ISO 44001 Documents in Affinitext's Intelligent Document Platform
The ISO44000 Standards/Guidance suite, with Collaborative Business Relationship Management System (CBRMS), Joint Relationship Management Plan(JRMP) documents transformed into structured, unified, interactive digital assets. A trusted, up-to-date source of truth, with clause-clause links, pop-up definitions, powerful searching and knowledge sharing, plus optional AffiniAI insights, AffiniTask tracking, and AffiniTag metadata—ensuring audit-ready compliance.
Features
- Intelligent Document Platform for Standards/Guidance and relationship documents.
- Structured, navigable digital documents with 99.5% digitisation accuracy.
- Fully conformed “single source of truth”
- Pop-up definitions and clause-to-clause links across documents.
- Powerful search across entire Platform
- Obligation and entitlement identification at paragraph-level precision.
- Permissioned online libraries for portfolios and stakeholders.
- AffiniTask (Optional): Task extraction, population, and workflows.
- AffiniTag (Optional): tagging to filter key document data quickly
- AffiniAI (Optional): with split-screen, clause-validated answers.
Benefits
- Unparalleled improvements in ISO 44001 certification process
- Reduces errors by eliminating confusion with 'single-truth'.
- Improves audit readiness with clause-linked evidence.
- Prevents missed deadlines through obligation and task tracking.
- Saves time and cost through automation and search.
- Engage proactively and seamlessly with all relationship stakeholders
- 5* Transparency
- Preserves institutional knowledge beyond staff turnover.
- Strengthens governance and proactive compliance management.
- Transforming certification management through mind-mapping, etc
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 4 7 9 5 2 0 3 0 1 4 8 6 2 8
Contact
AFFINITEXT (UK) LIMITED
Graham Thomson
Telephone: +44 (0) 2036674866
Email: contact@affinitext.com
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
- Document
Content services
- Enterprise Content Management Applications
- Content Sharing and Collaboration Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Affinitext can extend project platforms (e.g., CDE/PMIS), ECM/DMS (e.g., SharePoint), CAFM/asset management (e.g., Maximo), GRC/compliance systems, and BI/reporting tools. Integrations can use APIs and data exchange to push/pull contract metadata, obligations and tasks into existing workflows, while also operating as a standalone contract library.
- Cloud deployment model
- Hybrid cloud
- Service constraints
- Affinitext is delivered as a hosted service in a customer-specific environment, hosted in the UK. Planned maintenance is scheduled in advance and may require short service windows outside business hours where possible. Performance is unaffected by contract set size and/or user concurrency. Some integrations (SSO, APIs, task/metadata exchange) require customer-side configuration and access approvals. AffiniAI availability depends on customer approval of the AI provider and security requirements, and may be restricted where external LLM processing is not permitted.
- System requirements
-
- Modern web browser: Chrome, Edge, Firefox, or Safari.
- Stable internet connection suitable for document viewing and search.
- JavaScript enabled; cookies permitted for authentication sessions.
- HTTPS/TLS access to service URL through corporate firewall/proxy.
- Supported screen resolution for split-screen reading and navigation.
- User accounts via email; role-based permissions configured by administrators.
- Optional SSO: SAML2/OIDC, buyer identity provider configured.
- Optional integrations: API access enabled; whitelisted IPs if required.
- PDF viewer enabled in browser for embedded document rendering.
- If VDI used, sufficient bandwidth and latency for web apps.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Within 60 minutes during working hours
Within 12 hours on weekends - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
-
Affinitext web chat is designed to be usable with standard browser accessibility features and assistive technologies. It is primarily text-based, and our approach aligns with WCAG 2.1 Level A principles relevant to text pages; our G-Cloud service description notes pages are “nearly always text pages only” and meet most WCAG 2.1A principles.
Apply to Supply
+1
Users can:
Use keyboard-only navigation to read the conversation and enter messages.
Zoom the page and use browser reflow to increase readability.
Use screen readers to navigate page structure and read messages (behaviour varies by browser/AT).
Users may be limited:
Real-time message announcements may not be consistently auto-read by all screen readers.
Where chat outputs include non-text content (e.g., images/visualisations), equivalent alternatives may not be provided.
Apply to Supply
Accessibility of linked/source documents depends on the underlying files (e.g., scanned PDFs).
Accessibility checks are performed as part of interface testing by development/QA teams, as described in the G-Cloud listing. - Web chat accessibility testing
-
We have not yet undertaken formal usability testing of the web chat with assistive technology users (for example, screen reader users).
