Skip to main content

Help us improve the Digital Marketplace - send your feedback

RECORDPOINT SOFTWARE (EMEA) LTD

RecordPoint

RecordPoint is a cloud-based information and AI governance platform from RecordPoint, offered as a Software-as-a-Service and as a fully managed service.

RecordPoint automates policy control, analytics and reporting over content in cloud-based services (e.g. M365, Workday, Salesforce) and on-premises repositories (e.g. network drives and legacy document and records systems)

Features

  • AI Governance
  • Information Governance
  • Records Management
  • Reporting and analytics
  • Securing permissions to sensitive data
  • Discovery of Shadow AI
  • Centralised management across all data sources
  • Analysis of data for AI readiness
  • Legal Hold management
  • Automation of records classification and retention

Benefits

  • Reduce risk of PII leakage when using AI tools
  • Global view of risk in data across the organsation
  • Streamlining FOI and GDPR requests
  • Report centrally on all data under management
  • Reduce risk of data over retention
  • Comply with GDPR and other data protection obligations
  • Track risks in the use of AI across the organisation
  • Meet archival and records retention obligations
  • Reduce the risk of insecure content with incorrectly applied permissions
  • Minimal end user impact and low training overhead

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at salesemea@recordpoint.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 8 7 9 9 8 8 9 2 2 7 1 5 2 0

Contact

RECORDPOINT SOFTWARE (EMEA) LTD RecordPoint EMEA Sales
Telephone: +44 117 318 0540
Email: salesemea@recordpoint.com

About your service

Service categories

Applications

Content workflow and management

Content services

  • Enterprise Content Management Applications
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
As an inplace service RecordPoint requires customers to have a content repository to be managed. This may be as simple as a network file share.
System requirements
  • Current version of Edge or Chrome browser
  • Entra ID to manage authentication to the platform
  • Network connection to the Internet

User support

Email or online ticketing support
Yes
Support response times
Depending on the priority of the ticket between 4 hours and 2 business days
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
There is one level of technical support provided. Support operates 24/7 to respond to system issues or downtime.

Support responses are assigned based upon priority as follows:
- High - A critical issue that is causing significant degradation or impact to business operations. Response time is within 4 hours
- Medium - An issue with moderate impact to business operations, but the organization can still function OR a request for technical advice or guidance. Response time is within 1 business day
- Low - A minor issue with trivial impact to business operations OR a request for clarification. Response time is within 2 business days

There is no additional cost for support as it is incorporated into the service price.

Support is accessed via the support portal through a ticketing system which is available 24/7.

Every customer is assigned a Customer Success Manager who is the point of escalation for support or other issues. The Customer Success Manager can draw on other support resources including Cloud Engineering support for complex issues.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
RecordPoint provides online training, user documentation and onboarding support as part of the service.

All onboarding is managed through the Customer Success Manager and the Support team. Key tasks include:
- Registering tenant with customer Entra ID
- Setting up connectors for managed data/document sources
- Ingestion of content into RecordPoint for management

The goal is to have customers onboarded within a couple of weeks
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Customers can extract their data from RecordPoint at any time using the Export function.

In addition as part of any contract termination, there is a documented transitioning out process where RecordPoint support can extract the data and move it to an agreed secure location prior to the secure deletion of the customer tenant and all data.
End-of-contract process
Prior to the end of the contract period, customers may choose to export their content themselves using the available export functionality or choose to use RecordPoint services to assist with the extract of data. Using RecordPoint services may incur extra costs depending on the volume of content and complexity of the export.

Once data is extracted and returned to the customer, the tenant is destroyed with all customer data destroyed.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service can be accessed via a mobile browser as the application has a responsive design. There are no functional differences.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service interface is a web based application where end users can interact with all key functions of the service.

The application is designed to work with screen readers and other assistive technology
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have undertaken testing using VPAT
API
Yes
What users can and can't do using the API
RecordPoint is designed as an API first application and includes a comprehensive set of APIs which can be called by an authenticated user with appropriate permissions. The API can be used to integrate RecordPoint with other or custom applications for the processing of content and the automation of key information and AI governance processes.

The API falls into two broad categories - management APIs for the automation of RecordPoint functions such as classification, disposal and reporting and the Connector API which enables the development of custom connectors where a connector may not exist particularly if the target system is bespoke or legacy.

RecordPoint can integrate with any system that has a compatible modern API and will even support integration directly with databases or systems that do not provide a modern API.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Buyers can customise the service to suit their particular information sources that they wish to target through the use of the connector API or selecting different out of the box connectors.

Configuration options exist to enable different capabilities such as a completely isolated environment (not multi-tenanted) or to provide BYO storage for data.

Who can customise depends on the nature of the customisation. Connector customisation or creation can be managed by the customer or a third party. Customisation of the security architecture is something that RecordPoint would undertake on behalf of the customer.

Scaling

Independence of resources
RecordPoint uses scalable infrastructure which will automatically scale up or out as required to avoid service contention.

The service is licensed based on throughput and usage and is scaled to meet the service commitments to customers.

