Generative AI and Intelligent Knowledge Discovery
Our service transforms organisational knowledge into an intelligent, searchable, conversational resource through advanced Generative AI. We deliver modern retrieval-augmented generation (RAG) platforms, document intelligence solutions, and AI copilots making complex information easy to access. Our service combines smart search, summarisation, reasoning, and contextual understanding for documents, policies, and operational data.
Features
- Intelligent document processing (extraction, classification, summarisation)
- RAG architectures enabling accurate, source-grounded responses
- Domain-specific AI copilots
- Chat-based interfaces providing low-friction access to organisational knowledge
- Evaluation tooling for retrieval relevance, correctness, drift, and latency
- Integration with SharePoint, document stores, APIs, or enterprise platforms
Benefits
- Reduces time spent searching for information
- Increases organisational knowledge accessibility and consistency
- Enhances productivity through AI-powered reasoning and summarisation
- Improved accuracy and trust via grounded, source-linked responses
- Works seamlessly with existing document management systems
- Unlocks the value of unstructured data securely and efficiently
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 3 3 6 2 6 7 9 3 7 0 4 6 3 0
Contact
SQUARCLE CONSULTING LTD
Edina Opoczki
Telephone: 07955036707
Email: sales@squarcle.co.uk
About your service
- Service categories
-
Application Development and Deployment
AI platforms
- Search and knowledge discovery
AI life cycle
- AI Build Software
- MLOps and Foundation Model Ops Software
- Trustworthy AI Software
AI software services
- Conversational AI Software Services
- Generative AI Software Services
- Document AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- Service delivery depends on timely access to customer data sources, integrations, and agreed data quality standards. Availability and functionality may be influenced by third-party systems, data refresh frequencies, or external partner connectivity. Planned maintenance is scheduled in advance and communicated to customers where possible. Some advanced features may require specific data formats, integrations, or cloud environments. Performance and real-time visibility depend on upstream system availability and accuracy.
- System requirements
-
- Secure internet connectivity to cloud-hosted service
- Supported modern web browser
- User authentication and role-based access controls
- Access to customer supply chain data sources
- Supported data integration methods or APIs
- Data export capability in standard formats
- Secure network connectivity for data transfers
- Compatibility with customer security policies
- Ability to support real-time or scheduled data feeds
- Supported cloud environment for integrations
User support
- Email or online ticketing support
- Yes
- Support response times
-
Squarcle Consulting Ltd implement a triage system that determines the sequence for escalating incidents. During the initial evaluation, we take actions based on the incident’s impact to the client. This enables us to rank incidents on a scale from Priority 1 to Priority 4.
Priority 1 > 1 hr
Priority 2 > 4 hours
Priority 3 > 8 hours
Priority 4 > 24 hours
Weekends: Response to Priority 1 calls only. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Keyboard-only navigation: Confirmed logical tab order, visible focus states, Escape/Enter behaviour, and that all functions (send, edit, react, open settings) are operable without a mouse.
Low-vision support: Checked browser zoom up to 400%, reflow without horizontal scrolling, and compatibility with high-contrast modes. - Onsite support
- Yes
- Support levels
-
Priority 1 - Critical:
Priority 1 incidents are likely to critically impact your ability to conduct business. We’ll respond to a Priority 1 incident within 1 hour.
Priority 2 - High Impact Disruption:
Priority 2 incidents are high-impact problems that interrupt your organisation, but there’s still capacity to continue to be productive. We’ll respond to a Priority 2 incident within 4 hours.
Priority 3 - Minor Impact Disruption:
Priority 3 incidents are medium-to-low impact problems that comprise of limited loss of non-critical business functionality. We’ll respond to a Priority 3 incident within 8 hours.
Priority 4 – Information Request:
Priority 4 issues include requests that do not fall within the Priority 1 – Priority 3 classifications. We will respond to a Priority 4 incident within 24 hours. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We help users start using the AI system through a structured onboarding process designed to ensure rapid adoption and confidence. Onboarding begins with setup support, including access configuration, data integration, and confirmation of user roles and permissions.
We provide a combination of onboarding options depending on customer needs, including onsite training sessions, remote online training, and guided walkthroughs of the platform. Training focuses on how to use dashboards, interpret analytics, manage alerts, and navigate key workflows.
User documentation is provided in accessible digital formats and includes user guides, operational procedures, and reference materials. Where appropriate, video tutorials and in-application guidance are also available. Ongoing support is provided after onboarding to help users refine configurations and fully embed the service into day-to-day operations. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, users can extract their data in a controlled and secure manner. Data extraction methods depend on the data type and service configuration and typically include secure file transfer, approved APIs, or standard export formats such as CSV or JSON.
Where users have appropriate permissions, they may initiate data exports directly through the application interface or API. For larger, complex, or sensitive datasets, Squarcle supports the extraction process on the customer’s behalf following formal authorisation. Extracted data includes customer-owned datasets, configurations, and reports relevant to the service.
