Trust Information Portal
TIPS is a cloud-hosted information governance and discovery platform that unifies fragmented reports, dashboards and KPIs into a single trusted source. It reduces reporting noise, restores data confidence, and provides AI-ready metadata for safe, explainable analytics and AiDA—without replacing existing BI investments. Trusted front-door to insight.
Features
- Cloud-hosted software platform for governed information discovery
- Single catalogue for reports, dashboards and KPIs
- Configurable governance workflows with approvals and lifecycle management
- Built-in ownership, version control and audit trails
- Seamless integration with existing BI platforms
- Standardised KPI definitions and enterprise metadata management
- Structured information request management capability
- Embedded data quality and assurance rules
- Modular App Store with configurable software capabilities
- AI-ready metadata model enabling AiDA
Benefits
- One trusted front door to organisational insight
- Dramatically reduced reporting duplication and inefficiency
- Faster access to approved, reliable information
- Greater confidence in decision-making data
- Consistent KPIs across teams and leadership
- Strong governance without slowing delivery
- Clearer, higher-quality information request
- Increased value from existing BI platforms
- Lower reporting risk and data errors
- Safe, scalable pathway to AI adoption
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 6 4 9 1 9 0 3 4 8 5 1 3 6 7
Contact
NEW COMPANY SERVICES LIMITED
Zoe Dronfield
Telephone: +447779029737
Email: zoe.dronfield@ncs-it.co.uk
About the service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Advanced and predictive analytics
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- TIPS is part of the NCS Bedrock product portfolio that comprises AI/BI components including real-time data warehousing and analytics. TIPS is a system agnostic front door to any informational resource and can run as part of Bedrock or at organisations who have different analytics systems.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- TIPS requires connectivity to source reporting objects (e.g. Tableau/Qlik/PowerBI/SSRS etc) and execution access. Deployment is hosted within the buyer’s cloud or on-premise environment, requiring appropriate subscriptions, permissions and network configuration. Planned maintenance windows are agreed in advance. Service performance depends on source system availability and data quality.
- System requirements
-
- Azure, Oracle Cloud, or on-prem infrastructure required
- Secure network connectivity to source objects
- Buyer-managed identity and access controls
- Secure VPN or private network connectivity
- Downstream analytics or storage platform available
User support
- Email or online ticketing support
- Yes
- Support response times
- Bedrock provides email and ticket-based support through the NCS-IT Service Desk. Tickets are triaged immediately and assigned a priority based on impact and urgency. Standard response times are within 4 working hours for Priority 1 issues, 1 business day for Priority 2, and 2 business days for lower-priority requests. Weekend and bank holiday coverage follows an on-call escalation model for critical issues only.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
NCS-IT provides a structured, scalable support model designed for NHS organisations using Bedrock and related data services. Support is delivered by UK-based analysts, engineers, and architects operating within standard business hours (09:00–17:00, Monday–Friday), with optional extended or 24/7 cover.
Our support tiers include:
• Standard Support (included):
Email and ticketing support, monitoring, incident triage, issue resolution, and product updates. Responses are prioritised by severity, with critical issues acknowledged within one hour.
• Enhanced Support (optional):
Out-of-hours cover, weekend support, enhanced SLAs, and priority routing to senior engineers.
• Premium Support (optional):
Dedicated Technical Account Manager (TAM), proactive service reviews, architecture guidance, and roadmap planning. Aligned to SFIA Levels 4–6 roles for expert-level assurance.
All support is delivered by qualified staff following ITIL-aligned processes. Consultants work within defined day rates (SFIA Levels 1–7) as outlined in our rate card, ensuring transparency and predictable costs (SFIA pricing provided in the rate card document)
163106170115230-sfia-rate-card-…
.
Tickets can be raised via our online portal or email. Clients may manage ticket priority, view progress, and receive automated updates. Major incidents follow a structured escalation path through Lead Engineers and Solution Architects. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
NCS-IT provides a structured onboarding process to help Trusts begin using TIPS quickly and safely. We start with a Discovery and technical readiness assessment to confirm expectations, and determine what the organisation is wanting to surface to the user population.
A review of source systems, technical capabilities, governance and security is undertaken to ensure safe, controlled and smooth deployment.
Authorised super-users receive comprehensive training albeit this is generally straightforward due to the design of the user interface. User documentation is online and easily available to all users.
A dedicated technical account manager supports the Trust through activation and early adoption, ensuring issues are resolved quickly and knowledge transfer is completed.
This structured onboarding approach ensures Trusts can begin using TIPS confidently and achieve early measurable outcomes. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- TIPS is a front-end to existing data sources and objects and does not hold the source data within the system. Application data, such as usage tracking, logins and execution metrics are held within an application database that remains with the client should off-boarding be required.
- End-of-contract process
-
At the end of the contract, no data extraction is required because all data processed by TIPS remains fully within the buyer’s cloud or on-premise environment. The buyer retains full ownership and access to all datasets, marts, logs, lineage, and dashboards created during the engagement.
The standard end-of-contract process includes:
Removal of NCS-IT access from the buyer’s environment (Azure AD, NHS Identity, VPN or equivalent).
Handover of documentation, including pipeline specifications, data model definitions, solution architecture, operational notes, and support logs.
Confirmation of service closure, including the cessation of monitoring, alerting, and scheduled support activities.
Optional knowledge-transfer session to ensure internal teams understand how to operate or transition the service.
