Secure Document & Data Sharing Platform - Finworks
Finworks’ Secure Data Sharing Platform allows secure information sharing within departments and with agencies, suppliers and third parties via the web or APIs. Collaborative workflows and configurable document creation allow the rapid definition, management and automation of business processes. The digital transformation results in efficiency gains and sustainable process improvement.
Features
- Advanced workflow automation capabilities to manage document flows
- Automated quality control to clean and validate information
- User defined case data structures, business rules and workflows
- Powerful collaboration capabilities for secure multi-organisation workflows
- Case management, documentation management, prioritisation and escalation
- Robust management information, reporting, dashboard and audit trail capabilities
- Secure access through full role-based permission control
- Full auditability for all user and system actions
- Compliant to Government security standards up to an OFFICIAL SENSITIVE
- Open APIs for easy integration to legacy and other systems
Benefits
- Enterprise solution focused on improving workflows and process transparency
- Reduce operational costs and improve efficiency
- Fast on-boarding; our expert team is experienced in rapid deployments
- Cloud agnostic - public, private or hybrid cloud
- Simple user interface to configure the platform to business needs
- Improve security; provide secure data sharing and information redistribution
- Secure access and automated notifications for external suppliers and agencies
- Provides real time business intelligence
- Acceleration of operational processes through workflow monitoring and review capabilities
- Well-established platform for mission critical deployments in the public sector
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 5 7 8 6 4 6 2 8 7 2 7 6 1 1
Contact
FINCORE LIMITED
Brian Diboll
Telephone: +44 (0)207 397 0620
Email: government@fincore.com
About your service
- Service categories
-
Applications
Content workflow and management
- Document
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
-
Service Maintenance
As part of Finworks service and support, maintenance windows exist for
1. security patching
2. feature upgrades
3. to apply live proving of releases to production and facilitate other client User Acceptance Testing (UAT) activities
As we provide systems that are often expected to run 24/7, we aim to agree on maintenance windows that fit in with our customer’s operational model. Finworks outage and maintenance management aims to agree and set the maintenance and release schedule with the client.
Product Releases: You will benefit from product releases at an agreed schedule and Release Notes will be provided. - System requirements
-
- Latest versions of Chrome, Edge, Firefox, or Safari
- Supported operating system
- Connectivity: Reliable broadband or private network
- Ports/Protocols: HTTPS (TCP 443) Outbound access to email/SMS gateways
- Integration: Webservices and SOAP/REST APIs available for integration
User support
- Email or online ticketing support
- Yes
- Support response times
-
Client SLAs will define response time depending on the severity of the issue and the business context. The service operates a severity-based support model. Current SLAs do not include weekends but this can be supported.
Severity 1 (Critical): Initial response within 30 minutes during business hours.
Severity 2 (High): Initial response within 1 hour during business hours.
Severity 3 (Medium): Initial response within 2 business hours.
Severity 4 (Low): Initial response within 2 business days.
Response time is defined as the time to acknowledge and begin investigation. Resolution times are agreed based on impact and complexity. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AAA
- Web chat accessibility testing
- We use MS Teams to chat with clients.
- Onsite support
- Yes, at extra cost
- Support levels
-
Finworks offers both Standard Support and Custom Support packages. Support hours are dependent on client requirements and formalised in an SLA. Incident management details including prioritisation, response times, updates and resolution times are also formalised in the SLA.
Support and maintenance work includes the following activities:
- Helpdesk service and associated issue resolution – usually 3rd and 4th line but
can be expanded to include 1st and 2nd line
- Major incident (e.g., disaster recovery) and security incident management
- Incident escalation
- Maintenance (application and hosting)
- Service monitoring
- Capacity management
- Release management, which will typically include:
— Implementation and rollback plans
— Release notes and other release documentation
— Complying with our customers’ standard release processes
— Internal release testing
— Support to customer UAT testing and live proving for upgrade and issue
resolution releases
- Backup and disaster recovery management
- KPI reporting (frequency as agreed with the customer)
- Service reviews (frequency as agreed with the customer)
- Support for the customer’s ongoing internal documentation of Service Delivery
Packages and other necessary customer internal documentation
- Day-to-day security management including maintenance and patching - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
Onboarding follows a robust, defined process and, depending on your requirements, can be achieved very quickly through a phased and agile rollout approach.
The Implementation plan depends on the requirements of the project deliverables. A typical implementation approach is:
• Project Governance
• Project Kick off
• Discovery
• Requirements Definition and Design and Configuration
• Alpha Phase and Configuration
• Data Migration
• Beta Testing
• Go-Live
• Operation and Maintenance
We can help with all aspects of deployment, configuration, interfacing, and integration to other systems. If needed, we can also help you migrate from other systems and services. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- ODT
- End-of-contract data extraction
-
In a managed conclusion of a Finworks service, by agreement Finworks will provide access to copies of all data and all data will be disposed of and servers decommissioned through a structured process. Finworks can export your data in a documented open standards file format (e.g., XML, CSV, ODF) for archival purposes or to facilitate your migration to an
alternative service provider.
