Cleata
Cleata is a cloud-hosted workflow automation and integration platform that removes manual processes and operational workarounds around existing systems. It connects enterprise platforms through reusable workflows, improving data flow, auditability and efficiency without replacing core applications.
Features
- Automates manual, repeatable operational processes
- Removes system workarounds and spreadsheet-based processes
- Reusable workflows across multiple business services
- Integrates enterprise systems using secure APIs
- Cloud-agnostic deployment across public cloud platforms
- Low-code configuration without core system changes
- Event-driven and scheduled automation
- Role-based access and audit trails
- Scalable workflows adaptable to changing service needs
Benefits
- Reduces manual effort and operational overhead
- Eliminates reliance on spreadsheets and email workarounds
- Improves data accuracy across connected systems
- Accelerates process delivery without core system changes
- Lowers cost and risk of system customisation
- Improves auditability and operational transparency
- Enables faster response to changing service requirements
- Reduces errors through automated validation
- Enhances integration between existing enterprise platforms
- Scales automation consistently across departments and services
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 3 3 5 7 9 8 3 4 2 2 2 9 2 5
Contact
EYE-I SYSTEMS LTD
Brendan Tate
Telephone: 07889 842417
Email: brendan.tate@eye-i.co.uk
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Robotic process automation
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Cleata is system-agnostic and can extend any software service that provides a means of integration, such as APIs, web services or secure data exchange. It is commonly used alongside enterprise platforms including CAFM, finance, HR and compliance systems.
- Cloud deployment model
- Public cloud
- Service constraints
- No material constraints beyond standard planned maintenance windows. The service is cloud-hosted and does not require specific hardware or client-side installations.
- System requirements
-
- Existing systems must permit API access under their licences
- Access via modern web browser and secure APIs only
User support
- Email or online ticketing support
- Yes
- Support response times
- We normally respond to questions within one working day. Urgent queries are normally responded to within one hour during support hours. Support is provided 9am to 5pm, Monday to Friday, excluding UK public holidays.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Standard Support
Email and phone support during business hours (9am–5pm, Monday–Friday, UK public holidays excluded)
Response within one working day for non-urgent issues
Urgent issues responded to within one hour during support hours
Guidance and assistance with workflow configuration and updates - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- The supplier supports onboarding through guided remote setup, configuration assistance and user documentation. Training and walkthrough sessions are provided online, with knowledge transfer to support ongoing use. Documentation is provided to enable users to operate the service, configure deployed workflows and manage integrations independently within the scope of their permissions.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- At contract end, all customer data will be made available for extraction. The client administrator will be provided with a secure link to download their data for an agreed period following contract termination. After this period, the data will be securely deleted in accordance with the supplier’s data retention and deletion policies.
- End-of-contract process
- At the end of the contract, all configured automated processes are halted and no further workflows will run. The client is provided with a secure link to download their data, which is included in the contract price. Data remains available for an agreed period before secure deletion. Additional services, such as consultancy support for migration to an alternative solution, can be provided on request and are charged separately.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Cleata is accessed through a secure web-based portal that allows authorised users to view, configure and manage deployed pre-built workflows. Users can deploy available workflows, start, stop and monitor workflow executions, and configure workflow parameters such as credentials, schedules, thresholds and routing options. Workflow design and development are managed by the supplier. The interface provides visibility of workflow status, execution history and errors, supporting operational oversight and audit requirements. Role-based access controls ensure users only see and manage workflows relevant to their responsibilities.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Accessibility has been considered during design and tested using screen readers and keyboard navigation. Feedback is incorporated iteratively, and further testing can be carried out with buyers if required.
- API
- Yes
- What users can and can't do using the API
-
Users can integrate with Cleata using secure APIs and webhooks to trigger workflows, submit data, retrieve workflow status, and receive event notifications.
Users can make changes through the API by providing workflow inputs, updating integration data, and initiating or stopping workflow executions where permitted. API use is limited by configured workflows, enabled integrations and role-based permissions;
Core platform configuration and tenancy management are not available via the API. - API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Cleata is customisable through pre-built workflow templates and configurable process options. Workflows are designed by the supplier to reflect common real-world scenarios across enterprise systems. Authorised users can tailor workflow behaviour by configuring parameters such as thresholds, schedules, routing options, data mappings and approvals within the constraints of the deployed workflow. Workflow design, creation and structural changes are managed by the supplier to ensure consistent governance and control. The supplier creates and manages the tenant and provides initial setup and guidance. New workflow patterns and enhancements are added regularly based on feedback from existing customers.
