HabiTrack
HabiTrack is a cloud-based software service that helps organisations embed and measure behaviour change. It enables organisations to define habits that work towards organisational goals, track participation and progress over time, and understand adoption and engagement across individuals, teams and the organisation.
Features
- Configurable habits linked to behaviour and learning programmes
- Linking habits to organisational goals and KPIs
- User and cohort-based habit tracking
- Realtime reporting: dashboards showing engagement, adoption and progress over time
- Role-based access controls for organisations, programmes, and users
- Cloud-hosted service accessible via web browser
- Microsoft Teams integration for user access and notifications
- Programme-level configuration and management tools
Benefits
- Embed behaviour change across programmes and teams
- Embed learning through small, repeatable habit-based actions
- Measure behaviour adoption alongside organisational goals and KPIs
- Track participation and progress without manual reporting overhead
- Gain real-time visibility of engagement across individuals and teams
- Manage programmes centrally with clear governance and access controls
- Enable user participation through familiar web and Teams interfaces
- Reduce reliance on surveys for ongoing behaviour monitoring
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 9 1 2 7 7 9 5 2 6 9 3 4 6 9
Contact
FabricShift Limited
Johanna Beresford
Telephone: +44 0203 150 0000
Email: info@fabricshift.com
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- HabiTrack is a standalone cloud-based SaaS platform. It optionally integrates with corporate collaboration platforms such as Microsoft Teams and Slack to allow users to interact with the service within tools they already use. All core functionality is available via the web application and does not require these integrations.
- Cloud deployment model
- Public cloud
- Service constraints
- HabiTrack is delivered as a centrally hosted, cloud-based SaaS service. The service is accessed via a supported web browser and requires internet connectivity. Planned maintenance and updates are managed by FabricShift in line with standard SaaS practices, with advance notice provided where reasonably possible. The service is not provided as a customer-hosted or self-managed deployment.
- System requirements
-
- Modern web browser supporting current HTML and JavaScript standards
- Internet connection for accessing the cloud-hosted service
- User authentication via SSO using the buying organisation's identity provider
- OPTIONAL: Microsoft Teams licence for Teams-based access
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support queries are typically acknowledged within 1 business day. Standard support is provided during UK business hours (Monday to Friday). Weekend support is limited, with responses provided on the next business day.
Support requests are acknowledged during UK business hours (Monday to Friday) and prioritised by severity. Critical issues (service unavailable): within 4 business hours. High priority issues (significant functionality impaired): within 8 business hours. Normal queries: within 2 business days.
Weekend support is limited, with responses provided on the next business day. - User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
- FabricShift provides a standard support level for HabiTrack, included within the service price. Support is provided via email or online ticketing during UK business hours, with queries prioritised based on severity and service impact. Customers are assigned a named account manager who acts as the primary point of contact for relationship management, onboarding coordination, and service queries. This role is not a dedicated technical support or cloud engineering function. At present, we do not offer tiered support levels or a dedicated technical account manager or cloud support engineer.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Buyers are supported through a structured onboarding process. This includes guidance and documentation to support initial setup, such as configuring programmes, defining habits, and assigning users / teams. Where applicable, organisational goals and KPIs will also be configured within the service. Implementation is supported remotely, working with buyer stakeholders to ensure the service is configured appropriately for their organisation. End users are onboarded through an invite-based process. Users receive a secure link to access the service, where they are guided through an introductory experience explaining how to use the platform and participate in assigned programmes. Supporting user guidance is provided within the service and through onboarding materials.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At the end of the contract, buyers can request the extraction of their data from the service. Data is provided in commonly used, machine-readable formats suitable for reuse or import into other systems. Data extraction is supported as part of the offboarding process, with arrangements agreed to ensure secure transfer of data. Access to the service is then withdrawn in line with contract terms. Any remaining data held by the supplier is handled in accordance with agreed data retention and deletion policies.
- End-of-contract process
- At the end of the contract, access to the service is withdrawn in line with agreed notice periods. Buyers are supported through an offboarding process, including the extraction of their data where requested. Standard offboarding activities, including account closure and data export in an agreed format, are included within the contract price. Any additional services beyond standard offboarding, such as extended access periods, bespoke data transformations, or additional support requirements, may be provided at additional cost by agreement.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile and desktop services provide the same functionality. The mobile experience uses a responsive layout optimised for smaller screens, which may differ in presentation and navigation.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure web-based user interface and collaboration platform interfaces, allowing users to interact with the service without local installation. The interface provides a home view displaying assigned habits, with additional navigation to features such as insights and programme information. Where enabled, organisational goals and KPIs can also be viewed. The layout uses clear navigation and card-based components to support ease of use.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service has been tested using common accessibility tools and techniques during development, including keyboard-only navigation, screen reader checks, and colour contrast review. The interface is built using accessible UI components designed to work with assistive technologies such as screen readers and keyboard navigation. Accessibility considerations are incorporated into ongoing development and testing processes, and feedback from users is used to identify and address usability or accessibility issues as the service evolves. Where accessibility issues are identified, they are addressed in line with WCAG 2.2 AA guidance.
