Alfresco Digital Business Platform
Alfresco Digital Business Platform (DBP) is Hyland's cloud-native, open-source content services platform that includes industry-leading content, process, and governance services. Alfresco DBP enables enterprises to build smart, content-centric business applications that transform their businesses: enhancing customer experiences and improving decision making, while ensuring compliance with regulatory requirements.
Features
- Manages protects and connects your most important information
- Safeguards confidential corporate assets wherever they're accessed or stored
- Federated Service allows access to content across systems from UI
- Unmatched combination of simplicity and control for information governance
- Remote access
- Fast, powerful search including full-text search of metadata
- Analytics components report data to external databases and monitoring systems
- Built on open-source core, supports open standards and open APIs
- Configurable user interfaces enabling employees to easily access relevant content
- Web-enabled; works on smartphones, tablets, or any standards-compliant browser
Benefits
- Digitize and streamline content, governance and processes in one platform
- Collaborate with confidence, whilst maintaining data confidentiality
- Access content without risky, costly and time-consuming bulk migration
- Confidence in your ability to demonstrate continued compliance
- Automatically enrich content and gain valuable insights
- Find the information you need when you need it
- Make better decisions based on real-time data
- Easily integrate with other applications (and content) for efficient working
- Employees view content in way that works best for them
- Supports a mobile workforce, ensuring critical information always at hand
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 1 6 2 3 2 2 4 1 0 6 8 5 6 4
Contact
HYLAND UK OPERATIONS LIMITED
Stacey Chapman
Telephone: +121 639 60261
Email: governmentcontracts@hyland.com
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
- Document
Content services
- Enterprise Content Management Applications
- Content Sharing and Collaboration Applications
Persuasive content management
- Website Software
- Digital Asset Management Applications
- Product Content Management Applications
- Content Marketing Applications
- Video Platforms
- Digital Adoption Platform
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Integrated Employee Workspaces
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
Alfresco Scheduled Maintenance Windows – modification or repairs to shared infrastructure or platform patching and upgrades that Alfresco has provided notice of at least seventy-two (72) hours in advance or that occurs during 6:00 am to 10:00 am on Saturdays Eastern Time Zone.
Scheduled Customer Maintenance – maintenance of customer configuration that customer requests and that Alfresco schedules with customers in advance.
Scheduled Customer Deployments – as with maintenance, these are customer requests that Alfresco schedules with the customer in advance.
Emergency Maintenance – critical unforeseen maintenance needed for the security or performance of customer configuration or Alfresco's network. - System requirements
-
- Red Hat Enterprise Linux; Windows Server 2019
- Amazon; Linux; CentOS; Ubuntu
- MySQL; MS SQL Sever; Oracle; PostgreSQL; MariaDB; Amazon Aurora
- Mozilla Firefox; Microsoft Edge; MS Internet Explorer; Chrome; Safari
User support
- Email or online ticketing support
- Yes
- Support response times
- Hyland does not guarantee response times; however, support issues that materially impact production use of the system are addressed immediately. Hyland endeavors to identify a workaround whenever a permanent solution to a software error cannot be provided within a reasonable timeframe. The Technical Support analyst assigned to a support case is empowered to determine its impact on a customer’s implemented product per defined Severity Levels, and to obtain immediate attention to the issue as required.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Hyland Technical Support offers multiple self-service and assisted support opportunities to assist customers in resolving issues being experienced with their implemented Hyland technology solution.
Hyland technical support is standard with subscription to the Alfresco solution.
