DBS Update Service Checker
We provide a DBS Update Service checker to check the status of DBS certificates that are signed up the Update service. Once the certificates have been added to the system, there is automatic daily checking with instant notifications when there is additional information or the Update Service subscription expires.
Features
- Add and manage DBS certificates for Update Service status checks
- Automatic daily DBS Update Service status checking for all certificates
- Instant notifications when DBS certificate status changes or updates found
- Alerts when Update Service subscription expires or due to expire
- Central dashboard showing current status across all monitored certificates
- Audit trail of checks completed, results, and notification history
- Role-based user access with administrator-controlled permissions and 2FA login
- Secure data storage and encrypted access to certificate status information
- Exportable reports of certificate status, check history, and exceptions
- API integration into ChatGPT to setup automations on custom GPTs
Benefits
- Reduce manual DBS recheck administration through automated daily status monitoring
- Receive instant alerts when new information appears on DBS status
- Prevent compliance gaps with subscription expiry notifications and reminders
- Maintain continuous DBS monitoring without repeating full DBS applications
- Improve safeguarding by detecting status changes as soon as possible
- Save time by managing all certificates from one dashboard
- Strengthen audit readiness with complete check history and reporting
- Support faster onboarding decisions with up-to-date DBS status visibility
- Reduce risk of missed updates through automated checking and tracking
- Improve workforce compliance management across teams, roles, and locations
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 5 1 5 8 4 0 6 4 4 0 1 1 4 8
Contact
EUROCOM C.I. LIMITED
Jagriti Patwari
Telephone: 01372886920
Email: info@eurocomci.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
Our service is delivered online and may occasionally require planned maintenance to ensure performance and security. Scheduled maintenance is normally conducted outside standard UK working hours and customers will be notified in advance of any disruption. Service availability may also depend on buyers having stable internet connectivity and modern web browsers. No installation is required, and the service operates within our defined hosting environment, with no support for on-premise deployment.
Large upload of certificates will be done securely via the back end of the application; data will be shared via a secure link. - System requirements
-
- Modern web browser such as Chrome, Edge, Firefox or Safari.
- Stable internet connection for accessing the cloud-based service platform.
- Email access for receiving Update notifications and system alerts.
- Device capable of running standard web applications securely.
- ChatGPT subscription if using it for automations
User support
- Email or online ticketing support
- Yes
- Support response times
- Support tickets are answered within one working day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We have carried out internal accessibility testing of our web chat function using a range of assistive technologies and accessibility tools. This included testing with keyboard-only navigation to ensure all interactive elements can be accessed without a mouse, confirming visible focus states, and verifying that messages can be sent and received using keyboard controls.
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide comprehensive support for employers as part of our standard Update Service Checking service. Support is available via web support/helpdesk, live chat, telephone and email, and covers all aspects of using the platform, including adding and managing certificates, monitoring status checks, interpreting results and alerts, and using the dashboard and reports.
Support is provided by a dedicated customer support team during business hours (09:00–17:00, Monday to Friday, excluding UK public holidays). Where technical issues are identified, these are escalated to technical support staff for investigation and resolution.
There are no separate paid tiers for support. The full support service is included within the per-certificate managed service fee, with no additional charges for standard support. We do not charge separately for a technical account manager or cloud support engineer; support is included within the standard service offering. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We support customers through a structured onboarding process to ensure the DBS Update Service Checker is configured correctly and users can begin monitoring certificates immediately.
Onboarding and setup support
We start with an onboarding meeting with key customer stakeholders to confirm:
1. User access requirements (administrator and standard users)
2. How certificates will be added (manual entry or bulk upload if applicable)
3. Notification preferences and who should receive alerts
4. Any internal teams/divisions that require separate reporting views
We then create access for the relevant users and set up the customer workspace, including dashboard views and user permissions.
Training
Once setup is complete, we provide online training for platform users.
Training covers:
1. How to add and manage DBS certificates for checking
2. How daily status checks work and how to interpret results
3. How to manage alerts for status changes and subscription expiry
4. How to use the dashboard and export reports/audit history
Documentation and ongoing support
Customer-specific user guidance is provided via our helpdesk platform. Ongoing support is available via web support, live chat, email and phone during business hours. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
Users can extract their data throughout the contract and at contract end. As part of the service, customers receive a monthly report summarising all certificates currently held on the system, certificates where an update has been identified, and certificates that are no longer subscribed to the DBS Update Service.
At the end of the contract, certificate information can be exported directly from the front end of the application. This includes the certificate list, current monitoring status, and any recorded update or subscription expiry events. Customers can download the exported data for their own records and internal compliance audit purposes.
