RecordPoint
RecordPoint is a cloud-based information and AI governance platform from RecordPoint, offered as a Software-as-a-Service and as a fully managed service.
RecordPoint automates policy control, analytics and reporting over content in cloud-based services (e.g. M365, Workday, Salesforce) and on-premises repositories (e.g. network drives and legacy document and records systems)
Features
- AI Governance
- Information Governance
- Records Management
- Reporting and analytics
- Securing permissions to sensitive data
- Discovery of Shadow AI
- Centralised management across all data sources
- Analysis of data for AI readiness
- Legal Hold management
- Automation of records classification and retention
Benefits
- Reduce risk of PII leakage when using AI tools
- Global view of risk in data across the organsation
- Streamlining FOI and GDPR requests
- Report centrally on all data under management
- Reduce risk of data over retention
- Comply with GDPR and other data protection obligations
- Track risks in the use of AI across the organisation
- Meet archival and records retention obligations
- Reduce the risk of insecure content with incorrectly applied permissions
- Minimal end user impact and low training overhead
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 8 7 9 9 8 8 9 2 2 7 1 5 2 0
Contact
RECORDPOINT SOFTWARE (EMEA) LTD
RecordPoint EMEA Sales
Telephone: +44 117 318 0540
Email: salesemea@recordpoint.com
About your service
- Service categories
-
Applications
Content workflow and management
Content services
- Enterprise Content Management Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- As an inplace service RecordPoint requires customers to have a content repository to be managed. This may be as simple as a network file share.
- System requirements
-
- Current version of Edge or Chrome browser
- Entra ID to manage authentication to the platform
- Network connection to the Internet
User support
- Email or online ticketing support
- Yes
- Support response times
- Depending on the priority of the ticket between 4 hours and 2 business days
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
There is one level of technical support provided. Support operates 24/7 to respond to system issues or downtime.
Support responses are assigned based upon priority as follows:
- High - A critical issue that is causing significant degradation or impact to business operations. Response time is within 4 hours
- Medium - An issue with moderate impact to business operations, but the organization can still function OR a request for technical advice or guidance. Response time is within 1 business day
- Low - A minor issue with trivial impact to business operations OR a request for clarification. Response time is within 2 business days
There is no additional cost for support as it is incorporated into the service price.
Support is accessed via the support portal through a ticketing system which is available 24/7.
Every customer is assigned a Customer Success Manager who is the point of escalation for support or other issues. The Customer Success Manager can draw on other support resources including Cloud Engineering support for complex issues. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
RecordPoint provides online training, user documentation and onboarding support as part of the service.
All onboarding is managed through the Customer Success Manager and the Support team. Key tasks include:
- Registering tenant with customer Entra ID
- Setting up connectors for managed data/document sources
- Ingestion of content into RecordPoint for management
The goal is to have customers onboarded within a couple of weeks - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
Customers can extract their data from RecordPoint at any time using the Export function.
In addition as part of any contract termination, there is a documented transitioning out process where RecordPoint support can extract the data and move it to an agreed secure location prior to the secure deletion of the customer tenant and all data. - End-of-contract process
-
Prior to the end of the contract period, customers may choose to export their content themselves using the available export functionality or choose to use RecordPoint services to assist with the extract of data. Using RecordPoint services may incur extra costs depending on the volume of content and complexity of the export.
Once data is extracted and returned to the customer, the tenant is destroyed with all customer data destroyed. - Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service can be accessed via a mobile browser as the application has a responsive design. There are no functional differences.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
The service interface is a web based application where end users can interact with all key functions of the service.
The application is designed to work with screen readers and other assistive technology - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have undertaken testing using VPAT
- API
- Yes
- What users can and can't do using the API
-
RecordPoint is designed as an API first application and includes a comprehensive set of APIs which can be called by an authenticated user with appropriate permissions. The API can be used to integrate RecordPoint with other or custom applications for the processing of content and the automation of key information and AI governance processes.
The API falls into two broad categories - management APIs for the automation of RecordPoint functions such as classification, disposal and reporting and the Connector API which enables the development of custom connectors where a connector may not exist particularly if the target system is bespoke or legacy.
RecordPoint can integrate with any system that has a compatible modern API and will even support integration directly with databases or systems that do not provide a modern API. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise the service to suit their particular information sources that they wish to target through the use of the connector API or selecting different out of the box connectors.
Configuration options exist to enable different capabilities such as a completely isolated environment (not multi-tenanted) or to provide BYO storage for data.
Who can customise depends on the nature of the customisation. Connector customisation or creation can be managed by the customer or a third party. Customisation of the security architecture is something that RecordPoint would undertake on behalf of the customer.
Scaling
- Independence of resources
-
RecordPoint uses scalable infrastructure which will automatically scale up or out as required to avoid service contention.
The service is licensed based on throughput and usage and is scaled to meet the service commitments to customers.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Customers can view metrics using the in built reporting capability as well as using the RecordPoint dashboard. The metrics provided are customisable but may include records ingested over time, classified/unclassified percentage, disposed records over time, risk metrics relating to PII and PCI, etc,
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- RecordPoint includes the facility for customers to export data held in the platform at any time. This can be achieved either through the UI or via the RecordPoint API.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- Native file format
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- Native file format
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The standard service availability, measured by Monthly Uptime Percentage for RecordPoint is 99.9%.
