AI Contract Redaction
AI Contract Redaction Software is a SaaS-based, browser-accessed solution for redacting contracts and legal documents. It uses AI to reduce redaction time from hours to minutes, combining automated PII detection with custom and manual redactions, and stripping document metadata before download.
Features
- AI-powered automated redaction of contracts and legal documents
- Automated detection and redaction of personally identifiable information (PII)
- Customisable redaction rules to meet organisational requirements
- Manual redaction and review for user oversight and accuracy
- Metadata stripping before document download
- Browser-based access
- Reduces document redaction time from hours to minutes
Benefits
- Reduces contract redaction time from hours to minutes
- Automates contract and legal document redaction
- Identifies and removes personal and sensitive information
- Allows manual checks alongside automated redactions
- Removes hidden document metadata before download
- Easy access through a standard web browser
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 9 4 2 2 8 7 7 6 4 6 4 0 1 5
Contact
HUDSON&HAYES LTD
Arron Clarke
Telephone: 07983336017
Email: arron.clarke@hudsonandhayes.co.uk
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI software services
- Generative AI Software Services
- Document AI Software Services
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service is accessed via a web browser and requires a supported internet connection. Planned maintenance may be required from time to time, during which the service may be temporarily unavailable. The service does not support offline use.
- System requirements
-
- Access to a web browser
- Standard organisational endpoint security on user devices
- Internet connection
User support
- Email or online ticketing support
- Yes
- Support response times
- We respond to email and ticketed support requests within 1-2 business days during standard working hours, Monday to Friday. Requests received outside of these hours or at weekends are responded to on the next business day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
We provide a single standard support level for the service, delivered via email and online ticketing during normal business hours, Monday to Friday. Support includes user guidance, issue triage, and fault resolution related to the operation of the service.
We aim to respond to support requests within 1-2 business days. Requests received outside business hours or at weekends are responded to on the next business day.
Standard support is included within the service fees at no additional cost. Enhanced or extended support arrangements, such as additional coverage hours, can be discussed separately if required.
A dedicated technical account manager or cloud support engineer is not provided as standard. Support is delivered by the service support team responsible for maintaining the service. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Users can get started with the service through clear onboarding guidance and user documentation provided as part of the service. Online guidance is available to help users understand how to upload documents, review redactions, and download outputs. Where required, additional onboarding support or training can be discussed separately.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Users can extract their data by downloading their redacted documents and related outputs directly from the service before the contract ends. This includes final document files generated through the service. Guidance is provided to support users in completing data extraction prior to contract termination.
- End-of-contract process
- At the end of the contract, users are given the opportunity to download their documents and any outputs generated through the service before access is withdrawn. Standard support during the contract term, including access to the service, user documentation, and issue resolution during business hours, is included in the agreed contract price. Any additional services, such as extended support hours, enhanced onboarding, or bespoke support arrangements, are not included as standard and can be discussed and priced separately if required.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding documentation is provided in an online, browser-accessible format and written in clear, plain language. The documentation is structured to support straightforward navigation and understanding, helping users follow key steps for getting started and ending use of the service. Accessibility considerations are reviewed as part of ongoing documentation updates.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is accessed through a web-based user interface via a browser. Users upload contract documents, initiate automated redaction, review suggested redactions, make manual adjustments where required, and download redacted documents and audit logs through the interface.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service is accessed through a web-based user interface using a standard browser. Users interact with clear on-screen controls to upload documents, review suggested redactions, make manual adjustments, and download outputs. The interface is designed to support straightforward navigation and user workflows. Accessibility considerations are reviewed as part of ongoing service development.
- Accessibility testing
- The service has been tested with end users during development to ensure the interface is clear and usable. Formal testing with users of assistive technologies, such as screen readers, has not yet been undertaken. Accessibility is considered as part of ongoing service development and future improvements.
- API
- No
- Customisation available
- Yes
- Description of customisation
- Users can customise how documents are redacted by defining custom redaction rules and applying manual adjustments alongside automated redactions. All customisation is carried out through the web-based interface, where users review suggested redactions, make changes as required, and finalise documents before download. Customisation is available to authorised users, in line with the buyer’s internal access controls and user permissions.
Scaling
- Independence of resources
- The service is delivered using cloud-based infrastructure designed to support multiple users concurrently. Resources are managed by the platform to ensure normal usage by one customer does not adversely affect others. The service is monitored and capacity is managed as part of ongoing service operation to maintain consistent performance.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users export their data by downloading their documents and any outputs generated by the service directly through the web-based interface. Data is made available in standard file formats, allowing users to retain copies of their documents before access to the service ends.
- Data export formats
- Other
- Other data export formats
-
- DOC
- DOCX
- Data import formats
- Other
- Other data import formats
-
- DOC
- DOCX
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- The service is provided on a best-endeavours basis using cloud-hosted infrastructure designed for high availability. At this time, no formal uptime percentage SLA is guaranteed. Availability is monitored and managed as part of normal service operation. Where service availability issues occur, users can raise support requests in line with the standard support arrangements. Any service credits, refunds, or contractual remedies related to availability would be addressed on a case-by-case basis in accordance with the agreed contract terms.
- Approach to resilience
- The service is delivered using cloud-hosted infrastructure designed to support reliable and resilient operation. The underlying datacentre environment is managed by a third-party cloud provider and includes built-in redundancy and physical security controls. Data is protected through encryption both at rest and in transit, and the service benefits from the cloud provider’s availability, backup, and recovery capabilities. Service availability and capacity are monitored as part of normal operations. Further details on the resilience and recovery approach can be provided on request.
- Outage reporting
- Service outages are communicated to users via email where appropriate, and issues can be reported through standard support channels. The service does not currently provide a public status dashboard or outage notification API.
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
- F
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- No
- Security governance certified
- No
- Security governance approach
- Security governance is managed through established delivery and operational processes, with responsibility shared across senior technical and delivery leadership. Security is considered throughout the design, development, and day-to-day operation of the service, including data protection, access control, and risk management. Security risks and issues are reviewed regularly, and governance arrangements are refined as the service continues to evolve.
- Information security policies and processes
- Information security is managed through internal policies and operational processes covering data handling, access control, and secure working practices. Security responsibilities sit with senior technical and delivery leadership, with risks and issues reviewed through regular operational oversight.
- Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management are managed through internal delivery processes. Service components are tracked using version control and deployment records, and changes are reviewed for potential security and operational impact before being applied by authorised personnel.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management is handled through internal operational processes. Potential threats are assessed by reviewing changes to the service, monitoring platform updates, and considering the impact of newly identified vulnerabilities on the service. Information about potential threats is obtained from cloud platform providers, software vendors, and publicly available security advisories. Patches and updates are applied as part of regular maintenance and release activities, with higher-risk issues prioritised and addressed as soon as practicable.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is carried out through internal operational processes and the monitoring capabilities provided by the underlying cloud platform. Potential compromises are identified through routine monitoring of service activity, system alerts, and error logs, with unusual behaviour or unexpected events investigated as they arise. When a potential compromise is identified, it is reviewed and assessed by the delivery and technical team, with appropriate actions taken to contain, investigate, and resolve the issue. Incidents are responded to as soon as practicable, with higher-risk issues prioritised for immediate attention in line with operational support arrangements.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Incident management follows supplier-defined operational processes, with common events handled through established internal procedures. Users report incidents via standard support channels, and incident updates or summaries are shared with users where appropriate following investigation and resolution.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Db118d73-603e-4705-8398-66653df24b5e
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
-