Suchee- Product Catalogue Tool
An end-to-end data enterprise data catalogue SaaS solution combining AI enabled tooling, governance concepts and data models all designed to enable data in your organisation to be mobilised effectively for business growth, reporting and compliance, across all domains and constituents
Features
- Data Analytics and Strategy
- Master Data Management
- Data Migration
- Data Governance
- Data Integration
- Change Management
- Metadata Information
Benefits
- Data and Analytics Strategy improves operational efficiency
- Data Management helps to reduce storage costs, minimize data redundancy,
- Data Governance leads to Improved Data Quality hence better decisions.
- Data Integration leads to Unified View of Data
- Data Integration enhances business analysis
- Metadata Management ensures security and privacy of the data assets
- Metadata Information provides context to data, provides data quality metrics
- Master Data Management ensures a single source of truth
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 8 4 7 9 7 6 4 1 8 2 4 8 6 3
Contact
DIGITAL DATA CONSULTANCY LTD
Sam Ghosh
Telephone: 0208 090 2929
Email: operations@digitaldataconsultancy.com
About your service
- Service categories
-
Application Development and Deployment
Data management
Data integration and intelligence
- Metadata Management Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Service constraints
-
Regarding Suchee, our service constraints will be defined within the Project scope and will vary from one client to another.
Suchee’s service constraints are defined within the agreed project scope. As a metadata-driven data catalogue and governance platform, Suchee relies on external systems (such as MDM or data platforms) for data model import and metadata synchronization. APIs are not exposed by default and any API enablement, integration approach, deployment environment, or operational constraints are mutually agreed with the Buyer during project initiation and documented prior to service commencement. - System requirements
-
- Any device (excluding a mobile) with an internet connection.
- Any device (excluding a mobile) with a compatible browser.
User support
- Email or online ticketing support
- Yes
- Support response times
-
We usually use the Buyer's Project Management tool, such as Jira, Confluence, or Asana, for users to raise tickets for identified issues.
If the Buyer does not have a tool, we will provide our client with an email id created by us (DDC) for users to raise tickets/post queries.
Acknowledgement:
Working Days-Response within an hour of the ticket being raised.
Weekends-Response will be provided within two hours of the ticket being raised. - User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support Levels cost during the Implementation phase:
- Zero, if it is an issue during the course of the Project arising because of a bug in our software.
- Zero, if it is an issue during the course of the Project arising from an error on the client side. However, this could result in an extension of the Project Timeline and the buyer incurring unplanned additional costs.
We will specify this clearly in the Agreement signed by both parties prior to the start of the Project, and the cost implications in such a situation.
Support Levels cost Post-Implementation/Project end:
At an agreed cost prior to the support being provided, if needed, or as per the Buyer's needs, for e.g. during working hours only and/or during weekends.
Support Level Responsibility:
We will provide a Technical Account Manager, and the cost will be included in the Support contract. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We can provide all three (onsite training, online training, or user documentation) or a combination of all the three as agreed with the Buyer.
We can provide and will ideally need to provide a mix of onsite training, online training and User documentation which will be made available containing the best practices for using the features of the software.
We then provide online/onsite assistance and training for the users to understand the various features of the software and how it can be used to incorporate the business data model (bespoke data model ).
We shall help our client to onboard their organisation's details, data assets, relationships between the data assets, policies , data processes relating to the data assets into the software from their existing data sources which will provide them with a full picture and story of their data and its usage for their organisation. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- The Buyer can extract all the data they need for their organisation as and when required by downloading it in .xls and/or .pdf format with the bulk extract feature in the solution.
- End-of-contract process
-
The solution is sold in a SaaS model with an annual subscription - see pricing.
At the end of the contract, we will provide User Documentation and confirm with the Buyer the level of Support needed, if any.
The Buyer can access support for the software either by email or by raising a ticket within the software.
This additional support comes at a cost, and it will be in accordance with an agreed contract detailing the level of support and the associated costs between the Buyer and us.
