Opigno Learning Management System (LMS)
ISO 9001/27001-certified Drupal-powered Opigno LMS SaaS for delivering structured digital learning and training. Opencentric’s GDPR-compliant platform implements the Opigno distribution to support courses, assessments, certifications and learning paths. Delivered as a fully managed, accessible SaaS, it enables scalable and user-centred learning services.
Features
- Opigno learning management system delivered as SaaS
- Course, module and learning path management
- Assessments, quizzes and certification workflows
- Role-based access for learners, tutors and administrators
- Browser-based course authoring and administration
- Progress tracking and learner reporting dashboards
- Gamification features including badges and achievements
- Integration with identity and external learning systems
- GDPR-compliant handling of learner data
- Secure, fully managed UK-based Opigno LMS SaaS platform
Benefits
- Enables structured and engaging digital learning programmes
- Supports certifications, compliance and skills development
- Proven Opigno distribution built on open-source Drupal
- Flexible configuration for varied training requirements
- UK-based agency with directly employed Opigno & Drupal delivery team
- Proven experience delivering education and training platforms
- Integrates with existing organisational systems
- Actively maintained platform with clear upgrade paths
- Accessible design improves learner inclusion and outcomes
- Excellent long-term value for public-sector organisations
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 0 7 5 8 0 0 8 0 5 8 1 4 4 9
Contact
OPENCENTRIC LIMITED
William Velasco
Telephone: 029 2000 4547
Email: info@opencentric.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Education
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service operates without buyer-specific hardware or infrastructure constraints. For onboarding or supporting third-party Drupal implementations, an initial audit is required to confirm security, compliance, accessibility and technical compatibility. This protects service integrity and users. Planned maintenance is scheduled, communicated in advance and designed to minimise disruption.
- System requirements
- None
User support
- Email or online ticketing support
- Yes
- Support response times
-
Response times are agreed as part of an SLA.
Typical response times are:
Priority 1 - 1 hour
Priority 2 - 2 hours
Priority 3 - 4 hours
Priority 4 - 8 hours - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Our open source web chat technology meets WCAG 2.2 AA accessibility guidelines, and the code has been written so that the chat box is navigable by keyboard using screen reader software, which has undergone community testing by the Drupal project.
- Onsite support
- Yes, at extra cost
- Support levels
-
In addition to our fully managed hosting platform, we offer two support options. Your Opencentric project manager will be your single point of contact throughout your support contract.
• Standard Support - Work is billed to the nearest 30 minutes and charged at our standard rates with no surcharges - £700 a day. Support will be provided during office hours, Monday to Friday, 9.00 to 5.30pm. For additional cover, see our 24/7/365 support offering below.
Support time is flexible and can be used for support or ad-hoc development requests.
• 24/7/365 Support - for clients who demand the highest level of service. This is available 24 hours a day, 7 days a week, 365 days a year, and is an add-on to our Standard Support above. This level of support costs an additional £850 a month.
In the unlikely event your website or application becomes completely unavailable, our support team will be notified and will take immediate action, 24/7, to identify and resolve the issue, regardless of support level. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
We provide onsite training, user documentation and telephone support for client onboarding.
For complex onboarding, we also offer a paid bespoke service where we will perform the onboarding for you. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- We will provide full access to the CMS or application software code. We will also provide full access to the database and files on your server environment. We can also help with extracting this for you if required.
- End-of-contract process
-
We will provide full access to the CMS or application software code. We will also provide full access to the database and files on your server environment. We can also help with extracting this for you if required.
This is all included as standard within the price of the contract. Additional support would be chargeable. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- A fully responsive mobile version is available for administration of the service with no limited features.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Full site administration is provided, including the ability to: - Create, clone, and migrate Drupal instances. - Verity sites. - Reset passwords. - Run scheduled tasks. - Create and restore backups on demand. - Disable or delete a site. - Run database updates. These options may be limited by role.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Our open-source web technology meets WCAG 2.2 AA accessibility guidelines, and the code has been written so that the service interface is navigable by keyboard using screen reader software, which has undergone community testing by the Drupal project.
- API
- Yes
- What users can and can't do using the API
-
Drupal offers many open-source, off-the-shelf, configurable APIs.
These include APIs for Authentication, Cache, Configuration, Database, Entity, Filter, Form, JavaScript, Layout, Logging, Menu, Migrate, REST, Render, Routing, Services, State, Translation and Update management.
Full details can be found at: https://www.drupal.org/docs/develop/drupal-apis
These APIs enable buyers to integrate the service with identity providers, analytics platforms, CRMs and other line-of-business systems without custom development. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- ODF
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
You can pick and choose from a wide range of contributed modules to add functionality to your site, and from a wide range of contributed themes to change your site's appearance. These add-on modules and themes are also known as 'contrib', because they were contributed by members of our Drupal community, and are available on Drupal.org free of charge.
The service provides a selection of development and delivery options, each of which can be tailored to suit the buyer's requirements.
Scaling
- Independence of resources
- Service capacity is managed at the platform level to ensure tenant isolation and consistent performance. Workloads are logically separated, and resource usage is continuously monitored to prevent one tenant’s demand from affecting others. The platform automatically allocates additional capacity during short-term demand peaks and enforces limits where necessary to maintain service stability. Capacity thresholds and scaling behaviour are proactively managed to ensure predictable performance for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide you with full transparent access to all project data and service reports. These are accessible in real time, and automatically sent on at regular intervals (Typically monthly)
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
A number of options are available depending on the nature of the site:
A) User dashboard - self-download.
