Skip to main content

Help us improve the Digital Marketplace - send your feedback

ORIGIN SECURED LTD

Origin Secured Event Chain & Trust Orchestration Infrastructure

OS's trust infrastructure allows authoritative organisations to issue contextual assertions as cryptographic-proof, recorded on event-chains and reused across systems without centralising data or permissions. Operating as a trust overlay, enabling verification of who asserted what, in which context, and whether it remains valid, without integrating systems or exposing underlying information.

Features

  • Trust orchestration layer enforcing policy-driven authority and verification
  • Contextual credentials, assertions and endorsements cryptographically linked to authorities
  • Time-bound, scoped and revocable authority with deterministic lifecycle control
  • Reusable confirmed authority across organisations without repeated credential checks
  • Privacy-preserving verification enabling decisions without exposing underlying data
  • Reduced onboarding, audit and assurance friction using reusable Digital Licences
  • Enhances IAM, SSO, PAM and MFA with authority-aware trust signals
  • Event-level recording of trust decisions with immutable provenance
  • Instant proof of authority, compliance and entitlement without document exchange
  • Granular permissioning and delegation controlled by community governance rules

Benefits

  • Secure information sharing without data exposure using cryptographic, zero-knowledge proofs
  • Integration-less interoperability enabling unified digital presence across existing environments
  • Removes duplicated verification and approval checks across organisations
  • Faster real-time decision-making at point of action
  • Reduces cyber risk via continuous verification, not perimeter trust
  • Clear accountability, traceability, and auditability supporting governance and GRC
  • Works with existing infrastructure and cloud platforms without rip-and-replace
  • Consistent trust across programmes, partners, and federated ecosystems
  • Improved permissions, access control, and least-privilege authorisation
  • Scales securely across complex delivery chains and partner ecosystems

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at marc.ayres@originsecured.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 8 4 5 6 4 6 9 7 7 5 9 4 6 7

Contact

ORIGIN SECURED LTD Marc Ayres
Telephone: +447725544864
Email: marc.ayres@originsecured.com

About your service

Service categories

Systems Infrastructure Software

Security

  • Cloud native application protection platform
  • Endpoint security
  • Security analytics
  • Governance, risk and compliance

Identity and access management

  • Access
  • Privilege

Network security

  • Trusted network access and protection
  • Active application security

Data security

  • Information protection
  • Digital trust
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Identity and Access Management (IAM) platforms
Cloud and application security platforms
Governance, risk, and compliance (GRC) and audit systems
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
No
System requirements
  • Standards-based cloud or on-prem infrastructure
  • Modern identity, application, or platform integrations
  • End-user devices

User support

Email or online ticketing support
Yes
Support response times
Critical
Same Business Day (where practicable)
High
1–2 Business Days (where practicable)
Medium
Within a reasonable time
Low
Within a reasonable time
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
No
Support levels
Critical
Same Business Day (where practicable)
High
1–2 Business Days (where practicable)
Medium
Within a reasonable time
Low
Within a reasonable time

No changes in support costs
A technical account manager will be provided
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Origin Secured helps users get started through online onboarding and self-service enablement.

We provide online training materials covering service setup, governance configuration, and API integration, alongside comprehensive user and technical documentation. Documentation includes administrative guidance, API references, security and governance concepts, and integration examples to support system-to-system adoption.

Onboarding focuses on enabling administrators and technical teams to configure communities, trust policies, and integrations independently. The service does not require onsite training; users can start using the platform remotely using the provided online resources and documentation.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
When a contract ends, users can extract their data through documented and controlled data export processes designed to ensure availability, integrity, and confidentiality of service user data.

Service user data is made available for export in commonly used, structured formats via secure transfer mechanisms. Data extraction can be initiated by an authorised customer representative and is supported by clear offboarding documentation outlining the steps, timelines, and responsibilities involved.

During the extraction period, access controls remain in place to ensure only authorised users can access or export data. Data exports are logged and monitored in line with security and audit requirements. Customers are provided with a defined period following contract termination to complete data extraction before data is securely sanitised in accordance with industry-standard data destruction and retention processes.

The end-of-contract data extraction process is aligned with the organisation’s ISO/IEC 27001 information security management system, ensuring that data handling during offboarding is managed securely and consistently, with appropriate oversight and auditability throughout the process.
End-of-contract process
At the end of the contract, the service enters a controlled offboarding process designed to ensure service continuity, secure data handling, and a clear separation of responsibilities between the parties.

Upon contract termination, customer access to the service is restricted in line with agreed notice periods, while authorised access is retained for the purpose of data extraction. Customers are supported through documented offboarding procedures that describe how to export service user data and the timelines involved. Following completion of data extraction, service user data is securely deleted or sanitised in accordance with documented data retention and destruction processes and contractual requirements.