Where required, we can support customers with a complete end-of-contract export to ensure all relevant certificate monitoring information has been retrieved before the service is closed. After confirmation of extraction, user access is disabled and data is retained or securely deleted in line with the customer’s retention requirements and contractual obligations. - End-of-contract process
-
At the end of the contract, we agree an offboarding plan with the customer and confirm whether the service will be renewed or closed. We support the customer to extract any required data (including certificate check reports) and confirm successful completion of exports before access is removed.
Once data extraction is completed, we disable user accounts, revoke API credentials/integrations where applicable, and close the customer environment. Data is then securely deleted in line with the customer’s retention requirements and our contractual and regulatory obligations. Confirmation of deletion can be provided on request.
Included within contract price: standard offboarding support, access deactivation, and availability of individual screening exports and reports generated during service delivery.
Additional costs (if required): bespoke bulk data extraction, specialist reporting formats, or additional technical support for complex HR system integrations or migration activity. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There is no functional difference between the desktop and mobile versions of the service. The same features, content and workflows are available across devices. The service uses a responsive design that automatically adapts to different screen sizes, with layouts, navigation and touch controls optimised for mobile use to ensure usability, accessibility and performance on smartphones and tablets.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service provides a secure, web-based user interface accessible via desktop and mobile devices. Employer users can log in to add certificates for daily monitoring, view updates and download reports. The interface is designed to be intuitive and role-based, ensuring users only see information relevant to their permissions.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
-
Accessibility testing to date has been carried out internally as part of our design and quality assurance processes. The interface has been reviewed against WCAG 2.2 Level A criteria, including keyboard navigation, form labelling, colour contrast, focus states and screen reader compatibility. Internal testing has included the use of common assistive technologies such as screen readers and browser accessibility tools to identify and address potential barriers.
While formal testing with external users of assistive technology has not yet been undertaken, accessibility is considered throughout development and enhancements are made iteratively. We are committed to continuous improvement and are open to conducting further accessibility testing, including user-led testing, in collaboration with clients where required. - API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Our service is hosted on AWS and is designed to scale automatically based on demand. We use autoscaling to increase compute capacity during peak usage and can run multiple instances to maintain consistent performance. Workloads are managed to prevent any single customer’s activity impacting others, including request throttling and queueing where appropriate. We actively monitor performance, availability, and capacity, with alerting and operational procedures in place to respond to spikes in demand. This ensures the platform remains responsive and users are not adversely affected by the activity levels of other organisations.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide real-time service usage metrics through a dashboard showing all certificates being checked. Metrics include time and status of each check, lists of ongoing certificates and their subscription renewal dates on the system. This allows HR users to monitor certificates and speak to candidates about their upcoming certificate renewals.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Our service is hosted on Amazon Web Servers. All customer data stored within the platform is protected using AWS’s default encryption at rest, which encrypts data automatically using strong encryption (AES-256) without requiring customer configuration. Encryption keys are securely managed by AWS's hardened key management systems with strict access controls and auditing. AWS data centres are protected by robust physical and environmental security controls and are subject to independent assurance and compliance reporting (for example ISO/IEC and SOC reports).
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Users can export data directly from the platform of all the checks completed on a certificate and a list of al the certificates on the account.
The system automatically sends a monthly report of:
1. All certificates with update notifications this month
2. All certificates that have fallen off the update service
3. All certificates that are on the update service and have no notifications
4. All certificates which are due to renew in the next month - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We aim to provide continuous availability of the service and host the platform on resilient, autoscaling infrastructure in AWS cloud. We depend on the DBS Update Service API availability to be able to run the update checks.
We operate the following support service levels during standard office hours (09:00–17:00, Monday to Friday, excluding UK public holidays):
Full service unavailability: We will respond within 2 working hours of notification and aim to resolve within 10 working hours.
Major functionality unavailability: We will respond within 5 working hours of notification and aim to resolve within 20 working hours.
Minor functionality issues: We will respond within 10 working hours of notification and aim to resolve within 10 working days.
Full service and major functionality issues should be reported by telephone to meet the response timelines. Minor issues can be reported by telephone or email.
We do not provide automatic service credit refunds for missed service levels. However, service performance is monitored and we will work with customers to investigate incidents, provide updates, implement corrective actions, and prevent recurrence. - Approach to resilience
-
Our service is hosted on Amazon Web Servers (AWS) and is designed to be resilient and highly available. The platform uses autoscaling infrastructure to automatically increase capacity during periods of high demand, helping to maintain consistent performance for all users.
We use a resilient cloud architecture with redundancy across key components to minimise single points of failure. Service health and performance are continuously monitored, with alerting in place to support rapid investigation and resolution of incidents.
