Skip to main content

Help us improve the Digital Marketplace - send your feedback

IDOX SOFTWARE LTD

CasparGov

The CasparGov Software as a Service application is a comprehensive financial and case management solution for Public Deputies, Solicitors, Appointees and their teams to manage the property and financial affairs of their clients under the orders and rules of the Court of Protection.

Features

  • Realtime graphical dashboards with configurable financial and caseload reporting
  • Onscreen account reconciliation with bank transaction imports
  • Court of Protection workflows with system-generated application documentation
  • Configurable report writer with saved, user-defined report templates
  • Integrated diary, client notes, visit logging and funeral records
  • Data encryption with MultiFactor Authentication and Single Sign-On
  • Letter and document template generator populated from live case data
  • Prepopulated statutory reporting aligned to Office of Public Guardian requirements
  • Comprehensive audit trail across all financial and case actions
  • Role-based access controls aligned to deputyship responsibilities

Benefits

  • Single, integrated client record removes spreadsheets and duplicated data entry
  • Centralised case and financial management across all deputyship activities
  • Clear caseload allocation improves oversight, continuity and team accountability
  • More accurate, compliant account reconciliation with reduced manual intervention
  • Reduced dependence on local ICT teams through fully-managed SaaS delivery
  • Significantly reduces time spent preparing Office of Public Guardian returns
  • Faster access to reliable reports for operational and statutory decision-making
  • Automated fee calculations reduce errors and ensure consistent charging
  • Clear audit trails support statutory reporting, inspections and internal governance
  • Streamlined Court of Protection applications with consistent, system-generated documentation

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@idoxgroup.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 6 2 0 0 5 1 9 0 6 7 2 7 4 1

Contact

IDOX SOFTWARE LTD Jen.roberts@idoxgroup.com
Telephone: 0333 011 1200
Email: bidteam@idoxgroup.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Adult Social Care
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
Access to the service requires Multi-Factor Authentication by default. Users therefore require access to a compatible authenticator application, such as Microsoft or Google Authenticator, which is typically installed on a smartphone.

As an alternative, Microsoft Single Sign-On can be enabled, which may also require an authenticator application depending on the buyer’s identity configuration.

Planned maintenance is infrequent and communicated in advance. The service is accessed via supported modern web browsers and does not require specialist hardware.
System requirements
  • Laptop or desktop computer
  • Stable internet connection with 5Mbit download and 0.5Mbit upload
  • Service access is restricted to connections originating from the UK
  • Google Chrome version 100 or later
  • Microsoft Edge version 100 or later
  • Windows or macOS operating system

User support

Email or online ticketing support
Yes
Support response times
CasparGov support requests are logged via email, online ticketing, or web chat and are triaged during normal working hours, 9am to 5pm UK time, Monday to Friday, excluding Bank and Public holidays in England.

Response times are governed by defined support priority levels. Business-critical issues are responded to within 1 hour during working hours, with other issues responded to in line with their assigned priority. Requests received outside of working hours are logged and responded to on the next working day. Weekend and out-of-hours support is not provided as standard
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
None - For users unable to use our web chat we recommend using our standard email or telephone support service.
Onsite support
Yes, at extra cost
Support levels
Priority 1 - High
Description: Business Critical – Total System Failure

Response Time: 1 hours
Fix time: 8 working hours

Priority 2 - Medium
Description: An important or critical component of the system has failed causing partial failure of the system.

Response Time: 4 hours
Fix time: 18 working hours

Priority 3 - Low
Description: Non serious – an isolated issue which does not fll into the categories listed above. Proposed resolution may include a workaround until the problem can be fully resolved. Resolution of minor requests and bugs may be included in a future release.

Response Time: 8 hours
Fix time: 45 working hours

Charges are included in the annual system subscription charge.
A nominated account manager is provided alongside the technical support team.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
We support customers through a structured onboarding process designed to ensure users can confidently start using CasparGov.

Implementation typically begins with an initial workshop, delivered remotely or onsite where required. This session provides an overview of standard system functionality, confirms configuration choices, and covers security and access requirements. It also allows us to tailor the setup to the organisation’s operating model.

Training is delivered through a combination of live online training sessions and self-service user documentation, including step-by-step guides and short “how-to” videos covering key system functions. Training can be role-based to reflect different user responsibilities, such as administrators, caseworkers or finance staff.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
When a CasparGov contract ends, customers can request a full extract of their data held within the system as at the contract end date. This extract is provided in open, machine-readable formats, typically CSV files, supplied within a secure, compressed (ZIP) archive.