Analytics

Service usage metrics
Yes
Metrics types
Customers can view metrics using the in built reporting capability as well as using the RecordPoint dashboard. The metrics provided are customisable but may include records ingested over time, classified/unclassified percentage, disposed records over time, risk metrics relating to PII and PCI, etc,
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
RecordPoint includes the facility for customers to export data held in the platform at any time. This can be achieved either through the UI or via the RecordPoint API.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • Native file format
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • Native file format

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The standard service availability, measured by Monthly Uptime Percentage for RecordPoint is 99.9%.

Downtime is defined as any period of time when the RecordPoint Platform is unavailable, and the service is not in a maintenance window. Unavailable is defined as an end-user being unable to connect to the RecordPoint portal (see service limitations for details).

The Monthly Uptime Percentage is calculated using the following formula:
(Service Minutes - Downtime Minutes) / (Service Minutes) x 100

Service Credits are your sole and exclusive remedy for any performance or availability issues for any Service under the Agreement and this SLA. You may not unilaterally offset your Applicable Monthly Service Fees for performance or availability issues.

RecordPoint will provide service credits based on the following:
under 99% monthly uptime percentage - 2.5% standard service credit
under 95% monthly uptime percentage - 5% standard service credit

Exclusions due to connectivity issues, caused by the underlying platform provider or factors outside our reasonable control
Approach to resilience
Using a distributed service architecture, RecordPoint is able to spread processing tasks across clusters of compute nodes, thereby eliminating service availability impacts of individual compute nodes failing.

In addition, the following technical controls are in place to maximize service availability:
- Service load balancing across compute clusters.
- Persistent message queuing to enable service components to pass durable messages to each other.
- Cloud-scale domain name systems (DNS).
- Segmentation of compute clusters into separate availability sets and update domains.
- Availability sets ensure that compute nodes within the same availability set are serviced by the same physical hosts, storage units, and network switches.
- Update domains ensure that updates are applied in a rolling fashion (one-by-one) across a single compute cluster.
- Storage redundancy to ensure that critical service data, such as customer data, is stored across multiple data centers.

RecordPoint tests service continuity and disaster recovery automation and procedures annually.
Outage reporting
RecordPoint reports outages via email alerts to affected customers. Usually this takes the form of an outbound alert from our Service Desk.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
For customer users access can be configured and restricted using the RecordPoint RBAC model. This provides a granular set of roles that can be used to ensure users only have access to the data and functions they require based on the principle of least privilege.

For RecordPoint backend administrators, access is controlled through RBAC and the use of Azure Privileged Identity Management which imposes further security controls around access to manage the service.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Other
Description of management access authentication
For RecordPoint administrators Azure Privileged Identity Management.

Use of Azure Bastion and a dedicated jumpbox

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • Other
Other security governance standards
IRAP to PROTECTED (Australian Federal Government standard)
SOC 2 Type 2 controls standard which includes consideration of security governance
Information security policies and processes
The CISO and Head of Risk are accountable for the development and implementation of security policies with devolved responsibility to the relevant areas for the creation and maintenance of supporting processes.

RecordPoint follows the requirements of the ISO27001 standard in terms of defining the required policies that contribute to the ISMS. This includes consideration of policy based controls relating to personnel, regulatory obligations, technical controls and associated processes.

Policies are enforced through both education and training including mandatory annual sign off by all staff as well technical enforcement.

Breaches in policy are subject to disciplinary action.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
RecordPoint uses a range of tools to manage and track configuration changes. Infrastructure as Code (IaC) is used to ensure a consistent deployment approach with a centralised template updated and then deployed for every tenant. All software changes are tracked and managed in Azure DevOps.

Every change is subject to the change management process which involves a risk based review of any proposed changes. All changes are subject to a security review including automated testing.

All changes are implemented by a different team with clear separation of duties.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
RecordPoint uses a range of information sources to understand the emerging threat landscape including government (NSCSC, ACSC and CISA) and vendor resources (Microsoft, Snowflake etc) and third party security partner information (Rapid 7).

The RecordPoint platform is scanned in realtime for vulnerabilities and use DAST and SAST tools to identify vulnerabilities as part of the software development process. This includes open source libraries which are regularly scanned for vulnerabilities.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
RecordPoint uses the Rapid 7 managed service to monitor key endpoints and infrastructure as well as tools available in Azure such as Cloud Defender. Events are collected in a SIEM, correlated and analysed both through automation and manually. Based on a ruleset, alerts are generated and either acted on by the managed service or by RecordPoint staff.

The Cloud Operations team and the Rapid 7 Managed services team are available 24/7 and will respond immediately to a security incident to initially triage, determine severity and then set a resolution time based on that analysis.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
RecordPoint has a defined playbook for the management of incidents (both security and non-security related). This includes all stages from identification, triage, communication through to resolution and post-incident reviews.

The focus is on immediately identifying if data is at risk and immediately stopping any risk of data loss. Users may raise incidents via the support portal for immediate triage and attention. In the event of an incident, affected customers are notified within 4 hours with updates at least every further 4 hours for as long as unresolved.

RecordPoint is happy to involve customers in post incident reviews if desired.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
40%
Between £250,000 and £500,000
30%
Between £500,001 and £1,000,000
30%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
6e46beff-fa6e-4c63-b12a-f88abb41bb24
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
  • Australian Federal Government IRAP (PROTECTED)
  • SOC 2 Type 2

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at salesemea@recordpoint.com. Tell them what format you need. It will help if you say what assistive technology you use.