Red Ant Cloud Software
Cloud software for applications, with a particular focus on data collection, ingestion, integration and orchestration. Typical use cases include pharmacovigilance for monitoring drug safety/adverse drug reactions, device incidents and vigilance, at-scale data collection, backend services for consumer-facing webforms, websites and mobile apps, or other datacentric developments.
Features
- Data orchestration
- Systems integration
- Front-end templates
- Data ingestion
- Data cleansing
- Data storage
- Analytics
Benefits
- Securely collect data directly from users
- Integrate multiple sources of data together
- Provide a simple backend for public-facing websites
- Compare and reference multiple data sources
- Quickly develop new APIs
- Provide easy-to-use reporting interfaces
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 9 0 6 7 9 4 2 3 0 1 9 8 1 7
Contact
RED ANT DIGITAL LIMITED
Sarah Friswell
Telephone: 08454593333
Email: accounts@redant.com
About your service
- Service categories
-
Application Development and Deployment
Software quality and life cycle
- Software change, configuration and process management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- No specific service constraints
- System requirements
- No specific system requirements
User support
- Email or online ticketing support
- Yes
- Support response times
- Red Ant Service Desk process all Service Requests (inlcuding questions) within business hours: 9:00 – 17:00, Monday to Friday, excluding UK public holidays and following the SLAs set out in the MSA where appropriate.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- No
- Support levels
- Red Ant Service Desk will process P1 incidents 24/7 without limitation. All P2-P3 incidents will be processed within business hours: 9:00 – 17:00, Monday to Friday, excluding UK public holidays and SLAs apply within these timeframes only. To be able to process incidents within SLA and in a timely manner, all incidents must be submitted in the correct format and including the correct information. Full details on SLAs, issue resolution and measurement and penalties can be found in Red Ant’s master service agreement.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Full onboarding is provided including training (onsite, online or both as required) alongside relevant documentation. All stakeholders within the client team are invited to a session called “Delivering with Red Ant”. During this session the Red Ant team are introduced, the expectations of the phases of the engagement are outlined and delivery process documents including example Sprint reports, Test scripts and release notes are shared to prepare the client and outline what
is expected of their own team during the process to achieve a successful outcome. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Red Ant will work with the user to extract their data in the required format (CSV, XML, etc.).
- End-of-contract process
- At the end of the contract that reaches its natural end date, there will be a check to ensure all costs agreed as part of the contract have been fulfilled.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Documentation is created in a simple, easy-to-understand format (PDF) and provided via a secure link or folder as required.
DocuSign is used for any documentation that needs signing
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- It's a responsive website so the key difference is layout and UX.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- Yes
- Description of customisation
- Reports can be fully customised including translations, custom responses to questions, conditional questions. For website management you can customise the theme, the report forms, page content and control where reports are sent to. The user interface & user journeys within the app are highly configurable, with a specific focus on branding, language localization and role management. A wide variety of the product features can be enabled/disabled at a platform level for targeting different use cases.
Scaling
- Independence of resources
- Monitoring is in place and resources can be scaled as and when required
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- There is bulk report exporting functionality in CSV or XML format and reports can also be exported individually as XML.
- Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
-
- XML
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Red Ant Service Desk process P1 incidents 24/7 without limitation. All P2-P3 incidents are processed within business hours: 9:00 – 17:00, Monday to Friday, excluding UK public holidays and SLAs apply within these timeframes only. In the instance that Red Ant do not achieve the agreed SLA for an incident ticket, this will be reported on within the quarterly report and a service credit can be provided, if appropriate. Credit amount is dependent on the overage and reason for the delay and is at the discretion of Red Ant.
- Approach to resilience
- Available on request
- Outage reporting
- In the event of any outages, the Red Ant service desk team will contact impacted users.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Red Ant have an Access Control Policy which is used for controlling, approving and administering access to such platforms operated by Red Ant through the roles present
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Red Ant are committed to the security of information, and have developed and approved an information security policy in line with the requirements of the ISO 27001 standard. The Information Security Policy is communicated to all employees as part of our employee induction programme, and periodically following any changes to the policy.
- Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Red Ant have a Change Control Procedure document. This procedure is applied to all changes to Red Ant's operations that impact the information and information systems that fall within the scope of Red Ant's information security management system, and are classified as Normal, Major, or Emergency changes. Standard changes are managed through Red Ant's standard operating procedures.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Annual penetration testing alongside other third party services used to regularly scan and alert if relevant threats/vulnerabilities are found. Vulnerability information sources such as security alert feeds, blogs and forums are also used to maintain awareness of emerging threats and vulnerabilities. Patching cycles take into consideration the criticality of the assets and associated services.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Red Ant may become aware of potential incidents from various sources and once notified follow Red Ant's Incident Response Procedure. Possible escalation of the incident is prepared by carrying out a preliminary assessment to determine if it is a potential security incident, with mobilisation of the Incident Reponse Team if verified.
Response times for severity 1 and 2 incidents is 45 minutes. - Incident management type
- Supplier-defined controls
- Incident management approach
- In the event of an incident Red Ant follow the pre-defined Incident Response Procedure which has been developed based on best practice principles for responding to information security incidents. Users report P1 incidents with the Red Ant Service Desk team via phone to ensure service levels can be achieved and P2 and below via the Service Desk portal. Incident reports are provided in PDF format via the Service Desk portal.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 4%
- Between £1,000,001 and £2,500,000
- 6%
- Between £2,500,001 and £5,000,000
- 8%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Nqa
- ISO/IEC 27001 accreditation date
- Friday 20 September 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Volunteering opportunities for staff
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-