Enterprise Solution Architecture
A&A Digital Tech Enterprise Solution Architecture Services provide cloud-based tools and services to support the design, modelling and governance of enterprise solutions. The service enables organisations to define, visualise and manage solution architectures using standard modelling approaches, supporting application development, integration and deployment activities.
Features
- Cloud-hosted solution architecture and modelling platforms
- Support for multiple development languages and environments
- Support for multiple development languages and environments
- Business process modelling tools
- Enterprise architecture modelling and repositories
- Architecture standards and templates
- Integration with development and delivery toolchains
- Collaboration and version control features
- Architecture governance and review support
- Secure access and role-based controls
Benefits
- Improved consistency in solution design
- Clear visibility of application and system architectures
- Better alignment between business processes and technology
- Improved collaboration across delivery teams
- Reduced architectural risk and rework
- Faster solution design and validation
- Support for scalable and maintainable architectures
- Improved governance and architectural control
- Reusable architecture artefacts
- Enhanced decision-making during development and deployment
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 9 4 5 7 3 2 1 5 4 7 4 3 0 1
Contact
A&A DIGITAL TECH LTD
Murala Rama Rao
Telephone: 07799343396
Email: rmurala@aadigitaltech.com
About your service
- Service categories
-
Application Development and Deployment
Application development
- Development languages, environments and tools
Modelling and architecture
- Object Modelling Tools
- Business Process Modelling Tools
- Enterprise Architecture Tools
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- The service can be delivered remotely, on-site, or using a hybrid delivery model for onboarding and support, depending on buyer requirements and agreement at call-off. The service is delivered as cloud-hosted SaaS and depends on supported browsers and cloud platforms. Functionality may vary depending on integration with third-party tools. The service does not replace enterprise-wide governance processes unless explicitly configured.
- System requirements
-
- Internet connection to access cloud-hosted development platform
- Modern web browser supported by the service
- User accounts with appropriate access permissions
- Buyer-owned development tool licences where required
- Secure identity and access management in place
- Compatibility with supported development languages and frameworks
- Ability to export data using supported formats
- Compliance with buyer security and governance policies
- Endpoint security controls on user devices
- Email access for notifications and support communication
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- A&A Digital Tech responds to buyer questions within two working day during standard UK business hours. Where an urgent response is required, this can be agreed at the start of the engagement.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Accessibility of our web chat functionality is considered during design and testing activities, including checks using assistive technologies such as screen readers and keyboard-only navigation. We follow recognised accessibility standards and address any issues identified as part of ongoing service improvement. Where buyer-specific requirements exist, additional accessibility testing can be agreed.
- Onsite support
- Yes, at extra cost
- Support levels
- A&A Digital Tech provides flexible support levels tailored to buyer needs and the criticality of the service. Level 1 support provides first-line support for service queries, incident logging, basic troubleshooting and request handling during UK business hours. Level 2 support provides second-line technical support, including deeper investigation, issue resolution and configuration support, with extended hours available by agreement. Level 3 support provides specialist and expert-level support, including complex fault resolution, architectural input and escalation handling. Support costs vary depending on the selected support level, hours of coverage and service scope. Pricing is agreed with the buyer at the start of the engagement and detailed in the call-off contract. A named technical account manager or cloud support engineer can be provided for Level 2 and Level 3 support, acting as the primary point of contact and supporting service governance and escalation.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- A&A Digital Tech supports users in getting started through structured onboarding, including account setup, access configuration and initial service walkthroughs. We provide user documentation and online guidance materials to support self-service use of the platform. Remote training sessions can be provided where required, with on-site training available by agreement to support user adoption.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At the end of the contract, users can extract their data and application artefacts using the service’s supported export tools and standard file formats. A&A Digital Tech provides guidance on the extraction process to support a secure and orderly exit. Data extraction responsibilities and any assistance required are agreed with the buyer in advance as part of the exit plan.
- End-of-contract process
- At the end of the contract, A&A Digital Tech supports an orderly service exit in line with the agreed exit plan. This includes enabling access to data and application artefacts and providing agreed documentation. Activities included in the contract price are those defined in the agreed service scope. Any additional support, such as extended data export assistance, bespoke handover activities or on-site support beyond the agreed scope, may incur additional costs and will be agreed with the buyer in advance.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is primarily designed for use on desktop and laptop devices, which provide full access to development tools, configuration options and modelling capabilities. Mobile access may be available for viewing dashboards, notifications or basic administration, but full development, configuration and modelling functions are supported on desktop devices only.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- User environments are logically segregated within the service to ensure isolation between buyers. Resource allocation and access controls are configured to prevent one user’s demand from affecting another’s service performance. Where shared platform components are used, capacity management and monitoring are applied to maintain consistent service availability for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- A&A Digital Tech provides service metrics covering platform availability, service performance and support responsiveness. Metrics may include service uptime, incident and request volumes, response and resolution times, and usage information where available. Reporting frequency and specific metrics are agreed with the buyer at the start of the contract to ensure they align with service objectives and governance requirements.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users export their data using built-in export functionality provided by the service, supporting standard and commonly used file formats. Data exports can be initiated through the web interface by authorised users, with guidance provided to ensure data is transferred securely and in line with the agreed exit plan.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- A&A Digital Tech targets high service availability aligned to the underlying cloud platform’s service levels. Availability commitments and any service level agreements (SLAs) are agreed with the buyer at call-off and documented in the contract. Where availability targets are not met, service credits or other remedies may be applied in line with the agreed SLA. Refunds or credits are calculated based on the impact and duration of the availability issue, as set out in the contract.