Downtime is defined as any period of time when the RecordPoint Platform is unavailable, and the service is not in a maintenance window. Unavailable is defined as an end-user being unable to connect to the RecordPoint portal (see service limitations for details).
The Monthly Uptime Percentage is calculated using the following formula:
(Service Minutes - Downtime Minutes) / (Service Minutes) x 100
Service Credits are your sole and exclusive remedy for any performance or availability issues for any Service under the Agreement and this SLA. You may not unilaterally offset your Applicable Monthly Service Fees for performance or availability issues.
RecordPoint will provide service credits based on the following:
under 99% monthly uptime percentage - 2.5% standard service credit
under 95% monthly uptime percentage - 5% standard service credit
Exclusions due to connectivity issues, caused by the underlying platform provider or factors outside our reasonable control - Approach to resilience
-
Using a distributed service architecture, RecordPoint is able to spread processing tasks across clusters of compute nodes, thereby eliminating service availability impacts of individual compute nodes failing.
In addition, the following technical controls are in place to maximize service availability:
- Service load balancing across compute clusters.
- Persistent message queuing to enable service components to pass durable messages to each other.
- Cloud-scale domain name systems (DNS).
- Segmentation of compute clusters into separate availability sets and update domains.
- Availability sets ensure that compute nodes within the same availability set are serviced by the same physical hosts, storage units, and network switches.
- Update domains ensure that updates are applied in a rolling fashion (one-by-one) across a single compute cluster.
- Storage redundancy to ensure that critical service data, such as customer data, is stored across multiple data centers.
RecordPoint tests service continuity and disaster recovery automation and procedures annually. - Outage reporting
- RecordPoint reports outages via email alerts to affected customers. Usually this takes the form of an outbound alert from our Service Desk.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
-
For customer users access can be configured and restricted using the RecordPoint RBAC model. This provides a granular set of roles that can be used to ensure users only have access to the data and functions they require based on the principle of least privilege.
For RecordPoint backend administrators, access is controlled through RBAC and the use of Azure Privileged Identity Management which imposes further security controls around access to manage the service. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Other
- Description of management access authentication
-
For RecordPoint administrators Azure Privileged Identity Management.
Use of Azure Bastion and a dedicated jumpbox
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- Other
- Other security governance standards
-
IRAP to PROTECTED (Australian Federal Government standard)
SOC 2 Type 2 controls standard which includes consideration of security governance - Information security policies and processes
-
The CISO and Head of Risk are accountable for the development and implementation of security policies with devolved responsibility to the relevant areas for the creation and maintenance of supporting processes.
RecordPoint follows the requirements of the ISO27001 standard in terms of defining the required policies that contribute to the ISMS. This includes consideration of policy based controls relating to personnel, regulatory obligations, technical controls and associated processes.
Policies are enforced through both education and training including mandatory annual sign off by all staff as well technical enforcement.
Breaches in policy are subject to disciplinary action. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
RecordPoint uses a range of tools to manage and track configuration changes. Infrastructure as Code (IaC) is used to ensure a consistent deployment approach with a centralised template updated and then deployed for every tenant. All software changes are tracked and managed in Azure DevOps.
Every change is subject to the change management process which involves a risk based review of any proposed changes. All changes are subject to a security review including automated testing.
All changes are implemented by a different team with clear separation of duties. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
RecordPoint uses a range of information sources to understand the emerging threat landscape including government (NSCSC, ACSC and CISA) and vendor resources (Microsoft, Snowflake etc) and third party security partner information (Rapid 7).
The RecordPoint platform is scanned in realtime for vulnerabilities and use DAST and SAST tools to identify vulnerabilities as part of the software development process. This includes open source libraries which are regularly scanned for vulnerabilities. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
RecordPoint uses the Rapid 7 managed service to monitor key endpoints and infrastructure as well as tools available in Azure such as Cloud Defender. Events are collected in a SIEM, correlated and analysed both through automation and manually. Based on a ruleset, alerts are generated and either acted on by the managed service or by RecordPoint staff.
The Cloud Operations team and the Rapid 7 Managed services team are available 24/7 and will respond immediately to a security incident to initially triage, determine severity and then set a resolution time based on that analysis. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
RecordPoint has a defined playbook for the management of incidents (both security and non-security related). This includes all stages from identification, triage, communication through to resolution and post-incident reviews.
The focus is on immediately identifying if data is at risk and immediately stopping any risk of data loss. Users may raise incidents via the support portal for immediate triage and attention. In the event of an incident, affected customers are notified within 4 hours with updates at least every further 4 hours for as long as unresolved.
RecordPoint is happy to involve customers in post incident reviews if desired. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 40%
- Between £250,000 and £500,000
- 30%
- Between £500,001 and £1,000,000
- 30%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 6e46beff-fa6e-4c63-b12a-f88abb41bb24
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- Australian Federal Government IRAP (PROTECTED)
- SOC 2 Type 2
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
-