Skip to main content

Help us improve the Digital Marketplace - send your feedback

HYLAND UK OPERATIONS LIMITED

Alfresco Digital Business Platform

Alfresco Digital Business Platform (DBP) is Hyland's cloud-native, open-source content services platform that includes industry-leading content, process, and governance services. Alfresco DBP enables enterprises to build smart, content-centric business applications that transform their businesses: enhancing customer experiences and improving decision making, while ensuring compliance with regulatory requirements.

Features

  • Manages protects and connects your most important information
  • Safeguards confidential corporate assets wherever they're accessed or stored
  • Federated Service allows access to content across systems from UI
  • Unmatched combination of simplicity and control for information governance
  • Remote access
  • Fast, powerful search including full-text search of metadata
  • Analytics components report data to external databases and monitoring systems
  • Built on open-source core, supports open standards and open APIs
  • Configurable user interfaces enabling employees to easily access relevant content
  • Web-enabled; works on smartphones, tablets, or any standards-compliant browser

Benefits

  • Digitize and streamline content, governance and processes in one platform
  • Collaborate with confidence, whilst maintaining data confidentiality
  • Access content without risky, costly and time-consuming bulk migration
  • Confidence in your ability to demonstrate continued compliance
  • Automatically enrich content and gain valuable insights
  • Find the information you need when you need it
  • Make better decisions based on real-time data
  • Easily integrate with other applications (and content) for efficient working
  • Employees view content in way that works best for them
  • Supports a mobile workforce, ensuring critical information always at hand

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at governmentcontracts@hyland.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 1 6 2 3 2 2 4 1 0 6 8 5 6 4

Contact

HYLAND UK OPERATIONS LIMITED Stacey Chapman
Telephone: +121 639 60261
Email: governmentcontracts@hyland.com

About your service

Service categories

Applications

Content workflow and management

  • Capture
  • Document

Content services

  • Enterprise Content Management Applications
  • Content Sharing and Collaboration Applications

Persuasive content management

  • Website Software
  • Digital Asset Management Applications
  • Product Content Management Applications
  • Content Marketing Applications
  • Video Platforms
  • Digital Adoption Platform

Enterprise portals and digital workspaces

  • Multi-Audience Portals
  • Integrated Employee Workspaces
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Alfresco Scheduled Maintenance Windows – modification or repairs to shared infrastructure or platform patching and upgrades that Alfresco has provided notice of at least seventy-two (72) hours in advance or that occurs during 6:00 am to 10:00 am on Saturdays Eastern Time Zone.
Scheduled Customer Maintenance – maintenance of customer configuration that customer requests and that Alfresco schedules with customers in advance.
Scheduled Customer Deployments – as with maintenance, these are customer requests that Alfresco schedules with the customer in advance.
Emergency Maintenance – critical unforeseen maintenance needed for the security or performance of customer configuration or Alfresco's network.
System requirements
  • Red Hat Enterprise Linux; Windows Server 2019
  • Amazon; Linux; CentOS; Ubuntu
  • MySQL; MS SQL Sever; Oracle; PostgreSQL; MariaDB; Amazon Aurora
  • Mozilla Firefox; Microsoft Edge; MS Internet Explorer; Chrome; Safari

User support

Email or online ticketing support
Yes
Support response times
Hyland does not guarantee response times; however, support issues that materially impact production use of the system are addressed immediately. Hyland endeavors to identify a workaround whenever a permanent solution to a software error cannot be provided within a reasonable timeframe. The Technical Support analyst assigned to a support case is empowered to determine its impact on a customer’s implemented product per defined Severity Levels, and to obtain immediate attention to the issue as required.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Hyland Technical Support offers multiple self-service and assisted support opportunities to assist customers in resolving issues being experienced with their implemented Hyland technology solution.

Hyland technical support is standard with subscription to the Alfresco solution.

