Skip to main content

Help us improve the Digital Marketplace - send your feedback

Tetra

Tetra Operating Theatre Scheduling

An off-the-shelf, cloud-hosted SaaS platform that helps NHS hospitals optimise surgical throughput using AI. Users access Tetra to schedule surgeries, understand opportunities for list efficiency and productivity improvement, and optimise patients for surgery. With an additional suite of data-driven support tools, Tetra produces lists that finish on time.

Features

  • Artificial intelligence driven theatre scheduling and optimisation for NHS trusts
  • Probabilistic surgical case duration prediction using AI and machine learning
  • Real-time waiting list insights, waiting list prioritisation and scheduling recommendations
  • Automated theatre list building based on local clinical constraints
  • AI analysis of surgical free text and medical notes
  • NHS PAS integration, EPR integration and other scheduling systems integration
  • Wraparound analytics tools: Demand modelling, capacity modelling and activity modelling
  • Adaptable workflows aligned to specialty practices and hospital practices
  • User-friendly booking interface with automated administration for waiting list teams
  • Secure cloud-hosted platform with NHS information governance support

Benefits

  • Improved elective theatre utilisation on the same capacity outlay
  • Reduces cancellations, reduces overruns and underruns, and saves administrative time
  • More patients treated, with clinical risk reduction & treatment optimisation
  • Avoids cancellations, reduces disruption and reduces last-minute schedule changes
  • Improved demand and capacity visibility for elective planning decisions
  • More predictable lists through improved procedure time accuracy
  • Reduced reliance on manual judgement with formalised scheduling processes
  • Lower administrative workload for medical secretaries, clerks and booking teams
  • Elective backlog transformation support and recovery programme delivery support
  • Decision assurance and improved confidence in clinical scheduling decision making

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jamie.papasavvas@tetratech.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 1 6 4 1 5 6 0 6 4 9 8 0 2 6

Contact

Tetra Jamie Papasavvas
Telephone: 07545162369
Email: jamie.papasavvas@tetratech.uk

About your service

Service categories

Application Development and Deployment

AI platforms

  • Search and knowledge discovery

AI software services

  • Anomaly Detection AI Software Services
  • Forecast AI Software Services
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service requires access to agreed data feeds from existing NHS systems.
Planned maintenance may occur outside core working hours with advance notice.
Internet connectivity and modern web browsers are required for access.
Integration scope and update frequency depend on local system availability and data quality.
System requirements
  • Users require a reliable internet connection
  • A modern web browser, as up-to-date as possible
  • Outbound HTTPS access to the hosted service domain

User support

Email or online ticketing support
Yes
Support response times
Email ticketing support is provided, with initial responses typically provided within one working day during business hours, often sooner. Messages may be monitored outside business hours.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
Onsite support can be provided where required, subject to prior agreement.

Standard support is provided remotely via email ticketing during business hours, with initial responses within one working day. This includes user support and issue triage.

Enhanced support is available on request and in advance, subject to the support team's availability and can include scheduled check-ins and additional onboarding or training sessions beyond those at first deployment. Where appropriate, onsite support can be provided for activities such as initial setup, stakeholder engagement, training, or service reviews.

Support arrangements are agreed with each customer based on local needs.

Customers are supported directly by the product and technical team. A named point of contact can be provided, acting as a technical account manager and coordinating support, configuration, and ongoing service improvement.
Support available to third parties
No

Onboarding and offboarding

Getting started
Users are supported through a structured onboarding process designed to minimise disruption to existing workflows.

Initial setup is supported both remotely and onsite as appropriate, and includes guidance on connecting required data feeds and configuring local booking rules and constraints. Onsite training sessions are provided for operational and clinical users, focusing on day-to-day scheduling and booking workflows. Training can be delivered to different user groups as required, both onsite and remotely as appropriate.

Comprehensive user documentation and guidance materials are provided as standalone, as well as in built to the platform, covering core functionality and common tasks. These are available for reference during and after onboarding.

Where required, additional training or support sessions can be provided, including onsite sessions, which may be charged at day rates available in our pricing document. Ongoing support is available via email ticketing to help users adopt and use the service effectively.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
  • Embedded tooltips and documents within the platform where appropriate
  • Online documentation in the form of Notion pages.
End-of-contract data extraction
At the end of the contract, customers can request an export of their data generated through use of the service. This includes configuration settings, scheduling outputs, and operational data created within the platform. Data is provided in commonly used, machine-readable formats such as CSV or JSON.

The service does not provide access to proprietary algorithms, models, or underlying analytical methodologies, including model parameters or training artefacts. Following confirmation of data transfer, customer data is retained or securely deleted in line with contractual terms and NHS data governance requirements.
End-of-contract process
At the end of the contract, customer access to the service is brought to an orderly close in line with the agreed termination date. An offboarding period is supported to allow for final operational activities and transition. Users will be notified ahead of the agreed termination date that their access will be disabled.