B) Admin user - download and send.
C) Developer - pull from the database and send. - Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- SQL
- Excel
- JSON
- XML
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- JSON
- XML
- SQL
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- SSH/SFTP
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- SSH/SFTP
Availability and resilience
- Guaranteed availability
-
99.95% for Standard Hosting
100% for High Availability Hosting
On a case-by-case basis, we offer service credits, which are discussed during the contract process. - Approach to resilience
-
The service is designed for resilience through layered monitoring, redundancy and automated recovery across the application and platform stack.
Service availability is continuously monitored using externally accessible HTTPS health checks against uncached endpoints to verify application, web, database and integration responsiveness. Monitoring operates continuously, including during planned maintenance, ensuring that reported availability reflects real service performance rather than paused checks.
The underlying platform is hosted in UK data centres designed for high availability, incorporating resilient power, cooling and network connectivity with multiple independent paths and automatic traffic failover. Full details of the datacentre architecture are available on request.
Automated self-healing processes operate at platform level to detect and recover from service degradation. Where a component becomes unresponsive, it is automatically restarted or recovered before user impact occurs. Events are logged and reviewed to support root-cause analysis and continuous improvement.
Business continuity and resilience controls are aligned with recognised standards, including ISO 27001 and ISO 22301, ensuring appropriate governance, testing and incident response processes are in place.
This approach delivers consistent service availability, operational continuity and rapid recovery from failures, supporting an achieved availability of 99.99% or higher. - Outage reporting
-
Incidents (high error rates, unusual resource usage, etc.) and outages (service failures, websites unavailable, etc.) are reported directly to responsible parties via e-mail and/or text messages, as well as to our internal monitoring system, where teams can coordinate to resolve issues.
An API and public or private dashboard is also available upon request.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
A current username and password, along with 2FA, are required to access our hosting systems.
Administrative connections may only be made over secured SSH or TLS channels.
It is impossible to have permanent access to your data (databases) - only temporary connections may be made while a concurrent and authorised SSH connection is open from the same IP address.
Access to filesystems is restricted via temporarily authorised and tracked SSH keys.
A password strength and rotation policy is in place and enforced. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- As part of our annual, audited ISO 9001 and 27001 systems, we have defined roles and responsibilities for information security, with overall responsibility being held by an Opencentric Ltd. Director.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We follow a robust change management process, which is audited annually under our ISO 9001 certification.
Changes are assessed for their impact and risk, and a process of continual identification, monitoring and review of the levels of IT services specified in the SLA ensures that quality is maintained.
All changes are implemented through a version-controlled configuration management system and progress through a series of automated and manual testing steps before being applied to the 'live' infrastructure.
This systematic and comprehensive approach ensures that changes to services are reviewed, tested, approved and communicated. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We follow the NIST Common Misuse Scoring System (NISTIR 7864). Each potential vulnerability is scored by the Drupal Security Team using this system.
The hosting platform (operating system, software, and applications) receives automated security patching for all software directly from the OS maintainers, with security patches applied as soon as they are available and have been tested on pre-production environments.
Alerts and newsletters are available from the maintainers, and technical staff monitor a number of respected advisory services for news.
Our Content Delivery Network includes a Web Application Firewall that is constantly updated to defend against newly released exploits. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Active web server monitoring will block the access first temporarily for one hour and permanently after many temporary blocks for any IP which is a source of DoS-like activity — too many connections in a very short timeframe.
Strict firewall monitoring automatically denies access temporarily for one hour if it detects too many failed login attempts for SSH, SFTP or FTPS, detects a port scan or other exploits.
The Web Application Firewall will similarly deny access to known exploits.
Staff are automatically notified during any potential compromise and will take immediate action at the infrastructure or application layer - Incident management type
- Supplier-defined controls
- Incident management approach
- Policies exist within our SLAs that describe our response process for common events, with coordination and escalation available for non-standard incidents. Users report incidents through our service desk via ticket, web chat, email or telephone, and are kept updated with the progress and state of the incident throughout the event via the ticketing system. Full incident reports are provided in the event of serious incidents (for example, extended outages or security events).
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Peers Quality Assurance Limited
- ISO/IEC 27001 accreditation date
- Monday 31 May 2021
- What the ISO/IEC 27001 doesn’t cover
- The certification covers the information security management system for the provision of secure online platform design and development services. It does not extend to customer-managed environments or third-party infrastructure operated entirely outside Opencentric’s control.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- QAS International
- ISO 9001 accreditation date
- Thursday 22 August 2013
- What the ISO 9001 doesn’t cover
- The ISO 9001 certification covers the organisation’s quality management system for the design, development, delivery and support of websites and enterprise digital systems. It does not extend to activities carried out entirely outside Opencentric’s control, such as customer-managed systems or third-party services not contracted or governed by our quality management processes.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 987ac584-52b7-4dca-b1c4-9fbae7c59511
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Ad92f07e-ab71-45a5-bc40-1c15ea6624a8
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-