Skip to main content

Help us improve the Digital Marketplace - send your feedback

KNOWLEDGE INTEGRATION LTD

Arches for HERs Software as a Service (SaaS)

Arches for HERs is a comprehensive, purpose-built open-source data management application for UK Historic Environment Records (HERs) and international heritage institutions built on, and incorporating the benefits and features of, the Arches platform. Originally developed by the Getty Conservation Institute in partnership with Historic England and the City of Lincoln.

Features

  • Conforms to MIDAS Heritage and FISH standards including terminologies.
  • Resource models designed for UK Historic Environment Records.
  • Comprehensive consultation and casework module including workflows.
  • Consultation letter document generation workflow autopopulated with Arches data
  • Supports British National Grid reference data and searching
  • Advanced data discovery mechanisms (semantic, temporal, spatial) and visualisation
  • Authentication supporting SSO and configurable data, user, group access control
  • Coherent and accessible user-interface supporting internationalisation
  • Data import/export/bulk transformation for migration and distribution
  • Data management, versioning, auditing and visualisation (reporting, relationships)

Benefits

  • Includes all functionality and benefits of the core Arches platform
  • Open-source removes any licensing restrictions and facilitates unlimited users
  • Engage in the growing international Arches open-source community
  • Designed for UK Historic Environment Records
  • Non-proprietary standard data formats ensure high data quality and longevity
  • Scalable and accommodates datasets of varying size and complexity
  • Quickly and efficiently discover a deeper understanding of your data
  • Complete control over your data, models, vocabularies, users and access
  • Includes essential built-in geospatial tools
  • Built on modern, popular and well-maintained open-source components

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@k-int.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 6 0 2 1 3 5 4 0 8 2 6 2 6 9

Contact

KNOWLEDGE INTEGRATION LTD Rob Tice
Telephone: 01142738271
Email: tenders@k-int.co.uk

About your service

Service categories

Application Development and Deployment

Data management

Database administration and development

  • Data Modelling
  • Database Development and Optimization

Data integration and intelligence

  • Data Ingestion and Transformation Software
  • Data Quality Software
  • Data Access Infrastructure Software
  • Composite Data Framework Software
  • Master Data Intelligence Software
  • Metadata Management Software
  • Data Archiving and Information LifD-Cycle Management
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
Support SLA covers business hours of 09:00-17:00 weekdays and excludes weekends and bank holidays. Support requested can be raised as tickets via the Zendesk outside of these hours and will be picked up when working hours resume.
System requirements
  • Must have stable internet access
  • Must have latest version of popular browsers
  • Mapbox API key must be supplied for mapping access

