Skip to main content

Help us improve the Digital Marketplace - send your feedback

FINCORE LIMITED

Secure Document & Data Sharing Platform - Finworks

Finworks’ Secure Data Sharing Platform allows secure information sharing within departments and with agencies, suppliers and third parties via the web or APIs. Collaborative workflows and configurable document creation allow the rapid definition, management and automation of business processes. The digital transformation results in efficiency gains and sustainable process improvement.

Features

  • Advanced workflow automation capabilities to manage document flows
  • Automated quality control to clean and validate information
  • User defined case data structures, business rules and workflows
  • Powerful collaboration capabilities for secure multi-organisation workflows
  • Case management, documentation management, prioritisation and escalation
  • Robust management information, reporting, dashboard and audit trail capabilities
  • Secure access through full role-based permission control
  • Full auditability for all user and system actions
  • Compliant to Government security standards up to an OFFICIAL SENSITIVE
  • Open APIs for easy integration to legacy and other systems

Benefits

  • Enterprise solution focused on improving workflows and process transparency
  • Reduce operational costs and improve efficiency
  • Fast on-boarding; our expert team is experienced in rapid deployments
  • Cloud agnostic - public, private or hybrid cloud
  • Simple user interface to configure the platform to business needs
  • Improve security; provide secure data sharing and information redistribution
  • Secure access and automated notifications for external suppliers and agencies
  • Provides real time business intelligence
  • Acceleration of operational processes through workflow monitoring and review capabilities
  • Well-established platform for mission critical deployments in the public sector

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at government@fincore.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 5 7 8 6 4 6 2 8 7 2 7 6 1 1

Contact

FINCORE LIMITED Brian Diboll
Telephone: +44 (0)207 397 0620
Email: government@fincore.com

About your service

Service categories

Applications

Content workflow and management

  • Document
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
Service Maintenance
As part of Finworks service and support, maintenance windows exist for
1. security patching
2. feature upgrades
3. to apply live proving of releases to production and facilitate other client User Acceptance Testing (UAT) activities
As we provide systems that are often expected to run 24/7, we aim to agree on maintenance windows that fit in with our customer’s operational model. Finworks outage and maintenance management aims to agree and set the maintenance and release schedule with the client.
Product Releases: You will benefit from product releases at an agreed schedule and Release Notes will be provided.
System requirements
  • Latest versions of Chrome, Edge, Firefox, or Safari
  • Supported operating system
  • Connectivity: Reliable broadband or private network
  • Ports/Protocols: HTTPS (TCP 443) Outbound access to email/SMS gateways
  • Integration: Webservices and SOAP/REST APIs available for integration

User support

Email or online ticketing support
Yes
Support response times
Client SLAs will define response time depending on the severity of the issue and the business context. The service operates a severity-based support model. Current SLAs do not include weekends but this can be supported.

Severity 1 (Critical): Initial response within 30 minutes during business hours.

Severity 2 (High): Initial response within 1 hour during business hours.

Severity 3 (Medium): Initial response within 2 business hours.

Severity 4 (Low): Initial response within 2 business days.