- Approach to resilience
- The service is designed to be resilient through the use of highly available cloud platforms operated by third-party providers. These platforms use resilient datacentre designs, including redundant power, networking and storage, and are distributed across multiple availability zones where supported. The service includes monitoring, backup and recovery capabilities to support continuity. Further details on resilience and datacentre architecture can be provided to buyers on request.
- Outage reporting
- Service outages are reported to users through email alerts, providing timely information on the nature of the issue, impact and progress updates. Where applicable, follow-up communications are sent to confirm resolution and any required actions. Additional reporting or notification mechanisms can be agreed with buyers where required as part of the service setup.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted through role-based access controls and least-privilege principles. User access is authenticated using approved authentication mechanisms, including multi-factor authentication where supported. Permissions are assigned based on role and reviewed regularly. Access to support channels is limited to authorised buyer contacts, and sensitive actions require additional verification or approval in line with defined security procedures.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- A&A Digital Tech operates a formal information security management system aligned to ISO/IEC 27001. We also follow ISO 9001, ISO 45001, ISO/IEC 20000-1 and ISO 14001 certified management processes to support quality, service management, health and safety, and environmental controls. Information security responsibilities are defined within a clear governance and reporting structure, with senior management oversight. Policies are communicated to staff, supported by mandatory training, and enforced through regular audits, risk assessments and continuous improvement activities. We are progressing certification to ISO/IEC 27017 and ISO/IEC 27018 to further strengthen cloud security and data protection controls.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- A&A Digital Tech manages configuration and change in line with recognised standards, including ISO/IEC 20000-1 and ISO/IEC 27001. Service components are recorded in configuration records that track assets, versions and dependencies throughout their lifecycle. Changes are formally assessed, approved and documented using defined change management processes. Security impact assessments are performed for changes that may affect confidentiality, integrity or availability, with appropriate testing and approval required before implementation.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- A&A Digital Tech manages vulnerabilities in line with recognised standards, including ISO/IEC 27001 and ISO/IEC 20000-1. Potential threats are assessed through regular vulnerability scanning, risk assessments and review of service configurations. Patches are prioritised based on risk and deployed in line with defined change management processes, with critical security patches applied as soon as practicable. Information on potential threats is obtained from cloud providers, vendor security advisories, industry threat intelligence sources and national cyber security guidance.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- A&A Digital Tech operates protective monitoring in line with recognised standards, including ISO/IEC 27001 and ISO/IEC 20000-1. Potential compromises are identified through monitoring of logs, alerts and security events from the service and underlying cloud platforms. When a potential compromise is identified, incidents are assessed, prioritised and managed through defined incident management processes, including containment and remediation actions where required. Response times are aligned to the severity of the incident, with security incidents investigated and acted upon as soon as practicable in line with agreed support arrangements.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- A&A Digital Tech operates defined incident management processes aligned to recognised standards, including ISO/IEC 27001 and ISO/IEC 20000-1. Pre-defined procedures are in place for common incident types to support consistent triage, escalation and resolution. Users report incidents via agreed support channels, such as email or service desk contact. Incident updates and reports are provided to users through email communications and, where required, formal incident reports detailing impact, resolution actions and lessons learned.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 3%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Qualitas Varitas
- ISO/IEC 27001 accreditation date
- Monday 6 October 2025
- What the ISO/IEC 27001 doesn’t cover
- Buyer-owned systems, infrastructure, networks or devices • Third-party cloud platforms, SaaS products or services not operated or managed by us • Customer data once exported from the service and stored outside our controlled environments • End-user devices, local networks and identity systems managed by the buyer • Third-party integrations where security controls are the responsibility of the external provider • Services or activities delivered outside the formally certified ISMS scope • Custom configurations or extensions implemented by the buyer without our involvement • Physical security controls at customer premises • Outcomes dependent on customer data quality, usage patterns or operational decisions
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Qualitas Varitas
- ISO 9001 accreditation date
- Friday 12 December 2025
- What the ISO 9001 doesn’t cover
- • Buyer-owned systems, infrastructure, tools and environments • Third-party products, platforms or services not controlled or managed by us • Activities performed entirely by subcontractors or partners outside our QMS scope • Customer processes, governance arrangements or operational decisions • Outcomes dependent on buyer-provided information, requirements or approvals • Services delivered outside the formally certified QMS scope • Bespoke changes or configurations implemented by the buyer without our involvement • Physical delivery locations or facilities not included within the certified scope • Performance of third-party suppliers beyond agreed contractual controls
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5481a3e1-b7cf-4de2-bf7e-b3d711a38339
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 21a1ac10-5833-41b1-aca9-87de0defea32
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 14001
- ISO 45001
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-