Skip to main content

Help us improve the Digital Marketplace - send your feedback

FabricShift Limited

HabiTrack

HabiTrack is a cloud-based software service that helps organisations embed and measure behaviour change. It enables organisations to define habits that work towards organisational goals, track participation and progress over time, and understand adoption and engagement across individuals, teams and the organisation.

Features

  • Configurable habits linked to behaviour and learning programmes
  • Linking habits to organisational goals and KPIs
  • User and cohort-based habit tracking
  • Realtime reporting: dashboards showing engagement, adoption and progress over time
  • Role-based access controls for organisations, programmes, and users
  • Cloud-hosted service accessible via web browser
  • Microsoft Teams integration for user access and notifications
  • Programme-level configuration and management tools

Benefits

  • Embed behaviour change across programmes and teams
  • Embed learning through small, repeatable habit-based actions
  • Measure behaviour adoption alongside organisational goals and KPIs
  • Track participation and progress without manual reporting overhead
  • Gain real-time visibility of engagement across individuals and teams
  • Manage programmes centrally with clear governance and access controls
  • Enable user participation through familiar web and Teams interfaces
  • Reduce reliance on surveys for ongoing behaviour monitoring

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@fabricshift.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 9 1 2 7 7 9 5 2 6 9 3 4 6 9

Contact

FabricShift Limited Johanna Beresford
Telephone: +44 0203 150 0000
Email: info@fabricshift.com

About your service

Service categories

Applications

Collaborative

  • Team collaboration
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
HabiTrack is a standalone cloud-based SaaS platform. It optionally integrates with corporate collaboration platforms such as Microsoft Teams and Slack to allow users to interact with the service within tools they already use. All core functionality is available via the web application and does not require these integrations.
Cloud deployment model
Public cloud
Service constraints
HabiTrack is delivered as a centrally hosted, cloud-based SaaS service. The service is accessed via a supported web browser and requires internet connectivity. Planned maintenance and updates are managed by FabricShift in line with standard SaaS practices, with advance notice provided where reasonably possible. The service is not provided as a customer-hosted or self-managed deployment.
System requirements
  • Modern web browser supporting current HTML and JavaScript standards
  • Internet connection for accessing the cloud-hosted service
  • User authentication via SSO using the buying organisation's identity provider
  • OPTIONAL: Microsoft Teams licence for Teams-based access

User support

Email or online ticketing support
Yes
Support response times
Support queries are typically acknowledged within 1 business day. Standard support is provided during UK business hours (Monday to Friday). Weekend support is limited, with responses provided on the next business day.

Support requests are acknowledged during UK business hours (Monday to Friday) and prioritised by severity. Critical issues (service unavailable): within 4 business hours. High priority issues (significant functionality impaired): within 8 business hours. Normal queries: within 2 business days.

Weekend support is limited, with responses provided on the next business day.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
No
Support levels
FabricShift provides a standard support level for HabiTrack, included within the service price. Support is provided via email or online ticketing during UK business hours, with queries prioritised based on severity and service impact. Customers are assigned a named account manager who acts as the primary point of contact for relationship management, onboarding coordination, and service queries. This role is not a dedicated technical support or cloud engineering function. At present, we do not offer tiered support levels or a dedicated technical account manager or cloud support engineer.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Buyers are supported through a structured onboarding process. This includes guidance and documentation to support initial setup, such as configuring programmes, defining habits, and assigning users / teams. Where applicable, organisational goals and KPIs will also be configured within the service. Implementation is supported remotely, working with buyer stakeholders to ensure the service is configured appropriately for their organisation. End users are onboarded through an invite-based process. Users receive a secure link to access the service, where they are guided through an introductory experience explaining how to use the platform and participate in assigned programmes. Supporting user guidance is provided within the service and through onboarding materials.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, buyers can request the extraction of their data from the service. Data is provided in commonly used, machine-readable formats suitable for reuse or import into other systems. Data extraction is supported as part of the offboarding process, with arrangements agreed to ensure secure transfer of data. Access to the service is then withdrawn in line with contract terms. Any remaining data held by the supplier is handled in accordance with agreed data retention and deletion policies.
End-of-contract process
At the end of the contract, access to the service is withdrawn in line with agreed notice periods. Buyers are supported through an offboarding process, including the extraction of their data where requested. Standard offboarding activities, including account closure and data export in an agreed format, are included within the contract price. Any additional services beyond standard offboarding, such as extended access periods, bespoke data transformations, or additional support requirements, may be provided at additional cost by agreement.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile and desktop services provide the same functionality. The mobile experience uses a responsive layout optimised for smaller screens, which may differ in presentation and navigation.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a secure web-based user interface and collaboration platform interfaces, allowing users to interact with the service without local installation. The interface provides a home view displaying assigned habits, with additional navigation to features such as insights and programme information. Where enabled, organisational goals and KPIs can also be viewed. The layout uses clear navigation and card-based components to support ease of use.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The service has been tested using common accessibility tools and techniques during development, including keyboard-only navigation, screen reader checks, and colour contrast review. The interface is built using accessible UI components designed to work with assistive technologies such as screen readers and keyboard navigation. Accessibility considerations are incorporated into ongoing development and testing processes, and feedback from users is used to identify and address usability or accessibility issues as the service evolves. Where accessibility issues are identified, they are addressed in line with WCAG 2.2 AA guidance.
API
Yes
What users can and can't do using the API
API access is provided to support agreed integration and data exchange use cases, rather than end-user interaction with the service. The API can be used to support activities such as syncing user and organisational data from external systems, managing user status updates (e.g., joiners, leavers, work hours), and exchanging programme-related data or metrics with other systems, such as HR, learning, or management information platforms. Where enabled, the API may also be used to ingest or extract organisational KPI or performance data for reporting purposes. Core service setup and management (including programme creation and habit definition) is performed through the service's user interface and is not exposed for full self-service configuration via the API. API access is subject to appropriate authentication, authorisation, and security controls, and is enabled on a per-customer basis for defined integration use cases.
API documentation
No
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Buyers can configure the service to suit their needs by defining their own programmes and habits, managing users and cohorts, and setting initiative parameters through the platform. For Enterprise implementations, organisational goals and KPIs can also be configured and linked to programmes. Configuration is performed through the service interface and, where required, supported through implementation services. The service can only be customised by approved users with appropriate administrative permissions - standard users can interact with assigned programmes and habits but cannot modify configuration.

