Arches for HERs Software as a Service (SaaS)
Arches for HERs is a comprehensive, purpose-built open-source data management application for UK Historic Environment Records (HERs) and international heritage institutions built on, and incorporating the benefits and features of, the Arches platform. Originally developed by the Getty Conservation Institute in partnership with Historic England and the City of Lincoln.
Features
- Conforms to MIDAS Heritage and FISH standards including terminologies.
- Resource models designed for UK Historic Environment Records.
- Comprehensive consultation and casework module including workflows.
- Consultation letter document generation workflow autopopulated with Arches data
- Supports British National Grid reference data and searching
- Advanced data discovery mechanisms (semantic, temporal, spatial) and visualisation
- Authentication supporting SSO and configurable data, user, group access control
- Coherent and accessible user-interface supporting internationalisation
- Data import/export/bulk transformation for migration and distribution
- Data management, versioning, auditing and visualisation (reporting, relationships)
Benefits
- Includes all functionality and benefits of the core Arches platform
- Open-source removes any licensing restrictions and facilitates unlimited users
- Engage in the growing international Arches open-source community
- Designed for UK Historic Environment Records
- Non-proprietary standard data formats ensure high data quality and longevity
- Scalable and accommodates datasets of varying size and complexity
- Quickly and efficiently discover a deeper understanding of your data
- Complete control over your data, models, vocabularies, users and access
- Includes essential built-in geospatial tools
- Built on modern, popular and well-maintained open-source components
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 6 0 2 1 3 5 4 0 8 2 6 2 6 9
Contact
KNOWLEDGE INTEGRATION LTD
Rob Tice
Telephone: 01142738271
Email: tenders@k-int.co.uk
About your service
- Service categories
-
Application Development and Deployment
Data management
Database administration and development
- Data Modelling
- Database Development and Optimization
Data integration and intelligence
- Data Ingestion and Transformation Software
- Data Quality Software
- Data Access Infrastructure Software
- Composite Data Framework Software
- Master Data Intelligence Software
- Metadata Management Software
- Data Archiving and Information LifD-Cycle Management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- Support SLA covers business hours of 09:00-17:00 weekdays and excludes weekends and bank holidays. Support requested can be raised as tickets via the Zendesk outside of these hours and will be picked up when working hours resume.
- System requirements
-
- Must have stable internet access
- Must have latest version of popular browsers
- Mapbox API key must be supplied for mapping access
User support
- Email or online ticketing support
- Yes
- Support response times
-
Calls logged on the helpdesk are triaged and initial reply sent within two working hours.
Further responses are dependent on nature and Tier of the now triaged call, with Critical Tier 1 tickets taking priority
Support SLA covers business hours of 09:00-17:00 weekdays and excludes weekends and bank holidays - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
First, second and third line corporate support is provided in house by our teams of application specialists, developers and consultants
Support starts £5K pa
Account management is provided on all levels - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We initially liaise with buyers to investigate their requirements and intentions with the Arches platform, and whether a stock, customisable instance or an existing application with pre-existing data structures (Arches for HERs or Arches for Science) is best placed. The selected service is auto-deployed in a blank state, ready for instant use to buyers. Required data migration projects will commence separately after deployment. Initial training is provided for all classes of users and specific targeted training (e.g. for internal developers. admin users) can be also included within the package. Initial training is always online but on-site training can be provided at extra cost. Detailed online end-user documentation is provided by the open-source Arches project, in addition to the seller’s bespoke documentation, including tutorials, glossaries and 'click through' videos.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- At the end of the contract the service is turned off and ceases to be publicly available. Data export functionality is available at any time during the contract so users can prepare for end of contract in a controlled manner. For a period of 1 month following shutdown, the service can be reinstated for data export (for example if any problems were discovered with the end of service data exports). There is no charge for data exports even during the month post contract end.