Hyland offers different Service Class levels to meet the business continuity requirements of our hosted customers. With these service classes Hyland commits to high service availability\uptime (i.e. 99.5% to 99.9%). Specific financial remedies are associated with each Service Class.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
As part of implementation, Hyland conducts on-site training for your organization's designated system administrators, testers, and trainers, who will then educate the user community. Training covers all basic system functions—such as scanning, storing, retrieving, and printing—as well as your organization’s specific applications and procedures, which may vary by department. Hyland also creates training materials tailored to your configured solution for use by your trainers. After training, the project team provides a period of support, typically remote, as users test and begin using the solution in the live environment. All solution training supplements the courses and certifications available from Hyland Education Services, which are separate from the solution-specific engagement. Hyland offers comprehensive training for end-users, solution architects, developers, business unit owners, and system administrators to ensure they can design, install, use, and maintain the solution. End-user training can be hosted on your internal network, and users also have access to self-paced, web-based courses at https://university.hyland.com/ to build foundational knowledge and comfort with the system.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Alfresco Cloud Off-boarding Assistance

In the event that a customer wishes to cancel the service, Hyland will provide the following off-boarding assistance for 30 days: 
 
While the Alfresco Cloud will go into read only mode, the customer will continue to have access to the data extraction capabilities for 30 days. This allows the customer to extract all content within the Alfresco Cloud.
If the customer provided custom code for Alfresco to deploy, upon the customer's written request, Alfresco will return a copy of that custom code to the customer.
For large content stores, Hyland will work with the customer to find the most cost effective method for retrieving or transferring the data. Additional fees may be required for this assistance and/or to migrate content in bulk.
While the Alfresco Cloud will go into read only mode, the customer will continue to have access to the data extraction capabilities for 30 days. This allows the customer to extract all content within the Alfresco Cloud.
End-of-contract process
In the unfortunate event that a customer wishes to cancel the service, Hyland will provide the following off-boarding assistance for 30 days:   
While the Alfresco Cloud will go into read only mode, the customer will continue to have access to the data extraction capabilities for 30 days. This allows the customer to extract all content within the Alfresco Cloud.
If the customer provided custom code for Alfresco to deploy, upon the customer's written request, Alfresco will return a copy of that custom code to the customer.
For large content stores, Hyland will work with the customer to find the most cost-effective method for retrieving or transferring the data. Additional fees may be required for this assistance and/or to migrate content in bulk.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • MacOS
  • Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile Android and iOS apps support fewer features than full browser access, but the core day to day end user functionality such as adding, searching, viewing documents and approving workflows is available.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
1. Alfresco REST API (v1.0)

Purpose: Complete application interface for accessing all Alfresco Repository features
Endpoint format: https://{your-alfresco-cloud-instance}/alfresco/api/-default-/public/alfresco/versions/1/...
Standard: RESTful API following OpenAPI specification
Documentation: Available through API Explorer at https://api-explorer.alfresco.com/api-explorer

2. CMIS REST API

Purpose: Standards-based content management interface
Benefit: Portability across different ECM vendors
Use case: When vendor-neutral integration is important

3. Process Services REST API

Purpose: Access to Alfresco Process Automation (APA) capabilities
Features: Start processes, complete tasks, manage workflows
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The Alfresco SaaS service can be accessed via a multi-layered approach, combining broad device compatibility with rigorous digital accessibility standards for users with disabilities. This approach is supported by external accessibility experts and an Accessibility Programme directed by Hyland. Recent updates, including Alfresco 7.4 and subsequent 2026 releases, have focused on achieving WCAG 2.2 AA compliance and creating the most up-to-date Accessibility Compliance Report (ACR) that also comply with Section 508 and European regulations for 2026.