A basic export can usually be achieved in less than five working days. If you have more complex export requirements, then additional time may be required.
Data exports will be charged on a time and materials basis in line with our SFIA rate card - End-of-contract process
-
A standard exit plan/approach is included as part of our Standard Service:
- To provide continuity of service, we will extend the service if requested for up to 12 months beyond any normal contractual termination point, on a 3-months rolling notice basis
- During this period, the terms and conditions, and fees due, under the contract that has been terminated will continue to apply
- On reasonable notice, we will undertake any reasonable actions required to transfer the service to a new provider, which may include:
• Providing a project manager and any other resources necessary for the exit
• Providing data extracts
• Advising third parties on data structures and migration approaches
• Documenting customer workflows, data structures, and any intellectual property
owned by or licensed to the customer, on an ongoing basis to the customer, e.g.,
documenting interfaces to the customer’s other systems
• Maintaining the service and customer data for up to 3 months after the final
transfer of service (as a contingency)
• Secure final deletion of the data
All work under the exit plan will be charged on a time and materials basis in accordance with our SFIA rate card. - Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The mobile and desktop services are based on the same core platform and functionality, ensuring a consistent user experience across devices.
While the full feature set is available on desktop, certain screens and workflows are streamlined on mobile to improve usability, performance, and readability. Functionality, data access, and security controls are aligned across both platforms, with differences limited primarily to presentation and interaction design rather than underlying capability. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
- The Admin or Settings Module allows for a low code, highly configurable approach to user and case management.
- Accessibility standards
- WCAG 2.2 AAA
- Accessibility testing
- We have undertaken a range of usability and accessibility-focused testing activities to ensure our admin functionality is usable with assistive technologies. This has included internal testing using common screen readers and keyboard-only navigation, as well as informal user testing with individuals who rely on assistive technology to access web-based systems. Feedback from these activities has been used to validate accessibility behaviour, identify usability issues, and inform ongoing improvements to interaction flow, focus management, and labelling. Accessibility testing is reviewed as part of our wider quality assurance and continuous improvement processes.
- API
- Yes
- What users can and can't do using the API
- The API supports secure authentication and role-based access control to ensure only authorised users or applications can perform activities. The API exposes a defined set of supported operations and does not provide unrestricted access to all system functions. Certain high-risk or structural configuration changes are restricted to administrative interfaces or require elevated privileges. Rate limiting, payload size limits, and concurrency controls are applied to protect system performance and stability. Schema changes, core workflow model changes, and platform-level configuration are not performed dynamically via the API and are managed through controlled release and governance processes.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- ODF
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The platform is designed as a low-code, highly configurable solution that enables organisations to tailor the system to their specific processes and operational requirements without extensive bespoke development. Configuration is primarily achieved through declarative models, rules, and configuration tools, allowing workflows, data models, user interfaces, and business rules to be adapted quickly and safely.
This approach supports rapid deployment and ongoing change, while preserving a standardised core platform that is maintained and upgraded centrally. Where requirements extend beyond configuration, targeted extensions can be developed using supported APIs and extension points, ensuring that customisation remains controlled, maintainable, and compatible with future platform updates.
Scaling
- Independence of resources
- The service is designed with single-tenant isolation, capacity management, and performance controls to ensure that the activity of users does not adversely affect others. Resources are monitored and scaled to meet demand, with workload segregation, rate limiting, and prioritisation applied where appropriate. Continuous performance monitoring and alerting are used ensuring consistent service levels for all users in line with agreed SLAs.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides a range of standard usage and performance metrics to support operational monitoring and service management. This includes metrics on user activity (such as active users, logins, and session volumes), volumes and throughput, workflow and task completion rates, and system performance indicators including response times and error rates. Usage data can be viewed through built-in dashboards and reports, and exported for external analysis. All metrics are subject to role-based access control and are used to support capacity planning, service improvement, and contractual reporting.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Data at rest is protected by encrypting Amazon S3 buckets using server-side encryption with Amazon S3 managed keys (SSE-S3) and encrypting EBS volumes using AWS KMS.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Data can be exported from the system through user-initiated reports, scheduled bulk exports, and secure APIs. Authorised users can export reports in standard formats such as HTML, XML, ODT, ODS, CSV, Excel, Word and PDF. For integration and exit purposes, the platform supports full and incremental data extracts via documented APIs and bulk export utilities, delivered in open formats with appropriate security controls, audit logging, and encryption.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- ODS
- ODT
- HTML
- XML
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- ODS
- ODT
- HTML
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- The platform is accessible to users on a 24 x 7 x 365 basis. The service availability of the solution is designed for high availability. The availability can be reported to clients monthly.