Response time is defined as the time to acknowledge and begin investigation. Resolution times are agreed based on impact and complexity.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AAA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AAA
Web chat accessibility testing
We use MS Teams to chat with clients.
Onsite support
Yes, at extra cost
Support levels
Finworks offers both Standard Support and Custom Support packages. Support hours are dependent on client requirements and formalised in an SLA. Incident management details including prioritisation, response times, updates and resolution times are also formalised in the SLA.
Support and maintenance work includes the following activities:
- Helpdesk service and associated issue resolution – usually 3rd and 4th line but
can be expanded to include 1st and 2nd line
- Major incident (e.g., disaster recovery) and security incident management
- Incident escalation
- Maintenance (application and hosting)
- Service monitoring
- Capacity management
- Release management, which will typically include:
— Implementation and rollback plans
— Release notes and other release documentation
— Complying with our customers’ standard release processes
— Internal release testing
— Support to customer UAT testing and live proving for upgrade and issue
resolution releases
- Backup and disaster recovery management
- KPI reporting (frequency as agreed with the customer)
- Service reviews (frequency as agreed with the customer)
- Support for the customer’s ongoing internal documentation of Service Delivery
Packages and other necessary customer internal documentation
- Day-to-day security management including maintenance and patching
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Onboarding follows a robust, defined process and, depending on your requirements, can be achieved very quickly through a phased and agile rollout approach.
The Implementation plan depends on the requirements of the project deliverables. A typical implementation approach is:
• Project Governance
• Project Kick off
• Discovery
• Requirements Definition and Design and Configuration
• Alpha Phase and Configuration
• Data Migration
• Beta Testing
• Go-Live
• Operation and Maintenance
We can help with all aspects of deployment, configuration, interfacing, and integration to other systems. If needed, we can also help you migrate from other systems and services.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
ODT
End-of-contract data extraction
In a managed conclusion of a Finworks service, by agreement Finworks will provide access to copies of all data and all data will be disposed of and servers decommissioned through a structured process. Finworks can export your data in a documented open standards file format (e.g., XML, CSV, ODF) for archival purposes or to facilitate your migration to an
alternative service provider.
A basic export can usually be achieved in less than five working days. If you have more complex export requirements, then additional time may be required.
Data exports will be charged on a time and materials basis in line with our SFIA rate card
End-of-contract process
A standard exit plan/approach is included as part of our Standard Service:
- To provide continuity of service, we will extend the service if requested for up to 12 months beyond any normal contractual termination point, on a 3-months rolling notice basis
- During this period, the terms and conditions, and fees due, under the contract that has been terminated will continue to apply
- On reasonable notice, we will undertake any reasonable actions required to transfer the service to a new provider, which may include:
• Providing a project manager and any other resources necessary for the exit
• Providing data extracts
• Advising third parties on data structures and migration approaches
• Documenting customer workflows, data structures, and any intellectual property
owned by or licensed to the customer, on an ongoing basis to the customer, e.g.,
documenting interfaces to the customer’s other systems
• Maintaining the service and customer data for up to 3 months after the final
transfer of service (as a contingency)
• Secure final deletion of the data
All work under the exit plan will be charged on a time and materials basis in accordance with our SFIA rate card.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile and desktop services are based on the same core platform and functionality, ensuring a consistent user experience across devices.
While the full feature set is available on desktop, certain screens and workflows are streamlined on mobile to improve usability, performance, and readability. Functionality, data access, and security controls are aligned across both platforms, with differences limited primarily to presentation and interaction design rather than underlying capability.
Service interface
Yes
User support accessibility
WCAG 2.2 AAA
Description of service interface
The Admin or Settings Module allows for a low code, highly configurable approach to user and case management.
Accessibility standards
WCAG 2.2 AAA
Accessibility testing
We have undertaken a range of usability and accessibility-focused testing activities to ensure our admin functionality is usable with assistive technologies. This has included internal testing using common screen readers and keyboard-only navigation, as well as informal user testing with individuals who rely on assistive technology to access web-based systems. Feedback from these activities has been used to validate accessibility behaviour, identify usability issues, and inform ongoing improvements to interaction flow, focus management, and labelling. Accessibility testing is reviewed as part of our wider quality assurance and continuous improvement processes.
API
Yes
What users can and can't do using the API
The API supports secure authentication and role-based access control to ensure only authorised users or applications can perform activities. The API exposes a defined set of supported operations and does not provide unrestricted access to all system functions. Certain high-risk or structural configuration changes are restricted to administrative interfaces or require elevated privileges. Rate limiting, payload size limits, and concurrency controls are applied to protect system performance and stability. Schema changes, core workflow model changes, and platform-level configuration are not performed dynamically via the API and are managed through controlled release and governance processes.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • ODF
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The platform is designed as a low-code, highly configurable solution that enables organisations to tailor the system to their specific processes and operational requirements without extensive bespoke development. Configuration is primarily achieved through declarative models, rules, and configuration tools, allowing workflows, data models, user interfaces, and business rules to be adapted quickly and safely.

This approach supports rapid deployment and ongoing change, while preserving a standardised core platform that is maintained and upgraded centrally. Where requirements extend beyond configuration, targeted extensions can be developed using supported APIs and extension points, ensuring that customisation remains controlled, maintainable, and compatible with future platform updates.

Scaling

Independence of resources
The service is designed with single-tenant isolation, capacity management, and performance controls to ensure that the activity of users does not adversely affect others. Resources are monitored and scaled to meet demand, with workload segregation, rate limiting, and prioritisation applied where appropriate. Continuous performance monitoring and alerting are used ensuring consistent service levels for all users in line with agreed SLAs.

Analytics

Service usage metrics
Yes
Metrics types
The service provides a range of standard usage and performance metrics to support operational monitoring and service management. This includes metrics on user activity (such as active users, logins, and session volumes), volumes and throughput, workflow and task completion rates, and system performance indicators including response times and error rates. Usage data can be viewed through built-in dashboards and reports, and exported for external analysis. All metrics are subject to role-based access control and are used to support capacity planning, service improvement, and contractual reporting.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Data at rest is protected by encrypting Amazon S3 buckets using server-side encryption with Amazon S3 managed keys (SSE-S3) and encrypting EBS volumes using AWS KMS.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Data can be exported from the system through user-initiated reports, scheduled bulk exports, and secure APIs. Authorised users can export reports in standard formats such as HTML, XML, ODT, ODS, CSV, Excel, Word and PDF. For integration and exit purposes, the platform supports full and incremental data extracts via documented APIs and bulk export utilities, delivered in open formats with appropriate security controls, audit logging, and encryption.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • ODS
  • ODT
  • HTML
  • XML
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • ODS
  • ODT
  • HTML
  • XML

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The platform is accessible to users on a 24 x 7 x 365 basis. The service availability of the solution is designed for high availability. The availability can be reported to clients monthly.
Approach to resilience
Depending on the client requirements, the service offers disaster recovery from S3 backup spanning multiple availability zones. Further information is available on request.
Outage reporting
Service outages and significant incidents are published through our defined service communications channels. Planned maintenance and known service interruptions are notified in advance via the service portal and direct customer communications. Unplanned outages are communicated promptly through service status updates, with regular progress updates provided until resolution.