Once offboarding activities are complete, user access is disabled and the service is decommissioned for that customer. Customer data is then handled in accordance with contractual terms, NHS data governance requirements, and applicable data protection legislation. Requests for data extractions are handled as detailed in other questions.

No ongoing dependency on the service remains following contract termination.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and offboarding documentation is provided in digital formats that can be accessed using standard web browsers and common document viewers. Documentation is written in clear language, structured with headings and consistent formatting to support readability.

Materials can be used with standard browser and operating system accessibility features such as screen zoom, keyboard navigation, and browser-based assistive tools. Documentation is primarily text-based, with minimal reliance on images, and avoids unnecessary formatting that could limit accessibility.

Where users have specific accessibility requirements, reasonable adjustments to documentation format can be discussed and provided where feasible.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service is delivered via a secure, browser-based web interface. Users log in to manage elective schedules, waiting lists, and capacity using a structured, task-focused layout aligned to common booking and scheduling workflows, such as reviewing sessions, assessing predicted case durations, and assigning patients to theatre lists. Information is presented through tables, forms, and visual indicators to support operational decisions. Schedule changes are made directly in the interface and reflected in real time. The service is used by NHS operational and clinical teams on standard desktop or laptop devices, with role-based access controls limiting data and functionality by user role.
Accessibility standards
None or don’t know
Description of accessibility
The service is accessed via a web browser and has been designed to be usable with standard accessibility features such as keyboard navigation, screen zoom, and browser-based assistive tools. Content is presented using clear layouts, consistent navigation, and readable text. The service has not been formally audited against WCAG or EN 301 549 standards. Some advanced assistive technology use cases, such as full screen reader optimisation, may not be fully supported. The service is primarily designed for desktop use by operational staff. Accessibility feedback from users is reviewed and addressed where feasible.
Accessibility testing
The service has not undergone formal interface testing with users of assistive technologies. Accessibility considerations have been incorporated through standard web design practices and feedback from users. Any accessibility-related issues reported by users are reviewed and addressed where feasible.
API
No
Customisation available
Yes
Description of customisation
Users can configure booking rules and operational constraints that govern how procedures are recommended into theatre sessions, reflecting local organisational, specialty, and surgeon practices. Workflows can be tailored to local ways of working, including role-based permissions and approval steps. Users can customise how information is displayed through filters, sorting, and views to support different operational tasks. Basic interface preferences, such as colour scheme, can also be adjusted.

Scaling

Independence of resources
The service is designed to support multiple users (and customers) concurrently without one user's usage impacting another’s. Capacity is managed centrally, with monitoring in place to track service load and performance.

Workloads are isolated at the application and data level, and resources are scaled to accommodate demand across customers. Usage patterns are monitored to identify abnormal or unexpected load, and controls are in place to prevent individual users or activities from adversely affecting overall service performance.

This approach ensures consistent service availability and performance for all users.

Analytics

Service usage metrics
Yes
Metrics types
Metrics include user activity, frequency of use, and interaction with key workflows. Operational metrics relating to schedules and lists created within the service are also captured.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Encryption of all physical media
  • Other
Other data at rest protection approach
We implement an additional layer of encryption of direct patient identifiers, like patient name or date of birth.

These are not stored in plain text on our database servers, but decrypted at the point of use when served to authenticated users.
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can request a data export through via email to their account manager. Data exports are prepared by the service team and provided securely following verification and approval.

Data is transferred using secure methods appropriate to NHS data governance requirements.
Data export formats
  • CSV
  • Other
Other data export formats
Other structured data formats can be supported by agreement
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
For data transfer into our network, additional encryption is applied on direct patient identifiers and other sensitive fields. This data is only decrypted at the point of use when served to authenticated users.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Data is held for a short period in our transfer server before ingestion to a secure central database with role-based access controls in place. The database server is only accessible to network machines on our cloud VPN

Availability and resilience

Guaranteed availability
We guarantee 99% availability during client business hours, excluding planned maintenance.

Availability is defined as the ability for authenticated users to access the service and core functionality via the public interface. Planned maintenance is scheduled in advance and performed outside of normal UK business hours where possible.

If availability falls below the guaranteed level in a given month, customers may request a service credit applied to the next billing period. Service credits are calculated as a proportion of the monthly service fee, scaled to the level of unavailability. Credits are the customer’s sole and exclusive remedy for failure to meet the availability SLA.

No refunds are provided for outages caused by factors outside our reasonable control, including customer-side connectivity issues, third-party service failures outside Azure, or force majeure events.

Full SLA terms are documented in the customer contract or service schedule.
Approach to resilience
The service is designed to be resilient through a combination of cloud-native architecture and managed infrastructure controls.

The application is hosted on Microsoft Azure, using UK-based data centres. Core components are deployed on resilient Azure services that provide built-in redundancy, automated failover, and high availability at the infrastructure layer.

