Athena - Location and Geospatial Data Management and Analytics
XBP Europe’s Athena is an AI-powered geospatial platform for managing and analyzing location-based data. It integrates GIS, remote sensing, and structured data to provide actionable spatial intelligence. Leveraging Agentic AI, Athena automates site identification, asset mapping, and risk modeling with high-precision visualization and secure access controls.
Features
- Advanced GIS integration for real-time spatial data visualization.
- AI-powered automated feature extraction from satellite and aerial imagery.
- High-precision geospatial indexing for rapid location-based queries.
- Seamless integration with OGC standards like WMS and WFS.
- Automated site suitability modeling using multi-criteria spatial analysis.
- Intelligent asset tracking and infrastructure mapping across territories.
- Mobile-ready field data collection and real-time synchronization.
- Secure RBAC ensures data access based on geographic location.
- Open API connects geospatial data to existing enterprise systems.
- Dynamic heatmap generation for density and trend analysis.
Benefits
- Enhances decision-making through accurate, real-time spatial insights.
- Improves operational efficiency by automating manual mapping tasks.
- Reduces costs through optimized field resource and asset allocation.
- Increases data accuracy with automated AI imagery a
- Facilitates rapid response for emergency and infrastructure planning.
- Breaks down data silos by unifying disparate geospatial sources.
- Ensures compliance with UK GDPR and data residency laws.
- Scalable platform handles vast datasets without performance loss.
- Intuitive interface makes complex spatial data accessible to everyone.
- Promotes collaboration through shared, interactive geospatial maps.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 5 9 0 9 3 4 2 5 5 9 1 9 9 6
Contact
XBP EUROPE LIMITED
Daren Williams
Telephone: 07960191798
Email: daren.williams@xbpeurope.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Location and geospatial data management and analytics
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Athena extends various services by aggregating disparate data into unified dashboards.
EON Platform: Provides advanced visualization for automated workflows.
Enterprise Tools: Connects to Excel/JSON, and proprietary systems.
Legacy Databases: Integrates with SQL/NoSQL stores and disparate datastreams.
Third-Party Platforms: Embeds via iFrame for software integration.
Smart-Lockers: Reports real-time accountable tracking metrics. - Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
Maintenance Windows: Scheduled universal updates apply to the cloud version; however, on-premises installations require individual manual updates to access new releases.
Hardware Dependencies: While cloud-hosted, on-premises or specific hosted deployments require minimum configurations (e.g., 4 Core/32GB RAM for database servers) to ensure performance.
Data Integration: Real-time synchronization is supported, but custom configurations for specific legacy databases or proprietary systems are defined during the initial discovery phase.
Accessibility Standards: Full Section 508 compliance and integration with Active Directory/LDAP require specific product customization. - System requirements
-
- Cloud deployment: Fully serverless on AWS/Azure; requires no local hardware.
- Web Browser: Requires a modern web browser (e.g., Chrome/Edge/Safari).
- On-premises CPU: Minimum 4 Core (m4.xlarge) for the application server.
- On-premises RAM: Minimum 16 GB memory for the application server.
- Database Server-CPU: Minimum 4 Core (m4.2xlarge) for dedicated database servers.
- Database Server-RAM: Minimum 32 GB memory for high-performance database operations.
- Operating System: Compatible with Windows Desktop for management and development.
- Data Connectivity: Requires API/ODBC access to source SQL/NoSQL databases.
- Security Authentication: Supports two-factor authentication and IP address whitelisting.
- Network Protocol: Secure data-in-transit via HTTPS/TLS 1.2 or higher.
User support
- Email or online ticketing support
- Yes
- Support response times
-
XBP provides comprehensive support with varying response times depending on service type and incident severity.
Standard Support Hours: 08:00 to 18:00 Monday to Friday
Emergency Coverage: 24/7 support available for Severity 1 and 2 incidents
Response Times:
Calls answered within 20 seconds (90% target)
Severity 1 & 2: 15-minute response, 2-4 hour resolution
24/7 operations center staffed including weekends and holidays
Weekend Differences: Regular queries handled during business hours only, but critical incidents receive full 24/7 coverage with same response standards. Emergency contact available for security incidents.
Our ServiceFirst model offers three-tier support through telephone, chat, and email channels. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
XBP Europe conducts rigorous accessibility testing for its web chat and support interfaces to ensure compliance with WCAG 2.2 Level AA and EN 301 549 standards. Our testing methodology integrates both automated scans and manual evaluations using real assistive technologies to validate the end-to-end user journey.