Hyland offers different Service Class levels to meet the business continuity requirements of our hosted customers. With these service classes Hyland commits to high service availability\uptime (i.e. 99.5% to 99.9%). Specific financial remedies are associated with each Service Class. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- As part of implementation, Hyland conducts on-site training for your organization's designated system administrators, testers, and trainers, who will then educate the user community. Training covers all basic system functions—such as scanning, storing, retrieving, and printing—as well as your organization’s specific applications and procedures, which may vary by department. Hyland also creates training materials tailored to your configured solution for use by your trainers. After training, the project team provides a period of support, typically remote, as users test and begin using the solution in the live environment. All solution training supplements the courses and certifications available from Hyland Education Services, which are separate from the solution-specific engagement. Hyland offers comprehensive training for end-users, solution architects, developers, business unit owners, and system administrators to ensure they can design, install, use, and maintain the solution. End-user training can be hosted on your internal network, and users also have access to self-paced, web-based courses at https://university.hyland.com/ to build foundational knowledge and comfort with the system.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Alfresco Cloud Off-boarding Assistance
In the event that a customer wishes to cancel the service, Hyland will provide the following off-boarding assistance for 30 days:
While the Alfresco Cloud will go into read only mode, the customer will continue to have access to the data extraction capabilities for 30 days. This allows the customer to extract all content within the Alfresco Cloud.
If the customer provided custom code for Alfresco to deploy, upon the customer's written request, Alfresco will return a copy of that custom code to the customer.
For large content stores, Hyland will work with the customer to find the most cost effective method for retrieving or transferring the data. Additional fees may be required for this assistance and/or to migrate content in bulk.
While the Alfresco Cloud will go into read only mode, the customer will continue to have access to the data extraction capabilities for 30 days. This allows the customer to extract all content within the Alfresco Cloud. - End-of-contract process
-
In the unfortunate event that a customer wishes to cancel the service, Hyland will provide the following off-boarding assistance for 30 days:
While the Alfresco Cloud will go into read only mode, the customer will continue to have access to the data extraction capabilities for 30 days. This allows the customer to extract all content within the Alfresco Cloud.
If the customer provided custom code for Alfresco to deploy, upon the customer's written request, Alfresco will return a copy of that custom code to the customer.
For large content stores, Hyland will work with the customer to find the most cost-effective method for retrieving or transferring the data. Additional fees may be required for this assistance and/or to migrate content in bulk. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile Android and iOS apps support fewer features than full browser access, but the core day to day end user functionality such as adding, searching, viewing documents and approving workflows is available.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
1. Alfresco REST API (v1.0)
Purpose: Complete application interface for accessing all Alfresco Repository features
Endpoint format: https://{your-alfresco-cloud-instance}/alfresco/api/-default-/public/alfresco/versions/1/...
Standard: RESTful API following OpenAPI specification
Documentation: Available through API Explorer at https://api-explorer.alfresco.com/api-explorer
2. CMIS REST API
Purpose: Standards-based content management interface
Benefit: Portability across different ECM vendors
Use case: When vendor-neutral integration is important
3. Process Services REST API
Purpose: Access to Alfresco Process Automation (APA) capabilities
Features: Start processes, complete tasks, manage workflows - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
The Alfresco SaaS service can be accessed via a multi-layered approach, combining broad device compatibility with rigorous digital accessibility standards for users with disabilities. This approach is supported by external accessibility experts and an Accessibility Programme directed by Hyland. Recent updates, including Alfresco 7.4 and subsequent 2026 releases, have focused on achieving WCAG 2.2 AA compliance and creating the most up-to-date Accessibility Compliance Report (ACR) that also comply with Section 508 and European regulations for 2026.