These activities are included within the contract at no additional cost.
Optional, chargeable services are available on request, including:
Technical support to migrate pipelines, dashboards, or integrations to another platform or supplier.
Reconfiguration or decommissioning of infrastructure that sits outside NCS-IT control.
Additional training, consultancy, or service transition support.
NCS-IT retains no buyer data and performs no backups, storage, or archiving outside the buyer’s environment, ensuring full GDPR/DSPT compliance and eliminating vendor lock-in. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Other
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
TIPS provides a clean, intuitive web interface designed for rapid adoption by both clinical and corporate users. The UI prioritises clarity and speed, with role-based dashboards, powerful global search, and simple filters to quickly find trusted reports, dashboards and KPIs.
From a UX perspective, TIPS uses consistent navigation patterns, plain-language labels and progressive disclosure so users only see complexity when they need it. Guided workflows support approvals, reviews and information requests, while responsive design ensures a consistent experience. The result is minimal training overhead, fast user confidence, and sustained engagement. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Interface testing has been undertaken with a pilot client with feedback from existing clients being the vehicle for product enhancements and improvements. The interface is simple to use and works with standard Windows assistive features.
- API
- No
- Customisation available
- Yes
- Description of customisation
- The TIPS web interface can be personalised to suit individual users and roles. Users can customise dashboards, saved searches and favourites to surface the reports, KPIs and views most relevant to them. Role-based layouts ensure clinicians, analysts and managers see tailored content, reducing clutter and improving usability.
Scaling
- Independence of resources
- Users are protected from performance impact through dedicated cloud resource allocation, workload isolation, and dynamic autoscaling. Compute and storage capacity scale independently for each environment, ensuring high throughput even during peak usage. Role-based access controls and tenancy frameworks keep data and workloads logically separated. Performance is continuously monitored, with alerts and automated remediation to prevent contention. This guarantees consistent service responsiveness regardless of other users’ activity.
Analytics
- Service usage metrics
- Yes
- Metrics types
- TIPs provides comprehensive service usage metrics through built-in dashboards and automated reporting. Metrics include login activity, data ingestion volumes, query frequency, report usage, data refresh performance, storage consumption, and API utilisation. Administrators can view user activity trends, peak usage times, adoption levels, and operational performance. Metrics support governance, capacity planning, optimisation, and cost control. Custom usage reports can be configured on request.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Data can be exported as necessary and within the governance limits of the organisation. Exports are simple point and click processes as they are in the underlying products such as PowerBI or Tableau.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLSX
- Data import formats
-
- CSV
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- NCS-IT provides managed service availability in line with the Bedrock Statement of Managed Services (SMS), supported by defined service levels for incident response and resolution. Service availability is underpinned by proactive monitoring, incident management, and priority-based response aligned to business impact. Incidents are classified from Priority 1 (Critical) to Priority 5 (Advice & Guidance). P1 (Critical) incidents, where core business processes are unavailable, receive an initial response within 10 minutes and engineering engagement within 15 minutes, with continuous effort until service restoration. P2 (Major) incidents receive an initial response within 20 minutes and engineering response within 10 minutes. P3–P5 incidents are managed on a time-bound basis as defined in the SMS, with progress managed during standard support hours. Where guaranteed service levels are not met, service credits and remedies are applied in accordance with the contracted Statement of Managed Services. Availability commitments, service credits, and escalation processes are documented and agreed with the Customer as part of the service agreement.
- Approach to resilience
- Multi Cloud - Multi Region
- Outage reporting
-
Monitoring API
SMS Alerts
Email Alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Username or password
- Access restrictions in management interfaces and support channels
- Whitelist IP
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Add from ISO
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- NCS manages configuration and change through its service portal and ticketing system. All changes are logged as change tickets and classified as standard or emergency. Each change records scope, affected systems, risk, rollback actions, and relevant SLA priority. Standard changes are reviewed and approved by the Change Manager prior to implementation. Emergency changes required to restore service are implemented immediately, logged retrospectively, and formally reviewed. Configuration details are updated following approved changes. All change records, approvals, and outcomes are retained within the ticketing system to provide traceability, control, and audit evidence.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- NCS operates a comprehensive vulnerability management programme, including weekly scans of critical systems and applications. Patches are risk-assessed and prioritised based on severity and threat intelligence. Emergency patches posing imminent risk are applied without delay, while all other Windows patches are deployed within 14 days. System administrators monitor security alerts and publications to ensure emerging threats, technologies, and best practices are addressed promptly.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Security logging and alerting controls are in place to detect and prevent security incidents, covering systems such as Active Directory, Intrusion Protection Systems (IPS), and Data Loss Prevention (DLP). Monitoring solutions also alert administrators to capacity and resource issues. Logs are stored centrally and reviewed daily.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- NCS manages incidents through its service portal and ticketing system. Pre-defined processes are in place for common incident types, including service outages, performance degradation, security events, and monitoring alerts. Users report incidents exclusively via the service portal, which acts as the single point of contact and ensures incidents are logged, prioritised, and tracked consistently. Monitoring services may automatically generate incidents. All incident actions, updates, and communications are recorded within the ticket. For Priority 1 incidents, NCS provides formal incident reports, including root cause analysis, following resolution.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Time limited trial period of key functionality on request
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- Eb839a74-c517-4c99-9cab-d1cd8d0b2339
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- D73fffbb-48c4-41bd-9905-7306ac0b9c6c
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce