MyContentScout
MyContentScout enables organisations to find answers and insights from their information more easily, faster, and with more accuracy than ever before, precisely when they need it.
Leveraging the latest AI technology with advanced search capabilities, MyContentScout is a cutting-edge solution increasing organisational productivity, accelerates decision-making, creating better user experiences.
Features
- Natural Language Search
- AI Answers & Summaries
- Multilingual Search
- Permissions & Access Controls
- Branded & Themed U
- Search Analytics & Usage Patterns
- Works seamlessly on desktop, tablet and mobile
- Bookmarking & Saved Results
- Cloud-based delivery via AWS/Azure
Benefits
- Find answers instantly from your organisations content
- Reduce time spent searching by asking questions in natural language
- Make faster, better-informed decisions
- Avoid duplicate work by surfacing existing knowledge and content
- Support remote and hybrid working
- Onboard staff faster with immediate access to organisational knowledge
- Improve consistency and accuracy
- Identify content gaps quickly by seeing what users search
- Reduce reliance on key individuals with knowledge accessible to everyone
- Access information on the from anywhere, anytime
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 3 1 5 8 4 6 4 1 6 4 9 3 2 2
Contact
The Virtual Forge Limited
The Virtual Forge
Telephone: +44 (0) 207 078 8855
Email: connect@thevirtualforge.com
About your service
- Service categories
-
Application Development and Deployment
AI platforms
- Search and knowledge discovery
AI life cycle
- Trustworthy AI Software
AI software services
- Conversational AI Software Services
- Document AI Software Services
- Personalize AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- This is SAAS and so is deployed onto our VPCs within AWS or Azure
- System requirements
-
- Browser access
- Whitelisted domain
- Data for ingestion directly or via a connector
User support
- Email or online ticketing support
- Yes
- Support response times
- During core hours, the helpdesk support priority levels (P1 to P4) are detailed below. These can be reviewed as per the customer's requirements. P1 (Urgent/System Down) receives 24/7 support with a 2-hour initial response time. P2 (High) and P3 (Medium, with a workaround) also have a 2-hour response time during business hours. P4 (Low impact) has a 4-hour initial response time during business hours. Target resolution for all is "Best efforts."
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 A
- Web chat accessibility testing
- Thorough testing scenarios have been carried out, covering the entire user flow, including initiating the chat, navigating the chat window, submitting messages, receiving agent replies, managing error states, and ending the conversation.
- Onsite support
- Yes, at extra cost
- Support levels
- We provide tiered support levels designed to align with your business needs and criticality. Our service structure is built upon the following elements: Support Tiers Our support is categorised to ensure the right level of coverage and resource allocation: Essential Support: Covers P2, P3, and P4 incidents, with support provided during Business Hours only. This is suitable for non-critical systems or applications where performance degradation is not immediately catastrophic. Premium Support: Extends P1 incident coverage to 24/7/365 availability, ensuring the fastest response for System Down (P1) and other critical incidents. This tier is vital for business-critical functions requiring continuous support. Pricing Structure The cost for each support level is not standardised and is determined on a per-customer basis. Pricing is subject to the scope of services and components defined in the customer's contract. Guaranteed response and resolution times are dependent on a mutually agreed-upon Service Level Agreement (SLA) All support is provided by certified specialists in both AWS and Azure. Dedicated resources are available, including Cloud Support Engineers (CSEs) & Technical Account Manager (TAM)
- Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- We offer a white glove onboarding service that supports clients throughout the setup and implementation process. This service can include tailored on-site or remote training and client specific user documentation, to ensure effective and confident use of the platform.
- Service documentation
- No
- End-of-contract data extraction
- It will be deleted
- End-of-contract process
- The contract can be renewed or cancelled
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- For the end user none. Administration area to manage content can only be accessed via desktop
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Yes via a web application
- Accessibility standards
- None or don’t know
- Description of accessibility
- Users can ask natural language questions by text queries or voice.
