Skip to main content

Help us improve the Digital Marketplace - send your feedback

IDOX SOFTWARE LTD

EROS Cloud Electoral Management System

The service is a cloud-based Electoral Management System for UK local authorities and Scottish Valuation Joint Boards. It supports all electoral activity such as electoral registration, canvass activity, and election delivery, enabling secure, efficient management of statutory electoral processes without requiring on-premise infrastructure.

Features

  • High availability and high resilience cloud infrastructure
  • Comprehensive functionality covering all electoral business activities
  • Data-matching and mining and automatic register creation and distribution module
  • Geospatial boundary review and boundary changes module
  • Online self-service staffing portal
  • Integrations with Gov.UK Notify
  • LLPG Module enabling efficient address maintenance
  • Telephone canvassing module which can be used by temporary staff
  • Postal Vote Checking application
  • Real-time and overnight cloud reporting suite

Benefits

  • Reduces staff training time by simpliyfing complex electoral workflows
  • High availability and resilience for business-critical elections services
  • Reduces time, effort and cost through integrated electoral management modules
  • Supports rapid operational changes during live annual canvass activities
  • Enables elections deadlines to be met through streamlined processes
  • Highly accurate postal vote verification for reliability and efficiency.
  • Reduces boundary review and change effort through automated geospatial management
  • Improves decision making through clear operational and statistical reporting
  • Improves register accuracy and completeness efficiently through automated data matching
  • Enables interoperability through integration with LLPG/CAG and GOV.UK Notify

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@idoxgroup.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 0 2 9 5 7 1 3 1 0 7 1 2 8 3

Contact

IDOX SOFTWARE LTD Jen.roberts@idoxgroup.com
Telephone: 0333 011 1200
Email: bidteam@idoxgroup.com

About your service

Service categories

Application Development and Deployment

Application development

  • Business rules management
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Hybrid cloud
Service constraints
End user PCs must run a version of Windows that is supported by Microsoft
System requirements
  • Core back-office web applications support Microsoft Edge.
  • End-user PCs must run a supported version of Windows
  • Public-facing web applications support all major browsers.

User support

Email or online ticketing support
Yes
Support response times
According to our SLA for support which is available on request/during the G-Cloud clarifications stage.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
The customer portal is accessible via a standard web-browser (e.g. Microsoft Edge, Chrome, Firefox and Safari), therefore browser accessibility features may be utilised.
Onsite support
Yes, at extra cost
Support levels
According to our SLA for support which is available on request/during the G-Cloud clarifications stage.
Support available to third parties
No
AI chatbot
No

Onboarding and offboarding

Getting started
We support users through a structured onboarding process designed to minimise risk and ensure effective adoption and utilisation of our offerings.

Onboarding typically begins with a service initiation session with project management team dedicate to the onboarding process, to confirm scope, timelines, user roles, and data requirements. We then configure the service to the customer's operation needs and agree access controls. Data migration and validation are supported where required. Onboarding activities are managed through to live service operation with relevant stakeholders.

Training is delivered through a combination of role-based remote sessions and optional onsite training. Training is focused on enabling users to become productive quickly. Refresher training is available as required.

Comprehensive online documentation is provided through an integrated help system, covering all core functionality. This includes step-by-step guidance and longer-form operational guides for larger electoral activities. Contextual help is available within the service.

Users have access to a dedicated support team throughout live service operation. Support is available via email and telephone during our usual support hours.

Offboarding is supported through structured service exit processes. We provide a data and file export and support service closure activities to ensure continuity of service.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Customers retain ownership of all data througout. At contract end, Idox will liaise with the local authority as part of our structured offboarding process to arrange for extracts of their databases and relevant files to be exported. No proprietary tooling is required to access exported data once the service has ended. Data handling during offboarding is managed in line with applicable data protection and security requirements.
End-of-contract process
Offboarding is supported through structured service exit processes with our dedicated offboarding project team. We provide a data and file export and support service closure activities to ensure continuity of service. We would work with the local authority to ensure a smooth transition.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and offboarding documentation is available in PDF format on request, and as part of the project to move a local authority to cloud.

Using the service

Web browser interface
Yes
Supported browsers
Microsoft Edge
Application to install
Yes
Compatible operating systems
Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
For the public-facing products that have been designed to work on mobile devices, there is no difference in the available features between mobile and desktop use.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The central product Eros (containing most EMS functionality e.g. electoral registration) is a hybrid web application. The end user requires a supported Windows machine. The application runs on Azure Virtual Desktop on Microsoft Edge, and as a desktop application.