The platform is designed to work with screen readers in multiple combinations and includes features such as keyboard-only navigation for key modules, including: Dashboard, Browse, File Libraries, Move/Copy, and Modal Flows, to name a few. - API
- Yes
- What users can and can't do using the API
- Users can perform a wide range of tasks using the Alfresco APIs, including integrating Alfresco with other systems, automating processes, and extending platform functionality. Common actions include programmatically creating, updating, retrieving, and deleting documents, folders, and metadata; automating workflows; performing advanced searches; integrating with third-party systems; managing users, groups, permissions, and access control lists; building custom applications and dashboards; managing metadata; handling version control; extracting data for reporting and analytics; and transforming content into different formats. There are no restrictions on file types or sizes for uploads or downloads, but client connectivity and network conditions should be considered for large files. However, users cannot perform actions outside the scope of these API capabilities, such as modifying core application source code directly or bypassing established security and access controls.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users can customize Alfresco in several comprehensive ways to tailor the platform to their specific business needs. The primary method is through Low-Code Development using Alfresco Process Automation (APA), which provides a visual, drag-and-drop interface for modeling applications, defining custom content models, creating BPMN 2.0 workflows, designing forms, integrating with external services, building decision tables, adding scripts, and designing custom user interfaces. This approach is accessible to both developers and non-technical users, requires no infrastructure management, and is cloud-native with automatic scaling. Users can also customize the Digital Workspace by creating custom UIs based on the default template, modifying source code with Angular/ADF, and uploading the customized UI back to the platform. Alfresco supports API-based integrations, offering REST API v1.0, CMIS API, and Process Services REST API for workflow automation, allowing users to build custom applications that interact with the content repository, trigger workflows, and integrate with third-party systems. Content-centric application development is supported, enabling users to build business applications with document approval workflows, event-based automation, CRM/ERP integration, and AI-powered features. Additionally, Alfresco provides pre-built integrations with cloud services like DocuSign, Slack, Twilio, Salesforce, and machine learning services for enhanced functionality.
Scaling
- Independence of resources
-
Cloud-Native Dynamic Scaling:
"Cloud-native architecture offers maximum availability and dynamic scaling"
Kubernetes automatically scales resources based on demand
Applications can scale independently without affecting others
Analytics
- Service usage metrics
- Yes
- Metrics types
- Alfresco provides service metrics through its Admin Application Monitoring, which tracks application deployments, user permissions, and application status. The Analytics App offers standard reports on process and task metrics, including process instance counts, usage statistics, duration, completion rates, task counts, SLA reports, and status. Reports can be customized by process definition, date range, task status, and aggregated by hour, day, week, month, or year, with graphical, tabular, and statistical views.
- Reporting types
- API access
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Hyland protects data at rest through multiple layers of security. All data repositories are encrypted using AES-256 encryption with cryptographic keys managed via AWS Key Management Service. Access is restricted through strict role-based access controls, and data resides within isolated Virtual Private Clouds to prevent unauthorized network access. Integrity controls, such as write-once-read-many (WORM) technologies and file share scanning, help maintain data integrity. Data Loss Prevention (DLP) policies and monitoring are enforced to prevent unauthorized movement or leakage. Additionally, AWS data centers provide robust physical security, including controlled access, surveillance, and environmental protections.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export their data using several methods. The primary method is through the REST API, which allows programmatic access to all repository content, including files, folders, metadata, and folder structures, and supports bulk export operations. The CMIS API offers a standards-based approach for content retrieval across different ECM platforms. Users can also export data manually via the Digital Workspace or Share interface, enabling individual or bulk downloads. Additionally, third-party migration tools such as Xillio, migration-center, and Texport support Alfresco exports, providing further options for data migration and export.
- Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
-
- Alfresco accepts virtually ANY file format
- Alfresco philosophy is format-agnostic storage.
- Alfresco supports over 1,400+ different MIME types
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
From 99.0% to 99.9% depending on the Tier Level purchased.
In the event the Monthly Uptime Percentage during any calendar month is less than the applicable Monthly Uptime Percentage, the
customer shall be eligible to receive the applicable credit against Fees, provided Customer submitted a technical support request within twenty-four (24) hours of such Downtime.
If, following delivery of a Failover Notice, the Alfresco Cloud Service is not Restored within the applicable Recovery Time objective , the
customer shall be eligible to receive the applicable credit against Fees, provided the customer submitted a technical support request within twenty-four (24) hours of such Downtime. - Approach to resilience
- The Alfresco Cloud is designed with a comprehensive backup and recovery framework to ensure resilience. It provides fault-tolerance and automated restores in most cases, protecting customer data from accidental loss due to hardware or system failure. Hyland maintains a fault-tolerant system by storing complete system backups for 30 days, which include database snapshots and versioned content store backups replicated to a secondary region for fail-over. Backups are scheduled for all instances, monitored for errors, and restoration procedures are regularly tested through scheduled drills. In the event of a service disruption, Hyland initiates disaster recovery protocols to restore services promptly, potentially phasing restoration to maximize customer benefit. Data not immediately accessible after a disruption is restored from the most recent backup. These measures exclude any exceptions described in the Alfresco Cloud Master Services Agreement.