- API
- Yes
- What users can and can't do using the API
- API access is provided to support agreed integration and data exchange use cases, rather than end-user interaction with the service. The API can be used to support activities such as syncing user and organisational data from external systems, managing user status updates (e.g., joiners, leavers, work hours), and exchanging programme-related data or metrics with other systems, such as HR, learning, or management information platforms. Where enabled, the API may also be used to ingest or extract organisational KPI or performance data for reporting purposes. Core service setup and management (including programme creation and habit definition) is performed through the service's user interface and is not exposed for full self-service configuration via the API. API access is subject to appropriate authentication, authorisation, and security controls, and is enabled on a per-customer basis for defined integration use cases.
- API documentation
- No
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Buyers can configure the service to suit their needs by defining their own programmes and habits, managing users and cohorts, and setting initiative parameters through the platform. For Enterprise implementations, organisational goals and KPIs can also be configured and linked to programmes. Configuration is performed through the service interface and, where required, supported through implementation services. The service can only be customised by approved users with appropriate administrative permissions - standard users can interact with assigned programmes and habits but cannot modify configuration.
Scaling
- Independence of resources
-
HabiTrack operates a multi-tenant architecture designed to manage demand across customers and reduce risk of resource contention. Under standard multi-tenant model, customers receive: Application-Level Isolation (tenant data logically separated within shared database with strict access controls), Defined Resource Limits (CPU and memory limits configured per deployment, preventing resource contention), Row-Level Security (database queries scoped to authenticated tenant), and Auto-Scaling (deployments automatically scale with additional pods based on resource consumption).
For customers requiring enhanced isolation, HabiTrack offers dedicated Kubernetes namespaces: Full Namespace Isolation, Dedicated Database, Dedicated Resource Allocation, Independent Deployments, Auto-Scaling
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The service provides usage and engagement metrics to help organisations understand adoption and progress. Metrics include habit tracking activity, engagement levels, and programme-level summaries across teams and cohorts. Where enabled, metrics can also include progress against organisational goals and KPIs.
Metrics can be viewed over time and at organisational and programme level to support monitoring of behaviour change and engagement. - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Authorised users for the buying organisation can request the export of their data during the contract or as part of the offboarding process. Data exports are provided securely by the supplier in commonly used, machine-readable formats suitable for analysis or import into other systems.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- HabiTrack is provided with a target monthly availability of 99.5%, measured on a monthly basis using platform monitoring data. Availability is calculated as the percentage of time the service is operational during the measurement period. Where availability targets are not met, service credits may be applied in accordance with the terms set out in the service agreement. No additional financial compensation is provided beyond agreed service credits.
- Approach to resilience
-
[1] Physical Location / Legal Jurisdiction:
Data processed within AWS data centres, eu-west-2 (London, UK); Customer data accessed only by authorised personnel, no third-party data sharing
[2] Data Centre Security:
HabiTrack relies on AWS data centre security controls:
ISO 27001 certification;
SOC 2 Type II compliance;
Physical access controls, CCTV, 24/7 security personnel;
Environmental controls (fire suppression, climate control, redundant power).
[3] Data Encryption:
AES-256 for data at rest / databases / backups; TLS 1.2+ for data in transit; EBS volume encryption, S3 server-side encryption; server-side encryption with AWS-managed keys
[4] Data Sanitisation / Equipment Disposal:
When customer environments decommissioned, all associated data is deleted from databases/backups after retention period; AWS handles secure sanitisation/destruction of physical storage media in accordance with NIST 800-88 guidelines
[5] Physical Resilience / Availability
Multiple application replicas managed by Kubernetes with automatic failover; Rolling updates ensuring continuous availability during deployments; Automated health monitoring with automatic container restart on failure; Infrastructure as Code enabling rapid recovery and reproducible deployments; Database backups stored in AWS S3 with versioning enabled; Point-in-time recovery capability from versioned backups; Backups stored separately from production infrastructure; Immutable infrastructure pattern (compromised systems replaced, not repaired).