Included in the contract price:

Standard offboarding support

Provision of onboarding and offboarding documentation

Secure data export in standard formats

Secure data deletion and sanitisation following the agreed retention period

Additional costs (if required):

Extended data retention beyond standard periods

Bespoke data exports or non-standard formats

Additional offboarding support outside standard support hours

This approach ensures transparency, security, and predictability for customers at contract end while aligning with recognised information security and service management practices.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
No
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
N/A
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
Origin Secured provides secure, API-first access to its Event Chain and Trust Orchestration infrastructure for system-to-system integration.

Using the API, authorised users can:

Set up and configure tenants, Entities, Communities, roles and governance rules

Issue, update, suspend and revoke Assertions, Endorsements, Digital Views and Digital Licences, with all lifecycle actions recorded as immutable Events

Verify Digital Licences and Assertions (including current status and revocation) via cryptographic proofs on the Event Chain

Orchestrate trust workflows, including consent-led access, selective disclosure, Alias Handles, and integration with external authoritative systems

Subscribe to or query trust events to automate downstream actions and compliance reporting

Users cannot:

Bypass community governance rules or policy enforcement

Alter or delete historical Events on the Event Chain

Access private or restricted data without permission or valid proofs

Perform primary identity proofing or KYC (these are provided by accredited third parties)

Use the API as a consumer-facing application interface

All API access is role-, scope- and tenant-restricted, with security controls, audit logging, and rate limiting applied by default.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customise Origin Secured through configuration and governance controls, rather than bespoke development.

What can be customised

Community structures, membership rules, roles and permissions

Trust schemas, including required Assertions and Digital Licence structures

Digital Licence lifecycle rules (issue, renew, suspend, revoke)

Privacy and disclosure models (public, private, restricted, distributed, zero-knowledge)

Orchestration and verification rules, including event triggers and notifications

API integrations, scopes and event subscriptions

How users can customise

Using secure administrative interfaces and APIs

By configuring governance policies, schemas and rules enforced by the Orchestration layer

Through event-driven configuration that responds automatically to Event Chain activity

Who can customise

Authorised administrators within the customer tenant

Community governors (for shared or federated trust frameworks)

All customisation is role- and permission-controlled; end users cannot alter governance or core platform behaviour.

Scaling

Independence of resources
The service is delivered using a logically segregated, cloud-based architecture designed to ensure that user workloads and data are isolated from one another. Resource allocation is managed to prevent one user’s activity from adversely impacting the performance or availability experienced by other users.

Capacity is monitored continuously, with automated scaling and alerting used to manage demand and maintain service performance. Service performance and availability are reviewed as part of ongoing operational monitoring and management review processes.

This approach ensures fair use of shared infrastructure while maintaining consistent performance, resilience, and availability for all users.

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users export their data using documented, secure export processes provided as part of the service. Authorised users can request or initiate data exports in standard, commonly used formats to support portability and reuse.

Data exports are delivered through secure transfer mechanisms and are subject to access controls, logging, and validation to ensure data integrity and confidentiality. Clear guidance is provided in service documentation to support users through the export process.

Data export remains available during the contract term and for a defined period following contract termination, in line with the documented offboarding process.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is designed to operate with high availability and resilience using a cloud-native architecture.

We guarantee 99.5% service availability, measured on a monthly basis, excluding scheduled maintenance notified in advance. Availability is defined as the ability for authorised users to access and use the core service functionality.

Availability is monitored continuously using automated monitoring and alerting. Performance and availability metrics are reviewed regularly as part of operational management and management review processes.

If the guaranteed availability level is not met, customers are entitled to service credits in accordance with the service level agreement. Service credits are calculated as a proportion of the monthly service fee and applied to the next billing period. Refunds are provided as service credits rather than cash payments.

SLA breaches, root cause analysis, and corrective actions are formally reviewed to prevent recurrence and to support continual improvement of the service.
Approach to resilience
Origin Secured is designed for resilience in line with the government’s Cloud Security Principle 2: Asset protection and resilience.

The service is delivered on UK-hosted cloud infrastructure with logical tenant isolation. Core components are deployed across multiple availability zones to reduce single points of failure and support continued operation during infrastructure faults. Data is protected using redundancy and automated backups to support recovery following incidents.

The Event Chain architecture is inherently resilient: events are append-only, cryptographically linked, and independently verifiable, allowing trust state to be reconstructed deterministically even after partial outages. Separation between the integrity, orchestration, and data layers reduces blast radius and supports graceful degradation.

Continuous monitoring, alerting, and health checks are used to detect and respond to service degradation. Documented incident, backup, and recovery procedures support restoration of service in the event of failure.

Details of specific datacentre locations, configurations, and disaster recovery parameters are considered sensitive and are available on request to public sector buyers under appropriate assurance arrangements.
Outage reporting
Service outages and service degradation events are reported through clear and timely communication channels to ensure users are kept informed.

Outages are communicated to customers via email alerts sent to nominated service contacts, providing details of the issue, impact, and progress updates. Where appropriate, follow-up communications are issued to confirm service restoration and outline any corrective actions taken.

