Skip to main content

Help us improve the Digital Marketplace - send your feedback

QAPLUS LIMITED

QA360 Configurable Case and Workflow Management Platform

QA360 is a secure, cloud-based case and workflow management platform configurable for multiple industries. It supports structured assessments, workflows, document management and reporting, with assistive, (AI), features that improve efficiency while ensuring all decisions remain fully user-controlled and auditable.

Features

  • Assistive assessment support (AI-enabled): Supports assessments, fully user controlled
  • Configurable case management: End-to-end record lifecycle tracking
  • Structured workflows: Guides tasks, approvals and handoffs
  • Secure document management: Linked content and records
  • Role-based access control: Supports least-privilege acces
  • Audit and traceability: Full activity logging and oversight
  • Customisable dashboards: Operational visibility and metrics
  • Reporting and analytics: Performance and workload insights
  • Mobile access: Supports work across devices
  • Modular configuration: Adaptable to different industries

Benefits

  • Improved efficiency: Reduces administrative burden
  • Consistent processes: Supports standardised operations
  • Better oversight: Improves accountability and transparency
  • User-controlled decisions: Maintains professional judgement
  • Strong security: Protects sensitive data
  • Flexible deployment: Adapts to organisational needs
  • Reduced duplication: Minimises repeated data entry
  • Improved compliance: Supports audits and reviews
  • Faster outcomes: Streamlines case resolution
  • Scalable platform: Grows with demand

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@qaplus.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 0 6 1 0 9 7 2 4 5 8 9 3 5 7

Contact

QAPLUS LIMITED Sion Davis
Telephone: 01633876142
Email: info@qaplus.co.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
  • Education
  • Adult Social Care
  • Children's Social Care
  • Other
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
QA360 optimally functions with modern browsers for enhanced system capabilities. Mandatory updates occur every twelve weeks, with interim patches applied as necessary. Advance notifications for updates are communicated with comprehensive Release Notes via the helpdesk support team, ensuring seamless system performance and security
System requirements
None as this is a cloud based solution

User support

Email or online ticketing support
Yes
Support response times
QAPlus provides responsive helpdesk support, with all queries acknowledged and investigation initiated within four working hours during standard helpdesk hours (9:00am to 5:30pm, Monday to Friday, excluding public and statutory holidays), in accordance with our Service Level Agreement.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Unlimited Helpdesk Support is available for trained users of the solutions, for how to use queries. This is included within the investment for the licence. Helpdesk calls are triaged depending on agreed urgency and severity to H1 requiring conclusion within 4 hours, H2 within a week and H3 within a month.

Each client is allocated a Client Service Manager who will meet quarterly as a minimum standard. Should it be more frequent meet ups are required this will be charged as per the pricing document.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
QA360 provides a structured and fully managed onboarding experience designed to support successful implementation of the platform across a wide range of organisational contexts. Our approach is collaborative and tailored to ensure the solution is configured to meet agreed operational requirements and objectives.

During onboarding, an experienced project manager works closely with customer stakeholders to develop a detailed implementation plan. This plan defines key activities, milestones, responsibilities, and dependencies, supporting a controlled transition to live operation. Configuration activities may include workflows, assessments, roles, permissions, and reporting, aligned to agreed processes and governance arrangements.

QA360’s onboarding approach is designed to minimise risk, support user readiness, and ensure the platform is adopted effectively from day one. Training and knowledge transfer are incorporated as required to enable confident use of the service.

Offboarding is managed in a structured manner, supporting data extraction and service exit in line with contractual and data protection requirements. This ensures continuity, transparency, and a smooth transition at the end of the service lifecycle.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
QA360 assures collaboration to extract and export your data into a usable format. Additional costs, based on data size and scope, will be calculated and communicated upfront, ensuring transparency and informed decision-making regarding any incurred expenses.
End-of-contract process
QA360 acknowledges that the end-of-contract process is tailored to each client, considering factors like retention periods and data format preferences. While typically not chargeable, any additional work may incur fees, which will be assessed once all requirements are known. Please refer to the terms and conditions for detailed information regarding end-of-contract procedures and associated charges.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and offboarding documentation is provided in PDF format and is written in clear, plain English to support ease of understanding for a wide range of users. The documentation is structured with logical headings, consistent formatting, and step-by-step guidance to aid navigation and comprehension.

Where required, documentation can be shared electronically to enable the use of assistive technologies such as screen readers, zoom tools, and text reflow features supported by standard PDF readers. Customers may also request alternative versions or additional support during onboarding and offboarding to ensure information is accessible to their users.

In addition to written documentation, onboarding and offboarding activities are supported by direct engagement from the QA Plus team, allowing users to ask questions and receive clarification where needed. This approach helps ensure that all users can effectively access and understand the information provided, regardless of individual accessibility needs.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is accessed via a responsive web interface. Selected modules and features are optimised for use on mobile devices to support users working remotely or in the field, while full functionality is available via desktop browsers.
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
There not any current open source APIs. New APIs can be developed on a case-by-case basis, tailored to specific requirements, and provided as a chargeable service.
API documentation
No
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
QA360 is supported by a comprehensive suite of professional services designed to enable configuration and adaptation of the platform to meet a wide range of organisational and operational requirements across different sectors.

Customisation can be undertaken during implementation and throughout the lifecycle of the service, allowing the solution to evolve as needs change.