Other products use either a .NET application or web-based user interface depending on which is most appropriate for the product's use case.
Accessibility standards
None or don’t know
Description of accessibility
Individual products (internal and external) can be used in conjunction with many of the inbuilt Windows and browser accessibility settings. For products that are directly used by electors such as our canvass response service, we target WCAG 2.2 A compliance.
Accessibility testing
This is not currently included in our testing process for the products that form this service.
API
No
Customisation available
Yes
Description of customisation
The service is configurable to meet the operational needs of local authorities of different sizes and geographies across the UK.

Configuration options include controlling which data fields and records are displayed on specific screens, managing user access through a granular permissions model, and configuring various settings to reflect local operational practices. Users can also customise correspondence by managing letter and email templates used for statutory and operational communications.

The above customisations are carried out through administrative configuration screens within the service and does not require software development. This allows changes to be made quickly and safely without impacting core service functionality.

Customisation permissions are restricted to authorised users who are assigned these permissions according to their role.

This approach allows local authorities to tailor the service to their processes while maintaining consistency, security, and control.

Scaling

Independence of resources
Each customer is provisioned with a dedicated service environment hosted on separate Azure virtual machines. Resources such as compute, memory, and storage are not shared between customers, ensuring that demand from one customer cannot impact the performance or availability of another customer’s service.

Virtual machine specifications are selected based on the customer’s size and expected usage to ensure appropriate performance within each customer environment. Capacity can be adjusted independently where required.

Analytics

Service usage metrics
Yes
Metrics types
On request, we can provide reports on a variety of metrics such as service availability, usage, disk space and disk space growth. We can also provide information about who has successfully logged into the AVD environment over a specified period of time.
Reporting types
Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Data at rest is protected using encryption across the service environment.

All Azure virtual machine disks that store service data are encrypted, including operating system and data disks used by application and database servers. This protects data stored within the infrastructure.

Database data is additionally protected using SQL Server encryption features. Access to encrypted storage and databases is restricted through role-based access controls and managed service permissions.

These controls ensure that service data remains protected if underlying storage media is accessed or compromised.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export data directly from the service in commonly used formats, including CSV.

Data can be exported in bulk or from specific screens, allowing users to extract complete datasets or filtered views as required. Reporting outputs support multiple file formats for operational and statutory use. A print queue is provided to generate downloadable files such as letters where required.

Where bespoke data extracts are required, these can be requested and may come at an extra charge. The exports can be configured and executed by Idox in line with agreed requirements and security controls.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • DOCX
  • XLSX
  • TSV
  • XBE
  • XBR
Data import formats
  • CSV
  • Other
Other data import formats
  • We support cross-boundary election data (XBE/XBR as applicable).
  • Idox can provide a tool that imports application-data in JSON

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Data in transit between the buyer’s network and our services is protected using industry-standard encryption.

For back-office applications, users access the service via Azure Virtual Desktop, which uses TLS 1.2 encryption. Application data is processed within the hosted environment and is not transmitted to the user’s local device; only an encrypted screen stream is delivered.

For public-facing applications, all web and API traffic is served exclusively over HTTPS using TLS encryption. Insecure protocols are not supported.

These controls ensure confidentiality and integrity of data during transmission.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Data transmitted within the service environment is protected using private network segmentation and encrypted communications.

Service components, including application servers, core service components, and database servers, communicate over private internal networks that are not directly exposed to the internet. Internal connectivity is restricted to required services only.

All internal service-to-service communication uses HTTPS with TLS encryption. Insecure protocols are not supported.

These controls protect the confidentiality and integrity of data as it moves within the service environment.

Availability and resilience

Guaranteed availability
We guarantee availability of 99.9% per 30-day period during working hours.
Approach to resilience
The service is designed to provide high availability and resilience using Microsoft Azure cloud infrastructure.

Service components are hosted across resilient Azure datacentre environments, with built-in redundancy at infrastructure and platform levels. This reduces the risk of single points of failure and supports continued service operation in the event of component or infrastructure failure.

Core application services and databases are deployed using architectures designed to support fault tolerance and rapid recovery. Platform-managed services are used where appropriate to benefit from Azure’s built-in resilience, monitoring, and automated failover capabilities.

Regular backups are taken to support data recovery and service restoration. Backup and recovery processes are tested periodically to ensure they remain effective.

The service is monitored continuously to detect and respond to availability issues. Incidents are managed in line with defined support and incident management processes.

This approach aligns with the government’s cloud security principle on asset protection and resilience by ensuring service continuity, protecting data, and supporting timely recovery from failures.
Outage reporting
Service availability is monitored continuously by Idox using platform and service monitoring tools. When service issues or outages are identified, they are logged internally and escalated to the appropriate technical teams for investigation and resolution.

