Mobilise Essentials
Mobilise Essentials is a digital support infrastructure that helps councils and their partners connect carers they already identify into a simple, always available digital support system. The software offers a reliable digital layer for information, guidance, and community support, without commissioning proactive identification, intensive operational oversight, or managed service delivery.
Features
- 24/7 digital support accessible outside standard office hours
- Immediate responses to common carer questions
- Needs-led conversational support that adapts over time
- Access to national carers information and guidance library
- Access to a national peer support community
- Community moderation by trained carer support staff
- Simple referral-based on-boarding from councils or local partners
- Standardised service with minimum local configuration
Benefits
- Acts as a foundation for digital expansion of carer support
- Supports Care Act information and advice duties
- Requires minimal operational overhead
- Provides access to digital support for identified carers
- Improves access to information for identified carers
- Reduces pressure on council helpline and inboxes
- Connects carers to trusted peer support
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 2 1 2 4 3 4 2 4 3 0 9 4 8 7
Contact
MOBILISE CARE LTD
James Townsend
Telephone: 07816779635
Email: tenders@mobiliseonline.co.uk
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
Conferencing and virtual event
- Virtual Event Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- N/A
- System requirements
- A computer with a modern web browser.
User support
- Email or online ticketing support
- Yes
- Support response times
- Mobilise provides remote support through a ticketing system and email, with standard response times of one business day for general queries and four hours for urgent issues. Where needed, web chat or video support can be arranged.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Mobilise provides a comprehensive support structure focused on rapid resolution and long-term client partnerships. Our standard support includes remote assistance via a dedicated ticketing system and email, with a guaranteed four-hour SLA for urgent issues and one business day for general queries. For real-time collaboration, web chat or video support is available as required.
During the onboarding phase, we assign a dedicated Delivery Manager and technical support is available throughout to ensure a seamless rollout. Direct expert guidance is available via phone from 09:00 to 17:00 (UK time), Monday through Friday, throughout the project lifecycle.
We offer ongoing strategic care through a dedicated Partnership / Customer Success Manager. This role serves as your consistent point of contact, ensuring proactive alignment with your organisational goals and long-term success.
Notably, all support levels—including dedicated onboarding technical support and ongoing partnership management—are provided at no additional cost. This all-inclusive model provides high-level strategic and technical guidance without the budgetary unpredictability of premium-tier or per-incident fees. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Mobilise Essentials is implemented through a structured, low-friction onboarding process designed to embed the service quickly. We provide a comprehensive implementation and communications pack, including project plans, launch assets and carer-facing communications, enabling councils to mobilise consistently across teams and partners. Full training is provided to staff users.
Reporting and live dashboards are configured early so you have visibility. - Service documentation
- No
- End-of-contract data extraction
- At contract end Mobilise will provide a complete file of council data in a format of their choosing.
- End-of-contract process
-
There are no additional costs at the end of a contract.
Users will be notified of a change of service and data will be exported in a format of the council's choice.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- None
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Unpaid carers initiate the service using a form on a web page and can access certain features, like guidance and information also on web pages. Much of the service is delivered via WhatsApp or SMS.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Mobilise is compliant to WCAG 2.1 AA and working towards compliance with 2.2 AA
- Accessibility testing
- Mobilise has used automated web testing to review its interfaces and ensure that they are accessible.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Mobilise Care prevents users being affected by demand from others by hosting all services on scalable, cloud-native platforms. Our solutions deliver resilient databasing and our web servers deliver auto-scaling web infrastructure, allowing the system to adjust instantly to demand spikes.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Monthly active users
Source of users
Engagement data - Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
-
Mobilise ensures that all personal and sensitive data is encrypted both at rest and in transit across all systems. All core platforms including Supabase, HubSpot, BigQuery, Heroku, Vercel, and Twilio enforce encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent). Event logs (Axiom) and code (GitHub) are also protected accordingly.
Where appropriate, VPNs or private networking are used to further protect internal communications. Key management responsibilities remain with the providers, following industry best practices. All encryption keys are stored securely, and key rotation policies are enforced to ensure data confidentiality and integrity. - Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Mobilise's expert technical team support clients in getting the exported data they require.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Our platforms are architected to support 99.9% uptime during business-critical hours (9:00am to 5:00pm, Monday to Friday).
Refunds will be considered on a case by case basis. - Approach to resilience
-
Mobilise Care’s services are built on scalable, cloud-native platforms, to ensure high availability and resilience.