The platform is designed to work with screen readers in multiple combinations and includes features such as keyboard-only navigation for key modules, including: Dashboard, Browse, File Libraries, Move/Copy, and Modal Flows, to name a few.
API
Yes
What users can and can't do using the API
Users can perform a wide range of tasks using the Alfresco APIs, including integrating Alfresco with other systems, automating processes, and extending platform functionality. Common actions include programmatically creating, updating, retrieving, and deleting documents, folders, and metadata; automating workflows; performing advanced searches; integrating with third-party systems; managing users, groups, permissions, and access control lists; building custom applications and dashboards; managing metadata; handling version control; extracting data for reporting and analytics; and transforming content into different formats. There are no restrictions on file types or sizes for uploads or downloads, but client connectivity and network conditions should be considered for large files. However, users cannot perform actions outside the scope of these API capabilities, such as modifying core application source code directly or bypassing established security and access controls.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customize Alfresco in several comprehensive ways to tailor the platform to their specific business needs. The primary method is through Low-Code Development using Alfresco Process Automation (APA), which provides a visual, drag-and-drop interface for modeling applications, defining custom content models, creating BPMN 2.0 workflows, designing forms, integrating with external services, building decision tables, adding scripts, and designing custom user interfaces. This approach is accessible to both developers and non-technical users, requires no infrastructure management, and is cloud-native with automatic scaling. Users can also customize the Digital Workspace by creating custom UIs based on the default template, modifying source code with Angular/ADF, and uploading the customized UI back to the platform. Alfresco supports API-based integrations, offering REST API v1.0, CMIS API, and Process Services REST API for workflow automation, allowing users to build custom applications that interact with the content repository, trigger workflows, and integrate with third-party systems. Content-centric application development is supported, enabling users to build business applications with document approval workflows, event-based automation, CRM/ERP integration, and AI-powered features. Additionally, Alfresco provides pre-built integrations with cloud services like DocuSign, Slack, Twilio, Salesforce, and machine learning services for enhanced functionality.

Scaling

Independence of resources
Cloud-Native Dynamic Scaling:

"Cloud-native architecture offers maximum availability and dynamic scaling"
Kubernetes automatically scales resources based on demand
Applications can scale independently without affecting others

Analytics

Service usage metrics
Yes
Metrics types
Alfresco provides service metrics through its Admin Application Monitoring, which tracks application deployments, user permissions, and application status. The Analytics App offers standard reports on process and task metrics, including process instance counts, usage statistics, duration, completion rates, task counts, SLA reports, and status. Reports can be customized by process definition, date range, task status, and aggregated by hour, day, week, month, or year, with graphical, tabular, and statistical views.
Reporting types
API access
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Hyland protects data at rest through multiple layers of security. All data repositories are encrypted using AES-256 encryption with cryptographic keys managed via AWS Key Management Service. Access is restricted through strict role-based access controls, and data resides within isolated Virtual Private Clouds to prevent unauthorized network access. Integrity controls, such as write-once-read-many (WORM) technologies and file share scanning, help maintain data integrity. Data Loss Prevention (DLP) policies and monitoring are enforced to prevent unauthorized movement or leakage. Additionally, AWS data centers provide robust physical security, including controlled access, surveillance, and environmental protections.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can export their data using several methods. The primary method is through the REST API, which allows programmatic access to all repository content, including files, folders, metadata, and folder structures, and supports bulk export operations. The CMIS API offers a standards-based approach for content retrieval across different ECM platforms. Users can also export data manually via the Digital Workspace or Share interface, enabling individual or bulk downloads. Additionally, third-party migration tools such as Xillio, migration-center, and Texport support Alfresco exports, providing further options for data migration and export.
Data export formats
CSV
Data import formats
Other
Other data import formats
  • Alfresco accepts virtually ANY file format
  • Alfresco philosophy is format-agnostic storage.
  • Alfresco supports over 1,400+ different MIME types

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
From 99.0% to 99.9% depending on the Tier Level purchased.
In the event the Monthly Uptime Percentage during any calendar month is less than the applicable Monthly Uptime Percentage, the
customer shall be eligible to receive the applicable credit against Fees, provided Customer submitted a technical support request within twenty-four (24) hours of such Downtime.
If, following delivery of a Failover Notice, the Alfresco Cloud Service is not Restored within the applicable Recovery Time objective , the
customer shall be eligible to receive the applicable credit against Fees, provided the customer submitted a technical support request within twenty-four (24) hours of such Downtime.
Approach to resilience
The Alfresco Cloud is designed with a comprehensive backup and recovery framework to ensure resilience. It provides fault-tolerance and automated restores in most cases, protecting customer data from accidental loss due to hardware or system failure. Hyland maintains a fault-tolerant system by storing complete system backups for 30 days, which include database snapshots and versioned content store backups replicated to a secondary region for fail-over. Backups are scheduled for all instances, monitored for errors, and restoration procedures are regularly tested through scheduled drills. In the event of a service disruption, Hyland initiates disaster recovery protocols to restore services promptly, potentially phasing restoration to maximize customer benefit. Data not immediately accessible after a disruption is restored from the most recent backup. These measures exclude any exceptions described in the Alfresco Cloud Master Services Agreement.
Outage reporting
1. Email Notifications When a system outage occurs, customers receive email notifications about the incident.

