Skip to main content

Help us improve the Digital Marketplace - send your feedback

USERTESTING TECHNOLOGIES LIMITED

UserTesting

Moderated and unmoderated user experience testing on concepts, websites, applications, prototypes, content, imagery and real-world experiences.

Recruit from our panel using screener questions or use your own. Gather rapid qualitative and quantitative feedback to gain user insights and improve digital services.

UserTesting can also run end-to-end research for customers.

Features

  • Remote moderated interviews. Calendar integration for scheduling and note-taking
  • Remote unmoderated testing, diary studies and survey capabilities. No plugin.
  • Record screen, face, voice and digital interactions (with transcripts)
  • 120+ test templates for Discover, Design, Build, Iterate phases
  • Mobile, desktop, app, prototype testing: validate/evaluate UX/CX decisions
  • Card Sorting, Tree Testing, prioritisation matrix, System Usability Scale testing
  • Automated reporting: AI insight summaries, sentiment analysis, data visualisations, metrics
  • Think-out-loud feedback from our panel or your own
  • Tag insights and create clips and highlight reels of insights
  • Download insights or share into commonly used tools

Benefits

  • Run fast, high-quality qualitative & quantitative research at scale
  • Easily reach your target audience in just a few hours
  • Ability to test with your own users without a plugin
  • Access to feedback on any real-world or digital experience
  • Embed feedback and insights in many more decisions
  • Uncover key insights quickly (automated analysis and AI insight summaries)
  • Catch usability problems early and avoid expensive rework/fixes later
  • Create better hypotheses by understanding the “why” behind user behaviour
  • Build a common understanding of your users throughout the organisation
  • World-class training/support & research projects delivered by UX expert

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sporthouse@usertesting.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 5 7 5 5 3 5 8 8 4 0 4 2 4 8

Contact

USERTESTING TECHNOLOGIES LIMITED Steven Porthouse
Telephone: 07795 110 232
Email: sporthouse@usertesting.com

About your service

Service categories

Application Development and Deployment

Analytics and business intelligence

  • Business Intelligence
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Minimum technical requirements:
At least 1GB of RAM with at least 0.5 GB available for applications.
An Internet connection is required to access the platform.
Browsers supported: latest versions Google Chrome, Firefox, Edge , and Safari (latest version on macOS)
System requirements
  • Access your account via computer or mobile device to test.
  • JavaScript enabled: Necessary for platform functionality.
  • Modern browser with TLS 1.2 encryption.

User support

Email or online ticketing support
Yes
Support response times
Priority Critical /Emergency <15 minutes ; High <30 minutes; Medium< 1hour; Low<2 Hours Responses (unless highly critical) will only be answered during weekdays
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
EN 301 549
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
WCAG 2.1 Level AA however, we do conform to most WCAG 2.2 Level AA standards
Web chat accessibility testing
WCAG 2.1 Level AA however, we do conform to most WCAG 2.2 Level AA standards
Onsite support
No
Support levels
3 tiers of service: Basic / Enhanced /Premier.

Basic is provided free of charge.
Enhanced and Premier are based on a % of the total subscription cost

In addition to support (platform and technical), customers will have a dedicated account manager and a solutions consultant (technical and subject matter expert).

We can also provide Research Consultants and Customer Success Managers, depending on a customer's level of investment.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Choice of paid-for and free services; *Account Configuration*
Our consultants guide account administrators to set up your account, workspaces, and reusable templates aligned to your needs.

*Team enablement*
Hand-on, personalised enablement with a consultant so teams develop skills and familiarity in finding customer insights and what the platform can do / how to use the platform.

*UserTesting Jump Start*
Instructor-led and on-demand training courses and resources for individuals to get started on the UserTesting platform, develop best practices, and build skills with confidence.

*UserTesting University*
Access 100+ on-demand courses, live trainings, and comprehensive Knowledge base content to provide a deeper dive into platform features and methodologies. Gain UserTesting accredited certifications.

*UserTesting CommUnity*
Ask questions, share ideas and best practices, learn alongside others, and earn certifications in the UserTesting CommUnity - a network of other UserTesting peers

*Post-onboarding support*
3 tiers of support: Basic / Enhanced /Premier. Basic is provided free of charge. Enhance and Premier are based on a % of the total subscription cost.

In addition to support (platform and technical), customers will have a dedicated Customer Success Manager, a solutions consultant who is a technical and subject matter expert (subject to level of investment)
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Customers need to download their data before their subscriptions ends
End-of-contract process
Users will choose to terminate the contract or renew for another annual period.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile app lets study participants take studies/tests/surveys that are designed for mobile devices on using their own personal mobile device (for e.g. testing unreleased apps, live apps, mobile websites and mobile prototypes)
Service interface
No
User support accessibility
EN 301 549
API
Yes
What users can and can't do using the API
UserTesting maintains close relationship with a broad and growing range of technology partners and product companies. The platform currently includes a range of pre-built, partner integrations.

Because we use OAuth 2.0, the industry standard for ecosystems, it takes less effort to design and maintain integrations, and provides a consistent auth flow to customers.

All API requests to UserTesting platform must be made over HTTPS.

UserTesting APIs require:
Client Id and Secret (Partner Authentication)
OAuth2 bearer token (UserTesting customer user Authorization)

Using secure APIs on UserTesting’s developer portal requires an access token to successfully send requests. You’ll use these credentials for tasks like authorization.

Further information can be found here: https://developer.usertesting.com
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
UserTesting settings allow account administrators to customise their workspace, test templates, workflow management, integrations, permissions, and add their own branding to specific test types.