Testing Procedures & Tools
Screen Reader Validation: We test chat functionality with the latest versions of NVDA, JAWS, and VoiceOver. This ensures that dynamic content, such as new incoming messages or status alerts, is properly announced to the user using WAI-ARIA live regions.
Keyboard-Only Navigation: Our teams verify that all interactive elements, including message input fields, emoji pickers, and attachment buttons, are fully operable via the keyboard alone, maintaining a logical tab order without "keyboard traps".
Contrast and Reflow: Testing includes verifying that the chat widget remains functional at 200% zoom and maintains a minimum contrast ratio of 4.5:1 for all text.
User-Centric Feedback: We collaborate with accessibility specialists to simulate real-world interactions, ensuring that our AI-powered virtual agents provide clear, perceivable responses for all users. - Onsite support
- Yes, at extra cost
- Support levels
-
XBP Europe provides a structured ServiceFirst support model for Athena, ensuring 24/7 availability via telephone, web chat, and email. This model is organized into three distinct technical tiers:
1st Line Application Support: Provides initial incident recording, query handling, and problem/change management.
2nd Line Application Support: Delivers deeper technical analysis of incidents, including fact-finding and detailed reporting.
3rd Line Application Support: Focuses on high-level infrastructure monitoring, system performance, and security.
Account Management and Technical Personnel
Every Athena deployment includes access to both a Technical Account Manager (TAM) and a Cloud Support Engineer. Additionally, a dedicated Client Relationship Manager (CRM) is assigned to handle incident escalations, conduct regular performance meetings, and provide monthly Management Information (MI) based on agreed KPIs.
Pricing
Standard support as described above is included within the core license fee. However, additional specialized insights, onsite technical assistance, or bespoke reporting beyond the standard dashboard will incur incremental costs. These are typically billed according to the SFIA Rate Card, with daily rates ranging from £660 to £1,100 depending on the required seniority. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
XBP Europe provides a structured, collaborative onboarding experience for Athena to ensure rapid adoption and operational confidence. We move beyond a simple checklist, treating setup as a strategic partnership tailored to your department's specific goals.
Onboarding and Training Features
Collaborative Discovery: We begin by analyzing your existing workflows and data sources to tailor the platform configuration to your specific use cases.
Onsite and Instructor-Led Training: For complex deployments, we offer onsite support and live workshops led by expert instructors. These sessions can be customized by department or specialty.
Online and Self-Paced Learning: Users gain access to a searchable virtual catalog featuring eLearning modules, workflow-specific videos, and tutorials that staff can revisit at any time.
Comprehensive Documentation: A dedicated Success Community portal provides quick-reference guides, sample reports, and peer-to-peer troubleshooting forums.
1:1 Coaching: We provide personalized coaching for key staff members on high-impact workflows, such as clinical data modeling or revenue cycle management. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
-
XBP Europe ensures that buyers retain full ownership and control of their data, providing multiple pathways for extraction at the end of a contract.
Data Extraction Process
Upon contract termination or expiry, users can extract their data using the following standard methods:
Self-Service S3 Export: Users can configure the service to deliver query results and processed datasets directly into their own Amazon S3 buckets. This allows for the bulk download of data in open formats like CSV, Parquet, or JSON.
API Extraction: Technical teams can use the Athena REST API to programmatically query and retrieve all stored records, metadata, and "Saved Queries" for migration into an alternative system.
JDBC/ODBC Connectors: Organizations can connect their new destination environment directly to Athena to perform a final data pull using standard database integration tools.
Termination Support
Decommissioning Window: XBP typically provides a 30-day grace period following the contract end date, during which the interface remains accessible for final exports.
Data Purging: Following the successful extraction and confirmation by the buyer, all hosted data is securely purged from XBP’s environment in accordance with ISO 27001 standards and UK GDPR requirements. - End-of-contract process
-
XBP Europe ensures a transparent and structured exit for Athena users, adhering to G-Cloud framework standards for data portability and security.
End-of-Contract Process
Notice and Initiation: Upon receiving an Exit Notice, a 30-day "grace period" begins. During this time, the platform remains fully accessible for final data exports.