Customers are informed of service-affecting incidents through agreed communication channels. Where an incident impacts customer use of the service, affected customers are notified by email as soon as practicable, with updates provided as the incident is investigated and resolved.

There is no public status dashboard or outage reporting API. Instead, outage communications are managed directly to customers to ensure accurate, relevant information is shared based on the nature and impact of the incident.

Incident communications and updates are provided promptly to the customer as soon as they are discovered.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to the service as a whole is managed within the Azure environment. Idox maintain a set of accounts for named local authority users on behalf of the local authority, adding new ones and deactivating old ones on request.

Access to each product within the service environment is further controlled within the core EMS (either by Idox or by the customer). The customer will nominate named users to be given access to the Idox Customer Portal to raise support requests.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Idox Software Ltd operates an ISO/IEC 27001-certified Information Security Management System (ISMS).

The ISMS covers all business functions, including information systems, networks, physical environments, incident and threat management, project and contract management, and personnel management. Information security policies and procedures are defined, maintained, and reviewed in line with the ISMS.

Information security awareness training is provided to staff to ensure policies are understood and followed. Compliance with policies and controls is monitored through regular internal reviews and audits.

The ISMS is independently assessed and externally certified annually as part of the ISO/IEC 27001 certification process. Audit findings and identified risks from both internal and external audits are formally recorded, reviewed, and acted upon.

Governance oversight is provided through management review meetings involving the Information Security Manager, relevant senior business leads, and a representative with delegated board-level authority. Actions arising from reviews are tracked to completion to ensure continuous improvement and ongoing compliance.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Service components are tracked through their lifecycle using controlled configuration and change records within the change management system.

All changes are managed through formal change requests. Each request includes a documented justification, assessment of potential security and service impact, a rollback plan, and required approvals. Changes are scheduled and communicated to relevant stakeholders.

Changes are implemented and verified in a separate quality assurance environment before release to production. Only approved changes are deployed to live service environments.

This process ensures configuration control, traceability, and reduced risk when changes are introduced.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Potential threats to the service are identified through continuous monitoring of vulnerability intelligence sources, including OWASP guidance and vendor security advisories. Automated web application scanning, host-based vulnerability scanning, and external perimeter testing are used to detect design, configuration, and patching weaknesses.

Identified vulnerabilities are assessed for risk and impact within the service context and prioritised by severity. Remediation actions, including patching or configuration changes, are deployed in line with defined timescales appropriate to the risk level, with higher-severity issues addressed as a priority.

Vulnerability management processes are monitored and reviewed as part of the ISO/IEC 27001 Information Security Management System.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Protective monitoring is implemented using monitoring tools that detect abnormal server, storage, network, and perimeter activity. Alerts are generated for unusual behaviour that may indicate potential compromise.

Alerts are actively monitored and reviewed by authorised personnel. Where suspicious activity is identified, incidents are escalated in line with the security incident management process for investigation and containment.

Incidents are triaged promptly based on severity, with higher-risk events prioritised for immediate response. Monitoring and response activities are managed in accordance with the ISO/IEC 27001 Information Security Management System.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Incident management is governed by documented policies and predefined procedures for common security and service events.

Incidents may be reported by users via the Service Desk or identified through automated monitoring. All incidents are logged, assigned a unique reference, and triaged based on severity. Security incidents are escalated to the Information Security Manager and tracked through to resolution.

Major incidents are managed through a formal incident response process involving relevant technical and business stakeholders. Incident outcomes and corrective actions are documented, and incident reports are provided to customers where appropriate. GDPR-related incidents are managed in line with regulatory reporting requirements.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
A hosted version of Idox's EMS to enable prospective customers to try it out for themselves

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Citation ISO Certification Limited
ISO/IEC 27001 accreditation date
Monday 27 May 2024
What the ISO/IEC 27001 doesn’t cover
Our ISMS is certified and tested to ISO27001 standards annually and covers our entire organisation.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation ISO Certification Limited
ISO 9001 accreditation date
Thursday 11 April 2024
What the ISO 9001 doesn’t cover
Our ISMS is certified and tested to ISO9001standards annually and covers our entire organisation.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
5c6de739-c45d-4eee-916a-013a0c2ce8f7
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
26018f8f-da19-4856-8fd2-b719e0c21047
Other security certifications
Yes
Any other security certifications
ISO 22301

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@idoxgroup.com. Tell them what format you need. It will help if you say what assistive technology you use.