Data extracts are prepared on request and are normally available for secure transfer within 5 business days, subject to confirmation of scope and security arrangements. Any charges associated with producing a full data extract are agreed with the customer in advance.

In addition to the end-of-contract extract, users can export their own data at any time during the contract using standard system functionality. CasparGov includes built-in reporting and export tools that allow authorised users to extract specific datasets, reports or records in CSV or Excel format, supporting ongoing access to and portability of customer data.

This approach ensures customers retain control of their data both during the contract and at exit.
End-of-contract process
At the end of the contract, customers can request a full export of their data held in CasparGov as at the contract end date. This is included within the contract price and provided free of charge. Data is supplied in open, machine-readable formats, typically CSV files, with associated documents and files provided in a compressed (ZIP) format for secure transfer.

Data extracts are made available via an agreed secure transfer method within a reasonable timescale following the request. Customers can also continue to use standard system export and reporting functionality up to the contract end date to extract specific datasets as required.

Additional costs
If a customer requires assistance with data migration to another system, including data mapping, transformation or technical support beyond the standard export, this is provided as an optional professional service. Any such work is charged at the prevailing professional services rates and agreed in advance based on scope and complexity.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AAA
Description of service interface
CasparGov is accessed through a secure, browser-based web interface designed for desktop and laptop use. The interface provides role-based access to financial management, case management, reporting, and statutory workflows aligned to Court of Protection requirements. Users navigate the service through structured menus, searchable lists, and task-focused screens that support day-to-day operational work. The interface allows users to view and manage client records, reconcile accounts, generate reports, complete statutory documentation, and maintain audit trails. No local software installation is required, and access is provided via supported modern web browsers
Accessibility standards
WCAG 2.2 AAA
Accessibility testing
Formal usability testing with assistive technology users has been limited. Accessibility considerations are addressed through internal reviews during development and by using standard web technologies that support assistive tools through modern browsers. Feedback received through customer support has been used to identify and resolve usability issues where possible.

The service relies on browser-level accessibility features, including screen readers, keyboard navigation, and adjustable zoom, rather than bespoke accessibility tooling. Where users experience difficulties using the service interface, alternative support is provided via email or telephone, and reasonable adjustments are considered on a case-by-case basis. Accessibility remains an ongoing consideration within the product roadmap, with improvements assessed alongside functional and regulatory requirements.
API
Yes
What users can and can't do using the API
CasparGov provides an API to support secure data integration and reporting, rather than full system configuration or administration.

What users can do using the API
The API allows authorised users to retrieve client, case and financial data from CasparGov for use in external systems such as business intelligence and corporate reporting tools. This includes structured data relating to clients, bank accounts, transactions, balances, fees and reconciliation outcomes, subject to user permissions and security controls.
The API also supports limited, controlled data input where this is required to enable specific reporting or integration use cases.

How users set up and make changes through the API
API access is enabled and managed by system administrators. Authentication, permissions and access scope are configured within CasparGov. Changes to integrations, such as adding reports or data consumers, are managed through configuration rather than direct system setup via the API.

Limitations
The API does not support full system setup or administration. Core activities such as user management, workflows, reconciliation, document management and statutory reporting are completed through the CasparGov user interface.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
  • Other
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Customisation available to Users with Super Admin access level includes the following:
-User access levels to system areas
-Document and letter templates
-Reports
-Fee charging
-Dropdown reference tables
-Legal Workflows

Scaling

Independence of resources
CasparGov is delivered using separate Virtual Private Cloud (VPC) environments, ensuring that customer data and system resources are logically isolated. This separation prevents activity or load generated by one customer from impacting the performance or availability experienced by others.

The service is hosted on scalable cloud infrastructure with monitored resource allocation, allowing capacity to be adjusted as demand changes. Background processing, reporting and batch operations are managed to avoid contention and maintain consistent performance for all users. This architecture ensures predictable service behaviour even as usage varies across customers.

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Authorised users can export data directly from CasparGov using built-in export functionality. The Report Generator allows users with appropriate permissions to create and export custom reports covering client, case and financial data. In addition, many standard system pages provide direct export options for lists and reports, such as transactions, notes, documents and reference data.