Data Extraction: Users can perform self-service bulk exports via the Athena API or direct delivery to their own Amazon S3 buckets in open formats (CSV, Parquet, JSON).
Decommissioning: Once the buyer confirms successful migration, XBP initiates a secure Data Purge. All customer-generated data, metadata, and configurations are permanently destroyed in accordance with ISO 27001 and UK GDPR standards.
Pricing: What’s Included vs. Additional
Included in Contract Price:
24/7 technical support (1st, 2nd, and 3rd line).
Core platform maintenance and security patches.
Access to the standard web-based GUI and API Gateway.
Standard onboarding documentation and virtual learning tools.
Additional Costs:
SFIA Professional Services: Bespoke dashboard development or legacy data migration.
Third-Party Cloud Costs: External storage (S3) or Data Catalog (AWS Glue) fees incurred during data processing.
Custom Training: Onsite workshops or instructor-led sessions tailored to specific departments. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Athena provides a consistent, high-performance experience across all platforms with minor interface optimizations.
User Interface: The desktop service offers an expansive, multi-pane dashboard for deep data exploration. The mobile version uses a responsive "tile-based" layout optimized for vertical scrolling and touch interaction.
Functionality: Desktop users have full access to complex administrative settings and report design tools. Mobile users primarily focus on consumption, receiving real-time push alerts, viewing live KPIs, and performing quick drill-downs in the field.
Performance: Both utilize the same cloud-native backend, ensuring real-time data synchronization and accuracy across all devices. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Athena offers a versatile service interface that caters to both operational users and technical integration teams.
Core Interface Components
Web-Based GUI: An intuitive, browser-accessible dashboard featuring responsive "tiles" and drag-and-drop tools for real-time visualization and reporting.
API Gateway: A robust REST/SOAP API allows seamless data exchange with legacy databases, ERPs, and third-party software like Salesforce or JIRA.
Embedded iFrame: Enables users to embed specific analytics charts directly into external enterprise portals.
Data Connectors: Standard JDBC/ODBC support allows integration with BI tools such as Power BI and Tableau. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
XBP Europe follows a structured approach to accessibility testing for Athena, aligning with WCAG 2.2 Level AA standards to ensure the platform remains inclusive for all public sector users.
Testing Methodology
Our testing incorporates both automated audits and real-world validation with assistive technologies:
Screen Reader Validation: We perform rigorous testing using NVDA (Windows) and VoiceOver (iOS/macOS) to ensure all dashboards, data tables, and navigation elements are announced with correct semantic roles and ARIA labels.
Keyboard-Only Navigation: We verify that 100% of the platform’s functionality (including complex data drill-downs) is accessible via keyboard shortcuts and logical tab orders, supporting users with motor impairments.
Visual Adjustments: Testing includes validation of High Contrast modes and ensuring a minimum 4.5:1 contrast ratio for text and interactive components to assist users with low vision or color blindness.
External Audits: Athena’s interface undergoes periodic evaluation by third-party experts to identify contextual barriers that automated tools might miss.
While our core interface is designed for high accessibility, we acknowledge that specific script-generated components may occasionally require manual oversight. We provide an active feedback loop via tutela@athena.eu for users to report and resolve any specific accessibility barriers. - API
- Yes
- What users can and can't do using the API
-
Athena’s API Gateway provides a robust, integration-first interface for automating business intelligence workflows.
API Capabilities
Users can programmatically perform the following actions:
Service Setup: Provision and configure Workgroups, defining data usage limits, encryption settings (e.g., SSE-KMS), and S3 output locations for query results.
Data Management: Create and modify databases, tables, and views using CTAS (Create Table As Select) statements to automate ETL processes.
Query Execution: Start, stop, and track the status of asynchronous SQL queries or manage Prepared Statements for repeated execution.
Administrative Changes: Update workgroup states (Enabled/Disabled), modify engine versions, and manage capacity reservations to control processing power.
Limitations
Rate Limits: Standard production environments are typically limited to 150 calls per second (QPS) and 500,000 calls per day to ensure platform stability.
S3 Dependencies: The API cannot override S3 bucket permissions; users must separately configure IAM roles for data access.
Partitioning: While users can automate partitioning through the API, CTAS queries are limited to creating a maximum of 100 partitions in a single execution.
Format Conversion: Specific legacy formats may require external processing via AWS Glue before they can be modified through the Athena API. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Athena is designed with a modular architecture that allows buyers to tailor the platform to their specific operational and branding needs.