To support accessibility, we rely on internal functional testing in modern browsers using keyboard-only navigation, zoom/reflow and general UI checks, and we address accessibility issues as they are identified. We can also work with buyers to agree reasonable adjustments and prioritise improvements where specific assistive technology needs are identified during onboarding or early use. - Onsite support
- Yes, at extra cost
- Support levels
-
Support is included in the subscription price. Support is available via email/ticketing and web chat during agreed business hours. It includes incident triage, troubleshooting, configuration and usage guidance, and coordination of technical issues.
A named Account Manager is always provided as the single point of contact for all delivery, training, support, web chat queries, and technical matters. They coordinate internal specialists as needed to resolve issues and support adoption.
Regular online training is included in our Support, including onboarding sessions and periodic refresher clinics for users and administrators.
We also offer on-site training and tailored workshops (e.g., advanced workflows, stakeholder rollouts) as optional paid services, priced on a case-by-case basis based on location, duration, and attendee numbers. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We help users start using Affinitext through a structured onboarding process, supported by our named Account Manager and regular online training.
Document intake (buyer-provided): the buyer provides the full document suite, including all amendments/variations, so we can convert and consolidate them into the live, up-to-date digital set.
Secure transfer: where the buyer cannot provide a secure SharePoint link for controlled access, we set up a secure NextCloud portal for document upload and exchange.
Library setup: we configure the hosted library, user roles/permissions, and portfolio structure (projects, folders, stakeholders) aligned to the buyer’s governance requirements.
Regular online training (included): onboarding sessions for admins and users, plus refresher clinics covering search/navigation, clause links/definitions, obligation and task workflows, and knowledge capture.
User guidance: practical user documentation and quick-start guides tailored to the buyer’s configuration and contract set.
Optional onsite training: available at additional cost for large rollouts, role-based workshops, and train-the-trainer programmes. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
On contract end, Affinitext provides a simple, quick exit so buyers can retrieve their data or move supplier. We return all documents and data in line with the Call-Off Contract, including the processed document content in industry-standard formats. Buyer-generated data (for example tasks/metadata/exports) can be exported by the Buyer in Word, PDF, Excel and/or csv as appropriate.
Following confirmation of successful handover, Affinitext will purge and destroy buyer data from Affinitext systems, storage devices and media in accordance with the Call-Off Contract and the law. - End-of-contract process
-
On contract end, Affinitext provides a simple, quick exit so buyers can retrieve their data or move supplier. We return all documents and data in line with the Call-Off Contract, including the processed contract content in industry-standard formats. Buyer-generated data (for example tasks/metadata/exports) can be exported by the Buyer in Word, PDF, Excel and/or csv as appropriate.
Following confirmation of successful handover, Affinitext will purge and destroy buyer data from Affinitext systems, storage devices and media in accordance with the Call-Off Contract and the law. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Our onboarding and offboarding documentation is provided in two accessible formats:
Online knowledge base (Zendesk): users can access guidance in a standard web browser, use keyboard navigation, adjust zoom/text size, and use screen readers to read HTML content (subject to the user’s browser/assistive technology). This format also supports search and clear page structure for easier navigation.
PDF guides: we provide PDF versions for offline use and controlled distribution. Users can zoom, search within text-based PDFs, and use screen readers where the PDF contains selectable text and appropriate tagging. Where documentation includes diagrams, we can provide supporting text descriptions on request.
If a buyer has specific accessibility needs, we can prioritise providing documentation in the most suitable format (for example, HTML-first, or tagged PDFs) and agree reasonable adjustments during onboarding.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service scales to size on mobile devices
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Yes. Affinitext is accessed through a web-based user interface (browser UI), and (where required) it also supports integration interfaces such as APIs for data exchange.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Affinitext is a browser-based service designed to work with standard accessibility features. Users can navigate key functions using keyboard controls, adjust browser zoom and text size, and use screen readers to read on-screen text (behaviour varies by browser/assistive technology). Users can search, navigate clause links, view definitions, and manage tasks within the web interface. Optional AffiniAI provides chat-style Q&A with links back to source clauses for validation.
- Accessibility testing
-
We have not yet undertaken formal interface testing with users of assistive technology (for example, dedicated testing with screen reader users).