Data extraction activities are planned and coordinated as part of the exit process to ensure data integrity, security, and continuity. Any bespoke extraction, transformation, or migration support beyond standard - End-of-contract process
-
At the end of the contract, Squarcle works with the customer to manage a structured and orderly service exit. This includes confirming termination dates, disabling user access, and supporting the handover of operational knowledge where required. Standard end-of-contract activities are designed to ensure services are closed down securely and without disruption.
The contract price includes service delivery up to the contract end date, standard support during the notice period, and cooperation with reasonable transition planning. Customer documentation and standard data export capabilities remain available during this period.
Additional activities such as detailed exit planning, large-scale data extraction, data migration to alternative platforms, extended access beyond contract end, or bespoke handover support are treated as additional services. These are scoped and agreed separately to ensure transparency and best value for money. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The desktop service provides full functionality, including detailed analytics, advanced filtering, and complex visualisations across the supply chain. The mobile service offers a streamlined interface optimised for smaller screens, focusing on key alerts, high-level dashboards, and status updates. Some advanced configuration and deep analysis features are limited on mobile. Mobile access prioritises usability and responsiveness, enabling users to monitor supply chain performance and receive notifications while on the move.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through standard web-based interfaces and integrated ITSM tooling. Users interact with the service via secure online portals, email, and approved ticketing systems to raise incidents, requests, and changes. Monitoring dashboards provide visibility of service status, alerts, and performance metrics. Where required, APIs enable integration with customer systems for event ingestion and reporting. Access is role-based to ensure appropriate visibility and control.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Keyboard-only navigation: Confirmed logical tab order, visible focus states, Escape/Enter behaviour, and that all functions (send, edit, react, open settings) are operable without a mouse.
Low-vision support: Checked browser zoom up to 400%, reflow without horizontal scrolling, and compatibility with high-contrast modes. - API
- Yes
- What users can and can't do using the API
-
Users can interact with the AI system through a secure API to integrate data, automate workflows, and retrieve information. Using the API, users can configure data connections, submit data feeds, and retrieve operational and analytical outputs such as status updates, alerts, and performance metrics. Configuration activities supported by the API are limited to approved setup functions, such as registering data sources or enabling integrations.
Users can make permitted changes through the API, including updating data inputs, adjusting thresholds, and triggering predefined processes. However, users cannot use the API to alter core platform configuration, security controls, system logic, or underlying analytics models. Access to API functions is controlled through authentication and authorisation, and available endpoints are documented.
These limitations ensure system stability, data integrity, and security while allowing users sufficient flexibility to integrate the service with their existing systems and processes. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise the AI system to align with their operational priorities and decision-making needs. Customisable elements include dashboards, reports, alerts, thresholds, data views, and notification preferences. Users can also tailor data sources, business rules, and visualisations to reflect their custom performance indicators.
Customisation is performed through configuration rather than code changes. Authorised users can adjust settings using the application interface or approved APIs, allowing changes to be applied quickly without disrupting the core platform. More complex changes, such as onboarding new data sources or modifying analytics rules, are supported through structured change requests managed by Squarcle.
Customisation rights are role-based. Operational users can personalise dashboards and alerts, while administrators and designated service owners can configure integrations, data models, and reporting structures. This approach ensures flexibility for users while maintaining security, governance, and service stability.
Scaling
- Independence of resources
- The service is designed to ensure resource independence between users. Logical segregation, access controls, and workload isolation prevent one customer’s usage from impacting another. Capacity monitoring and automated scaling are used to manage demand and maintain performance. Where required, dedicated or isolated resources can be provided. These measures ensure consistent service performance regardless of other users’ activity.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The AI system provides a wide range of operational metrics to support oversight and decision-making. Metrics include model performance indicators and system reliability. Additional metrics support regulatory compliance, risk and resilience monitoring, and service availability. Reporting and dashboarding provide real-time and historical insights, while design and optimisation metrics support continuous improvement. Metrics are available through dashboards, reports, and data exports, aligned to customer priorities and operational objectives.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users export their data using secure, agreed methods based on data type and service configuration. Exports can be completed through the application interface, approved APIs, or standard file formats such as CSV or JSON. Where direct export is not appropriate, Squarcle performs data extraction on the customer’s behalf following authorisation. Export processes are controlled to ensure data integrity, security, and compliance with applicable policies.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Squarcle Consultancy Ltd provides availability commitments aligned to the operational criticality of the AI system and customer requirements. Availability is defined and measured during agreed service hours and documented within the Service Level Agreement (SLA). Standard availability targets are supported by resilient design, proactive monitoring, and structured incident management processes.
Specific availability targets, including uptime percentages and measurement methods, are agreed at contract start and may vary based on service scope, deployment model, and support level. Enhanced availability options can be agreed where higher resilience is required.
If agreed availability levels are not met, service credits may be applied in line with the SLA. Credits are calculated as a proportion of the affected service charges and are applied to future invoices. The SLA clearly defines availability targets, exclusions, and the credit mechanism to ensure transparency and best value for money. - Approach to resilience
-
Our AI systems are designed with resilience built-in. Services are deployed with redundancy across critical components, supported by continuous monitoring and controlled change management to minimise disruption. Data protection, backup, and recovery measures support service restoration in the event of failure.