- Outage reporting
-
1. Email Notifications When a system outage occurs, customers receive email notifications about the incident.
2. Downtime Reports After a downtime event occurs, customers can request a formal report that includes:
Detailed description of the incident
Start and end times
Duration of the incident
Business/functional impact
Description of remediation efforts taken
Outstanding issues or follow-up actions
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
For Alfresco Cloud, the recommended modern approach uses Identity Service with SAML/OAuth 2.0:
Initial Access Request
User navigates to Alfresco Cloud URL (Digital Workspace, Share, or API)
Application detects user is not authenticated
2. Redirect to Identity Service
Alfresco redirects user to Alfresco Identity Service (built on Keycloak)
Identity Service determines which authentication provider to use
3. SAML/OAuth Authentication
For SAML SSO:
Identity Service redirects to configured SAML Identity Provider (IdP)
User is presented with IdP's login screen
User enters credentials (username/password)
If MFA is enabled at IdP level, user completes second factor (authenticator app, SMS, biometric, etc.) - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- Less than 1 month
- How long system logs are stored for
- Less than 1 month
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Alfresco cloud governance framework aligns with internationally recognized standards and best practices. These include ISO/IEC 27001:2022 for information security management, SOC 2 Type II for service organization controls, CSA CCM for cloud security, and NIST SP 800-53 for operational security. Hyland also supports compliance with HIPAA, GDPR, PCI DSS, and FedRAMP equivalency for applicable deployments, ensuring robust governance and regulatory adherence across all hosted environments.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Hyland follows internal change management procedures when changes are initiated by Hyland, or when a customer requests to make a change on their behalf to existing systems, or when new systems are deployed to the Alfresco Cloud. Change requests are submitted via a change management system and are then evaluated by subject matter experts. Upon approval by such subject matter experts, changes are implemented, documented, and tested. In the event an issue occurs with the approved change, rollback procedures, documented as part of the change request, are performed in order to return the system to its original state
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Hyland's vulnerability management process includes application security testing with every product release, guided by a well-trained security team. Security is integrated throughout the product lifecycle, and all Product, Technology, and Hyland Cloud department members undergo security training. Mandatory checks are performed at key development stages. Static source code analysis tools are used in the code build pipeline to identify issues, including those related to the OWASP top 10. Third-party libraries are scanned for known vulnerabilities against the NIST and Synk.io databases. Penetration testing is conducted internally and by external companies before major releases.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- DAST and WebApp PenTest test OWASP top 10 and common web attacks.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Incident response and management policy that covers responding to product security vulnerabilities discovered after release and information security incidents within the Hyland Cloud. Issues are categorized and communicated as outlined in the Alfresco Support Handbook. Security fixes, patches, and updates are implemented as released, following testing and approval for the Hyland Cloud. Hyland welcomes vulnerability reports from customers and external consultants; these can be submitted via email to security@hyland.com and are handled responsibly. Incident response plan includes identifying involved parties, management protocols, reporting requirements, notification and handling procedures, and post-incident reviews. Procedures are tested annually and span multiple organizational levels.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Public Services Network (PSN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- There is no free option
- Link to free trial
- https://www.hyland.com/en/resources/alfresco-trial
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- EY CertifyPoint
- ISO/IEC 27001 accreditation date
- Friday 31 October 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI (British Standards Institution)
- ISO 9001 accreditation date
- Tuesday 25 February 2025
- What the ISO 9001 doesn’t cover
- N/a
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Friday 30 June 2023
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
-
Our CSA STAR Level 1 self‑assessment covers our Hyland‑managed cloud services as listed in the STAR Registry. It does not cover:
Customer‑hosted/on‑premises deployments of Hyland products
Hyland’s internal corporate IT systems
Non‑production environments (test, dev, demo)
Any Hyland offerings not delivered via the Hyland Cloud and related cloud services in the STAR listing. - PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 0cc7ac81-8e02-4c8b-8ccb-a7e903e880bf
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- SOC 2
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
-