Scaling

Independence of resources
HabiTrack operates a multi-tenant architecture designed to manage demand across customers and reduce risk of resource contention. Under standard multi-tenant model, customers receive: Application-Level Isolation (tenant data logically separated within shared database with strict access controls), Defined Resource Limits (CPU and memory limits configured per deployment, preventing resource contention), Row-Level Security (database queries scoped to authenticated tenant), and Auto-Scaling (deployments automatically scale with additional pods based on resource consumption).

For customers requiring enhanced isolation, HabiTrack offers dedicated Kubernetes namespaces: Full Namespace Isolation, Dedicated Database, Dedicated Resource Allocation, Independent Deployments, Auto-Scaling

Analytics

Service usage metrics
Yes
Metrics types
The service provides usage and engagement metrics to help organisations understand adoption and progress. Metrics include habit tracking activity, engagement levels, and programme-level summaries across teams and cohorts. Where enabled, metrics can also include progress against organisational goals and KPIs.
Metrics can be viewed over time and at organisational and programme level to support monitoring of behaviour change and engagement.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Authorised users for the buying organisation can request the export of their data during the contract or as part of the offboarding process. Data exports are provided securely by the supplier in commonly used, machine-readable formats suitable for analysis or import into other systems.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
HabiTrack is provided with a target monthly availability of 99.5%, measured on a monthly basis using platform monitoring data. Availability is calculated as the percentage of time the service is operational during the measurement period. Where availability targets are not met, service credits may be applied in accordance with the terms set out in the service agreement. No additional financial compensation is provided beyond agreed service credits.
Approach to resilience
[1] Physical Location / Legal Jurisdiction:
Data processed within AWS data centres, eu-west-2 (London, UK); Customer data accessed only by authorised personnel, no third-party data sharing

[2] Data Centre Security:
HabiTrack relies on AWS data centre security controls:
ISO 27001 certification;
SOC 2 Type II compliance;
Physical access controls, CCTV, 24/7 security personnel;
Environmental controls (fire suppression, climate control, redundant power).

[3] Data Encryption:
AES-256 for data at rest / databases / backups; TLS 1.2+ for data in transit; EBS volume encryption, S3 server-side encryption; server-side encryption with AWS-managed keys

[4] Data Sanitisation / Equipment Disposal:
When customer environments decommissioned, all associated data is deleted from databases/backups after retention period; AWS handles secure sanitisation/destruction of physical storage media in accordance with NIST 800-88 guidelines

[5] Physical Resilience / Availability
Multiple application replicas managed by Kubernetes with automatic failover; Rolling updates ensuring continuous availability during deployments; Automated health monitoring with automatic container restart on failure; Infrastructure as Code enabling rapid recovery and reproducible deployments; Database backups stored in AWS S3 with versioning enabled; Point-in-time recovery capability from versioned backups; Backups stored separately from production infrastructure; Immutable infrastructure pattern (compromised systems replaced, not repaired).