To support accessibility, we carry out internal functional testing of the web interface in modern browsers, including:
Keyboard-only navigation checks for core journeys (login, search, navigation, opening clauses, viewing definitions, and task workflows).
Zoom and reflow checks to ensure content remains usable at higher magnification.
General usability checks to identify obvious focus, contrast, and layout issues.
Where buyers have specific accessibility requirements, we will work with them to agree reasonable adjustments, prioritise fixes, and (where appropriate) arrange targeted testing during onboarding or early adoption. - API
- Yes
- What users can and can't do using the API
- Affinitext does not provide a standard, off-the-shelf public API as part of the core service. Where a buyer requires integration, we can develop a customer-specific API and/or data exchange interface to support agreed use cases (for example, exporting obligations/tasks or contract metadata into the buyer’s existing workflows). Service setup is normally completed through the web interface; API access is enabled only where an integration is commissioned. Changes supported through a bespoke API are limited to the agreed scope (typically data export and synchronisation); administrative configuration, permissions and core library management remain UI-based. Limitations include dependency on buyer-side systems, security approvals, network access/whitelisting, and the need for change control for any new endpoints or expanded functionality.
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- We guarantee independence in a multi-tenant environment through logical tenant isolation and capacity controls. Each customer’s data and access are segregated by tenant, with strict role-based permissions. We protect performance using monitoring, alerting and resource management to prevent “noisy neighbour” impacts, including throttling/rate controls where appropriate and prioritising critical workloads. We track utilisation and scale underlying infrastructure when needed to maintain service levels.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Reports include various collations and filtered reports of logins, substantive hits, searches, defined terms and clause link hits, etc.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Other
- Other data at rest protection approach
- Data at rest is protected through encryption of stored data (storage volumes and backups), strict role-based access controls and segregation of customer data, and third-party data centre physical security provided by our hosting provider. Where hardware/media handling is required, it follows the hosting provider’s controlled processes.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Document content is stored and supplied in industry-standard XML, and Buyer-generated data can be exported as Word, PDF and/or XML as appropriate.
- Data export formats
-
- CSV
- Other
- Other data export formats
- XML (core document content)
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- Buyers typically upload documents in PDF or Word
- We can also work from ODF-equivalent formats
- We can also work from CSV/Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee 98% uptime, measured over each month, excluding planned improvements/upgrades and any pre-agreed maintenance windows. Availability is monitored and incidents are prioritised by severity through our standard support process.
Service credits/refunds: we do not operate an SLA credit schedule. If availability falls below the guaranteed level, we will agree a fair remedy with the buyer in line with the Call-Off Contract and the circumstances of the outage, and we will provide a root-cause review and corrective actions. - Approach to resilience
-
Affinitext is designed for resilience through layered controls across the application, platform and hosting environment.
Hosting/datacentre resilience (Rackspace UK): the service is hosted in a professionally managed Rackspace UK data centre environment with resilient power, cooling and connectivity, plus controlled physical security. Detailed datacentre specifications can be provided on request.
Platform resilience: we use monitoring and alerting to detect incidents quickly, and we operate planned maintenance windows for upgrades to reduce unplanned downtime. Capacity is managed and scaled where required to maintain performance for multi-tenant usage.
Data resilience: contract content and buyer-generated data are protected through regular backups and recovery procedures to support restoration in the event of data loss or service disruption. Access controls and segregation protect each tenant’s data.
Operational resilience: incidents are triaged by severity via Standard Support, with a named Account Manager coordinating communications, remediation and follow-up actions, including root-cause review and preventative improvements after material incidents. - Outage reporting
-
Affinitext reports outages through direct customer communications rather than a public status page.
Public dashboard: No public outage dashboard is currently provided.
API: No standard API is provided for outage/status reporting.
Email alerts: Yes. For service-affecting incidents we notify customer contacts by email, and we provide updates until resolution.
Support channels: Customers can also report and receive updates via web chat and our support ticketing process, coordinated by the named Account Manager.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted through authenticated accounts, role-based permissions and least privilege. Administrative functions are limited to named administrators, with access reviewed and removed when no longer required. Support channels (web chat, email/ticketing) are controlled so only authorised customer contacts can raise requests affecting configuration, users or data. We verify requester identity for sensitive actions (for example account changes, permission changes, exports or incident requests) and require appropriate approvals where agreed. Internal support access is limited to trained staff, logged, and granted only as needed to resolve the specific issue, under our ISO/IEC 27001 controls.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials, Cyber Essential Plus and Mod Accreditation (Official Sensitive)
- Information security policies and processes
-
Affinitext operates an Information Security Management System (ISMS) aligned to ISO/IEC 27001:2022, supported by policies and procedures covering access control, secure configuration, encryption, vulnerability/patch management, incident management, business continuity, supplier risk, and change control. We also maintain Cyber Essentials Plus controls for core cyber hygiene.
