Connect+
Connect+ is a cloud-based Customer Communications Management service enabling organisations to create, manage, and deliver personalised, omni-channel communications. It supports secure, flexible digital and print delivery, ensuring consistent, relevant messages across all touchpoints - whether for simple notifications or complex campaigns - enhancing engagement and streamlining communication workflows.
Features
- Cloud‑native, multi‑tenant platform delivering lower costs, faster innovation, elastic scalability.
- End‑to‑end communication management on one platform, reducing complexity and risk.
- Omni‑channel engine delivering consistent experiences across all digital/physical channels
- High‑volume processing ensuring reliable, mission‑critical communications at peak demand.
- Event‑driven, API‑first integrations enabling seamless connection with core systems.
- Advanced templating enabling highly personalised communications without custom development.
- Security‑by‑design with enterprise‑grade compliance for regulated, high‑risk environments.
- Orchestrated delivery with failover guaranteeing continuity during outages or failures.
- Centralised monitoring providing real‑time visibility into performance, volumes, and SLAs.
- Modular hosted service delivering fast deployment, low customisation, predictable costs.
Benefits
- Lower total cost(Aprox.35%) through cloud scalability without customer infrastructure investments.
- Single platform control across design, delivery, and monitoring.
- Consistent omni-channel customer experiences from one governed communication source platform.
- Proven high-volume reliability for mission-critical transactional customer communications at scale.
- Seamless API-driven integration with enterprise systems and partner ecosystems globally.
- Highly personalized communications using dynamic templates, rules, and real-time data.
- Enterprise-grade security and compliance suitable for regulated industries worldwide environments.
- Guaranteed delivery continuity through intelligent routing, failover, and kill-switch controls.
- Full transparency via real-time monitoring, logging, reporting, and SLA management.
- Faster time-to-value(>50%) with modular configuration and predictable managed service costs.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 1 6 5 0 8 7 6 9 6 8 9 1 5 9
Contact
HARLOW PRINTING LIMITED T/A HARLOW SOLUTIONS
Jack Harrison
Telephone: 01914554286
Email: bidteam@harlowprinting.co.uk
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI software services
- Document AI Software Services
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No constraints
- System requirements
- No specific requirements
User support
- Email or online ticketing support
- Yes
- Support response times
- 24 hours, 7 days a week if required
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Users can reach 1st line support and submit tickets through the chat.
On request we will execute web chat accessibility testing. - Onsite support
- Yes, at extra cost
- Support levels
- We provide this through our Customer Success Manager, and this is standard within our offering
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- Training is provided online and/or onsite. Furthermore, extensive documentation is available for training and knowledge sharing.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Videos
- Training Courses
- End-of-contract data extraction
- Users can download their data when to contract ends.
- End-of-contract process
- At the end of the contract, the platform supports a controlled, secure, and transparent exit process to ensure full continuity, data ownership, and compliance. This means, we guarantee data ownership, secure export, controlled transition, and certified data deletion, ensuring a clean, compliant, and low-risk exit with no vendor lock-in.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There are no differences between the mobile and desktop service
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- Users can submit tickets through the service interface
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- Our test team has tested the interface
- API
- Yes
- What users can and can't do using the API
- API changes are recommended to be discussed with our technical team
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Templates, omnichannel scenario's, output channels etc. can be configured by business users of our clients through the portal.
Scaling
- Independence of resources
-
We prevent “noisy neighbour” effects through tenant isolation, per-customer quotas, traffic controls, and elastic scaling.
This guarantees predictable, SLA-backed performance for each customer, regardless of other users’ demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide transparent service usage metrics covering communication volumes, channel delivery, performance, user activity, and security events.
Metrics are available via dashboards, exportable reports, and APIs, supporting billing, SLA monitoring, and compliance. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
-
All customer data is encrypted at rest using industry-standard encryption (AES-256)
Encryption keys are securely managed and access-controlled
Key rotation and lifecycle management are enforced - Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
-
Users can export their data via role-based self-service in the platform, secured APIs, or a managed export service for large or complex datasets.