What can be customised:
Visual Dashboards: Users can create bespoke layouts using a "drag-and-drop" interface with over 21 chart types, including GIS maps, heatmaps, and trend lines.
Branding: The interface supports white-labeling, allowing organizations to apply custom colors, logos, and fonts.
Alerts & Triggers: Buyers can define custom data thresholds to trigger automated notifications via email, SMS, or push.
Data Models: Advanced users can create custom SQL views and "Saved Queries" to extract specific insights from unique datasets.
How and Who can customise
End Users: Can personalize their own workspace layouts and save filtered views for daily monitoring.
Administrators: Use the Athena Management Console to set organization-wide branding, define global KPIs, and configure security permissions.
Technical Teams: Leverage the REST API and JDBC/ODBC connectors to build custom integrations or embed Athena charts into existing internal portals.
Scaling
- Independence of resources
-
Athena uses a multi-tenant, serverless architecture that scales instantly to handle peak demand. To protect performance and prevent "noisy neighbors," we offer:
Workgroups: Logically isolate users into groups with independent query histories and settings.
Capacity Reservations: Provision Dedicated Capacity (DPUs) for mission-critical workloads, ensuring exclusive compute resources and zero-latency isolation.
Data Usage Controls: Set hard limits on data scanned per query or per workgroup to automatically terminate runaway processes.
Resource Throttling: Built-in safeguards manage concurrency and resource allocation across the shared pool to maintain stability.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Athena provides real-time insights into data operations and system health. These metrics are critical for managing costs, optimizing query efficiency, and ensuring compliance.
Provided Service Metrics:
Query Statistics: Total execution time, data scanned (bytes processed), and query status (Succeeded/Failed/Cancelled).
Performance Metrics: Real-time tracking query planning time, engine execution time, and resource queue wait times.
Cost Management: Detailed reporting on data scanned per user, workgroup, or project to monitor and control spend.
Audit Logs: Comprehensive logs via CloudTrail recording user identity, source IP, and specific API actions.
Infrastructure-Health: Monitoring system utilization, including processing power and storage limits, available via CloudWatch dashboards. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Users can export data from Athena through three primary methods:
Self-Service S3 Delivery: Direct query results to your own Amazon S3 buckets in open formats like CSV, Parquet, ORC, or JSON.
REST API: Programmatically retrieve datasets and metadata for automated integration with external systems or data lakes.
Standard Connectors: Use JDBC/ODBC drivers to pull data directly into third-party BI tools like Power BI, Tableau, or Excel.
All exports support encryption-at-rest and can be scheduled for automated, recurring delivery to ensure data portability. - Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- JSON
- Parquet
- ORC
- Avro
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- Apache Parquet
- Apache Avro
- ORC
- Logs: Apache, IIS server-logs, AWS CloudTrail , VPC Flow-Logs
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
XBP Europe guarantees a 99.9% Monthly Uptime Percentage for the Athena service. This availability is measured as the percentage of successful API requests (processed without 500 or 503 errors) within each 5-minute interval during a billing cycle.
Service Level Agreements (SLAs)
If uptime falls below the 99.9% threshold, users are eligible for Service Credits calculated as a percentage of their monthly bill for the affected region:
10% Credit: If Monthly Uptime is less than 99.9% but equal to or greater than 99.0%.
25% Credit: If Monthly Uptime is less than 99.0% but equal to or greater than 95.0%.
100% Credit: If Monthly Uptime falls below 95.0%.
Refund and Claim Process
Service Credits: Refunds are issued exclusively as Service Credits applied against future payments; cash refunds are not provided.
How to Claim: To receive a credit, users must submit a claim by opening a case in the Support Center.
Deadline: Claims must be received by the end of the second billing cycle following the incident.
Requirements: Requests must include the words "SLA Credit Request," the specific dates/times of the outage, and logs documenting the errors. - Approach to resilience
- Available on request.
- Outage reporting
-
XBP Europe provides comprehensive, real-time outage reporting for Athena through three main channels:
Public Dashboard: Users can monitor general service health via the AWS Health Dashboard, which provides a transparent, running log of service interruptions and performance degradations across all regions.
API Access: Technical teams can use the AWS Health API to programmatically ingest health events into their own monitoring tools. This allows for automated internal status updates and "self-healing" workflows.