User support

Email or online ticketing support
Yes
Support response times
Calls logged on the helpdesk are triaged and initial reply sent within two working hours.
Further responses are dependent on nature and Tier of the now triaged call, with Critical Tier 1 tickets taking priority
Support SLA covers business hours of 09:00-17:00 weekdays and excludes weekends and bank holidays
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
First, second and third line corporate support is provided in house by our teams of application specialists, developers and consultants
Support starts £5K pa
Account management is provided on all levels
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We initially liaise with buyers to investigate their requirements and intentions with the Arches platform, and whether a stock, customisable instance or an existing application with pre-existing data structures (Arches for HERs or Arches for Science) is best placed. The selected service is auto-deployed in a blank state, ready for instant use to buyers. Required data migration projects will commence separately after deployment. Initial training is provided for all classes of users and specific targeted training (e.g. for internal developers. admin users) can be also included within the package. Initial training is always online but on-site training can be provided at extra cost. Detailed online end-user documentation is provided by the open-source Arches project, in addition to the seller’s bespoke documentation, including tutorials, glossaries and 'click through' videos.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
At the end of the contract the service is turned off and ceases to be publicly available. Data export functionality is available at any time during the contract so users can prepare for end of contract in a controlled manner. For a period of 1 month following shutdown, the service can be reinstated for data export (for example if any problems were discovered with the end of service data exports). There is no charge for data exports even during the month post contract end.
End-of-contract process
Users are contacted in writing 2 months before contract ends, with a quote to clarify the terms of the continuation (e.g. any RPI price increases). If any material changes to the service are required in response to this quote, these are costed and a revised quote issued. When this is accepted then the service simply rolls over and continues.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The Arches service user interface is primarily intended for desktop use, but has an accessible responsive design for mobile and tablet compatibility. While possible, functionality such as data entry, including interaction with mapping widgets will have difficulty on smaller devices.
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
The Arches service role-based user interface covers all core functionality of the platform. Users are able to discover and visualise data using semantic, advanced query, and map-based searching. Data structures and terminologies can be constructed using the comprehensive and configurable, ontological (CIDOC CRM) focused resource model designer interface, and the controlled list manager, respectively. Resources are populated and managed using the resource editor or extensible workflow stages, and viewed with configurable reports, access control permitting. Interface pages can be created and modified using standard web framework methods, or extended with custom made or community plugins or “Arches Applications
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Accessibility of the public-facing Arches interface is a community responsibility and well documented, including approved tools and browser extensions. Such tools include: WAVE Evaluation Tool, Lighthouse, Landmarks, NVDA screen reader, W3C HTML Validator, Contrast checker.
API
Yes
What users can and can't do using the API
Many features of the Arches software are accessible via permission-based APIs. The service has APIs for authentication using the secure OAuth 2.0 authentication mechanism, data population/modification for the ability to manage Arches data when integrated with additional solutions or during data migrations and extractions, and paginated searching and data retrieval in JSON or JSON-LD (for linked data) formats. Also included are a number of geospatial endpoints, including spatial view management for retrieving, creating and editing Arches spatial views, and the GeoJSON endpoint for accessing a GeoJSON representation of resource instance data. A history and changelog of collections and resource instance data API is available for use with integrations including the CIIM middleware platform.
Built on a modern and extensible web framework, any missing API functionality can be introduced through plugins or Arches Applications
The service is managed via a tailored CI/CD pipeline which both monitors your configuration and tests/deploys changes to using the Argo API into Kubernetes.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
As an open-source application, any feature or modification can be introduced provided that it aligns with the AGPL3 licence and the project code of conduct.
The service offering can be customised via the user interface in a multitude of ways; buyers can configure data structures and entry fields using the resource model designer, and the resulting public appearance of the data reports templates, plus any specific data customisations such as geospatial styles. Controlled vocabularies used within data can be configured and extended, allowing a buyer to implement their own lists or customise existing ones. A buyer has full control of their data, and possesses the ability to import, export and modify existing data in bulk. Advanced searches can be carefully constructed and saved with images and descriptions for future use or public display.
Further non-user interface customisation can be implemented through written software extensions called “Arches Applications”, or integrations with other components (mapping services) or software.

Scaling

Independence of resources
When the systems are configured (as part of the onboarding), limits are placed on the amount of resource each tenant can utilise. This guarantees that even under heavy load there is no cross instance performance degradation. The overall architecture always has headroom to allow it to be temporarily 'burstable' to deal with transient heavy load and there are multiple API caches (including cloudflare optionally) to also balance system throughput. If an ongoing resource increase is required for a specific tenant this can be configured and redeployed automatically.

Analytics

Service usage metrics
Yes
Metrics types
The service has data history and auditing analytics, in addition to the ability to integrate with Google Analytics for site-wide metrics.
Helpdesk response times, service availability and resource usage are also provided
Reporting types
  • API access
  • Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Physical access control, complying with CSA CCM v4.0
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
The service includes built-in data exporting functionalities for bulk operations or specific subsets of data (e.g. via searches). Users are able to interact with this feature via a user interface, giving full control to users. Data can also be exported via the command-line interface or directly from the PSQL database.
Data export formats
  • CSV
  • Other
Other data export formats
  • Json
  • Xml
  • SQL
  • Shapefile
  • Excel
  • HTML
  • JPEG
  • PNG
  • DOCX
Data import formats
  • CSV
  • Other
Other data import formats
  • Json
  • SQL
  • Excel
  • Shapefile

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection between networks
Secure SSH tunnels can be configured if options above are not available
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)