All exports are encrypted, fully auditable, and compliant with GDPR and ISO 27001, ensuring secure and verifiable data portability. - Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- XML–primary structured input format for transactional and batch communications
- JSON–modern API-based and event-driven data ingestion
- TXT(fixed-width or delimited) – legacy and mainframe-style data sources
- PDF/PDF-A – document ingestion and enrichment use cases
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- XML
- JSON
- TXT
- PDF/PDF-A
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
-
Data exchanged between the buyer’s network and our platform is protected using strong encryption, secure authentication, network segmentation, and continuous monitoring.
This ensures confidential, tamper-resistant, and auditable data exchange at all times. - Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
We protect data internally through encryption at rest, strict access controls, tenant segregation, network segmentation, and continuous monitoring.
This ensures customer data remains secure, isolated, and auditable throughout its lifecycle.
Availability and resilience
- Guaranteed availability
-
We guarantee 99.5% monthly availability, backed by continuous monitoring and transparent reporting.
If availability falls below agreed levels, customers receive clearly defined service credits applied to future invoices. - Approach to resilience
-
The platform operates on a multi-datacentre, multi-availability-zone architecture with built-in redundancy, replication, and automated failover.
Detailed datacentre and resilience documentation is available on request under NDA. - Outage reporting
- Yes, we provide real-time performance dashboards and API email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Other
- Other user authentication
- Single Sign-On (SSO) via industry-standard protocols (e.g. SAML 2.0 / OpenID Connect) to integrate with customer identity providers
- Access restrictions in management interfaces and support channels
-
We restrict access to management and support interfaces using RBAC, MFA, network controls, and time-bound authorisation.
All administrative and support activities are logged, monitored, and regularly reviewed to ensure secure operations. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Other
- Description of management access authentication
- Single Sign-On (SSO) via industry-standard protocols (e.g. SAML 2.0 / OpenID Connect) to integrate with customer identity providers
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
SOC2 Type 2 Assurance
Our security governance is built on a certified ISO 27001 ISMS, supported by SOC 2 Type II operational assurance and full GDPR compliance.
This ensures security controls are defined, independently validated, continuously monitored, and regulator-ready. - Information security policies and processes
-
We operates 40 formal information security policies, managed and evidenced via Sprinto, aligned with ISO 27001, SOC 2 Type II, and GDPR.
Clear governance, executive oversight, continuous monitoring, and audits ensure policies are consistently followed and enforced across the organisation. We can provide more details on request. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
The platform tracks all service components through their full lifecycle using central configuration management, version control, and audit logs.
All changes undergo formal approval and security impact assessment to protect service integrity and customer data. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
We continuously identifies and assesses vulnerabilities using automated scanning, threat intelligence, and security testing, prioritised by risk.
Patches are deployed via controlled pipelines with defined SLAs, supported by trusted external and internal threat intelligence sources. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
We use continuous monitoring, alerting, and anomaly detection to identify potential compromises in real time.
Incidents are rapidly triaged, contained, and remediated, with defined response times and full auditability. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
We use pre-defined incident runbooks, clear user reporting channels, and structured escalation to manage incidents effectively.
Customers receive timely updates and formal incident reports, ensuring transparency, accountability, and continuous improvement. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Other
- Other public sector networks
- Several Public Networks in the Netherlands
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- This is a POC environment reflecting the full platform capabilities. This is offered for a predefined period which is agreed with customer
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 2%
- Over £5,000,001
- 2%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Management Systems Certification Ltd
- ISO/IEC 27001 accreditation date
- Wednesday 3 December 2025
- What the ISO/IEC 27001 doesn’t cover
- N/a
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Management Systems Certification Ltd
- ISO 9001 accreditation date
- Friday 21 June 2024
- What the ISO 9001 doesn’t cover
- N/a
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ea3c770a-df8f-4cf0-a770-3ce0458cab10
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 15293816-46b8-46a0-9ac2-5fab25408c08
- Other security certifications
- Yes
- Any other security certifications
- NHS Data Security and Protection Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
-