SEAtS Campus Safe Student Communications Add-On
SEAtS Campus Safe Student Comms provides a secure, integrated communication channel for reaching students quickly and reliably. The add‑on supports in‑app messaging, targeted group broadcasts, and automated alerts. enabling institutions to share updates, safety notices, and essential information directly within the SEAtS platform.
Features
- Easy to use, run on browser and mobile devices
- Supports Microsoft EntraID, AzureAD and SAML SSO authentication
- SEAtS mobile app for students available on Apple and Android
- Secure in‑app messaging for individual and group student communications
- Targeted broadcast alerts to defined cohorts or campus groups
- Integrated communication workflows within the SEAtS platform
- Mobile‑friendly communication via the SEAtS student app
Benefits
- Deliver urgent updates to students quickly and securely
- Improve communication reach with targeted group broadcasts
- Reduce admin workload through automated alerts and workflows
- Enhance student engagement with in‑app, mobile‑friendly messaging
- Track message delivery and engagement for compliance visibility
- Support safety communications during incidents or disruptions
- Centralise all student communications in one secure platform
- Strengthen student support with two‑way messaging capability
- Ensure consistent messaging across teams and departments
- Improve response times with real‑time communication tools
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 0 3 9 5 4 5 1 9 3 9 4 3 8 5
Contact
SEATS SOFTWARE UK LIMITED
Heather Foster
Telephone: +44 203 35144071
Email: sales@seatssoftware.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Education
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- A planned maintenance schedule for platform updates is in place. Events will be notified in advance via the SEAtS Status page.
- System requirements
- None applicable
User support
- Email or online ticketing support
- Yes
- Support response times
- Incident response times are determined by the severity of the problem when registered with SEAtS Software. We aim to response to most tickets within 2 hours during business hours. We offer both a standard SLA and tailored SLA's for an additional fee. Support desk service hours are Mon-Fri 8.30am-6.30pm GMT, excluding Bank Holidays.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
SEAtS Software provides two support tiers: Standard and Enhanced, both governed by the same SLA framework to ensure consistent, high-quality service.
Standard Support is included for all customers and offers:
Access to the SEAtS Support Desk via ticketing and email.
Coverage during UK business hours (Mon–Fri, 09:00–17:30, excluding public holidays).
SLA-aligned response times (e.g. Critical – 2 hours; High – 4 hours; Medium – 1 business day; Low – 3 business days).
Access to the SEAtS Knowledge Base and product documentation.
Support for incidents, configuration queries, and operational troubleshooting.
Escalation to Technical and Product teams when required.
Enhanced Support (£24,945) is an optional add-on for institutions seeking deeper engagement. It includes:
Priority ticket handling within severity categories.
Expedited triage and direct routing to technical specialists.
A named Customer Success Manager for strategic alignment, adoption, and performance reviews.
Optional quarterly workshops, roadmap briefings, and priority scheduling for training or configuration changes.
Enhanced Support is particularly valuable for larger or multi-campus institutions where SEAtS is deployed across multiple Schools or departments, or where compliance/engagement monitoring is a critical operational function.
SLA response times remain identical across both tiers; Enhanced Support expands engagement scope, not baseline entitlement. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Online documentation and soft copy manuals are offered as standard. Our knowledge-base provides comprehensive 'How To' articles with accompanying video guides. Customers who onboard are given access to a customer project portal with a comprehensive suite of documentation and online project management features. Customers can purchase onsite training for users and administrators, and train-the-trainer style sessions, Please see our website for further details.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- Users who off-board can choose to receive their data in flat file .csv format as an encrypted .zip file.
- End-of-contract process
- The customer can choose to continue the contract. If they choose to end the contract their data will be offboarded to them as described. We give customers 30 days to change their minds. After this time, their data and system will be deleted, or we can delete immediately on request.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Format: Wherever possible, we publish our documents in HTML format, which allows users to customise their browser settings, making it more adaptable for various needs. We avoid relying solely on formats like PDF, which can be challenging for users with assistive technologies like screen readers.
Simple Language: We use clear and straightforward language and explain technical terms, abbreviations and acronyms.
Simple Document Structure: We give our documents meaningful titles and structure them with headings. We keep sentences and paragraphs short and use bullet points. We use a simple font with a minimum size of 12 points and avoid using all caps, italics or underlining for regular text. We avoid relying on colour of text alone to convey meaning.
Images and Charts: We are currently reviewing all documentation to provide an alternative description for people with visual impairments. Accessibility Checker: We use built-in accessibility checks to identify and fix issues.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The SEAtS platform is built using a responsive framework. The only differences between app behaviour on a tablet or mobile phone is in screen and menu layout. The objective is to maximise screen real estate and enable touch functionality. SEAtS also provide a mobile app for students that is compatible with Android or iOS devices. UX is consistent across all SEAtS applications by design.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
- SEAtS has a number of API calls for different data sets. The API calls are extensible. Users can request additional field entries within the API definition through the support desk. Most API calls for Student, Schedule and Course catalogue are generic and fully described. C# code examples of API calls are provided in the API documentation, which can be provided on request.