During implementation, customers work collaboratively with QA360 to define project plans, configure workflows, assessments, forms, roles, permissions, and reporting structures. This approach ensures the platform is aligned to organisational processes, governance requirements, and operational objectives.

QA360 also offers a range of optional, chargeable services to support extended use of the platform. These may include project and programme support, user training, integration design, configuration changes, and bespoke development where required.

Customisation activities are delivered in a controlled manner to maintain service stability, security, and supportability. Full details of available services, pricing, and delivery options are provided in the QA360 pricing documentation.

Scaling

Independence of resources
QA360 is delivered using dedicated virtual environments per client, ensuring that one customer’s usage does not impact the performance experienced by others. The service is designed with security, scalability, and resilience in mind, with capacity to accommodate increases in user numbers and web traffic.

The platform uses auto-scaling and high-availability capabilities to dynamically adjust resources in response to demand. Resource utilisation is monitored daily, and the service is continuously monitored 24x7x365 by a dedicated team, enabling proactive management and rapid resolution of any performance or capacity issues to ensure consistent service levels for all users.

Analytics

Service usage metrics
Yes
Metrics types
QA360 provides monthly and quarterly service metrics aligned to agreed success measures. These reports support service review and help customers understand how the solution is performing against agreed objectives.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
QA360 provides a range of standard reports to meet most user needs, with additional reports available upon request (which may incur charges). Users can export data from all list pages using export-to-Excel functionality, and SQL-based reports can be exported in Excel, CSV, or PDF formats.

In addition, at the end of the contract or upon request, QA Plus supports the secure export of customer data in commonly used electronic formats to support data portability and transition to alternative systems, in line with agreed exit arrangements.
Data export formats
  • CSV
  • ODF
Data import formats
  • CSV
  • ODF

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
QA360 is designed for high availability and provides 99% uptime during business hours, excluding pre-planned and emergency maintenance. Planned maintenance is communicated in advance and scheduled outside business hours wherever possible to minimise disruption.
Approach to resilience
QA360 is designed with resilience and availability as core principles. The service is hosted on resilient cloud infrastructure and uses load balancing and redundancy to minimise single points of failure and maintain service availability in the event of component failure.

The platform is deployed across multiple backend components and supports automatic scaling to manage demand and maintain performance. All releases are subject to controlled deployment processes and thorough testing prior to production to ensure stability and reliability.

Data is hosted in UK-based datacentres that meet recognised industry standards for resilience and physical security. Regular backups are performed and stored securely to support data recovery and service restoration if required.

Further details of the infrastructure design and datacentre arrangements are available on request.
Outage reporting
System outage will be reported to the technical director at QA360.

This will then be communicated to clients via the QA360 support portal.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted to authorised personnel only. User authentication is required using unique usernames and passwords, with 2-factor authentication applied to administrative and support access where appropriate. Access is role-based and limited to the minimum required to perform assigned duties. Administrative and support access is monitored and reviewed regularly, and access is removed promptly when no longer required.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
IG Toolkit
Information security policies and processes
The information security policies for QA360 are available on request.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
QA Plus operates defined configuration and change management processes to support secure and stable service delivery. Service components are tracked throughout their lifecycle using controlled versioning and configuration records from development through to live operation. All changes are subject to formal change control and assessed for risk and potential security impact prior to approval. Changes are tested in non-production environments before deployment, and access to make changes is restricted to authorised personnel only, with all changes logged for audit purposes.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
QA Plus operates a defined vulnerability management process to identify, assess, and remediate potential security threats. Potential vulnerabilities are assessed based on risk, impact, and exploitability, with priority given to issues affecting data security or service availability. Security patches and updates are deployed in a timely manner following testing, with critical patches applied as a priority. Information about potential threats is obtained from cloud platform providers, software vendors, security advisories, and ongoing operational monitoring, supporting proactive management of vulnerabilities.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
QA Plus operates defined protective monitoring processes to identify and respond to potential security incidents. System activity and service performance are continuously monitored to detect unusual behaviour or indicators of compromise. Alerts are investigated promptly by authorised personnel, and appropriate containment and remediation actions are taken where required.

Incidents are handled in line with internal incident management procedures, with priority given to issues affecting data security or service availability. Response times are based on the severity of the incident, with critical issues investigated immediately during support hours and escalated as necessary.
Incident management type
Supplier-defined controls
Incident management approach
QA Plus operates defined incident management processes for handling common incident types, including service availability and security-related events. Users report incidents via the QA Plus helpdesk during standard support hours, where incidents are logged, prioritised, and managed to resolution. Customers are kept informed as appropriate, and incident reports can be provided following resolution, particularly where incidents impact service availability or data security.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
20%
Between £250,000 and £500,000
40%
Between £500,001 and £1,000,000
50%
Between £1,000,001 and £2,500,000
60%
Between £2,500,001 and £5,000,000
65%
Over £5,000,001
65%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation
ISO 9001 accreditation date
Thursday 18 December 2025
What the ISO 9001 doesn’t cover
The ISO 9001 certification covers our quality management system and related business processes. It does not certify specific products, individual customer implementations, or guarantee the performance or availability of the service itself.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
C7e476c2-1312-42ae-9fae-de961c890cdd
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
3c53c59c-521e-472b-be08-f8506111bf7c
Other security certifications
Yes
Any other security certifications
NHS Data Security and Protection Toolkit

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@qaplus.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.