- Approach to resilience
- Depending on the client requirements, the service offers disaster recovery from S3 backup spanning multiple availability zones. Further information is available on request.
- Outage reporting
-
Service outages and significant incidents are published through our defined service communications channels. Planned maintenance and known service interruptions are notified in advance via the service portal and direct customer communications. Unplanned outages are communicated promptly through service status updates, with regular progress updates provided until resolution.
All outage notifications include the nature of the issue, affected services, expected impact, and estimated restoration times where available. A post-incident summary is provided for major incidents as part of our incident management and continual service improvement process.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is controlled through role-based access controls (RBAC), strong authentication, and the principle of least privilege, in line with ISO 27001 requirements. Only authorised personnel are granted access based on their responsibilities, and all access is regularly reviewed and audited. Management interfaces require secure login credentials and, where appropriate, multi-factor authentication, while support channels are protected through authenticated user accounts and verification processes to ensure that sensitive information is only disclosed to authorised users. All access and activity are logged to provide a complete audit trail for accountability and compliance purposes.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Fincore operates a comprehensive Information Security Management System (ISMS) certified to ISO/IEC 27001:2022, ISO 27018, BS 10012 and Cyber Essentials Plus, and aligned with GDPR and the UK Data Protection Act. The ISMS is supported by formal policies and procedures including Information Security, Privacy, Risk Management, Incident Management, Access Control, Vulnerability Management, Document Control and Secure Data Handling. These policies define how information is protected, how risks are assessed and treated, and how security incidents are managed.
Information security risks are identified, assessed and recorded in an ISO 27001 Risk Register. Controls are monitored through internal audits, management reviews, continuous monitoring and logging processes defined within the ISMS.
Reporting Structure and Assurance:
Overall accountability for information security sits with Top Management. Day-to-day responsibility for the ISMS is assigned to the Chief Information Security Officer and the Compliance function, with defined roles and responsibilities documented in internal governance records.
Adherence to policies is maintained through mandatory staff training, ongoing security awareness, incident reporting and escalation procedures, internal and external audits, and corrective action tracking. The ISMS is regularly reviewed and continually improved to ensure effectiveness and compliance. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
All configuration items and system components are managed under formal configuration management controls. JIRA is used to record and track all change requests, defects, and enhancements, providing full traceability from initiation through approval, implementation, testing, and release. Source code, configuration, and infrastructure definitions are maintained in version-controlled repositories,
All changes are subject to a defined change management process that includes documented risk and impact assessment prior to approval. Automated security and quality checks are integrated into the CI/CD pipeline. All deployments are logged, auditable, and capable of rollback in accordance with ISO 27001 change management controls. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Our process is aligned with ISO 27001 requirements and forms part of our formal information security management system. Potential threats are identified and assessed through regular vulnerability scanning, code analysis, penetration testing, and risk assessments, with findings evaluated in terms of their impact on confidentiality, integrity, and availability. Critical security vulnerabilities are expedited and deployed in line with defined patch management timescales following appropriate testing and approval. Information on emerging threats is obtained from trusted sources including vendor security advisories, CVE databases, NCSC guidance, and recognised threat intelligence services, and is incorporated into our ongoing risk and change management processes.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Our protective monitoring approach is aligned with ISO 27001 requirements. Potential compromises are identified through continuous logging, centralised monitoring, automated alerting, and regular review of security events across applications, infrastructure, and network components. When a potential compromise is detected, it is triaged through a defined incident management process, with containment, investigation, and remediation actions initiated promptly in line with documented procedures. Incidents are prioritised based on severity and impact, with critical security incidents responded to immediately and escalated through on-call and management processes, and response times governed by defined incident response targets and service level objectives.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Our approach is aligned with ISO 27001 requirements and is defined within our formal incident response and service management procedures. Pre-defined processes and runbooks are in place for common incident types, enabling consistent triage, escalation, and resolution based on severity and impact. Users can report incidents through established support channels, including the service desk and online support portal, with all incidents logged, tracked, and managed within our incident management system. Incident reports are provided for significant incidents, including a summary of impact, root cause, actions taken, and preventative measures, and are used to support continual service improvement and audit requirements.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Peers Quality Assurance Limited
- ISO/IEC 27001 accreditation date
- Monday 17 February 2025
- What the ISO/IEC 27001 doesn’t cover
- All aspects are covered.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Peers Quality Assurance Limited
- ISO 9001 accreditation date
- Tuesday 12 November 2024
- What the ISO 9001 doesn’t cover
- All aspects are covered.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 3a299f13-dece-432c-997f-80d01dd5772a
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 7e069a80-5817-4fe3-913e-0e5d4be3bd06
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-