Exports are provided in open, commonly used formats, including CSV and Excel (XLSX), allowing data to be reused in external systems for reporting, analysis or archiving. User permissions control which data can be exported to ensure security and compliance.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • PDF
  • XLSX
  • DOCX
Data import formats
  • CSV
  • Other
Other data import formats
XLSX

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
In addition to encryption in transit, CasparGov protects data within the network through segmented Virtual Private Cloud (VPC) architecture, restricting traffic between components to only what is required. Network access is controlled using firewalls and security groups, limiting inbound and outbound connections to approved services and ports.
Administrative access is tightly controlled and authenticated, with monitoring and logging in place to detect unusual activity. Internal services communicate over private network connections rather than public endpoints wherever possible, reducing exposure and minimising the risk of interception or unauthorised access.

Availability and resilience

Guaranteed availability
The standard SLA provides for the hosted environment to be available for not less than 99% of the time in any given 30-day period. Availability is defined as the ability to access the URL, login to the client application, and use all basic functionality of the site.
Approach to resilience
Caspar Gov is hosted on AWS - London Availability zone. For more information please refer to https://aws.amazon.com/compliance/data-center/controls/

Caspar Gov instances are also load balanced and built to be fault tolerant, in case of a system failure a new image is deployed automatically in no more than 15 minutes.
Outage reporting
In case of a system outage affecting multiple customers, we notify all customers by email. Emails will be sent to the customer's nominated users.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
All management interfaces are secured with 2FA/SSO and secure passwords. Management interface access are also limited to a small number of staff; all staff with access to management interfaces are DBS checked and undergo internal Cyber Security Awareness and GDPR training.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Description of management access authentication
IP Whitelisting, Geo Restriction

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We have defined information security policies and processes, our policies are based on industry best practices, CE+ and ISO27001 certified. A brief list of policies and processes in place:
-Patch Policy
-Information Security Policy
-Incident Management Policy
-Secure Development Policy
-BYOD Policy
-Vulnerability Management Policy
-DRP and BCP policies
-Privacy Policy
-Backup Policy
-Data Protection Breach Policy
There is a rolling programme of review and education in place to ensure that staff are fully aware of their duties and responsibilities to report any divergence from the current policies.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Caspar Gov is built using Infrastructure as Code therefore infrastructure and software updates are both subject to our release pipeline and procedures. This approach ensures full tracking coverage for all major components of the service.
Code and built containers are scanned for potential security issues prior deployment to Production environment, this scan takes place per release. We also carry out code level scans on a weekly basis to identify newly discovered vulnerabilities and emerging threats on code level, this enables us to assess and fix vulnerabilities even when no standard release is scheduled.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Code is scanned on a weekly basis and servers on deployment with automated tools. Target timelines are defined below:

• Critical – Immediate action to be able to issue a fix or mitigate the vulnerability in no more than 48 hours with deployment to all affected environments as soon as a solution is available.
• High – Commence work to make patch available and deployed in 14 calendar days
• Medium - Commence work to make patch available and deployed in 21 calendar days
• Low – Depending on the nature of the vulnerability patch in 28 days or monitor
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Monitoring is carried out through manual and automated log reviews; we heavily rely on our IDS/IPS solution to discover and identify possible breaches, suspected incidents can also be reported by users. In case of a security incident we aim to investigate suspicious activity immediately during business hours and start our incident response procedure:
1, Immediate Containment / Recovery
2, Preliminary internal investigation
3, Notification to affected customers and if required the ICO
4, In depth internal review
5, CAPA Procedure
Incident management type
Supplier-defined controls
Incident management approach
Predefined processes are detailed in our Incident Management Policy. Users can report incidents on three channels, Online Chat, Support Desk and via phone. Incident reports are provided via email to the nominated Super Administrator for the affected user, other forms of reports are available upon request. If personal data suspected to be affected, and following an assessment it is determined that there will be risk to individuals, the incident is also reported to the ICO.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We can grant a limited licence trial period for test purposes to access CasparGov.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Citation ISO Certification Limited
ISO/IEC 27001 accreditation date
Monday 27 May 2024
What the ISO/IEC 27001 doesn’t cover
Our ISMS is certified and tested to ISO27001 standards annually and covers our entire organisation.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation ISO Certification Limited
ISO 9001 accreditation date
Thursday 11 April 2024
What the ISO 9001 doesn’t cover
Our ISMS is certified and tested to ISO9001standards annually and covers our entire organisation.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
5c6de739-c45d-4eee-916a-013a0c2ce8f7
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
26018f8f-da19-4856-8fd2-b719e0c21047
Other security certifications
Yes
Any other security certifications
ISO 22301

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidteam@idoxgroup.com. Tell them what format you need. It will help if you say what assistive technology you use.