Service availability and incidents are monitored continuously using automated monitoring and alerting. Information on significant incidents, including root cause analysis and remediation actions, is shared with customers as part of post-incident reporting.

At present, the service does not rely on a public status dashboard or outage reporting API. Outage communication is managed directly to customers to ensure accuracy, relevance, and appropriate handling of sensitive operational information.

This approach ensures transparent, controlled, and effective outage reporting aligned with service management and information security best practices.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted through role-based access control and the principle of least privilege.

Administrative access is limited to authorised personnel with defined responsibilities, enforced through strong authentication and individual user accounts. Access rights are approved, reviewed regularly, and revoked promptly when no longer required.

Support channels are restricted to verified customer contacts and authorised internal staff. Requests involving sensitive actions or data require additional verification before being processed.

Access activities are logged and monitored to detect unauthorised or inappropriate use, and controls are reviewed as part of ongoing security governance and audit processes.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
The organisation operates a formal information security management system (ISMS) aligned with ISO/IEC 27001, which defines the policies, processes, and governance arrangements used to protect information assets.

Information security policies cover areas including risk management, access control, incident management, asset management, supplier security, data protection, and secure system operation. These policies are documented, approved by senior management, and reviewed regularly to ensure they remain appropriate and effective.

Security governance is overseen by senior leadership, with defined roles and responsibilities for information security management. Security performance, risks, incidents, and compliance activities are reported through a structured management review process, ensuring appropriate oversight and decision-making.

Compliance with policies is enforced through access controls, documented procedures, staff training and awareness activities, and regular internal audits. Deviations, incidents, or nonconformities are recorded, investigated, and addressed through corrective action processes, supporting continual improvement.

This structured approach ensures information security policies are consistently applied, monitored, and improved in line with recognised best practice and regulatory expectations.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and change management is governed through documented, supplier-defined processes aligned with our ISO/IEC 27001 information security management system.

Service components are identified and tracked through their lifecycle using asset and configuration records, ensuring visibility of ownership and dependencies. Changes to systems, configurations, or services are formally requested, assessed, and approved prior to implementation.

All changes are assessed for potential security and operational impact, including risks to confidentiality, integrity, and availability. Where required, changes are tested before deployment. Post-implementation reviews confirm successful outcomes and identify corrective actions.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerability management is delivered through documented, supplier-defined processes aligned with our ISO/IEC 27001 information security management system.

Potential threats are identified through monitoring, penetration testing, vulnerability scanning, supplier review and platform security advisories. Identified vulnerabilities are assessed using a risk-based approach, considering severity, exploitability and potential impact on confidentiality, integrity and availability.

Patches and mitigations are prioritised based on risk. High-risk vulnerabilities are addressed as a priority, with patches deployed promptly following testing. Lower-risk issues are scheduled into maintenance cycles.

Threat intelligence is sourced from cloud providers, software vendors, security advisories, and industry sources, reviewed regularly to ensure timely response.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is delivered through documented, supplier-defined processes aligned with our ISO/IEC 27001 information security management system.

Potential compromises are identified through centralised logging, continuous monitoring, and automated alerts covering authentication events, system activity, and security-relevant behaviour. Logs are retained and reviewed to support detection and investigation.

When a potential compromise is identified, incidents are triaged, contained, and investigated in accordance with documented incident response procedures. Appropriate corrective actions are implemented to mitigate impact and prevent recurrence.

Security incidents are responded to promptly, with high-severity incidents prioritised for immediate action and escalation to senior management where required.
Incident management type
Supplier-defined controls
Incident management approach
Incident management is delivered through documented, supplier-defined processes aligned with our ISO/IEC 27001 information security management system.

Pre-defined procedures exist for common security and operational incidents, including unauthorised access, service disruption, and data security events. Incidents are logged, triaged, and managed according to severity and impact.

Users report incidents via email or the support ticketing process. All incidents are recorded and tracked through to resolution.

Incident reports are provided to affected users where appropriate, including details of impact, actions taken, and any required follow-up. Incidents, root cause analysis, and corrective actions are reviewed to support continual improvement.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
25%
Over £5,000,001
30%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Wednesday 13 August 2025
What the ISO/IEC 27001 doesn’t cover
The certification does not extend to customer-managed environments, customer endpoint devices, or third-party systems that are not operated or controlled by the organisation. Responsibility for the secure configuration and use of the service within customer environments remains with the customer.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau
ISO 9001 accreditation date
Wednesday 13 August 2025
What the ISO 9001 doesn’t cover
Third-party managed data centres and cloud infrastructure (e.g. AWS), which are outside of direct operational control. These services are instead managed through supplier assurance, contractual controls, and reliance on the third party’s own certified management systems.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
B37a829a-ac55-4130-af5f-c9fa608401e3
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Fe487148-6f13-49ca-8236-de75fb5f7d12
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at marc.ayres@originsecured.com. Tell them what format you need. It will help if you say what assistive technology you use.