SAFER Defence
SAFER Defence is an AI powered human risk and resilience platform for Defence environments. It supports personnel to manage cyber, safety, wellbeing and operational risk through just in time AI guidance, curated learning pathways, and assured Message of the Day delivery, strengthening awareness, judgement, behaviours and resilience culture across Defence.
Features
- Public cloud access via personal devices without issued hardware dependency.
- Defence specific language, scenarios, and examples aligned to operational contexts.
- Cyber awareness AI agent supporting secure workplace digital behaviours standards.
- Digital safety AI agent supporting families and home technology risks.
- Health and safety awareness AI agent supporting everyday operational safety.
- Mental wellbeing awareness AI agent supporting stress, resilience, and escalation.
- AI awareness and misuse prevention agent supporting responsible technology use.
- AI agents provide reactive guidance at the point of risk.
- Proactive learning pathways with Message of the Day video delivery.
- Full analytics suite evidencing engagement, behaviour, and query trends.
Benefits
- Provides AI-enabled answers aligned to modern expectations, reducing policy searching.
- Delivers immediate guidance, reducing hesitation, avoidance, and unreported uncertainty.
- Accessible across locations, including users without issued devices.
- Uses Defence-specific language, scenarios, and context relevant to operational environments.
- Reduces likelihood of minor errors escalating into incidents or investigations.
- Complements core training where one-off courses fail to sustain learning.
- Updates guidance rapidly responding to emerging threats and policy changes.
- Builds continuous awareness through short, timely Message of the Day.
- Supports consistent behaviour change at scale, improving organisational culture.
- Provides leadership with evidence of awareness, coverage, and engagement.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 0 7 7 0 0 9 9 7 4 7 1 6 4 9
Contact
Toro Digital
Michael Wills
Telephone: +447908276355
Email: support@torodigital.tech
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Defence
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- N/A
- System requirements
-
- A supported web browser (e.g. Chrome, Edge, Firefox, or Safari).
- A stable internet connection.
- Device with a screen resolution of at least 1280×768.
User support
- Email or online ticketing support
- Yes
- Support response times
- For incidents and support requests raised via the defined support channels: • P1 - Critical (service unavailable or severely degraded for all users). Target initial response: within 2 business hours. • P2 - High (major functionality impaired, significant impact on critical users). Target initial response: within 4 hours during UK business hours. • P3 - Medium (degraded functionality, workarounds available). Target initial response: by next business day. • P4 - Low (how‑to questions, minor issues, enhancement requests). Target initial response: within 2 business days.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- The service includes web based chat functionality delivered using standard web technologies and third party components. Accessibility has been addressed through standards based testing aligned to WCAG 2.2 AA, focused on configuration and validation rather than bespoke development. Testing has confirmed keyboard only operability, predictable focus order, visible focus indicators, and no reliance on pointer only interactions. Screen reader checks using NVDA and VoiceOver have been performed to validate announcement of controls, message content, and notifications using appropriate semantic structure. Where chat functionality relies on third party components, supplier accessibility documentation and conformance statements are reviewed as part of assurance. Direct testing with assistive technology users is planned as usage scales and feedback is gathered.
- Onsite support
- Yes, at extra cost
- Support levels
-
Toro Digital provides proportionate, service appropriate support aligned to Defence usage, criticality, and deployment context.
Standard support is included within the core SAFER Defence subscription. This provides access to support via email or managed support workflows for service queries, incident reporting, and fault resolution. Requests are triaged based on impact and urgency, with priority given to service availability, security, or safety related issues.
Enhanced support may be provided by agreement for organisations requiring defined response times, additional assurance, or closer operational engagement. This can include agreed response targets, scheduled service reviews, and enhanced incident communications. Pricing is in accordance with the pricing table.
For enterprise scale deployments, typically associated with large user volumes or complex organisational environments, a named key account manager or technical point of contact can be provided. This is commonly applicable to deployments exceeding 10,000 users or where enhanced operational coordination is required. Provision of a named account manager is agreed as part of enhanced support arrangements. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Users are supported to start using the service through a combination of self-service guidance, in-platform support, and optional onboarding assistance. The service is designed to be intuitive and usable without formal training, enabling users to engage immediately through the web interface or downloadable application.