Data is stored on encrypted, replicated storage to protect against hardware failure. Regular automated backups are taken and retained in line with defined retention policies, allowing recovery from data loss or corruption scenarios.

The service is continuously monitored for availability and performance. Alerts are triggered on failure conditions, enabling timely investigation and remediation. Planned maintenance is controlled and scheduled to minimise disruption.

Azure manages physical data centre resilience, including power, cooling, network redundancy, and physical security. Azure data centres are designed to tolerate component and hardware failure without service impact.

This approach aligns with the government’s cloud security principle on asset protection and resilience by ensuring data and services remain available, protected, and recoverable in the event of infrastructure or component failure.
Outage reporting
The service reports outages through direct email communication to nominated customer contacts.

In the event of a service disruption, affected users or customer administrators are notified by email with information on the nature of the issue, expected impact, and progress updates where appropriate.

At present, the service does not provide a public status dashboard or outage reporting API. These controls may be introduced as the service matures.

Internally, service availability is monitored to detect outages and trigger investigation and communication.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted to authorised personnel only. Administrative access is limited to a small number of trusted staff and advisors and is granted on a least-privilege basis.

Sensitive information is not shared over public or unauthenticated channels. Administrative actions are logged to support oversight and investigation where required. Password policies are enforced and strong, reliable password managers are in use.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Security governance is based on clear accountability and proportionate oversight aligned to organisational size and risk. Overall responsibility sits at board level, with the founder and director accountable for security strategy, risk acceptance, compliance, and incident escalation. Implementation of controls is delegated to senior engineering staff, supported by advisors where needed. Security risks are reviewed continuously as the service evolves, with controls updated accordingly. Certified cloud infrastructure provides physical security, while the organisation retains responsibility for application and data security, aligned with UK government security principles.
Information security policies and processes
The organisation follows a defined set of information security policies and operational processes that govern how systems and data are protected.

These include policies and procedures covering access control and identity management, data protection, retention and sanitisation, secure system configuration, change management, and incident detection and response.

Security issues, incidents, or policy breaches are reported to the board-level security owner, who is responsible for oversight, decision-making, and customer communication where required. Day-to-day security activities are carried out by senior engineering staff, with escalation to the board-level owner for significant risks or incidents.

Policies are enforced through a combination of technical controls and operational processes, including role-based access control, least-privilege permissions, encryption of customer data, code review, and controlled deployment processes. Monitoring and logging are used to identify issues requiring investigation.

Policies and processes are reviewed periodically and updated to reflect changes in the service, technology, or risk environment.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All service components and configuration are version controlled and tracked through their lifecycle using source control. Infrastructure and application changes are implemented through defined change processes, with peer review prior to deployment.
Changes are assessed for potential security impact as part of the development and review process, including consideration of access control, data handling, dependency changes. Automated checks and testing are used where appropriate to identify configuration or security issues before release.

Production changes are deployed in a controlled manner, with ability to roll back if issues are identified. Security-relevant changes are escalated to the board-level security owner where required.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Potential threats are identified through a combination of platform provider security advisories, general security guidance, and ongoing review of the service architecture and dependencies. Vulnerabilities are assessed based on severity, likelihood, and potential impact on customer data or service availability.

Where a vulnerability is identified, remediation actions are prioritised accordingly. High-risk issues are addressed as soon as practicable, with fixes tested before deployment to production. Lower-risk issues are scheduled into normal development cycles.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We collect logs and alerts from application and infrastructure sources (authentication events, errors, unusual patterns) and review them regularly. Alerts for potential compromise generate immediate investigation by the engineering team; confirmed incidents trigger containment, remediation, and root-cause analysis. Response times are prioritised by severity, with critical issues acted on as soon as detected (typically within hours) and lower-severity items reviewed within agreed sprint cycles. We escalate to leadership for confirmed or suspected breaches and document actions taken for audit and continuous improvement.
Incident management type
Supplier-defined controls
Incident management approach
The organisation has defined incident management processes proportionate to the service and risk profile. Common events such as service outages, data access issues, or security concerns follow pre-defined response steps covering identification, investigation, containment, and resolution.

Users report incidents via agreed support email channels or directly to named contacts. Incidents are triaged by senior engineering staff and escalated to the board-level security owner where required.

For significant incidents, customers are provided with a written incident report summarising the issue, impact, actions taken, and any follow-up measures. Response times are prioritised based on severity and potential risk.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We provide a trial period, which may, at our discretion, be provided free of charge. This includes the same platform functionality and support as the full subscription. It typically covers a a limited number of theatres, users or specialties. A trial typically covers 3 months of active-use of the platform.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E3823544-e80f-43cb-ae80-73903543aa24
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
NHS Data Security Protection Toolkit (Org number D5S2M)

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jamie.papasavvas@tetratech.uk. Tell them what format you need. It will help if you say what assistive technology you use.