Skip to main content

Help us improve the Digital Marketplace - send your feedback

Mobile Commons LLC

Rant & Rave

Rant & Rave is a cloud-based feedback solution that brings Customer Voice into the heart of the business. We do this by making feedback requests simple and engaging, focusing on what's important. We provide real time, actionable insight presented in dashboards that are designed to engage and support action.

Features

  • : Real-time feedback capture
  • Multi-channel feedback capture
  • Pro-active / Triggered feedback capture
  • Responsive / always-on feedback capture
  • Intuitive, persona led dashboards
  • Industry-leading sentiment engine
  • Customer recovery module
  • Frontline engagement
  • Deep dive customer insight analytics

Benefits

  • Increase the volume and quality of actionable insight
  • Gain immediate access to feedback
  • Quickly identify root cause of dissatisfaction
  • Recover customers and reduce complaints
  • Democratise feedback and empower frontline teams
  • Celebrate employees
  • Drive continuous improvements with evidence
  • Complete view of satisfaction across all customer journeys
  • Intuitive

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at kurt.sudyka@mobilecommons.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 5 8 4 4 5 8 4 6 4 4 9 5 5 8

Contact

Mobile Commons LLC Kurt Sudyka
Telephone: (929) 565-6560
Email: kurt.sudyka@mobilecommons.com

About your service

Service categories

Applications

Customer relationship management

  • Contact centre
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
N/A
System requirements
  • Latest versions of Edge/Chrome/Firefox/Safari
  • Broadband Internet connectivity
  • PC/laptop/MAC/Tablet with access to the Internet
  • IP & port whitelisting: https://app.rantandrave.com
  • Data exported via CSV, XLS or XLSX formats

User support

Email or online ticketing support
Yes
Support response times
P1 - 1 business hour
P2 - 4 business hours
P3 - 1 business day Monday to Friday support, 09:00 - 17:00 UK
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
P1 - Urgent - Production system Defect that prevents business critical work from being done, no Workaround exists, and Defect impacts most Users; Defect causes a material loss of Customer Data in production system; or Security-related Defect.
P2 - High - Production system Defect that prevents business critical work from being done and a Workaround exists; or Defect violates the material specifications in the Documentation and impacts Customer's production system.
P3 - Normal - All other Defects. Cloud incident (outage) - Rant & Rave's cloud service is unavailable and/or inaccessible for all Users.
Support available to third parties
No

Onboarding and offboarding

Getting started
Rant & Rave provides complete implementation, training, ongoing support, upgrades, maintenance, and consulting services. There is a range of local and remote post-implementation support and consulting services available to you. Rant & Rave Professional Services will complete the implementation process so the customer is enabled and trained to support future configuration effort themselves. This is configuration of the tool's inherent functionality through the GUI menus and options – and not customising source code. The initial implementation workshops will focus on the business architecture and analysis that must proceed any configuration in the user interface. Training options Rant & Rave offers a comprehensive range of training options tailored to fit each customer's specific needs and for each of our solutions offerings. Choose from instructor-led classes, simulations and train-the-trainer programmes — delivered in-person, remotely, or via computer-based training. Training will take place during the implementation for system admins and then formal sessions will be held for specific roles once the configuration is fully defined. Train the trainer is the preferred approach for end users – this ensures that you the customer is the ultimate owner of your tool.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
As per Terms & Conditions we will delete all the relevant data according to the relevant standards in a timeframe that is mutually agreed. This deletion requires no statement of work is included. Additional work will require a statement of work and relevant scoping. A Data Destruction Certificate will be issued once the process is agreed and completed.
End-of-contract process
Many areas of Rant & Rave that provide summations of data (e.g., Visual Portals, Dashboards, drill-through reports) can be exported in a variety of common formats (e.g., PDF, PowerPoint and Excel, etc.). Rant & Rave has the ability to generate a full data export in any format preferred (e.g. Excel).
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Documentation is accessible at any time.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Yes Differences between the mobile and desktop service: Dashboards will re-size based on the mobile device used.
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
The Rant & Rave platform offers RESTful web interfaces which supports the solicitation of feedback requests and return of data via API. It provides methods for accessing data via XML which can be used to import back into our clients' data warehouse.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Customers can select power users to be trained as administrators. These administrators have access to an administrative panel within Rant & Rave. All administration and configuration is achieved through the same browser interface that is used by end users. All screens, forms, reports, views are configured through the browser interface. No coding knowledge or skill is needed to perform configurations within Rant & Rave.

Scaling

Independence of resources
We ensure that one customer's usage does not impact another's performance through a multi-tenant architecture designed with logical isolation, auto-scaling, and resource allocation controls. Our infrastructure is built on cloud platforms that dynamically scale compute, storage, and network capacity based on demand. Continuous monitoring detects unusual load patterns or performance degradation, triggering automated scaling and alerting. Rate limiting and traffic shaping protect shared resources, while performance SLAs and redundancy ensure consistent service levels. Regular capacity planning and load testing validate that our systems maintain stability, availability, and performance regardless of other users' activity.