Getting started guidance is provided through a dedicated online wiki, which explains how to access and use key service features. The service also includes an introductory module within the AI knowledge bank, comprising short video guidance on how to use the AI agents effectively and responsibly.
From first use, the opening prompt encourages users to ask the AI agent questions about how to use the service, enabling contextual, just-in-time support without external documentation. This approach reduces reliance on formal training and supports rapid adoption across diverse user groups.
As part of the service roadmap, additional in-platform support will be introduced, including FAQs, contextual tooltips, and short video pop-ups to guide users through common tasks and features. Onsite training is not required, but remote onboarding support can be provided by agreement for organisations with specific needs. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
At the end of the contract, buyers are able to extract organisational data generated through use of the service in a proportionate and appropriate format. This includes aggregated usage analytics, coverage metrics, and trend reporting, which can be exported as reports (PDF) to support assurance, audit, and records retention requirements.
User interactions with AI agents are designed to support real-time awareness and decision-making and are not provided to the buyer as verbatim conversation transcripts. Where users access the service via personal devices, individual interaction data is treated as user-generated content and is not routinely disclosed to the buyer, except where required by law or explicit agreement. This approach supports privacy, psychological safety, and responsible use.
Educational video content and learning materials remain the intellectual property of the supplier and are not transferable at contract end.
On contract termination, buyer-accessible administrative access is withdrawn in line with agreed offboarding procedures, and any retained data is handled in accordance with contractual terms, data protection obligations, and applicable public sector requirements. - End-of-contract process
-
At the end of the contract, access to the service is withdrawn in line with our offboarding policy and procedures. User and administrative access is disabled, and buyer access to dashboards and analytics is removed. Prior to termination, the buyer may export available organisational analytics and reporting outputs for assurance and records purposes. User interaction data is handled in accordance with contractual terms, data protection obligations, and applicable public sector requirements. Supplier intellectual property, including learning content and video materials, is not transferred at contract end.
The contract price includes access to the SAFER Defence platform, use of AI agents, curated learning content, Message of the Day delivery, standard support, platform maintenance, security updates, and access to analytics and reporting features. There are no additional charges for standard service usage within agreed terms.
Optional services, available at additional cost by agreement, may include enhanced support arrangements, defined service level commitments, enterprise onboarding support, bespoke configuration, or integration with external identity or data systems. Any additional costs are agreed contractually in advance and reflect the scope and complexity of the requested services. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- All UIs are responsive to enable a full user experience on a mobile device
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure web-based interface and is also available as a downloadable mobile application for supported devices on the Apple App Store and Google Play Store. Users interact with the service via an intuitive interface providing AI chat, learning content, and Message of the Day delivery. An administrative interface is provided for authorised users to access analytics, configuration, and reporting. Use of the downloadable application requires installation on the user’s device, while web access is available via modern browsers.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Interface accessibility has been assessed using standards-based testing aligned to WCAG 2.2 AA, focusing on the end-to-end user experience of the integrated service rather than individual underlying components. Testing has verified that user interfaces are operable using keyboard-only navigation, provide predictable focus order and visible focus indicators, and do not rely on pointer-only interactions.
Screen reader checks have been performed using commonly adopted assistive technologies, including NVDA and VoiceOver, to confirm that interface controls, chat interactions, content, and system messages are announced appropriately and use correct semantic structure. Particular attention has been given to interactive elements introduced through integrated third-party AI services, ensuring accessibility is preserved through configuration and presentation within the service interface.
Where third-party components are used, supplier accessibility documentation and conformance statements are reviewed as part of assurance activities. Direct testing with users who rely on assistive technologies is planned as part of iterative accessibility improvement as service usage and feedback increase. - API
- No
- Customisation available
- No
Scaling
- Independence of resources
- The service is currently delivered using a scalable, cloud-based environment provided by an established third-party AI SaaS platform, which is designed to manage demand across multiple tenants and prevent customer usage from impacting others. The supplier monitors service usage and performance to ensure consistent availability. As part of the service roadmap, the platform will transition to a dedicated cloud hosting environment, with third-party AI services integrated via SDKs. This will further enhance workload isolation, capacity control, and resilience, while maintaining continuity of service and performance for users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides organisational metrics through an administrative dashboard to support assurance and oversight. Metrics include total registered users, number of users interacting with the service over time, and a list of active users. Engagement data is presented through measures such as active days per user and interaction frequency over time. Message delivery metrics include total messages sent and messages sent over time. The dashboard also highlights the top message themes engaged with by users, enabling organisations to understand areas of highest relevance and identify gaps in awareness for awareness development.
- Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Data at rest is protected through encryption provided by the underlying cloud hosting environment. All customer data stored within the service is encrypted at rest using industry-standard encryption mechanisms managed by the cloud provider. Physical storage media is protected through the provider’s accredited data centre controls, including physical access restrictions and secure handling of storage devices. The service does not manage or access unencrypted physical media directly. This approach aligns with the Government’s Asset Protection and Resilience principle and reflects a shared-responsibility SaaS model appropriate to the service’s operating context.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Buyers can export organisational data generated by use of the service through the administrative reporting interface. This includes aggregated usage analytics, coverage metrics, and trend reports supporting assurance and oversight. Reports can be exported in standard, human-readable formats such as PDF for audit, records retention, and internal reporting purposes. Data export is supported during the contract term and prior to contract termination in line with agreed offboarding procedures. The service does not require specialist tooling to export reports, and access is restricted to authorised administrative users.
- Data export formats
- Other
- Other data export formats
- Data import formats
- Other
- Other data import formats
- N/A
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is delivered using cloud‑hosted infrastructure designed for high availability and resilience, aligned with the commitments of our underlying cloud and SaaS providers.
We target a monthly service availability of 99.5%, excluding planned maintenance that is notified to users in advance where reasonably practicable. This target is designed to be realistic and proportionate to the service’s risk profile and operational use in public‑sector environments.
Service availability is monitored using platform‑level health indicators and provider status notifications, and availability incidents are triaged and resolved as a priority in line with our documented incident management processes.
Standard pricing does not include automatic service credits; however, where a Buyer requires enhanced availability commitments or service credits, these can be discussed and, if agreed, defined in the applicable G‑Cloud Call‑Off Contract (for example, as credits against future invoices where availability falls below an agreed threshold).
This approach provides transparency and proportionality for Buyers, while avoiding unnecessary cost escalation for those who do not require higher availability guarantees, and ensures that any bespoke SLAs or service credits are clearly documented in the Call‑Off where operationally required. - Approach to resilience
-
The service is designed for resilience using cloud-native SaaS principles, supporting availability, fault tolerance and recovery without reliance on single points of failure.
The platform is hosted on managed public cloud infrastructure, with resilience provided through the underlying cloud provider’s multi-zone architecture, redundant power and network connectivity, and physical security controls within accredited data centres. Detailed data centre information can be provided on request.
Application components are designed to tolerate component failure, using managed services where possible to reduce operational risk and simplify recovery. Customer data is protected through provider-managed replication and backup mechanisms, supporting restoration following service disruption.
Service resilience is further supported by operational processes, including continuous monitoring of service health, defined incident response procedures, and reliance on SaaS dependencies with established availability and resilience commitments. Service dependencies and incidents are reviewed periodically to inform continuous improvement.
This approach aligns with NCSC Cloud Security Principle 2 by protecting assets, minimising service disruption, and enabling recovery through proportionate, cloud-native controls appropriate to the service’s scale and deployment context. - Outage reporting
-
Service outages and significant service degradation are communicated to users in a timely and transparent manner.
Outage reporting is delivered primarily through direct email notifications to affected customers. Where a service-affecting incident is identified, notifications are issued as soon as practicable, with updates provided as the situation develops and on resolution.
Outage communications typically include a summary of the issue, known or suspected impact, actions being taken, and any guidance for users where relevant. Post-incident communication may be provided to confirm resolution and share high-level lessons identified.
The service does not currently provide a public status dashboard or outage reporting API. Outage communications are therefore designed to use direct channels that are likely to be monitored during an incident.