The buyer will be under no obligation to purchase the support. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Suchee provides a web-based service interface for managing enterprise data catalogues and metadata.
The interface enables users to define data governance policies, business rules, and workflows; manage role-based access and authorizations; visualize data lineage; and maintain project versioning with cloning capabilities.
Users can import and export metadata and data models and synchronize metadata with external MDM systems. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We use the Zoho platform, which supports users of assistive technology.
- API
- Yes
- What users can and can't do using the API
-
How users can set up the service through the API- Suchee is built on Spring-based APIs used internally by the platform for all user interface and system-to-system communication. These APIs are not exposed to end users by default; however, they can be exposed if required, subject to agreement with the Buyer and appropriate security and governance controls.
How users can make changes through the API-When enabled, authorized users or systems can view, add, update, and delete application-related and configuration metadata, including data models, governance rules, business rules, workflows, lineage information, versioned projects, and export/import artifacts.
Any limitations to how users can set up or make changes through the API- API access does not permit bypassing role-based access controls, authorization rules, or governance workflows. All API usage remains subject to security policies and contractual scope - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
What can be customised- Our client can and has the freedom to customise or configure at only a few levels. To be clear, the client can customise the functionality within each service feature through configuration only, but not the software's features themselves. Therefore, our software is not fully customisable but allows customisation only for certain features and some of the functionalities within those features.
Modification at the Hierarchy Level- Addition to the hierarchy level
Modification within the Data Lineage - Add sources, workflows and systems to make the Data Lineage process clearer.
How users can customise: Users will have options at each level to add, remove, or change specific functionality.
Who can customise? - Our software will provide access and permission levels for specific users based on their roles, depending on the features and functionality within each feature.
Scaling
- Independence of resources
-
Suchee software has no user account restrictions and depends on the bandwidth and elasticity of the cloud service on which it is hosted, currently AWS.
Each user will work in their own environment (this will ensure compliance with GDPR).
We will hold a formal discussion and reach an agreement before software implementation begins to confirm the approximate number of users. We will then recommend the correct licence to ensure elasticity is maintained for the number of users.
We will decide which licence to provide, depending on the organisation's current size and future scaling plans.
Analytics
- Service usage metrics
- Yes
- Metrics types
- It will be dependent on the type of licensing purchased.
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
The data is protected behind a cloud firewall with 128 bit encryption on the API's accessing the data.
The data is accessed by a limited set of users.
We have all standard measures of data integrity protection.
Data is securely deleted once the customer leaves the service.
All data is backed up in short frequency to a geographically remote cloud back up service. - Data sanitisation process
- No
- Equipment disposal approach
- In-house destruction process
Data importing and exporting
- Data export approach
-
The software supports exporting data in various formats, allowing data to be exported to the client's systems.
To facilitate this, the software allows exporting data in various formats, including .json, .csv, and/or .pdf. - Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
- Private network or public sector network
- Data protection within supplier network
- Other
- Other protection within supplier network
-
The data resides within the application, which is hosted on the AWS Cloud.
The security of the data will therefore depend on the security of the Cloud System we have chosen: AWS.
We believe AWS will be ideal for protecting our clients' data stored in the software in the cloud.
We chose AWS because we believe it is technically one of the best, adheres to industry-standard data protection regulations and practices, and includes appropriate data protection features within its cloud framework.
No data is transferred or held in the DDC's private network.
Availability and resilience
- Guaranteed availability
-
To be clear, our Data Catalogue software is not a day-to-day tool, and it is not required for day-to-day business operations.
However, we will have an agreed License Agreement and/or SLA between the buyer and us (the Supplier).
The License and/or the SLA agreement will detail the availability of the software and the rebate we will provide our client if the downtime exceeds the threshold agreed between the parties.
However, because buyers'/clients' needs and usage of the software vary, we usually draft an agreement based on the client's requirements and usage.