Availability and resilience

Guaranteed availability
"We guarantee 99.9% uptime for any public facing services. This excludes agreed scheduled downtime and any outages which are the result of issues caused by the underlying cloud provider platform being unavailable.
Uptime is monitored and reviewed as part of service renewal, any failure to hit the agreed availability will be considered and offset against any annual increase in renewal costs"
Approach to resilience
Our services can be delivered via all the common cloud platforms and are deployed on Kubernetes, typically using Amazon EKS. We specify the numbers of 'replicas' of service components via our automatic configuration management and this replica provides the underlying resilience and auto scaling for handling of burstable demand increases, as well as replacing unhealthy services with new healthy replicas. Where cloud platforms are used, their service guarantees cover the uptime of the Kubernetes Platform.
Outage reporting
Our services are deployed within a Kubernetes cluster, with cluster management via Argo. In addition our automated monitoring system automatically raises a support ticket when any system anomalies are detected. These anomalies are not limited to actual problems and can be used to pre-empt issues arising. This can include performance slowdowns, processing bottlenecks and API response times. Because these are raised as support tickets they are also visible to the customer when they log in to their support portal.
External monitoring tools are also configured to probe aliveness of deployed applications.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access is restricted in management interfaces and support channels by a minimum of 2fa. It can be additionally restricted by IP. In terms of the management authentication, it can also be integrated with an organisation's identity management system, so that additional account information is not required. In this case  access (and therefore by definition) the restrictions (in addition to 2FA) are based on the individual organisational identity management policy, however we can additionally disable accounts directly via our interfaces
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
We have internally allocated information security responsibilities with a regular review process.
Entry controls to restrict access to premises, equipment and data.
We ensure the security of home working and mobile devices.
We configure new and existing hardware to reduce vulnerabilities.
We assign user accounts to authorised individuals, and manage user accounts to provide the minimum access to information.
We have password security procedures and network 'rules' for access to information systems.
We have anti-malware defences to protect computers from malware infection (including at firewall level).
We have boundary firewalls (Fortigate) to protect from external attack and exploitation and help prevent data breaches.
Breaches or misuse are reported and escalated to Heads of Department and then Directors
Software Security Code of Practice
No

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Our core components, implementation code and configuration are managed/ tested within our CI/CD pipeline for all commits, with weekly large scale integration tests as part of this framework to allow us to capture any potential issues which only surface for large data sets. The potential security impact of any change is always reviewed in terms of changing the threat landscape, attack surface and whether our existing controls mitigate the change. If there is deemed an impact on security, then these threats are documented and mitigation is put in place. This is always validated by vulnerability and/or penetration testing as required.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We utilise OWASP dependency Check within our CI/CD build pipeline. Scanning of new and existing components happens at verify time as part of the build process. We utilise a central database, updating from the NVD database daily and all our builds use this database. We utilise Intruder.io to check external vulnerabilities daily and to email a report and these are also responded to within a 48 hour window. Both of these services monitor daily CVE updates to provide their analysis. For third party components, we utilise OpenVAS checking against an internal version registry to produce alerts.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Potential compromises are identified through technical controls and human input. Access and authentication logs are monitored for unusual activity such as repeated failed logins, privilege escalation, or abnormal access patterns. Tools such as OSSEC and Fail2ban are used to detect and automatically alert administrators to high-risk events and mitigate intrusive activity.
Security incidents are treated as a critical priority. Initial triage begins as soon as a potential threat is identified, with immediate action taken to confirm and contain the incident to minimise impact. Following containment, incidents are investigated, remediated, and affected customers are notified with relevant findings and actions taken.
Incident management type
Supplier-defined controls
Incident management approach
Incident management covers security compromises, service outages or degradation, data access breaches, and account or access misuse. Incidents are categorised by type and severity and follow a clear workflow of containment, investigation, resolution, and review. After resolution, reports are provided to affected customers summarising the cause, impact, and actions taken, including preventive measures, to ensure transparency, accountability, and continual improvement. Users can report incidents via our support ticketing system, Zendesk, ensuring prompt visibility of incidents, triage and escalation of high-priority events.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
17.5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
080561af-3109-4d58-8c86-ce86c20d6017
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Working conditions which promote an inclusive working environment and promote retention and progression
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@k-int.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.