000/month).

MISSION-CRITICAL SUPPORT: dedicated support + dedicated cloud support engineer + higher response-time commitments + extended-hours/rota + greater reserved engineering time (£32,500/month).
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We help users get started with the service through a structured onboarding and enablement approach. We provide a getting-started guide and user documentation to support initial setup, configuration, and day-to-day use. We deliver virtual training sessions for administrators and end users, covering core workflows, governance and permissions, integrations, and operational best practices.

Where required, we offer on-site training (chargeable) tailored to the buyer’s operating model and team roles. Training can be delivered as role-based sessions (for example: platform administrators, data owners/stewards, engineering teams, and service managers) and is supported with practical walkthroughs and Q&A.

During onboarding, we also provide implementation support to help buyers connect priority systems, validate configuration, and confirm the service is working as expected before wider rollout. Buyers can access ongoing guidance through our support channels, and we can run follow-up sessions after go-live to reinforce adoption and introduce advanced capabilities.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Users can extract their data at the end of the contract by requesting an export from Erisna Support. Data exports are provided as a secure, encrypted package and delivered via buyer-approved secure transfer; any passwords/keys are shared out-of-band. The export contains machine-readable files in commonly used formats such as CSV and JSON (Excel and Parquet where appropriate), together with supporting metadata needed to interpret the export (for example: schemas/field definitions and timestamps).

Exports can be scoped to the buyer’s requirements (for example: all datasets, metadata catalogue entries, lineage, validation results, tags, users/roles and audit logs). We agree on the scope and delivery method with the buyer, then deliver the export securely (e.g., via an encrypted download link or a buyer-approved secure file transfer).

Where requested, we can also provide a short handover note describing the export contents and how to import them into another system.
End-of-contract process
At the end of the contract, we follow a controlled offboarding process agreed with the buyer. We will:

1. Confirm the contract end date and offboarding plan (including export scope, delivery method and timelines).

2. Provide an end-of-contract data export (as requested) and validate successful delivery.

3. Revoke user access and disable integrations/tokens after the agreed final service date.

4. Decommission the buyer’s tenancy/environment and securely delete customer data in line with the contract and any agreed retention period.

5. Provide confirmation of decommissioning/deletion on request.

Included in the contract price:

- Standard offboarding support and coordination.

- One end-of-contract data export in common machine-readable formats (e.g., CSV/JSON; Excel where appropriate) delivered securely.

- Access removal and environment decommissioning.

Additional cost (if required):

- Multiple or repeated exports, bespoke export formats, or complex data transformation/mapping.

- Extended data retention beyond the contracted retention period.

- Migration/implementation services into a new platform, bespoke integrations, or onsite support.

- Standard/enhanced/dedicated/mission-critical dedicated support outside the contracted service scope or after the contract end date.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The Erisna Platform's service interface is a web-based UI / portal, and an API.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have not yet carried out formal usability testing sessions with users who rely on assistive technologies.

Accessibility testing is currently carried out through a combination of automated testing tools and internal manual checks aligned to WCAG 2.2 AA. This includes keyboard-only navigation testing, colour contrast checks, and semantic HTML validation.

Accessibility is considered throughout design and development, and issues identified through customer feedback or internal review are prioritised for remediation. We are committed to involving users of assistive technologies in future testing cycles as part of our ongoing accessibility improvements.
API
Yes
What users can and can't do using the API
Users can programmatically configure, read from and populate the Erisna Platform by creating and managing core governance objects and relationships exposed by the API reference.

Users call the API using the published base URL and include an API key in the X-Api-Key header.

Users cannot perform actions that are not exposed in the API recernce section.

Users cannot access or change anything that they are not authorised to access with their API key.
API documentation
Yes
API documentation formats
  • HTML
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Buyers can customise the Erisna Platform service to fit their environment, integrations, and governance requirements. We tailor deployments for cloud, hybrid, or on-prem, including environment provisioning, authentication, and configuration.

What can be customised: deployment topology; SSO/authentication and role-based access controls; API token provisioning; audit logging/monitoring; data sensitivity tagging and encryption guidance; and platform integrations with the buyer’s data stores and tools (e.g., warehouses/lakehouses, relational/document databases, ETL/ELT, BI, communications, and security).

How users can customise: buyers can configure environments and governance settings and enable integrations during implementation. Where requirements are bespoke, we build custom workflows and automations, including custom ingestion pipelines, webhook/event triggers, API-based orchestration with internal systems, and automated policy enforcement.

Who can customise: the buyer’s nominated administrators/data engineering team can manage configuration and governance settings; Erisna’s Implementation & Integration specialists can deliver and maintain bespoke integrations, workflows, and security/governance setup in collaboration with the buyer.

Scaling

Independence of resources
We protect buyers from “noisy neighbour” effects through tenancy isolation and capacity controls. Each buyer’s data and workloads are logically segregated, with per-tenant quotas and rate limits on APIs and background processing, so that no tenant can consume disproportionate resources. We monitor performance and availability (for example latency, error rates, and processing backlogs) with alerting and operational procedures to manage spikes in demand, including throttling and prioritisation where appropriate. Where additional isolation is required, we can provide a dedicated environment for the buyer to separate resources from other tenants.