- API documentation
- Yes
- API documentation formats
-
- HTML
- ODF
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- A configuration console is provided to edit screen layouts and user access to features. Typically, this is only available to Administrative users client-side. Menus and Labels can also be customised to support institutional logos, brand colours and terminology. Reports can be created, saved, renamed and shared by users with the correct access rights. Custom views can be created to include specific data sets, and again be saved, shared with other users or teams or set as the default view. Other features in SEAtS that can be customised include: file templates for communication, workflow triggers and actions, manual intervention steps, data sensitivity types, custom forms and fields, student tags, activity or absence types, lesson types and their associated early, late and absent time thresholds. The features and level of customisation available depend on the subscription level of each customer.
Scaling
- Independence of resources
- SEAtS have implemented an elastic computing model within their data centre resources. Computing resources are allocated on demand and have been modeled on required usage, based on customer peak usage profiles.
Analytics
- Service usage metrics
- Yes
- Metrics types
- % Uptime (availability of service) and Response time (ms)
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- The management console offers an export environment. Data from dashboards, views and reports can be exported to .csv and pdf formats. A job schedule can be configured to run a report at a set frequency, with the user being notified of its processing to allow them to download the exported file from their User Notifications area.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
- Service level objectives and associated credits are detailed in our service definition document. SEAtS offer 99.5% availability as standard.
- Approach to resilience
- Available on request
- Outage reporting
- SEAtS offer a pubic dashboard and email alerts by approved subscription
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- SEAtS restricts management interface and support access via role-based user profile accreditation with a default-deny posture. Direct SQL or raw DB access is discouraged; access is granted on a need-to-know basis and agreed during onboarding as part of a client-specific security model. All access is controlled, reviewed, and logged for accountability
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
SEAtS Software maintains a formal information security program aligned with ISO 27001 principles, GDPR and UK data protection obligations. Key policies cover Information Security, Data Classification and Handling, Access Control and Identity Management, Incident Response, Change and Release Management, Supplier Security, and Business Continuity / Disaster Recovery.
The Compliance Officers owns the security programme and reports to the CEO and the Board. A cross‑functional Security Committee (engineering, operations, product, DevOps) meets regularly to review risks, incidents and remediation plans.
We ensure compliance through:
- Mandatory security and privacy training for all staff
- Role‑based access controls, MFA, and least privilege
- Continuous monitoring and logging (SIEM), vulnerability scanning and scheduled penetration tests
- Regular internal audits, risk assessments and third‑party audits
- Clear incident playbooks, quarterly KPIs to the Board and tracked remediation tickets.
These measures ensure policies are active, measurable and continuously improved. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- SEAtS Software follows a structured change request process to manage updates to functionality, processes, or scope. Customers submit a change/control form, which is evaluated, scoped, and approved by SEAtS. Changes are assigned, implemented in a development or sandbox environment, tested in UAT, and signed off before deployment to production. All code submissions undergo peer review and security assessment. Automated unit and UI tests include dedicated security test suites to ensure integrity and compliance throughout the release cycle.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- SEAtS operates a risk‑based vulnerability management programme with continuous asset discovery and automated code and infrastructure scanning integrated into our deployment pipelines and Azure security telemetry. Findings are triaged by severity and business impact; critical issues are escalated and mitigated immediately, with patches or hotfixes deployed to meet service targets and rolled out gradually. We consume threat intelligence from public vulnerability databases, vendor and Microsoft advisories, special interest groups, plus customer reports. Fixes are verified by rescans and reported to the security lead and committee.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- SEAtS operates continuous protective monitoring with centralised log collection, anomaly detection, DDoS detection and alerting to identify suspicious activity and potential compromises. Alerts activate an incident management procedure for containment, forensic triage, eradication and recovery led by the security lead with cross‑functional support. Critical incidents are escalated immediately and acted on within hours; lower‑severity events follow defined SLAs. All incidents are logged, reviewed and reported to the security committee.
- Incident management type
- Supplier-defined controls
- Incident management approach
- SEAtS Software manages incidents through a structured three-stage process: identification and containment, system restoration with customer updates, and post-incident review. Incidents are reported via the customer service team or directly to the Data Protection Officer for data breaches. All incidents are logged using a Breach Incident Form. Updates are posted every 15 minutes on the SEAtS status page, and full incident reports are provided within 7 days. Regulatory notifications are made within 72 hours if required under GDPR. Post-incident reviews captures lessons learned, and ensure necessary updates to policies and procedures are actioned.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 25%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Centre for Assessment Ltd
- ISO/IEC 27001 accreditation date
- Tuesday 25 November 2025
- What the ISO/IEC 27001 doesn’t cover
-
Our ISO 27001 Certification covers all assets, staff and facilities involved in the provision of SEAtS Software’s SaaS-based solutions for customers, including information assets, infrastructure, systems, personnel, customer data handling, operational support, and both physical and digital resources. The following areas fall outside the certified scope:
Customer‑managed environments (including any on‑premise infrastructure, networks, devices, or integrations operated by the customer).
Third‑party systems that connect to our platform but are not under our operational control.
Customer data processing activities that occur outside our hosted service environment.
Internal corporate functions not directly supporting the delivery of the SEAtS cloud service (e.g., HR, marketing).
Physical security of customer sites, including end‑user devices and local access controls - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-