CasparGov
The CasparGov Software as a Service application is a comprehensive financial and case management solution for Public Deputies, Solicitors, Appointees and their teams to manage the property and financial affairs of their clients under the orders and rules of the Court of Protection.
Features
- Realtime graphical dashboards with configurable financial and caseload reporting
- Onscreen account reconciliation with bank transaction imports
- Court of Protection workflows with system-generated application documentation
- Configurable report writer with saved, user-defined report templates
- Integrated diary, client notes, visit logging and funeral records
- Data encryption with MultiFactor Authentication and Single Sign-On
- Letter and document template generator populated from live case data
- Prepopulated statutory reporting aligned to Office of Public Guardian requirements
- Comprehensive audit trail across all financial and case actions
- Role-based access controls aligned to deputyship responsibilities
Benefits
- Single, integrated client record removes spreadsheets and duplicated data entry
- Centralised case and financial management across all deputyship activities
- Clear caseload allocation improves oversight, continuity and team accountability
- More accurate, compliant account reconciliation with reduced manual intervention
- Reduced dependence on local ICT teams through fully-managed SaaS delivery
- Significantly reduces time spent preparing Office of Public Guardian returns
- Faster access to reliable reports for operational and statutory decision-making
- Automated fee calculations reduce errors and ensure consistent charging
- Clear audit trails support statutory reporting, inspections and internal governance
- Streamlined Court of Protection applications with consistent, system-generated documentation
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 6 2 0 0 5 1 9 0 6 7 2 7 4 1
Contact
IDOX SOFTWARE LTD
Jen.roberts@idoxgroup.com
Telephone: 0333 011 1200
Email: bidteam@idoxgroup.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Adult Social Care
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
Access to the service requires Multi-Factor Authentication by default. Users therefore require access to a compatible authenticator application, such as Microsoft or Google Authenticator, which is typically installed on a smartphone.
As an alternative, Microsoft Single Sign-On can be enabled, which may also require an authenticator application depending on the buyer’s identity configuration.
Planned maintenance is infrequent and communicated in advance. The service is accessed via supported modern web browsers and does not require specialist hardware. - System requirements
-
- Laptop or desktop computer
- Stable internet connection with 5Mbit download and 0.5Mbit upload
- Service access is restricted to connections originating from the UK
- Google Chrome version 100 or later
- Microsoft Edge version 100 or later
- Windows or macOS operating system
User support
- Email or online ticketing support
- Yes
- Support response times
-
CasparGov support requests are logged via email, online ticketing, or web chat and are triaged during normal working hours, 9am to 5pm UK time, Monday to Friday, excluding Bank and Public holidays in England.
Response times are governed by defined support priority levels. Business-critical issues are responded to within 1 hour during working hours, with other issues responded to in line with their assigned priority. Requests received outside of working hours are logged and responded to on the next working day. Weekend and out-of-hours support is not provided as standard - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- None - For users unable to use our web chat we recommend using our standard email or telephone support service.
- Onsite support
- Yes, at extra cost
- Support levels
-
Priority 1 - High
Description: Business Critical – Total System Failure
Response Time: 1 hours
Fix time: 8 working hours
Priority 2 - Medium
Description: An important or critical component of the system has failed causing partial failure of the system.
Response Time: 4 hours
Fix time: 18 working hours
Priority 3 - Low
Description: Non serious – an isolated issue which does not fll into the categories listed above. Proposed resolution may include a workaround until the problem can be fully resolved. Resolution of minor requests and bugs may be included in a future release.
Response Time: 8 hours
Fix time: 45 working hours
Charges are included in the annual system subscription charge.
A nominated account manager is provided alongside the technical support team. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We support customers through a structured onboarding process designed to ensure users can confidently start using CasparGov.
Implementation typically begins with an initial workshop, delivered remotely or onsite where required. This session provides an overview of standard system functionality, confirms configuration choices, and covers security and access requirements. It also allows us to tailor the setup to the organisation’s operating model.
Training is delivered through a combination of live online training sessions and self-service user documentation, including step-by-step guides and short “how-to” videos covering key system functions. Training can be role-based to reflect different user responsibilities, such as administrators, caseworkers or finance staff. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
When a CasparGov contract ends, customers can request a full extract of their data held within the system as at the contract end date. This extract is provided in open, machine-readable formats, typically CSV files, supplied within a secure, compressed (ZIP) archive.