Analytics

Service usage metrics
Yes
Metrics types
We provide standard service usage metrics via exportable reports (CSV/JSON) to support operational management and audit needs. Metrics include: active users and logins; feature usage and adoption by team/role; catalogue activity (assets registered, views); data quality/observability activity (rules executed, pass/fail rates); integration and job health (connector status, last run, success/failure counts); API usage (requests, errors, latency); and support metrics (ticket volumes, response/resolution times by severity). Metrics can be filtered by date range, environment and user group.
Reporting types
Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data in the Erisna Platform in CSV format. Alternatively, users can export their data by contacting Erisna Support. Data exports are provided as a secure, encrypted package and delivered via buyer-approved secure transfer; any passwords/keys are shared out-of-band.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • EXCEL
  • PARQUET
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
1. The service is not available and there is no alternative for users to carry out the activities. (Diagnosis Deadline: 1 hour / Solution Timeframe: 6 hours).

2. Some of the service is seriously affected, taking longer than normal to complete. (Diagnosis Deadline: 2 hours / Solution Timeframe: 8 hours).

3. An entire functionality or part of it is unavailable, affecting some specific End-user process. Alternatives are available to get the job done, although other activities may be affected while waiting for the problem to be resolved. (Diagnosis Deadline: 1 day / Solution Timeframe: 2 days).

4. A functionality is partially working, affecting some business processes, but not compromising the progress of the activities. There are alternatives available to perform the work. (Diagnosis Deadline: 2 days / Solution Timeframe: 5 days).
Approach to resilience
Information is available on request.
Outage reporting
Public dashboard on https://status.erisna.com/.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted using RBAC and least privilege. Administrative functions are limited to authorised buyer administrators and approved Erisna personnel. Authentication is enforced via SSO/MFA where supported, with strong password policies as fallback. Privileged actions are logged and reviewed, and production access is time-bound and approval-based, with elevated permissions required for sensitive operations.

Support channels are controlled through verified user accounts and tenant context for tickets/chat. Phone support uses caller verification and agreed escalation contacts. We only disclose sensitive information after confirming identity and authorisation, and all support interactions are recorded in the ticket history for audit.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials Certified
Information security policies and processes
We operate an information security management framework aligned to recognised good practice (for example Cyber Essentials principles) covering: secure configuration, user access control, malware protection, security update management (patch management), firewalls, access control and least privilege; and change management; secure software development; vulnerability management and penetration testing; incident management and breach reporting; logging and monitoring; business continuity and disaster recovery; data classification, retention and secure disposal; supplier/third-party security assurance; and HR security (onboarding/offboarding, acceptable use).

Regarding the reporting structure, overall accountability sits with senior leadership. Day-to-day security is owned by a nominated security lead who reports to the CEO (and escalates material risks/incidents to leadership). Data protection matters are managed with appropriate oversight (for example, via a DPO function).

To ensure policies are followed, policies are documented and reviewed at least annually or following a significant change. Staff complete mandatory security training and regular refreshers. Controls are enforced through role-based access, approvals for privileged actions, audit logging, periodic access reviews, and change controls. Compliance is monitored through internal checks, risk register reviews, and incident post-mortems, with corrective actions tracked to closure.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We use controlled configuration and change management to maintain service integrity. Service components (for example, application releases, infrastructure configuration, integrations and customer-specific settings) are versioned and tracked throughout their lifecycle using source control and change records, with an audit trail of who changed what and when. Changes follow a defined workflow (request, review, test, approve, deploy) and are deployed using repeatable procedures with rollback plans.

Security impact is assessed through risk-based review, including peer review, approval for privileged changes, dependency checks, and pre-release testing. High-risk changes require additional security sign-off and may trigger customer communication.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We use a risk-based vulnerability management process covering application, dependencies and hosting configuration. We assess threats through continuous monitoring, automated scanning, periodic penetration testing and security review of changes. Findings are triaged by severity, then tracked to remediation with ownership and due dates.

Patch deployment is prioritised by severity: critical vulnerabilities are treated as emergency changes and patched as soon as practicable (typically within 24–72 hours), high within days, and medium/low via planned release cycles. Threat intelligence comes from vendor advisories, cloud provider security bulletins, NCSC guidance, and security tooling alerts.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We identify potential compromises by collecting and reviewing security logs (e.g., authentication events, privilege changes, administrative actions, and API activity) and alerting on suspicious patterns, such as unusual login behaviour, repeated failures, or unexpected access to sensitive data.

If a compromise is suspected, we follow an incident response process to confirm and scope the impact, contain the issue (e.g., disable accounts/tokens and isolate affected components), remove the cause, restore service, and complete a post-incident review with corrective actions.

We begin triage within 1 hour for high-severity alerts and provide updates in line with agreed SLAs.
Incident management type
Supplier-defined controls
Incident management approach
We follow a documented incident management process covering detection, triage, containment, resolution, recovery and post-incident review. We maintain pre-defined runbooks for common events (e.g., service degradation, failed integrations/jobs, access issues, and suspected security incidents) with escalation paths and communications templates.

Users can report incidents via email, support portal/chat, or by phone for high-severity issues. Incidents are prioritised by severity and managed to agreed response and update SLAs, with clear ownership and escalation to engineering where required.

We provide incident reports for significant incidents, including timeline, customer impact, root cause, corrective/preventative actions, and any required follow-up, shared securely with the buyer.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
3%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
8%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
12%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
00c6155b-2cd4-485f-b6a2-dfaf5bf1a253
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ebube.abara@erisna.com. Tell them what format you need. It will help if you say what assistive technology you use.