Outage reporting processes are aligned with the service’s incident management procedures and are reviewed periodically to ensure they remain effective and proportionate to the scale and criticality of the service.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
- Authentication is currently performed using unique user accounts with username and password credentials, supported by account verification during onboarding. Password policies are enforced to reduce the risk of unauthorised access, and access is restricted based on user role and organisational context. Authentication and access controls are managed within the service and do not rely on government networks or external identity providers. The authentication approach is designed to be proportionate to the service’s operating context and aligned with the Government’s Identity and Authentication cloud security principle. The service roadmap includes support for stronger authentication mechanisms as the platform matures.
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted based on the principle of least privilege. Administrative access is limited to a small number of authorised supplier personnel using unique accounts and authenticated access. Role-based controls restrict permissions to those required for defined operational or support tasks, with access reviewed periodically. Support access is limited in scope and duration and does not provide unrestricted access to customer data. Sensitive actions are performed only by authorised personnel. Administrative and support activities are logged to provide traceability and support audit and assurance requirements.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials
- Information security policies and processes
- Our information security policies and processes are risk-based and aligned to good practice. We follow a structured set of information security policies covering areas such as access control, data protection, incident management, vulnerability management, secure configuration, supplier assurance, and user responsibilities. These policies are informed by frameworks including ISO 27001 principles and NCSC guidance. Information security governance is overseen through a defined reporting structure, with clear accountability for security decision-making and risk ownership. Security risks, incidents, and material issues are escalated through management channels as required, ensuring appropriate oversight and timely decision-making. Policy compliance is achieved through a combination of design controls, operational processes, and assurance activities. Security requirements are embedded into service design, supplier selection, and configuration decisions rather than applied retrospectively. Where third-party SaaS providers are used, we rely on their certified controls and contractual assurances, supplemented by internal review of documentation, certifications, and security posture. Policies are communicated to relevant personnel and reinforced through practical guidance and operational processes. Adherence is monitored through incident reviews, risk assessments, and periodic checks, with policies reviewed and updated to reflect changes in risk, technology, or regulatory expectations. This approach ensures information security is actively governed, consistently applied, and continuously improved.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management is governed through documented, supplier-defined controls supporting operational security and service stability. Changes are managed through a controlled process including assessment, approval, testing and release, with additional scrutiny applied to security, availability and data protection impacts. Configuration is centrally managed with role-based access controls and secure baseline settings. Updates and patches are delivered through planned releases, with defined exception handling for emergency changes. Change and configuration activities are logged to support traceability, incident investigation and assurance. These controls align with the Government’s Operational Security principle and are informed by ISO 27001 concepts and NCSC guidance.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management is implemented using a risk-based approach aligned to the shared-responsibility model for SaaS services. For third-party platforms, vulnerability identification and patching are primarily managed by the service providers, supported by contractual assurances, published security documentation, and continuous monitoring of vendor disclosures. Potential vulnerabilities are assessed based on service architecture, data sensitivity, and operational impact, informed by CVE disclosures, NCSC guidance, and vendor security advisories. Components under supplier control are patched in line with assessed severity and risk, with critical vulnerabilities prioritised for remediation. Patch deployment follows controlled processes to balance security, stability, and service availability, ensuring proportionate response.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is implemented using a proportionate, risk-based approach aligned with the shared-responsibility model for SaaS platforms. Potential security compromises are identified through a combination of cloud provider monitoring, audit logging, alerting, and platform-level anomaly detection, supplemented by review of application logs and access activity within supplier-controlled components. Suspected incidents are triaged to confirm scope and impact, with containment actions taken where required, including access restriction or account suspension. Incidents are handled based on severity, with high-risk events investigated immediately and escalated in line with contractual and customer reporting requirements.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Our incident management process is structured, proportionate, and aligned to recognised good practice. We maintain pre-defined incident response processes for common events, including service disruption, security incidents, and data-related issues, with clear roles, escalation paths, and decision points. Users can report incidents via established support channels, including email and service support workflows, with incidents logged, tracked, and prioritised based on impact and urgency. Incident reports are provided to clients as appropriate and include a clear summary of the issue, timeline, impact, actions taken, and any lessons identified, ensuring transparency, accountability, and continuous improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- 30 days free trial for 5 user licences.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 3%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 666e0ee2-0767-4d39-a5d8-3bd3caf61b7a
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-