If, for any reason, we are not able to provide our services for a particular duration during the software implementation process, we will either provide rebates or "Service credits" to our client. - Approach to resilience
- As the service is hosted on AWS, it conforms to AWS data centre resilience protocols.
- Outage reporting
-
Our software (Data Catalog) is a SaaS solution hosted on AWS.
Any outage caused by the cloud server, and any other outage not caused by the cloud server, will be reported to the client via email alerts.
An outage of the software here refers to the software itself or any of its features becoming unavailable to the users.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
Here are key approaches
1. Role-Based Access Control (RBAC): Implement RBAC to ensure that users only have access to the features and functionalities necessary for their tasks.
Define roles clearly and assign permissions according to the least privilege principle, which means giving users only the access they need to perform their jobs.
Multi-Factor Authentication (MFA): Users are verified using an MFA method, an additional measure to restrict access to management interfaces and support channels. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
We follow and conform closely to CSA CCM version 3.0.
We comply with the GDPR guidelines, although our software does not handle PII. - Information security policies and processes
-
We have an Information Security Policy in place, and our main policies and processes for achieving them are as below:
INFORMATION SECURITY POLICIES:
Authorisation required for the folowing:
Prior to Installation, or cause to be installed, any unauthorised software onto any DDC computer (DDC's IT Security officer can advise on what software is authorised)
Access any system (application, hardware, workstation ) that you are not specifically authorised to access
Access any data that you are not specifically authorised to access
Operate any software that is not compatible with your job function
Circumvent any user authentication and other security measures, or any DDC computing equipment
Use any DDC computing equipment for anything other than legitimate Digital Data Consultancy business.
SECURITY INCIDENT/DATA BREACH HANDLING PROCESSES
A security incident is any situation in which it is apparent that any of the stipulations in the Information Policy document have been violated.
All security incidents must be reported to the head of IT, who will direct the Digital Data Consultancy’s response.
Records will be made about the incident, the resolution and the RCA of the security breach incident will be recorded too. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
We use Confluence JIRA (a Software Management tool) to track development, change management, and maintenance of Suchee's features.
We have and will create Epics for existing and any new features/changes that are/have to be configured:
The configuration changes that we make will be assessed for any potential security impact by evaluating the following:
Examining the dependencies between the new changes and the existing features and functionalities
Assessing the vulnerability the software has been exposed to, if any new tools, software, and/or API gateway had to be implemented because of the change - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Antivirus, firewalls, and the cloud server on which Suchee is hosted will be responsible for assessing and blocking any threats.
The vulnerabilities and potential threats to Suchee will usually arise from a breach of the cloud server's network.
We regularly monitor and aim to be aware of the threats and vulnerabilities from OWASP and assess their impact on our software.
We regularly scan the infrastructure for vulnerabilities that could be exploited by attackers.
We manage identified vulnerabilities by deploying patches. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Log Management- Collecting and managing logs from all parts of the SaaS infrastructure, including application logs, system logs, and network logs. .
Security Information and Event Management (SIEM): Deploying SIEM systems to aggregate, correlate, and analyze data from different sources to identify patterns that may indicate a security threat.
Vulnerability Scanning: Regularly scanning the infrastructure for vulnerabilities that could be exploited by attackers.
Incident Response and Management: Establishing a structured process for responding to detected security incidents.
Regular Updates and Patch Management: Ensuring all software and systems are kept up to date to defend against known vulnerabilities. - Incident management type
- Supplier-defined controls
- Incident management approach
-
The everyday running of the client's business will not be affected by any failure of our Software, as it is not operational software.
However, for events that will have an impact on the usage of the software features, we have pre-defined processes:
Our Users will raise tickets by completing an Incident Reporting Form, which will be emailed to our official incident reporting email address. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Basic license for three months.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 15%
- Between £500,001 and £1,000,000
- 25%
- Between £1,000,001 and £2,500,000
- 30%
- Between £2,500,001 and £5,000,000
- 30%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 185e8214-0bd4-4a15-9037-cac100e55ad8
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-