Scaling
- Independence of resources
- Cleata operates in a multi-tenant cloud environment with resource isolation and scaling capabilities. Each tenant’s workflows and data are logically segregated to ensure that the demand from one user does not impact others. The service is designed to dynamically scale based on workload, with performance monitoring and proactive resource allocation to maintain service quality across users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Cleata provides operational service metrics relating to workflow execution and data processing activities. Metrics include workflow run counts, execution status, timestamps, and success or failure outcomes. Where workflows process records for import into target systems, users can view line-level results indicating which records were successfully processed and which failed validation or integration, including associated error messages. These metrics support reconciliation, troubleshooting and audit requirements. Metrics are available via the service interface and can be exported in open formats. The service processes data only as required to execute configured workflows.
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Cleata processes data in transit and stores only workflow metadata and credentials. Operational metrics can be exported via the service interface.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XLS/X
- TXT
- XML
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is designed to be highly available and is hosted on resilient public cloud infrastructure. The supplier targets service availability aligned to the underlying cloud platform, excluding planned maintenance. Planned maintenance is notified in advance and scheduled outside core business hours where possible.
While no formal percentage uptime SLA is guaranteed, service availability is actively monitored and incidents are prioritised in line with their impact and urgency. Where availability issues occur, the supplier will work with the customer to restore service as quickly as possible and provide incident updates.
Refunds or service credits are not automatically applied. Any service impact and associated remedies are considered on a case-by-case basis in accordance with the contract terms. This approach provides flexibility while ensuring issues are addressed promptly and transparently. - Approach to resilience
- The service is designed for resilience using managed public cloud infrastructure that provides redundancy across multiple availability zones within a region. Core platform components are monitored continuously and designed to recover automatically from common failure scenarios. Data is protected through encryption and managed backup mechanisms provided by the cloud platform. Datacentre resilience, including power, cooling and physical security, is delivered by the cloud infrastructure provider in line with recognised industry standards. Further detail on resilience controls can be provided to buyers on request where appropriate.
- Outage reporting
- Service outages and incidents are communicated to customers via email notifications to nominated contacts. Where appropriate, updates are also provided directly to customer administrators. The service does not currently provide a public status dashboard or dedicated outage reporting API. Incident information and post-incident updates are shared as required to ensure transparency and timely communication.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted through authenticated user accounts with role-based access controls, ensuring users can only access functions appropriate to their role. Multi-factor authentication is enforced for management access. Administrative actions are limited to authorised users and are logged for audit purposes. Access to support channels is restricted to nominated customer contacts, with identity verification performed before sensitive information is shared or changes are made. Permissions are reviewed periodically and adjusted as required.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Security governance is supported by alignment with the Software Security Code of Practice and Cyber Essentials controls, alongside supplier-defined security policies. Infrastructure security is provided by the underlying public cloud provider in line with recognised industry standards.
- Information security policies and processes
- The organisation follows documented information security policies covering areas including access control, data protection, incident management, vulnerability management and secure development. Policies are aligned with the Software Security Code of Practice and Cyber Essentials controls. Responsibility for information security sits with a named director who has overall accountability for security governance. Policies are communicated to staff and contractors and are supported by role-based access controls, technical safeguards and operational procedures. Compliance is monitored through regular reviews, incident reporting, external penetration testing and supplier oversight. Security incidents are reported and managed through a defined incident response process, with remediation actions tracked to completion.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management is controlled through documented processes. Service components, including workflow configurations, integrations and platform components, are version-controlled and tracked throughout their lifecycle. Changes are assessed for functional and security impact prior to implementation, with higher-risk changes subject to additional review. Access to make changes is restricted to authorised personnel and controlled through role-based permissions. Changes are implemented in a controlled manner, with testing in non-production environments where appropriate. Security considerations, including data handling, access control and dependency changes, form part of the change assessment process, and outcomes are recorded for audit and review.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerabilities are assessed through supplier reviews, dependency monitoring and external penetration testing. Threat intelligence is obtained from cloud providers, software vendors and trusted security advisories. Security patches are prioritised based on risk, with critical updates applied as soon as practicable and others deployed through controlled change processes. Vulnerabilities and remediation actions are tracked to resolution.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is performed through service logging, workflow execution monitoring and alerts from the underlying cloud platform. Potential compromises are identified by reviewing error patterns, abnormal activity and security alerts. When a potential compromise is detected, it is investigated promptly, access may be restricted if required, and remedial actions are taken in line with the incident management process. Incidents are responded to as soon as practicable, with urgent security issues prioritised for immediate investigation during support hours.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The organisation operates documented incident management processes, including pre-defined response procedures for common events such as service disruption, security alerts and integration failures. Incidents can be reported by users via email or phone during support hours. Incidents are logged, prioritised and managed based on impact and urgency. Customers are kept informed of progress as appropriate, and incident summaries or post-incident reports are provided following resolution where required. Lessons learned are reviewed and used to improve service resilience and security controls.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-