All outage notifications include the nature of the issue, affected services, expected impact, and estimated restoration times where available. A post-incident summary is provided for major incidents as part of our incident management and continual service improvement process.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is controlled through role-based access controls (RBAC), strong authentication, and the principle of least privilege, in line with ISO 27001 requirements. Only authorised personnel are granted access based on their responsibilities, and all access is regularly reviewed and audited. Management interfaces require secure login credentials and, where appropriate, multi-factor authentication, while support channels are protected through authenticated user accounts and verification processes to ensure that sensitive information is only disclosed to authorised users. All access and activity are logged to provide a complete audit trail for accountability and compliance purposes.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Fincore operates a comprehensive Information Security Management System (ISMS) certified to ISO/IEC 27001:2022, ISO 27018, BS 10012 and Cyber Essentials Plus, and aligned with GDPR and the UK Data Protection Act. The ISMS is supported by formal policies and procedures including Information Security, Privacy, Risk Management, Incident Management, Access Control, Vulnerability Management, Document Control and Secure Data Handling. These policies define how information is protected, how risks are assessed and treated, and how security incidents are managed.

Information security risks are identified, assessed and recorded in an ISO 27001 Risk Register. Controls are monitored through internal audits, management reviews, continuous monitoring and logging processes defined within the ISMS.

Reporting Structure and Assurance:
Overall accountability for information security sits with Top Management. Day-to-day responsibility for the ISMS is assigned to the Chief Information Security Officer and the Compliance function, with defined roles and responsibilities documented in internal governance records.
Adherence to policies is maintained through mandatory staff training, ongoing security awareness, incident reporting and escalation procedures, internal and external audits, and corrective action tracking. The ISMS is regularly reviewed and continually improved to ensure effectiveness and compliance.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
All configuration items and system components are managed under formal configuration management controls. JIRA is used to record and track all change requests, defects, and enhancements, providing full traceability from initiation through approval, implementation, testing, and release. Source code, configuration, and infrastructure definitions are maintained in version-controlled repositories,
All changes are subject to a defined change management process that includes documented risk and impact assessment prior to approval. Automated security and quality checks are integrated into the CI/CD pipeline. All deployments are logged, auditable, and capable of rollback in accordance with ISO 27001 change management controls.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Our process is aligned with ISO 27001 requirements and forms part of our formal information security management system. Potential threats are identified and assessed through regular vulnerability scanning, code analysis, penetration testing, and risk assessments, with findings evaluated in terms of their impact on confidentiality, integrity, and availability. Critical security vulnerabilities are expedited and deployed in line with defined patch management timescales following appropriate testing and approval. Information on emerging threats is obtained from trusted sources including vendor security advisories, CVE databases, NCSC guidance, and recognised threat intelligence services, and is incorporated into our ongoing risk and change management processes.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Our protective monitoring approach is aligned with ISO 27001 requirements. Potential compromises are identified through continuous logging, centralised monitoring, automated alerting, and regular review of security events across applications, infrastructure, and network components. When a potential compromise is detected, it is triaged through a defined incident management process, with containment, investigation, and remediation actions initiated promptly in line with documented procedures. Incidents are prioritised based on severity and impact, with critical security incidents responded to immediately and escalated through on-call and management processes, and response times governed by defined incident response targets and service level objectives.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Our approach is aligned with ISO 27001 requirements and is defined within our formal incident response and service management procedures. Pre-defined processes and runbooks are in place for common incident types, enabling consistent triage, escalation, and resolution based on severity and impact. Users can report incidents through established support channels, including the service desk and online support portal, with all incidents logged, tracked, and managed within our incident management system. Incident reports are provided for significant incidents, including a summary of impact, root cause, actions taken, and preventative measures, and are used to support continual service improvement and audit requirements.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Peers Quality Assurance Limited
ISO/IEC 27001 accreditation date
Monday 17 February 2025
What the ISO/IEC 27001 doesn’t cover
All aspects are covered.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Peers Quality Assurance Limited
ISO 9001 accreditation date
Tuesday 12 November 2024
What the ISO 9001 doesn’t cover
All aspects are covered.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
3a299f13-dece-432c-997f-80d01dd5772a
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
7e069a80-5817-4fe3-913e-0e5d4be3bd06
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at government@fincore.com. Tell them what format you need. It will help if you say what assistive technology you use.