Reporting structure: Information security is owned by senior management, with day-to-day responsibility assigned to an information security lead who coordinates risk assessment, controls, audits, and incident response. Security risks and material incidents are escalated to leadership and reviewed through management meetings and formal ISMS reviews.
How we ensure policies are followed:
Mandatory onboarding and periodic security awareness for staff and contractors.
Role-based access, least privilege, and regular access reviews.
Secure SDLC/change management, with peer review and controlled releases.
Independent security testing (including external penetration testing) and tracked remediation.
Logging/monitoring, incident runbooks, and post-incident corrective actions.
Internal audits and management review cycles to verify ISMS effectiveness, plus third-party audits for certification. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We operate formal configuration and change management under our ISO/IEC 27001 ISMS. Service components (code, infrastructure configuration, environments and key dependencies) are version-controlled and tracked through their lifecycle using change records/tickets, approvals, testing evidence, release notes and rollback plans. Changes are assessed for security impact by reviewing data handling, access permissions, authentication/authorisation, logging/monitoring, encryption, network exposure and third-party dependencies. Higher-risk changes require additional peer review, security review and validation before deployment. Emergency changes are controlled, documented and reviewed retrospectively. Post-release monitoring and incident learnings drive corrective actions and continuous improvement.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We assess threats through risk assessment under our ISO/IEC 27001 ISMS, considering likelihood/impact to confidentiality, integrity and availability. We monitor vulnerabilities across operating systems, applications and third-party components, prioritising remediation by severity and exploitability. Security patches are deployed promptly: critical/high issues are expedited through our change process, with emergency patching where required; other patches follow scheduled maintenance cycles. Threat intelligence comes from vendor security advisories (OS/application suppliers), CVE/NVD feeds, security mailing lists, and findings from external penetration testing and security reviews. We track actions to closure and verify remediation.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We use protective monitoring to identify potential compromise through security logging, alerting and review of unusual activity (for example abnormal logins, permission changes, unexpected data access, and service performance anomalies). Alerts are triaged by severity, with investigation and containment actions initiated where compromise is suspected (access revocation, credential resets, isolating affected components, and preserving logs). Incidents are managed through an incident response process with escalation to senior management and customer communication as appropriate. Response times are severity-based: critical incidents are actioned immediately during support hours and prioritised to restore service and protect data.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate a documented incident management process under our ISO/IEC 27001 ISMS. We maintain pre-defined playbooks for common events (for example availability incidents, suspected unauthorised access, privilege issues, and data handling errors), with severity-based triage, escalation, containment, remediation and recovery. Users report incidents via our support channels: web chat, email/ticketing, or through the named Account Manager. We provide incident communications during the event and, for material incidents, an incident report after resolution summarising timeline, impact, root cause, corrective actions and preventative measures, plus any buyer-specific actions required.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- If agreed, we offer a time-limited 8-week pilot. It includes a scoped library using buyer-provided contract documents, core search/navigation and user onboarding/support, with optional AffiniAI. It excludes full enterprise rollout, unlimited document conversion, bespoke integrations and onsite training, unless separately agreed.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12.5%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Wednesday 31 May 2023
- What the ISO/IEC 27001 doesn’t cover
-
Affinitext is certified to ISO/IEC 27001:2022. The Service is delivered and operated under our ISO 27001–certified Information Security Management System (ISMS). This covers the secure handling of customer documents (including intake, processing/conversion, and publication/hosting of customer libraries on secure servers), and the supporting operational controls used to deliver the Service (for example access control, incident management, change management, vulnerability management, and supplier management).
ISO/IEC 27001 certification applies to our ISMS within its defined scope (i.e., how we manage information security), rather than to a product. Third-party hosting providers’ facilities are not “certified by our certificate”; instead, they are managed under our ISO 27001 supplier management controls. Buyer-side systems, networks and devices are outside our certification scope. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 7badc3f3-8c93-4af5-9e6a-b61a47164b2c
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Bc02ab4a-6e60-42ce-92dd-c9f9b9be37cc
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-