The underlying cloud and datacentre environments are designed for high availability, including resilient power, networking, and infrastructure components. Where applicable, services are distributed across multiple regions or availability zones to reduce single points of failure. Detailed information on datacentre architecture, geographic distribution, and resilience controls is available on request, subject to appropriate security considerations. - Outage reporting
-
Our AI systems report outages through a combination of monitoring, dashboards, and direct notifications. Service availability is continuously monitored to identify outages or performance degradation.
Where appropriate, users are provided with access to a service status dashboard showing current service health, known incidents, and planned maintenance. Dashboards may be public or customer-restricted depending on security and service requirements. For customers requiring integration, outage and status information can also be made available via APIs to support ingestion into external monitoring or ITSM systems.
Email alerts are used to notify users of confirmed outages, significant incidents, and updates during resolution. Notifications include details of affected services, impact, and progress updates until restoration. Outage reporting methods are agreed during onboarding and documented within the Service Level Agreement to ensure clarity and consistency.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access controls. Users are granted access only to the functions and data required for their role. Authentication controls are applied to verify user identity before access is provided. Administrative and support access is limited to authorised personnel and reviewed regularly. Privileged access is monitored and removed promptly when no longer required, ensuring management interfaces and support channels remain secure and appropriately controlled.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
The AI system operates under a comprehensive set of information security policies and processes aligned to ISO/IEC 27001, to which Squarcle Consultancy Ltd is certified. These policies cover information security governance, access control, asset management, risk management, incident management, supplier security, data protection, and business continuity.
An Information Security Management System (ISMS) defines how security risks are identified, assessed, treated, and monitored. Information security responsibilities are clearly defined, with senior management oversight and designated roles accountable for implementation and assurance. Security incidents and non-conformities are reported through formal escalation and incident management processes.
Compliance with security policies is ensured through role-based access controls, mandatory staff training, regular risk assessments, internal audits, and management reviews. Policies and controls are reviewed periodically to ensure continued effectiveness and compliance with legal, regulatory, and contractual requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- The service uses structured configuration and change management processes to maintain control and service stability. Service components are tracked throughout their lifecycle using configuration records that capture ownership, relationships, and status. Changes are logged, assessed, approved, and implemented through controlled change procedures. Each change is reviewed for potential security, availability, and operational impact before approval. Higher-risk changes are subject to additional review and testing to reduce the risk of introducing vulnerabilities or service disruption.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- The service follows a structured vulnerability management process to identify, assess, and address security weaknesses. Potential threats are assessed through regular vulnerability scanning, configuration reviews, and evaluation of system exposure. Vulnerabilities are prioritised based on severity, likelihood, and potential impact. Critical patches are applied as a priority, with routine updates deployed through controlled change processes. Threat intelligence is obtained from software and cloud vendors, security advisories, industry sources, and government-backed cyber security guidance to ensure emerging risks are identified and managed promptly.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The service operates continuous protective monitoring to identify potential security compromises. Monitoring includes log analysis, alerting, and detection of unusual activity, unauthorised access attempts, and anomalous behaviour. When a potential compromise is identified, incident response procedures are initiated to contain the issue, protect affected systems, and prevent further impact. Actions may include isolating components, applying mitigations, and increasing monitoring. Incidents are prioritised by severity, with critical security events investigated and acted upon immediately to ensure rapid containment and
- Incident management type
- Supplier-defined controls
- Incident management approach
-
The service follows a structured incident management approach to ensure incidents are handled consistently and efficiently. Pre-defined processes and playbooks are in place for common incident types to support rapid triage, escalation, and resolution. Users report incidents through agreed channels such as an online ticketing system, email, or phone, depending on the service arrangement.
Incidents are logged, categorised, prioritised, and assigned to appropriate support teams, with progress updates provided throughout the incident lifecycle. For significant incidents, incident reports are produced and shared with customers. These reports include details of the incident, impact, actions taken, resolution, and lessons learned for CSI. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 4%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Amtivo Group Limited T/A British Assessment Bureau Ltd.
- ISO/IEC 27001 accreditation date
- Wednesday 5 March 2025
- What the ISO/IEC 27001 doesn’t cover
- ITSM, which is ITIL -aligned and externally (3rd party) validated by a certified body who conducted the ITIL Maturity Assessment.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Amtivo Group Limited T/A British Assessment Bureau Ltd.
- ISO 9001 accreditation date
- Monday 11 November 2024
- What the ISO 9001 doesn’t cover
-
Information which is covered by ISO 27001.
Financial Management & Accounting are out of scope. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 05732f35-a3cd-4a2b-b307-c468a4101420
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 53eabdfc-3503-4d56-8967-ff64f4dc58fe
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Ensuring new workers are informed of their right to join a trade union
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for positive actions with community groups.
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Working conditions which promote an inclusive working environment and promote retention and progression
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Content of the outreach activity is designed to suit the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-