Analytics

Service usage metrics
Yes
Metrics types
Analytics are a core component of the Rant & Rave analytics function and contain a robust collection of reports. Response rates, user logins, solicitations are all available via dashboards.
Reporting types
  • API access
  • Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Degaussing

Data importing and exporting

Data export approach
CSV, Other Other data export formats: XLS, XLSX
Data export formats
  • CSV
  • Other
Other data export formats
  • XLS
  • XLSX
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • XLS

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Forthcoming: SLA and Refund details from MSA.
Approach to resilience
AWS is utilized for IaaS and Rant and Rave is hosted out of EU-West-2 and US-East-1. AWS has redundancy built into its infrastructure through its global network of Regions and Availability Zones (AZs). Each AZ is a physically separate data center with its own power and networking, and multiple AZs are connected with highly redundant, low-latency networking to allow applications to automatically fail over between them to ensure high availability and fault tolerance.
Outage reporting
Customer dashboard, Support Portal, email alerts.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
We strictly control access to all management interfaces and support channels through role-based access control (RBAC), multi-factor authentication (MFA), and the principle of least privilege. Only authorized personnel with a legitimate business need are granted access, following documented approval and periodic review processes. Administrative and support actions are logged, monitored, and auditable. Access to production systems is isolated from corporate networks and requires VPN. Support channels handling customer data use encrypted communications, identity verification, and session controls to prevent unauthorized access or data exposure.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Our Information Security Management System aligns with ISO 27001:2022 and SOC 2 standards. Following Mobile Commons' acquisition of Rant & Rave in April 2025, we maintained the established security controls previously certified under ISO 27001/SOC 2 and are pursuing our own certifications in Q1/Q2 2026.

We maintain formal policies covering access control, data protection, secure development, incident management, change management, business continuity, and vendor risk management. These policies are reviewed annually and apply to all employees, contractors, and systems. Compliance is validated through internal audits, management reviews, and preparation for third-party certification assessments.
Information security policies and processes
Our organization operates under a comprehensive Information Security Management System aligned with ISO 27001:2022 standards and SOC 2 requirements. The ISMS provides the framework for managing security risks and ensuring the confidentiality, integrity, and availability of our SaaS platform and customer data. We maintain formal, documented information security policies and procedures that are reviewed and approved by executive management on an annual basis, and updated as needed to reflect changes in technology, regulations, and risk. These policies apply to all employees, contractors, and systems supporting our SaaS operations: *Access Control Policy *Data Protection and Privacy Policy *Asset and Configuration Management *Secure Development Lifecycle *Incident Management Process *Change Management *Business Continuity and Disaster Recovery *Vendor and Third-Party Risk Management *Risk Management *Remote Work and Endpoint Security *Security Awareness. Our ISMS and supporting policies integrate best practices from ISO 27001:2022 controls (Annex A) and SOC 2. Compliance is validated through regular internal audits, management reviews, and preparation for third-party certification assessments.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Configuration Management We maintain a centralized configuration management database and automated infrastructure-as-code tools to track and manage system configurations across our environments. Standard/Baseline configurations are defined, documented, and approved and established to ensure consistency, security, and compliance. Unauthorized changes are detected through monitoring and alerting. Configuration reviews ensure alignment with security baselines and hardening standards. Change Management All changes to production systems—including code deployments, infrastructure updates, and configuration modifications—are managed through a structured change control process: *Change Request Submission *Review and Approval *Testing and Validation *Implementation *Post-Implementation Review Emergency changes follow an expedited process with appropriate post-change review and documentation.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We maintain a formal Vulnerability Management Process aligned with ISO 27001 and SOC 2 standards. Regular automated scans, code analysis, and annual third-party penetration tests identify vulnerabilities across our SaaS platform and infrastructure. Threat intelligence sources and security advisories inform our threat assessments. Findings are prioritized based on severity and business impact, with critical issues remediated immediately through our controlled change management process. Lower-priority patches follow standard change timelines. Post-remediation verification ensures effectiveness, and compensating controls are applied when needed. Continuous monitoring, metrics, and management reviews drive improvement and accountability, ensuring timely detection and mitigation of security risks.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We maintain comprehensive protective monitoring across our SaaS platform aligned with ISO 27001 and SOC 2 standards. Automated security monitoring systems collect and analyze logs from authentication, network traffic, application activity, and infrastructure. Security alerts are generated based on threat patterns, anomalous behavior, and attack indicators. Potential compromises trigger immediate investigation by our Security Operations team, who assess severity, contain threats, and initiate incident response. Critical security incidents receive immediate response with containment within hours. Post-incident analysis identifies root causes and implements preventive measures. Continuous monitoring, threat intelligence integration, and regular review ensure effective identification and rapid response to threats.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We maintain a formal Incident Management Process aligned with ISO 27001 standards to ensure timely detection, reporting, and resolution of security incidents. Employees are trained to identify and escalate potential incidents through defined channels including email, ticketing system, and emergency contacts. Our Security-Operations team investigates, contains, eradicates, and recovers from incidents using pre-defined procedures for common incident types. Incident severity is classified to prioritize response, and affected customers are notified promptly with detailed incident reports. Post-incident reviews identify root causes and corrective actions, which are tracked to completion. Continuous monitoring, logging, and lessons learned strengthen security posture and reduce risk.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at kurt.sudyka@mobilecommons.com. Tell them what format you need. It will help if you say what assistive technology you use.