The system supports auto-scaling to handle demand spikes. Monitoring is conducted using built-in performance dashboards and third-party monitoring tools. Clients are proactively notified of maintenance, service degradation, or unexpected downtime via platform updates or direct communications. - Outage reporting
- Planned maintenance and updates are communicated to clients by email at least five days in advance, except in emergency situations. Release notes are provided for changes affecting platform features, functionality, or integrations.
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
-
Mobilise operates a secure IAM framework based on least privilege. Access is managed through RBAC and MFA across core systems and services, with SSO enabled where supported. Platforms without built-in MFA are monitored for compensating controls. Privileged accounts are tightly restricted, logged, and monitored. Provisioning and de-provisioning follow a documented process with approvals for elevated access and immediate removal when roles change or staff leave. MFA is enforced on sensitive systems to prevent unauthorised access. IAM processes undergo regular internal reviews and supplier audits.
Source: supplied text. - Access restriction testing frequency
- Less than once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
Mobilise approaches security governance through a structured, policy driven framework aligned with recognised UK guidance. Governance is coordinated by a named Information Security Lead, with defined responsibilities for risk management, incident response, data protection, supplier assurance, and policy maintenance.
Core governance activities include maintaining formal security policies, enforcing role based access control, conducting regular risk assessments, monitoring suppliers for compliance, and ensuring alignment with GDPR and Cyber Essentials practices. Governance processes are continually reviewed and updated in line with guidance from the NCSC. - Information security policies and processes
-
Mobilise maintains documented policies for:
- Cyber and Data Incident Response
- User Account Creation and Retention
- Data Protection
- Privacy
- Data and IT Security
- IT Security for Contractors
- Business Continuity and Disaster Recovery
- Quality Assurance
Security governance is led by a named Information Security Lead. Responsibilities include policy ownership, risk assessment, incident oversight, supplier assurance, and ensuring alignment with GDPR obligations. Data protection oversight is supported by a designated Data Protection Officer, as noted in the compliance section.
How policy compliance is ensured
Mobilise ensures policies are followed through:
- Mandatory staff training on data protection and security
- Defined approval workflows for system change control
- Continuous monitoring of access, configuration, and system behaviour
- Periodic internal reviews of policy effectiveness
- Supplier due diligence and monitoring
- Documented incident reporting and post incident reviews
- Regular backup, recovery, and audit logging checks - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Mobilise uses a structured change management process to track components through their lifetime and assess all changes for security impact. Change requests are documented, reviewed, approved, and version-controlled using GitHub, with deployments managed through our carefully selected suppliers.
Planned changes are tested in staging where possible, with defined rollback procedures for major releases. Emergency changes follow an expedited path with retrospective review.
SaaS provider updates, are monitored through release notes and status pages. All changes are logged, auditable, and reviewed for operational and security risks. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Mobilise uses a proactive vulnerability management process supported by automated scanning across internal environments and third-party components.
GitHub provides continuous code and dependency scanning, and suppliers are monitored for security bulletins and patch notices. Telemetry is used to detect behavioural anomalies. All identified vulnerabilities are assessed for severity and remediated according to internal SLAs, with critical issues addressed within 24 hours and non-critical within 7 days.
Vendors are required to meet equivalent standards.
Annual penetration testing by an independent CREST-accredited provider validates security posture and remediation quality, with critical and high-risk issues prioritised and summaries available to clients. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Mobilise uses continuous protective monitoring across its cloud environments and Dynamic Carer Assessments platform. Automated telemetry detects anomalies, suspicious access, dependency issues, and abnormal API activity. Alerts from GitHub and vendor security bulletins support early identification of potential compromise. When an alert is raised, the engineering lead triages it immediately, isolates affected components if required, and reviews logs to confirm impact. Critical incidents trigger rapid containment, patching, and supplier coordination. Mobilise responds to potential incidents within 24 hours, with confirmed critical issues addressed immediately and non critical issues resolved within agreed SLAs. This ensures fast detection and controlled remediation.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Mobilise maintains a tested Incident Response Plan covering detection, containment, eradication, recovery, and post-incident review. The plan includes predefined processes for common events and follows a repeatable workflow. Incidents are logged, categorised, and escalated according to severity. Users report incidents through established support channels, where they are recorded and managed. For significant events Mobilise provides formal incident reports detailing impact, actions taken, and lessons learned. All incidents undergo a structured review so that outcomes feed into improved controls and team training, ensuring issues do not recur.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 69b56b7b-7246-4005-b15f-14bac0b9ad4e
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-