Skip to main content

Help us improve the Digital Marketplace - send your feedback

DATA LANGUAGE (UK) LTD

Data Graphs

Data Graphs is a cloud-native platform that transforms fragmented data into a governed semantic knowledge backbone. It centralises reference data, catalogues, and entities in a unified knowledge graph, making information easy to discover, link, and reuse—enabling responsible AI, agent-assisted workflows, and MCP-ready services through an intuitive UI and standards-based APIs.

Features

  • Intuitive interface for secure data discovery, reuse, and understanding
  • Connects related data, records, and content across existing organisational systems
  • Standards-based linked data enabling interoperability across government platforms and suppliers
  • Controlled workflows with full version history supporting audit and traceability
  • Clear data ownership, governance, and stewardship across teams and departments
  • Reduces manual metadata management, duplication, and ongoing operational data maintenance
  • Supports consistent, high-quality information use across public services and programmes
  • Visualises relationships between datasets, records, and digital assets for insight
  • AI-ready data with natural language search and private LLM
  • Secure access controls supporting sensitive, regulated public-sector data usage

Benefits

  • Quickly find, understand, and reuse related data across systems
  • Manage metadata and reference data in one consistent environment
  • Reduce manual data preparation and duplication during daily operations
  • Apply controlled workflows to review, approve, and publish data changes
  • Track data changes over time using audit trails
  • Assign clear ownership and responsibility for datasets and metadata
  • Visualise relationships between records, datasets, and digital assets
  • Share governed data confidently across teams and programmes
  • Integrate connected data into existing reporting, analytics, and search tools

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at donna.esfandiary@datagraphs.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 7 0 0 0 2 9 8 9 9 8 6 4 0 4

Contact

DATA LANGUAGE (UK) LTD Donna Esfandiary
Telephone: 0794 222 3149
Email: donna.esfandiary@datagraphs.com

About your service

Service categories

Application Development and Deployment

Data management

Database management systems

  • Relational Database Management Systems
  • Low-Code Database Management Systems
  • Graph Database Management Systems
  • In-Memory Shared Data Managers

Database administration and development

  • Data Modelling
  • Database Development and Optimization

Data integration and intelligence

  • Data Ingestion and Transformation Software
  • Master Data Intelligence Software
  • Metadata Management Software
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
No
System requirements
  • Clients needs HTTPS access to the public internet
  • API clients require an standards-compliant HTTP client library for access

User support

Email or online ticketing support
Yes
Support response times
During UK office hours, we use all reasonable effort and commercial endeavours to rectify the fault(s) within 3 hours from the time of notification, and outside of such hours use reasonable endeavours to rectify the fault(s) as soon as is reasonably practicable.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Data Graphs is a self-service SaaS platform for day-to-day operation by customer teams.
Optional professional services are available to support onboarding, training, and specialist use cases.
The service is backed by defined service-level agreements (SLAs) covering availability and support response.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
User documentation
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Any training data that is uploaded by users is destroyed after contract end.
End-of-contract process
At the end of the contract, access to the user's SaaS product account is removed, training data is deleted, and the account and all data are deleted.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
We provide screens for creating, managing, searching, importing, and exporting datasets.
Accessibility standards
WCAG 2.2 A
Accessibility testing
We have performed structured accessibility testing using Lighthouse, keyboard-only navigation, and automated tools aligned with WCAG 2.2 A.
API
Yes
What users can and can't do using the API
All accounts come with API access to your Data Graphs. Each dataset can be configured with Public or Private access. You can grant one or more API keys to use the APIs. A dataset with public access means the API can be used with only the API key, and is suitable for integrating with a public-facing app, where you are happy for your data to be publicly accessible. A private access dataset can only be accessed via its API using OpenID / OAuth secure authentication. In this case, you must use credentials to request an authentication token, which can then be used to make API requests along with the API key.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
No

Scaling

Independence of resources
Each tenancy is fully isolated in the cloud, both for compute and data.

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
There is no user data stored in the platform.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON-LD
  • JSON
  • OWL/RDF
  • Excel
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON-LD
  • JSON

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Support is available Monday to Friday, 09:00–17:00 UK time (excluding UK bank holidays).

We guarantee an initial response within 4 hours during support hours (typically within 1 working hour).
Service availability issues are managed against defined priority SLAs:
Critical service outage: 4 business hours
Major functional impairment: 8 business hours
Minor issues: 3 business days

Service credits apply if guaranteed service levels are not met.
Approach to resilience
Data Graphs uses extremely robust enterprise-grade cloud storage. Multiple copies of data are stored in a distributed data store. Backups are taken very frequently and stored securely and robustly. While no storage service can ever rule out a catastrophic failure, the patterns we use are designed to mitigate the risks of data loss and include disaster recovery.
Outage reporting
Email alerting

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Can authenticate with enterprise SSO providers, such as Active Directory, or SAML based systems.
Access restrictions in management interfaces and support channels
We use a third party, best in class identity management service for managing authentication and authorisations. All human agent access control is enforced in the platform via the groups and roles associated with each user account, and all machine agent access control is enforced via OAuth client credentials and the permissions granted to the access token that is issued against the machine's credentials.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Physical access controls are covered through SOC 2–compliant third-party data centre providers.
Information security policies and processes
Data Graphs follows documented information security policies and processes aligned with SOC 2 requirements, covering access control, data protection, secure development, change management, incident response, and risk management.

Security governance is owned by senior management, with defined accountability and regular review. Compliance is ensured through role-based access controls, staff training, operational monitoring, and independent third-party audits as part of ongoing SOC 2 compliance.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We perform peer review of all changes which includes security impact assessment. We ensure all third party library dependencies are up to date, minimising the indirect vulnerability risk via third party dependencies. We use automated continuous integration/delivery pipelines for all service components, which run automated functional and code quality tests against the relevant codebase, perform versioned component release builds and publish the outputs to private/internal component registries. It is only possible to perform deployments via automated deploy scripts, which use previously built artefacts from the relevant component registries. This gives us full traceability of all components in every environment.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We assess vulnerabilities via peer code and architecture reviews, continuous vulnerability monitoring via our SOC2 Type 2 security provider and regular external penetration testing. Depending on the severity of the vulnerability, patches will be deployed either immediately or with the next automated feature release. We get information about potential threats from third party component notifications, cloud provider security notifications, our SOC2 security provider and/or the results of external penetration test cycles.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We identify potential compromises via code reviews, third party component dependency vulnerability notifications, cloud infrastructure vulnerability notifications and regular external penetration testing. The impact of potential compromises is then assessed to determine the impact risk, and anything above low impact is patched immediately. Low impact risks will then be patched as part of the next scheduled platform release.
Incident management type
Supplier-defined controls
Incident management approach
We have a detailed incident management process defined which sets out responsibility matrices, triage and prioritisation criteriam, standard categories of events, pre-defined processes for each category, the structure of the response team, target timelines for analysis, containment, eradication and recovery, communication protocols internally, to customers and to regulators where relevant, and post-incident activities regarding review, root cause analysis and any further remediations.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
3%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
8%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
12%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
33eb45b3-aee3-47f0-baae-e2507de99559
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
SOC2 Type 2

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at donna.esfandiary@datagraphs.com. Tell them what format you need. It will help if you say what assistive technology you use.