Data extracts are prepared on request and are normally available for secure transfer within 5 business days, subject to confirmation of scope and security arrangements. Any charges associated with producing a full data extract are agreed with the customer in advance.
In addition to the end-of-contract extract, users can export their own data at any time during the contract using standard system functionality. CasparGov includes built-in reporting and export tools that allow authorised users to extract specific datasets, reports or records in CSV or Excel format, supporting ongoing access to and portability of customer data.
This approach ensures customers retain control of their data both during the contract and at exit. - End-of-contract process
-
At the end of the contract, customers can request a full export of their data held in CasparGov as at the contract end date. This is included within the contract price and provided free of charge. Data is supplied in open, machine-readable formats, typically CSV files, with associated documents and files provided in a compressed (ZIP) format for secure transfer.
Data extracts are made available via an agreed secure transfer method within a reasonable timescale following the request. Customers can also continue to use standard system export and reporting functionality up to the contract end date to extract specific datasets as required.
Additional costs
If a customer requires assistance with data migration to another system, including data mapping, transformation or technical support beyond the standard export, this is provided as an optional professional service. Any such work is charged at the prevailing professional services rates and agreed in advance based on scope and complexity. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
- CasparGov is accessed through a secure, browser-based web interface designed for desktop and laptop use. The interface provides role-based access to financial management, case management, reporting, and statutory workflows aligned to Court of Protection requirements. Users navigate the service through structured menus, searchable lists, and task-focused screens that support day-to-day operational work. The interface allows users to view and manage client records, reconcile accounts, generate reports, complete statutory documentation, and maintain audit trails. No local software installation is required, and access is provided via supported modern web browsers
- Accessibility standards
- WCAG 2.2 AAA
- Accessibility testing
-
Formal usability testing with assistive technology users has been limited. Accessibility considerations are addressed through internal reviews during development and by using standard web technologies that support assistive tools through modern browsers. Feedback received through customer support has been used to identify and resolve usability issues where possible.
The service relies on browser-level accessibility features, including screen readers, keyboard navigation, and adjustable zoom, rather than bespoke accessibility tooling. Where users experience difficulties using the service interface, alternative support is provided via email or telephone, and reasonable adjustments are considered on a case-by-case basis. Accessibility remains an ongoing consideration within the product roadmap, with improvements assessed alongside functional and regulatory requirements. - API
- Yes
- What users can and can't do using the API
-
CasparGov provides an API to support secure data integration and reporting, rather than full system configuration or administration.
What users can do using the API
The API allows authorised users to retrieve client, case and financial data from CasparGov for use in external systems such as business intelligence and corporate reporting tools. This includes structured data relating to clients, bank accounts, transactions, balances, fees and reconciliation outcomes, subject to user permissions and security controls.
The API also supports limited, controlled data input where this is required to enable specific reporting or integration use cases.
How users set up and make changes through the API
API access is enabled and managed by system administrators. Authentication, permissions and access scope are configured within CasparGov. Changes to integrations, such as adding reports or data consumers, are managed through configuration rather than direct system setup via the API.
Limitations
The API does not support full system setup or administration. Core activities such as user management, workflows, reconciliation, document management and statutory reporting are completed through the CasparGov user interface. - API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Customisation available to Users with Super Admin access level includes the following:
-User access levels to system areas
-Document and letter templates
-Reports
-Fee charging
-Dropdown reference tables
-Legal Workflows
Scaling
- Independence of resources
-
CasparGov is delivered using separate Virtual Private Cloud (VPC) environments, ensuring that customer data and system resources are logically isolated. This separation prevents activity or load generated by one customer from impacting the performance or availability experienced by others.
The service is hosted on scalable cloud infrastructure with monitored resource allocation, allowing capacity to be adjusted as demand changes. Background processing, reporting and batch operations are managed to avoid contention and maintain consistent performance for all users. This architecture ensures predictable service behaviour even as usage varies across customers.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Authorised users can export data directly from CasparGov using built-in export functionality. The Report Generator allows users with appropriate permissions to create and export custom reports covering client, case and financial data. In addition, many standard system pages provide direct export options for lists and reports, such as transactions, notes, documents and reference data.