Detailed documentation available under NDA. - Outage reporting
- Service outages are reported through multiple channels. A public status page is provided at status.habitrack.fabricshift.com, which displays current service status and incident updates. Email notifications are used to proactively communicate service disruptions to customers. Planned maintenance is communicated via email with at least 48 hours' advance notice.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted on a least-privilege basis and limited to authorised personnel. Administrative access to HabiTrack platform and supporting services is restricted to designated staff with defined roles, formally approved and recorded in access register. Separate standard and administrative accounts used, production access is further restricted. Support channels are limited to controlled, email-based inboxes accessible to authorised personnel. Any system access required for support is approved, logged, and restricted to the minimum required. Access rights are reviewed periodically and removed promptly when no longer required, in line with FabricShift's ISO 27001-certified ISMS.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
- FabricShift operates an ISO 27001 certified Information Security Management System, supported by documented information security policies and procedures covering access control, risk management, incident management, supplier management, asset management, and business continuity. Information security governance sits with a named senior leader with organisational authority, with day-to-day technical controls implemented by the engineering function. Security risks are assessed through a formal risk register and reviewed regularly. Compliance with information security policies is ensured through role-based access controls, change management processes, regular security reviews, staff onboarding and awareness activities, and internal audits. Incidents are reported and managed through a defined incident response process, with escalation to senior leadership where required.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Version control achieved using Git (all configuration stored in repositories); Continuous Deployment via FluxCD (automated deployments triggered by Git commits); CI/CD Pipeline via GitHub Actions (automated testing and image building); Change Tracking via Git History (full audit trail of all changes); Peer Review via Pull Requests (all changes require peer review and approval); Automated Security Review via GitHub Actions (security scanning in pipeline; failing tests block merge).
Changes follow controlled path to production: Development (requires automated tests pass, peer review approved) to Staging/QA (requires QA sign-off, business stakeholder review) to Production (requires formal agreement from both technical and business teams). - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Vulnerability management is based on automated dependency monitoring and defined patching timelines. Application and infrastructure dependencies are continuously monitored for known vulnerabilities using automated scanning, with alerts raised when issues identified (GitHub Dependabot). Sources include GitHub Security Advisories, AWS Security Bulletins, National Vulnerability Database.
Patching is prioritised according to severity. Critical vulnerabilities are addressed within 48 hours, high-severity vulnerabilities within 7 days, and medium/low-severity vulnerabilities addressed as part of the next scheduled release.
Container security is maintained by updating base images and application dependencies on each build within the CI/CD pipeline, using minimal base images to reduce the attack surface. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Potential compromises identified through monitoring application logs (SigNoz) for anomalous access patterns, authentication failures, unexpected errors; infrastructure-level monitoring (AWS CloudWatch) for unusual resource consumption or network behaviour. Application dependencies, container images monitored through automated scanning during build/deployment (GitHub Dependabot, CI/CD Pipeline).
When potential compromise identified: automated alerts notify on-call engineer; initial triage assesses severity/scope; affected services isolated if necessary (namespace isolation, network policies); log analysis determines root cause and impact; Patching, credential rotation, or infrastructure rebuild as required; Customer notification if required
Response times severity-based. Critical incidents (data breach, service outage): within 15mins with immediate escalation. High-severity: <1h. Medium/low-severity: <24h. - Incident management type
- Supplier-defined controls
- Incident management approach
- FabricShift operates documented, pre-defined incident management processes covering common security events such as unauthorised access, data loss, or service disruption. These processes form part of the organisation's ISO 27001 Information Security Management System. Users can report incidents through agreed support channels, including email or ticketed support, which are monitored by authorised personnel. Internally identified incidents are logged and assessed in line with defined escalation procedures. Where appropriate, incident updates and reports are provided to affected customers, including details of the nature of the incident, actions taken, and any required follow-up, in line with contractual and regulatory obligations.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Alcumus ISOQAR
- ISO 9001 accreditation date
- Thursday 7 December 2023
- What the ISO 9001 doesn’t cover
- The current ISO 9001 certification covers FabricShift's consultancy and service delivery activities, including design, delivery management, strategy support and operational reviews delivered from a virtual office environment. It does not yet include the standalone operation of the HabiTrack SaaS platform as a distinct software product. Quality processes used for HabiTrack are aligned with the existing ISO 9001 quality management system.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 2bb276e5-3065-4762-8843-4124b710db25
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 4a33ca8d-30e9-457a-9547-2970b7dbbd5f
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-