 

2. Downtime Reports After a downtime event occurs, customers can request a formal report that includes:

Detailed description of the incident
Start and end times
Duration of the incident
Business/functional impact
Description of remediation efforts taken
Outstanding issues or follow-up actions

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
For Alfresco Cloud, the recommended modern approach uses Identity Service with SAML/OAuth 2.0:
Initial Access Request
User navigates to Alfresco Cloud URL (Digital Workspace, Share, or API)
Application detects user is not authenticated
2. Redirect to Identity Service
Alfresco redirects user to Alfresco Identity Service (built on Keycloak)
Identity Service determines which authentication provider to use
3. SAML/OAuth Authentication

For SAML SSO:

Identity Service redirects to configured SAML Identity Provider (IdP)
User is presented with IdP's login screen
User enters credentials (username/password)
If MFA is enabled at IdP level, user completes second factor (authenticator app, SMS, biometric, etc.)
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
Less than 1 month
How long system logs are stored for
Less than 1 month

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Alfresco cloud governance framework aligns with internationally recognized standards and best practices. These include ISO/IEC 27001:2022 for information security management, SOC 2 Type II for service organization controls, CSA CCM for cloud security, and NIST SP 800-53 for operational security. Hyland also supports compliance with HIPAA, GDPR, PCI DSS, and FedRAMP equivalency for applicable deployments, ensuring robust governance and regulatory adherence across all hosted environments.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Hyland follows internal change management procedures when changes are initiated by Hyland, or when a customer requests to make a change on their behalf to existing systems, or when new systems are deployed to the Alfresco Cloud. Change requests are submitted via a change management system and are then evaluated by subject matter experts. Upon approval by such subject matter experts, changes are implemented, documented, and tested. In the event an issue occurs with the approved change, rollback procedures, documented as part of the change request, are performed in order to return the system to its original state
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Hyland's vulnerability management process includes application security testing with every product release, guided by a well-trained security team. Security is integrated throughout the product lifecycle, and all Product, Technology, and Hyland Cloud department members undergo security training. Mandatory checks are performed at key development stages. Static source code analysis tools are used in the code build pipeline to identify issues, including those related to the OWASP top 10. Third-party libraries are scanned for known vulnerabilities against the NIST and Synk.io databases. Penetration testing is conducted internally and by external companies before major releases.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
DAST and WebApp PenTest test OWASP top 10 and common web attacks.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Incident response and management policy that covers responding to product security vulnerabilities discovered after release and information security incidents within the Hyland Cloud. Issues are categorized and communicated as outlined in the Alfresco Support Handbook. Security fixes, patches, and updates are implemented as released, following testing and approval for the Hyland Cloud. Hyland welcomes vulnerability reports from customers and external consultants; these can be submitted via email to security@hyland.com and are handled responsibly. Incident response plan includes identifying involved parties, management protocols, reporting requirements, notification and handling procedures, and post-incident reviews. Procedures are tested annually and span multiple organizational levels.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
Yes
Connected networks
Public Services Network (PSN)

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
There is no free option
Link to free trial
https://www.hyland.com/en/resources/alfresco-trial

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
EY CertifyPoint
ISO/IEC 27001 accreditation date
Friday 31 October 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI (British Standards Institution)
ISO 9001 accreditation date
Tuesday 25 February 2025
What the ISO 9001 doesn’t cover
N/a
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Friday 30 June 2023
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
Our CSA STAR Level 1 self‑assessment covers our Hyland‑managed cloud services as listed in the STAR Registry. It does not cover:

Customer‑hosted/on‑premises deployments of Hyland products

Hyland’s internal corporate IT systems

Non‑production environments (test, dev, demo)

Any Hyland offerings not delivered via the Hyland Cloud and related cloud services in the STAR listing.
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
0cc7ac81-8e02-4c8b-8ccb-a7e903e880bf
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
SOC 2

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at governmentcontracts@hyland.com. Tell them what format you need. It will help if you say what assistive technology you use.