Exports are provided in open, commonly used formats, including CSV and Excel (XLSX), allowing data to be reused in external systems for reporting, analysis or archiving. User permissions control which data can be exported to ensure security and compliance. - Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- XLSX
- DOCX
- Data import formats
-
- CSV
- Other
- Other data import formats
- XLSX
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
In addition to encryption in transit, CasparGov protects data within the network through segmented Virtual Private Cloud (VPC) architecture, restricting traffic between components to only what is required. Network access is controlled using firewalls and security groups, limiting inbound and outbound connections to approved services and ports.
Administrative access is tightly controlled and authenticated, with monitoring and logging in place to detect unusual activity. Internal services communicate over private network connections rather than public endpoints wherever possible, reducing exposure and minimising the risk of interception or unauthorised access.
Availability and resilience
- Guaranteed availability
- The standard SLA provides for the hosted environment to be available for not less than 99% of the time in any given 30-day period. Availability is defined as the ability to access the URL, login to the client application, and use all basic functionality of the site.
- Approach to resilience
-
Caspar Gov is hosted on AWS - London Availability zone. For more information please refer to https://aws.amazon.com/compliance/data-center/controls/
Caspar Gov instances are also load balanced and built to be fault tolerant, in case of a system failure a new image is deployed automatically in no more than 15 minutes. - Outage reporting
- In case of a system outage affecting multiple customers, we notify all customers by email. Emails will be sent to the customer's nominated users.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- All management interfaces are secured with 2FA/SSO and secure passwords. Management interface access are also limited to a small number of staff; all staff with access to management interfaces are DBS checked and undergo internal Cyber Security Awareness and GDPR training.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- IP Whitelisting, Geo Restriction
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We have defined information security policies and processes, our policies are based on industry best practices, CE+ and ISO27001 certified. A brief list of policies and processes in place:
-Patch Policy
-Information Security Policy
-Incident Management Policy
-Secure Development Policy
-BYOD Policy
-Vulnerability Management Policy
-DRP and BCP policies
-Privacy Policy
-Backup Policy
-Data Protection Breach Policy
There is a rolling programme of review and education in place to ensure that staff are fully aware of their duties and responsibilities to report any divergence from the current policies. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Caspar Gov is built using Infrastructure as Code therefore infrastructure and software updates are both subject to our release pipeline and procedures. This approach ensures full tracking coverage for all major components of the service.
Code and built containers are scanned for potential security issues prior deployment to Production environment, this scan takes place per release. We also carry out code level scans on a weekly basis to identify newly discovered vulnerabilities and emerging threats on code level, this enables us to assess and fix vulnerabilities even when no standard release is scheduled. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Code is scanned on a weekly basis and servers on deployment with automated tools. Target timelines are defined below:
• Critical – Immediate action to be able to issue a fix or mitigate the vulnerability in no more than 48 hours with deployment to all affected environments as soon as a solution is available.
• High – Commence work to make patch available and deployed in 14 calendar days
• Medium - Commence work to make patch available and deployed in 21 calendar days
• Low – Depending on the nature of the vulnerability patch in 28 days or monitor - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Monitoring is carried out through manual and automated log reviews; we heavily rely on our IDS/IPS solution to discover and identify possible breaches, suspected incidents can also be reported by users. In case of a security incident we aim to investigate suspicious activity immediately during business hours and start our incident response procedure:
1, Immediate Containment / Recovery
2, Preliminary internal investigation
3, Notification to affected customers and if required the ICO
4, In depth internal review
5, CAPA Procedure - Incident management type
- Supplier-defined controls
- Incident management approach
- Predefined processes are detailed in our Incident Management Policy. Users can report incidents on three channels, Online Chat, Support Desk and via phone. Incident reports are provided via email to the nominated Super Administrator for the affected user, other forms of reports are available upon request. If personal data suspected to be affected, and following an assessment it is determined that there will be risk to individuals, the incident is also reported to the ICO.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We can grant a limited licence trial period for test purposes to access CasparGov.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification Limited
- ISO/IEC 27001 accreditation date
- Monday 27 May 2024
- What the ISO/IEC 27001 doesn’t cover
- Our ISMS is certified and tested to ISO27001 standards annually and covers our entire organisation.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Thursday 11 April 2024
- What the ISO 9001 doesn’t cover
- Our ISMS is certified and tested to ISO9001standards annually and covers our entire organisation.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5c6de739-c45d-4eee-916a-013a0c2ce8f7
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 26018f8f-da19-4856-8fd2-b719e0c21047
- Other security certifications
- Yes
- Any other security certifications
- ISO 22301
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-