Consulting services are also available for additional customisations, change management and running end-to-end research on customers' behalf.

Scaling

Independence of resources
UserTesting leverages the AWS public cloud infrastructure. Our cloud SaaS based product is designed to automatically scale to meet user demands.

Analytics

Service usage metrics
Yes
Metrics types
Usage Summary of Session Units (Used/Available), Top Usage by Member/Workspace, Tests Launched.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
You can export data from UserTesting in several ways. Share or publish test results via link or email, including individual sessions with adjustable permissions. Export Insights Hub reports as PDFs for easy stakeholder access. Admins can export user roles and activity data from the People page for audits or compliance. Transcripts can be exported to Excel for in-depth analysis. These features support efficient sharing, governance, and deeper insights across teams.
Data export formats
  • CSV
  • Other
Other data export formats
  • MP4
  • PDF
  • CSV
  • URL
Data import formats
  • CSV
  • Other
Other data import formats
  • MP4
  • PDF
  • XLS
  • MOV
  • DOC
  • TXT

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
SLA's are defined on a per customer basis and are defined in the customer contracts.
Approach to resilience
This information is available upon request.
Outage reporting
A public dashboard can be found at: https://status.usertesting.com/

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
UserTesting carefully manages and regularly reviews access to its internal infrastructure to uphold the principle of least privilege. Users only retain the access necessary for their roles. All administrative access is tightly controlled, continuously monitored, and comprehensively logged within UserTesting's SIEM to maintain accountability and enhance threat detection. UserTesting restricts personnel access to all hypervisor management functions or administrative consoles for systems hosting virtualized systems based on the principle of least privilege and supported through technical controls. Access to customer data is limited to individuals with real business needs and controlled by an individual's role in the organization.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
UserTesting's information security policies and processes are designed to protect the confidentiality, integrity, and availability of information, aligning with industry best practices and regulatory requirements. The foundation of our approach is detailed across several key policy documents, including:

Document Retention Policy
Disaster Recovery Plan
Vendor Management Policy
Business Resilience Policy
Vulnerability Management Policy
Acceptable Use Policy
Incident Response Policy
Risk Management Policy
Information Security Policy

Our reporting structure includes the Chief Information Security Officer (CISO), who oversees the implementation of these policies, and the Compliance Governance Council, which approves policy changes and monitors compliance. Policies are reviewed annually or as necessary to adapt to evolving security landscapes and regulatory requirements. This comprehensive approach ensures not only compliance with legal and regulatory obligations but also fosters a culture of security awareness and continuous improvement throughout the organization.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
All changes require a review and approval process tailored to each system, ensuring no alterations occur without proper oversight. Business owners must define and record these processes to achieve objectives such as prohibiting individuals from unilaterally requesting, implementing, and approving changes, mandating pre-production approval, and conducting comprehensive quality assurance through various testing methods. Additionally, there must be a capability to revert changes if issues arise, retain change management records for at least a year, and generate a historical list of modifications for any system spanning back a year.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
UserTesting's vulnerability management process involves regular scans and risk assessments to identify threats to our services. We prioritize patch deployment based on threat severity, aiming to address critical vulnerabilities swiftly. Our information on potential threats comes from reputable sources, including security advisories and threat feeds.

Critical vulnerabilities (9.0 - 10.0): 7 days
High severity vulnerabilities (7.0 - 8.9): 30 days
Medium severity vulnerabilities (4.0 - 6.9): 90 days
Low severity vulnerabilities (0.1 - 3.9): 180 days
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
UserTesting's incident response process starts with the identification of potential compromises through 24/7 continuous monitoring and anomaly detection. Upon detecting a potential compromise, our incident response team swiftly isolates the affected systems, assesses the impact, and implements remediation actions to mitigate the threat. This rapid and systematic approach ensures minimal impact and strengthens our resilience against future threats​​.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
UserTesting's incident management processes include predefined protocols for common events, ensuring rapid and effective responses. Users report incidents via email, or an internal ticketing system, allowing for immediate escalation and investigation. Incident reports, detailing the nature of the incident, impact assessment, and remediation actions, are generated and disseminated to stakeholders. This structured approach enables us to efficiently manage and mitigate incidents, maintaining the integrity and security of our systems​​.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
We offer time-boxed and managed trials on a case-by-case basis.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
2.5%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
7.5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Coalfire
ISO/IEC 27001 accreditation date
Tuesday 29 October 2024
What the ISO/IEC 27001 doesn’t cover
The certificate scope comprises the Information Security Management System (ISMS) and Privacy Information Management System
(PIMS), which combined is the Integrated Management System (IMS) supporting the operations underlying the UserTesting Human
Insight Platform and UserZoom Manager. The organizational scope includes the Compliance Governance Council (CGC),
Information Security, Information Technology, Engineering, Human Resources, and Legal teams affecting the IMS. These activities
are governed by the implemented controls in accordance with the organizational Statement of Applicability which further extends to
the PII Controller and PII Processor controls defined within ISO/IEC 27701:2019.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
Yes
CSA STAR accreditation date
Wednesday 9 July 2025
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
Please refer to https://cloudsecurityalliance.org/star/registry/usertesting/services/usertesting-human-insight-platform/
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
Yes
Any other security certifications
  • SOC 2 Type II
  • ISO 27001
  • ISO 27701
  • HIPAA

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sporthouse@usertesting.com. Tell them what format you need. It will help if you say what assistive technology you use.