- End-of-contract process
- Users are contacted in writing 2 months before contract ends, with a quote to clarify the terms of the continuation (e.g. any RPI price increases). If any material changes to the service are required in response to this quote, these are costed and a revised quote issued. When this is accepted then the service simply rolls over and continues.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The Arches service user interface is primarily intended for desktop use, but has an accessible responsive design for mobile and tablet compatibility. While possible, functionality such as data entry, including interaction with mapping widgets will have difficulty on smaller devices.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- The Arches service role-based user interface covers all core functionality of the platform. Users are able to discover and visualise data using semantic, advanced query, and map-based searching. Data structures and terminologies can be constructed using the comprehensive and configurable, ontological (CIDOC CRM) focused resource model designer interface, and the controlled list manager, respectively. Resources are populated and managed using the resource editor or extensible workflow stages, and viewed with configurable reports, access control permitting. Interface pages can be created and modified using standard web framework methods, or extended with custom made or community plugins or “Arches Applications
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Accessibility of the public-facing Arches interface is a community responsibility and well documented, including approved tools and browser extensions. Such tools include: WAVE Evaluation Tool, Lighthouse, Landmarks, NVDA screen reader, W3C HTML Validator, Contrast checker.
- API
- Yes
- What users can and can't do using the API
-
Many features of the Arches software are accessible via permission-based APIs. The service has APIs for authentication using the secure OAuth 2.0 authentication mechanism, data population/modification for the ability to manage Arches data when integrated with additional solutions or during data migrations and extractions, and paginated searching and data retrieval in JSON or JSON-LD (for linked data) formats. Also included are a number of geospatial endpoints, including spatial view management for retrieving, creating and editing Arches spatial views, and the GeoJSON endpoint for accessing a GeoJSON representation of resource instance data. A history and changelog of collections and resource instance data API is available for use with integrations including the CIIM middleware platform.
Built on a modern and extensible web framework, any missing API functionality can be introduced through plugins or Arches Applications
The service is managed via a tailored CI/CD pipeline which both monitors your configuration and tests/deploys changes to using the Argo API into Kubernetes. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
As an open-source application, any feature or modification can be introduced provided that it aligns with the AGPL3 licence and the project code of conduct.
The service offering can be customised via the user interface in a multitude of ways; buyers can configure data structures and entry fields using the resource model designer, and the resulting public appearance of the data reports templates, plus any specific data customisations such as geospatial styles. Controlled vocabularies used within data can be configured and extended, allowing a buyer to implement their own lists or customise existing ones. A buyer has full control of their data, and possesses the ability to import, export and modify existing data in bulk. Advanced searches can be carefully constructed and saved with images and descriptions for future use or public display.
Further non-user interface customisation can be implemented through written software extensions called “Arches Applications”, or integrations with other components (mapping services) or software.
Scaling
- Independence of resources
- When the systems are configured (as part of the onboarding), limits are placed on the amount of resource each tenant can utilise. This guarantees that even under heavy load there is no cross instance performance degradation. The overall architecture always has headroom to allow it to be temporarily 'burstable' to deal with transient heavy load and there are multiple API caches (including cloudflare optionally) to also balance system throughput. If an ongoing resource increase is required for a specific tenant this can be configured and redeployed automatically.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The service has data history and auditing analytics, in addition to the ability to integrate with Google Analytics for site-wide metrics.
Helpdesk response times, service availability and resource usage are also provided - Reporting types
-
- API access
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- The service includes built-in data exporting functionalities for bulk operations or specific subsets of data (e.g. via searches). Users are able to interact with this feature via a user interface, giving full control to users. Data can also be exported via the command-line interface or directly from the PSQL database.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Json
- Xml
- SQL
- Shapefile
- Excel
- HTML
- JPEG
- PNG
- DOCX
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Json
- SQL
- Excel
- Shapefile
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Other
- Other protection between networks
- Secure SSH tunnels can be configured if options above are not available
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
-
"We guarantee 99.9% uptime for any public facing services. This excludes agreed scheduled downtime and any outages which are the result of issues caused by the underlying cloud provider platform being unavailable.