- Accessibility testing
- We recognise the value of testing with real users of assistive technology and are planning to include this as part of future usability testing to further improve accessibility and user experience.
- API
- No
- Customisation available
- Yes
- Description of customisation
- We can provide custom data and content connectors
Scaling
- Independence of resources
- Our architecture is distributed and autoscales using common cloud deisgn patterns
Analytics
- Service usage metrics
- Yes
- Metrics types
- Usage
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- At the moment this is done by requesting via helpdesk and we provide. This process is on the roadmap for automation via tehir priofie
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We aim to provide a reliable and highly available SaaS platform for all users. The service is designed to achieve 99.9% uptime per calendar month, excluding scheduled maintenance and events outside of our reasonable control (including force majeure, internet outages, or third-party service failures).
Availability is measured as the percentage of total minutes in a month during which the core platform is operational and accessible. Scheduled maintenance, where possible, will be communicated in advance and conducted during off-peak hours.
If monthly availability falls below the 99.9% target, affected customers may request service credits as compensation. Credits are applied to future subscription fees and are calculated on a pro-rata basis depending on the level of downtime experienced. Service credits are the sole and exclusive remedy for failure to meet availability commitments.
Refund requests must be submitted within 30 days of the end of the affected billing period, along with reasonable evidence of impact. This SLA applies only to paid subscription plans. - Approach to resilience
- We use aws / azure with two availability zones for all 'in time' services and load balanced auto scaled instances (or lambda functions where approriate). For overnight processes we use queues and FIFO processing with fault detection and auto replacement
- Outage reporting
- At the moment we use email alerts. in immediate roadmap is a public dashboard and in the longer roadmap is an api
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is based on the principle of least privilege. Admin and operational access is granted only to authorised personnel, and all accounts are unique and require MFA. Role-based access controls ensure users have the minimum permissions required to perform their roles and responsibilities. Regular access audits ensure permissions are routinely reviewed and removed where no longer required.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- We are iso 270001 approved and SOC 2. we have a compliance officer who sits at board level and are audited and inspected every year as well as having ongoing team training and education
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our configuration and change management processes are aligned with ISO 27001 principles, and our services are delivered using cloud-native components. Configuration and code is managed through Azure DevOps repositories and pipelines. Changes are tracked through their lifecycle from development through to deployment. Changes are initiated through change requests, with resulting code and config changes reviewed and approved before being deployed through automated pipelines. Security impacts are assessed as part of the change review process, with releases subject to rollback where required.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We follow a risk-based vulnerability management process aligned with recognised standards including ISO 27001, SOC 2 and Cyber Essentials. Potential threats are identified and assessed using a combination of vulnerability scanning and review of system configurations. Identified risks are triaged based on severity and exposure, with patches and mitigations prioritised according to their criticality, and deployed through the standard change control process. Advisories and security sources are leveraged to keep abreast of emerging threats.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Our protective monitoring processes are tailored to detect and respond to security events across cloud-hosted systems and services. Cloud-native monitoring and logging functionality provided by AWS and Azure are used to track potential security incidents. Alerts are escalated according to severity and reviewed by the cloud engineering team. If a security incident is detected, documented incident response procedures are followed to investigate and remediate the issue, with appropriate documentation and communication procedures.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Our incident management processes are risk-based with predefined procedures for common security events. Users can report incidents via ticketing portals, email or support channels. AWS and Azure monitoring and alerting services provide oversight and notify on infrastructure or application events, which are then triaged by the technical team. Incident reports summarise the cause, actions taken, impact and any further recommendations. Incident postmortems aim to identify learnings which can be fed back into improvements in the continuous monitoring practices.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- 30 - 90 day free trial with upto 5 to 100 users depending on usecase
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Monday 17 September 2018
- What the ISO/IEC 27001 doesn’t cover
- Nothing is stated on our certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
- SOC 2 Type II
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
-