Data resilience is supported through a structured backup approach. We perform automated incremental backups to enable recovery of recent data states, and we also maintain backups in a separate data centre to provide protection in the event of a site-level incident. Backup and recovery processes are tested and managed to support service restoration and continuity. - Outage reporting
-
We report service outages and disruptions through a combination of real-time visibility and direct customer communications. Customers can access a dashboard view to monitor the status of the certificates and identify notifications that they think might have been due to the DBS Update Service API being unavailable.
In the event of a confirmed outage or major service degradation, we notify customer stakeholders directly via email (and telephone where required for critical incidents). Updates include the nature of the issue, the expected impact, actions being taken, and regular progress updates until the service is restored.
Our internal monitoring and alerting systems detect service issues proactively, enabling rapid investigation and escalation to technical support. Following resolution, we can provide a summary of the incident, including root cause and corrective actions taken, on request.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is restricted using role-based access controls, with permissions assigned according to user role (for example, administrator vs standard user) and least-privilege principles. Customer administrators control who has access to the system and can add, remove, or amend user access as required. All users authenticate using multi-factor authentication (2FA).
Access to support channels is also restricted to authorised customer contacts. Support requests must be submitted via nominated email addresses or approved users, and identity is verified before any account changes are made. Administrative access changes are logged and auditable to maintain security and accountability. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We follow information security policies and processes aligned to ISO/IEC 27001 and secure software development good practice. This includes secure development practices such as controlled access to code repositories, peer code review, and testing prior to release. Access to systems and customer data is managed through role-based access control and multi-factor authentication (MFA), with access granted on a least-privilege basis and reviewed regularly.
We maintain vulnerability management and patching processes, including monitoring for security updates, applying patches in line with risk and severity, and tracking remediation actions to completion. Changes to the platform are managed through secure configuration and change control, including documented approvals and release management.
We operate an incident response process covering identification, containment, investigation, customer communications, and post-incident reviews to ensure corrective actions are implemented.
Security responsibilities are assigned within the organisation with escalation routes to senior management. Policies are communicated to staff, supported through onboarding and periodic awareness, and compliance is monitored through internal reviews and audits. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Customer user access is controlled through role-based permissions. The customer’s nominated administrator can add, amend, or remove users directly within the platform. All users authenticate using multi-factor authentication (2FA). If the customer administrator requires changes to their own access level, they must request this from their authorised email address and the change is verified and logged.
Platform configuration and software changes are managed through formal change control. Service components are version controlled and tracked through their lifecycle. Changes are assessed for operational and security impact, tested, deployed in a controlled manner with rollback procedures. All changes are logged and auditable. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We maintain a Technical Vulnerability Management Policy to identify, assess, and remediate vulnerabilities across our infrastructure and cloud services. We monitor vendor security advisories and trusted sources to stay informed of emerging threats, based on an up-to-date inventory of technology components and versions.
Patches and updates are obtained electronically and deployed according to risk, criticality, dependencies, and planned release schedules through our change management process.
We complete vulnerability assessments at least annually and may commission specialist penetration testing where required.
Configuration hardening and security awareness training are also used to reduce the attack surface. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We operate protective monitoring to identify potential compromises through continuous monitoring of service availability, authentication activity, and system/application logs. Alerts are generated for abnormal events (for example repeated failed logins, unusual access patterns, or service errors) and are reviewed by authorised technical staff. Where a potential compromise is detected, we follow an incident response process to investigate, contain the issue (including disabling access where required), and remediate. Critical incidents are prioritised for immediate triage and escalation, with customer updates provided as appropriate. Monitoring outputs also inform vulnerability management and change control to reduce recurrence and strengthen preventative controls.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
We follow a defined Information Security Incident Response Procedure covering detection, impact assessment, containment, eradication, recovery, and post-incident review.
Incidents can be reported by customers or third parties and are assessed promptly to determine severity and whether formal incident response is required.
Where necessary, an Incident Response Team is assembled, actions are coordinated through regular incident meetings, and communications are controlled to ensure timely and accurate updates.
Following resolution, we complete a debrief and formal post-incident review, and provide incident summaries/reports to customers on request. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Our free version provides the same functionality as the paid service, including access to customer’s required screening package. The free version is limited to 10 certificates being added to the system for monitoring.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British-assessment.co.uk
- ISO/IEC 27001 accreditation date
- Friday 30 August 2024
- What the ISO/IEC 27001 doesn’t cover
- The whole business is covered by the certification
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 50902c16-25a3-4a01-a004-7d61a9ba4a94
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Af943ed8-843f-465f-8c37-437109f871ea
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-