Uptime is monitored and reviewed as part of service renewal, any failure to hit the agreed availability will be considered and offset against any annual increase in renewal costs" - Approach to resilience
- Our services can be delivered via all the common cloud platforms and are deployed on Kubernetes, typically using Amazon EKS. We specify the numbers of 'replicas' of service components via our automatic configuration management and this replica provides the underlying resilience and auto scaling for handling of burstable demand increases, as well as replacing unhealthy services with new healthy replicas. Where cloud platforms are used, their service guarantees cover the uptime of the Kubernetes Platform.
- Outage reporting
-
Our services are deployed within a Kubernetes cluster, with cluster management via Argo. In addition our automated monitoring system automatically raises a support ticket when any system anomalies are detected. These anomalies are not limited to actual problems and can be used to pre-empt issues arising. This can include performance slowdowns, processing bottlenecks and API response times. Because these are raised as support tickets they are also visible to the customer when they log in to their support portal.
External monitoring tools are also configured to probe aliveness of deployed applications.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is restricted in management interfaces and support channels by a minimum of 2fa. It can be additionally restricted by IP. In terms of the management authentication, it can also be integrated with an organisation's identity management system, so that additional account information is not required. In this case access (and therefore by definition) the restrictions (in addition to 2FA) are based on the individual organisational identity management policy, however we can additionally disable accounts directly via our interfaces
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
We have internally allocated information security responsibilities with a regular review process.
Entry controls to restrict access to premises, equipment and data.
We ensure the security of home working and mobile devices.
We configure new and existing hardware to reduce vulnerabilities.
We assign user accounts to authorised individuals, and manage user accounts to provide the minimum access to information.
We have password security procedures and network 'rules' for access to information systems.
We have anti-malware defences to protect computers from malware infection (including at firewall level).
We have boundary firewalls (Fortigate) to protect from external attack and exploitation and help prevent data breaches.
Breaches or misuse are reported and escalated to Heads of Department and then Directors - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our core components, implementation code and configuration are managed/ tested within our CI/CD pipeline for all commits, with weekly large scale integration tests as part of this framework to allow us to capture any potential issues which only surface for large data sets. The potential security impact of any change is always reviewed in terms of changing the threat landscape, attack surface and whether our existing controls mitigate the change. If there is deemed an impact on security, then these threats are documented and mitigation is put in place. This is always validated by vulnerability and/or penetration testing as required.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We utilise OWASP dependency Check within our CI/CD build pipeline. Scanning of new and existing components happens at verify time as part of the build process. We utilise a central database, updating from the NVD database daily and all our builds use this database. We utilise Intruder.io to check external vulnerabilities daily and to email a report and these are also responded to within a 48 hour window. Both of these services monitor daily CVE updates to provide their analysis. For third party components, we utilise OpenVAS checking against an internal version registry to produce alerts.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Potential compromises are identified through technical controls and human input. Access and authentication logs are monitored for unusual activity such as repeated failed logins, privilege escalation, or abnormal access patterns. Tools such as OSSEC and Fail2ban are used to detect and automatically alert administrators to high-risk events and mitigate intrusive activity.
Security incidents are treated as a critical priority. Initial triage begins as soon as a potential threat is identified, with immediate action taken to confirm and contain the incident to minimise impact. Following containment, incidents are investigated, remediated, and affected customers are notified with relevant findings and actions taken. - Incident management type
- Supplier-defined controls
- Incident management approach
- Incident management covers security compromises, service outages or degradation, data access breaches, and account or access misuse. Incidents are categorised by type and severity and follow a clear workflow of containment, investigation, resolution, and review. After resolution, reports are provided to affected customers summarising the cause, impact, and actions taken, including preventive measures, to ensure transparency, accountability, and continual improvement. Users can report incidents via our support ticketing system, Zendesk, ensuring prompt visibility of incidents, triage and escalation of high-priority events.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 17.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 080561af-3109-4d58-8c86-ce86c20d6017
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-