Email and Multi-Channel Alerts: Through AWS Health Aware (AHA) and Amazon EventBridge, users can subscribe to proactive notifications. These alerts are delivered instantly via email, SMS, Slack, or Microsoft Teams whenever an event affects their specific account or resources.
For localized issues, XBP’s internal TIMO system tracks individual incidents, providing direct updates to affected users through the ServiceFirst portal.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- XBP restricts access through role-based controls with centralised authentication via Active Directory/LDAP. User interfaces are separated from management systems using segregated computers, operating systems, or virtualisation. Administrator and developer access requires reinforced controls including multifactor authentication, detailed logging, and regular reviews. All access follows the principle of least privilege. Authorisation requests are tracked through XBP's TIMO support desk system. Access rights undergo periodic reviews, conducted at least annually. Login restrictions limit access based on date/time thresholds and business needs.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
XBP follows a comprehensive security framework centered on the Information Security Program Charter (ISP-00). This includes over 100 specialized policies (covering asset management, encryption, and firewalls) mapped to the HM NCSC Risk Management Framework and CIS guidelines.
Compliance & Monitoring:
Certifications: We maintain ISO 27001:2013, PCI DSS Level 1, and Cyber Essentials Plus.
Governance: The SVP of Information Security & Risk leads oversight, supported by site-level QSE and IT security correspondents. A dedicated Data Privacy Manager ensures UK GDPR compliance.
Proactive Defense: In-house teams conduct regular penetration testing and AI-driven threat detection. All incidents are managed through our TIMO tracking system.
Policy Enforcement: Security is embedded via mandatory onboarding and annual training. Policies are accessible through the intranet and site hard copies. We perform annual legal register reviews to maintain compliance across 29+ regulatory frameworks, ensuring all policies remain management-approved and effective. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Configuration & Change Management
Tracking: All components follow our Configuration Management Standard and Life Cycle Standard, from acceptance through disposal. We maintain baseline configurations using CIS, ISO, and NIST hardening standards to ensure government-grade security.
Change & Security Impact: Governed by the Change Management Control Standard, all changes are tracked in TIMO with a full audit trail. Each change undergoes a Security Impact Assessment, testing in segregated environments, and risk assessments with documented back-out procedures. Changes affecting security require Change Management Board approval. ITIL and COBIT-aligned processes and approved software lists prevent unauthorized modifications. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
XBP Europe maintains a rigorous, risk-based process integrated with ISO 27001 and Cyber Essentials Plus.
Assessment & Sources: We perform continuous scanning and AI-driven detection. Intelligence is gathered via our ISS-06.03 Standard, monitoring official vendor updates, NVD/CVE databases, and real-time threat feeds.
Patch Deployment: Vulnerabilities are tracked in TIMO and remediated by risk level:
Zero-day: 7 days.
Critical: 14 days.
High: 30 days.
All patches undergo digital signing and testing in segregated environments to ensure integrity and service stability before production deployment. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
XBP Europe utilizes a 24/7/365 SOC and real-time SIEM with AI-driven anomaly detection to identify compromises. We employ dual-layer logging and Intrusion Detection Systems for continuous threat monitoring.
Response & Speed: Governed by ISS-05.01, our response follows a structured cycle: detection, analysis, containment, eradication, and recovery. TIMO generates immediate incident tickets upon detection. Potential compromises trigger real-time alerts for instant action by security analysts. Our SOAR capabilities enable rapid threat hunting and behavioral analytics, ensuring incidents are reported and assessed immediately to minimize organizational impact. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
XBP Europe utilizes an ITIL-aligned and ISO 20000-standardized framework for Athena incident management.
Pre-defined Processes: We employ proven playbooks and the ISS-05.01 Incident Response Standard for common events like service degradation or connectivity drops, ensuring rapid, systematic triaging.
Reporting: Users report incidents 24/7 via the ServiceFirst portal, email, or telephone helpdesk. All requests are logged in TIMO with unique tracking IDs for full auditability.
Incident Reports: Real-time status updates are provided via dashboards. For major events, comprehensive Post-Incident Reports (PIRs) are delivered, detailing root cause, impact, and permanent corrective actions. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Health and Social Care Network (HSCN)
- Other
- Other public sector networks
- AWS PrivateLink
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Wednesday 8 May 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Wednesday 20 November 2024
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 3ba37840-a85c-401e-87e8-9fa41ba642f2
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-