SS&C AI Gateway
SS&C AI Gateway is a governance platform designed to facilitate responsible AI integration into business processes. It addresses governance, compliance, and security challenges providing audit trails, risk notifications, and role-based access control. Focussing on ensuring data protection, it enables organizations to leverage AI, minimizing risks and adhering to regulatory standards.
Features
- AI risk management and compliance controls
- Hallucination, toxicity, accuracy and safety detection
- Plug-and-play framework works with existing AI models or third-party tools
- Built-in rules enforce governance standards across industries
- Prompt injection attack detection prevents adversarial manipulation
- Personally Identifiable Information (PII) – redaction
- Real-time risk notifications prevent unwanted sensitive data exposure
- Secure hosting
Benefits
- Faster, accurate decisions
- Accelerates workflows and minimizes risk
- Enhanced efficiency
- Automates critical financial and operational processes securely, ensuring compliance
- Secures large-scale data processing for AI/machine learning (ML) models
- Protects AI systems against adversarial attacks
- Maintains data privacy while using AI capabilities
- Adhers to complex, multi-layered regulatory regimes
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 7 9 0 2 6 5 3 4 7 7 2 5 8 5
Contact
BLUE PRISM LIMITED
Mark Lockett
Telephone: 07917 588254
Email: mark.lockett@sscinc.com
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI life cycle
- AI Build Software
- Trustworthy AI Software
AI software services
- Computer Vision AI Software Services
- Generative AI Software Services
- Document AI Software Services
- Anomaly Detection AI Software Services
- Personalize AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- SS&C Blue Prism Enterprise, SS&C Blue Prism Cloud, SS&C Blue Prism WorkHQ or any system that can drive an API
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- The SS&C AI Gateway service is made available according to the Service Availability - please refer to Terms and Conditions
- System requirements
-
- Requires API access to SS&C Private Cloud in the UK
- Will be available on a Hyperscaler soon
- Will be available on-premise soon
- Requires access to LLMs or use SS&C's own LLMs
User support
- Email or online ticketing support
- Yes
- Support response times
- P1 Issue Response 1hr P2 Issue Response 4hrs Mon-Fri only Enhanced (Business Critical) support with improved SLAs is available at extra cost
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- Production Maintenance and Support gives you peace of mind for all your important processes. You’ll benefit from response service level agreements (SLAs). Business-Critical Maintenance and Support is ideal if you’re automating business-critical processes and need 24x7 live support for high-priority issues. Enjoy a heightened response, target-resolution SLAs
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- There is a free University to learn how to build automated processes available https://university.blueprism.com/
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Through the export function in the Governance platform
- End-of-contract process
- The service stops - there will be no response from the service to a service request.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- Web-based Governance Platform
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- The web-based governance platform has been tested to WCAG 2.2A accessibility standard
- API
- Yes
- What users can and can't do using the API
- Please refer to https://docs.blueprism.com/en-US/bundle/ai-gateway-1-0/page/api/api-spec-home.htm
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users are required to customise the prompts they use to achieve the desired outcome.
Scaling
- Independence of resources
- The service is monitored 24 x 7 for any conditions that would lead to a breach of the service level agreement (see Terms and Conditions)
Analytics
- Service usage metrics
- Yes
- Metrics types
- The Governance platform provides metrics of the calls to LLMs and the results of those calls, including tokens used and perplexity scores.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Through the export facility in the Governance platform
- Data export formats
- CSV
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- Any format
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.9% of scheduled uptime within the agreed availability window - please refer to Terms and Conditions for the Service Level Agreement
- Approach to resilience
- The SS&C AI Gateway service is built for High Availability and Disaster Recover - more information is available on request
- Outage reporting
- Outages on the SS&C AI Gateway are made available on a Public Dashboard and via email
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
- The platform allows for Role Based Access Control (RBAC)
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- SS&C Blue Prism operate an Information Security Management System as part of our ISO27001 certification
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Please refer to https://www.blueprism.com/blue-prism-security/
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- Security, privacy, and compliance are at the core of our development ethos. Our intelligent automation platform was designed using the latest in security standards and protocols, and we continue to enhance our methods and processes to keep you safe from the latest threats. The list of latest security updates can be found here https://portal.blueprism.com/security-updates
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- Security, privacy, and compliance are at the core of our development ethos. Our intelligent automation platform was designed using the latest in security standards and protocols, and we continue to enhance our methods and processes to keep you safe from the latest threats. The list of latest security updates can be found here https://portal.blueprism.com/security-updates
- Incident management type
- Undisclosed
- Incident management approach
- Security, privacy, and compliance are at the core of our development ethos. Our intelligent automation platform was designed using the latest in security standards and protocols, and we continue to enhance our methods and processes to keep you safe from the latest threats. The list of latest security updates can be found here https://portal.blueprism.com/security-updates
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Police National Network (PNN)
- Joint Academic Network (JANET)
- Scottish Wide Area Network (SWAN)
- Health and Social Care Network (HSCN)
- Other
- Other public sector networks
- Any network given the correct permissions
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Time limited trial - as part of a Try Before You Buy programme
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Friday 12 July 2024
- What the ISO/IEC 27001 doesn’t cover
- The Information security management systems (ISMS) for SS&C Blue Prism complies with the requirements of ISO/IEC:27001:2022, for the provision of information security of the central process of design, development, maintenance, support, hosting and delivery of Intelligent Automation software and services. This includes the interface and communication with SS&C supporting functions as per statement of applicability v10.1
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Volunteering opportunities for staff
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-