Detailed documentation available under NDA.
Outage reporting
Service outages are reported through multiple channels. A public status page is provided at status.habitrack.fabricshift.com, which displays current service status and incident updates. Email notifications are used to proactively communicate service disruptions to customers. Planned maintenance is communicated via email with at least 48 hours' advance notice.

Identity and authentication

User authentication needed
Yes
User authentication
Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted on a least-privilege basis and limited to authorised personnel. Administrative access to HabiTrack platform and supporting services is restricted to designated staff with defined roles, formally approved and recorded in access register. Separate standard and administrative accounts used, production access is further restricted. Support channels are limited to controlled, email-based inboxes accessible to authorised personnel. Any system access required for support is approved, logged, and restricted to the minimum required. Access rights are reviewed periodically and removed promptly when no longer required, in line with FabricShift's ISO 27001-certified ISMS.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
FabricShift operates an ISO 27001 certified Information Security Management System, supported by documented information security policies and procedures covering access control, risk management, incident management, supplier management, asset management, and business continuity. Information security governance sits with a named senior leader with organisational authority, with day-to-day technical controls implemented by the engineering function. Security risks are assessed through a formal risk register and reviewed regularly. Compliance with information security policies is ensured through role-based access controls, change management processes, regular security reviews, staff onboarding and awareness activities, and internal audits. Incidents are reported and managed through a defined incident response process, with escalation to senior leadership where required.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Version control achieved using Git (all configuration stored in repositories); Continuous Deployment via FluxCD (automated deployments triggered by Git commits); CI/CD Pipeline via GitHub Actions (automated testing and image building); Change Tracking via Git History (full audit trail of all changes); Peer Review via Pull Requests (all changes require peer review and approval); Automated Security Review via GitHub Actions (security scanning in pipeline; failing tests block merge).

Changes follow controlled path to production: Development (requires automated tests pass, peer review approved) to Staging/QA (requires QA sign-off, business stakeholder review) to Production (requires formal agreement from both technical and business teams).
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerability management is based on automated dependency monitoring and defined patching timelines. Application and infrastructure dependencies are continuously monitored for known vulnerabilities using automated scanning, with alerts raised when issues identified (GitHub Dependabot). Sources include GitHub Security Advisories, AWS Security Bulletins, National Vulnerability Database.

Patching is prioritised according to severity. Critical vulnerabilities are addressed within 48 hours, high-severity vulnerabilities within 7 days, and medium/low-severity vulnerabilities addressed as part of the next scheduled release.

Container security is maintained by updating base images and application dependencies on each build within the CI/CD pipeline, using minimal base images to reduce the attack surface.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Potential compromises identified through monitoring application logs (SigNoz) for anomalous access patterns, authentication failures, unexpected errors; infrastructure-level monitoring (AWS CloudWatch) for unusual resource consumption or network behaviour. Application dependencies, container images monitored through automated scanning during build/deployment (GitHub Dependabot, CI/CD Pipeline).

When potential compromise identified: automated alerts notify on-call engineer; initial triage assesses severity/scope; affected services isolated if necessary (namespace isolation, network policies); log analysis determines root cause and impact; Patching, credential rotation, or infrastructure rebuild as required; Customer notification if required

Response times severity-based. Critical incidents (data breach, service outage): within 15mins with immediate escalation. High-severity: <1h. Medium/low-severity: <24h.
Incident management type
Supplier-defined controls
Incident management approach
FabricShift operates documented, pre-defined incident management processes covering common security events such as unauthorised access, data loss, or service disruption. These processes form part of the organisation's ISO 27001 Information Security Management System. Users can report incidents through agreed support channels, including email or ticketed support, which are monitored by authorised personnel. Internally identified incidents are logged and assessed in line with defined escalation procedures. Where appropriate, incident updates and reports are provided to affected customers, including details of the nature of the incident, actions taken, and any required follow-up, in line with contractual and regulatory obligations.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Alcumus ISOQAR
ISO 9001 accreditation date
Thursday 7 December 2023
What the ISO 9001 doesn’t cover
The current ISO 9001 certification covers FabricShift's consultancy and service delivery activities, including design, delivery management, strategy support and operational reviews delivered from a virtual office environment. It does not yet include the standalone operation of the HabiTrack SaaS platform as a distinct software product. Quality processes used for HabiTrack are aligned with the existing ISO 9001 quality management system.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
2bb276e5-3065-4762-8843-4124b710db25
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
4a33ca8d-30e9-457a-9547-2970b7dbbd5f
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@fabricshift.com. Tell them what format you need. It will help if you say what assistive technology you use.