Skip to main content

Help us improve the Digital Marketplace - send your feedback

The Virtual Forge Limited

MyContentScout

MyContentScout enables organisations to find answers and insights from their information more easily, faster, and with more accuracy than ever before, precisely when they need it.

Leveraging the latest AI technology with advanced search capabilities, MyContentScout is a cutting-edge solution increasing organisational productivity, accelerates decision-making, creating better user experiences.

Features

  • Natural Language Search
  • AI Answers & Summaries
  • Multilingual Search
  • Permissions & Access Controls
  • Branded & Themed U
  • Search Analytics & Usage Patterns
  • Works seamlessly on desktop, tablet and mobile
  • Bookmarking & Saved Results
  • Cloud-based delivery via AWS/Azure

Benefits

  • Find answers instantly from your organisations content
  • Reduce time spent searching by asking questions in natural language
  • Make faster, better-informed decisions
  • Avoid duplicate work by surfacing existing knowledge and content
  • Support remote and hybrid working
  • Onboard staff faster with immediate access to organisational knowledge
  • Improve consistency and accuracy
  • Identify content gaps quickly by seeing what users search
  • Reduce reliance on key individuals with knowledge accessible to everyone
  • Access information on the from anywhere, anytime

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at connect@thevirtualforge.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 3 1 5 8 4 6 4 1 6 4 9 3 2 2

Contact

The Virtual Forge Limited The Virtual Forge
Telephone: +44 (0) 207 078 8855
Email: connect@thevirtualforge.com

About your service

Service categories

Application Development and Deployment

AI platforms

  • Search and knowledge discovery

AI life cycle

  • Trustworthy AI Software

AI software services

  • Conversational AI Software Services
  • Document AI Software Services
  • Personalize AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
This is SAAS and so is deployed onto our VPCs within AWS or Azure
System requirements
  • Browser access
  • Whitelisted domain
  • Data for ingestion directly or via a connector

User support

Email or online ticketing support
Yes
Support response times
During core hours, the helpdesk support priority levels (P1 to P4) are detailed below. These can be reviewed as per the customer's requirements. P1 (Urgent/System Down) receives 24/7 support with a 2-hour initial response time. P2 (High) and P3 (Medium, with a workaround) also have a 2-hour response time during business hours. P4 (Low impact) has a 4-hour initial response time during business hours. Target resolution for all is "Best efforts."
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), 7 days a week
Web chat support
Yes, at an extra cost
Web chat support availability
9 to 5 (UK time), 7 days a week
Web chat support accessibility standard
WCAG 2.2 A
Web chat accessibility testing
Thorough testing scenarios have been carried out, covering the entire user flow, including initiating the chat, navigating the chat window, submitting messages, receiving agent replies, managing error states, and ending the conversation.
Onsite support
Yes, at extra cost
Support levels
We provide tiered support levels designed to align with your business needs and criticality. Our service structure is built upon the following elements: Support Tiers Our support is categorised to ensure the right level of coverage and resource allocation: Essential Support: Covers P2, P3, and P4 incidents, with support provided during Business Hours only. This is suitable for non-critical systems or applications where performance degradation is not immediately catastrophic. Premium Support: Extends P1 incident coverage to 24/7/365 availability, ensuring the fastest response for System Down (P1) and other critical incidents. This tier is vital for business-critical functions requiring continuous support. Pricing Structure The cost for each support level is not standardised and is determined on a per-customer basis. Pricing is subject to the scope of services and components defined in the customer's contract. Guaranteed response and resolution times are dependent on a mutually agreed-upon Service Level Agreement (SLA) All support is provided by certified specialists in both AWS and Azure. Dedicated resources are available, including Cloud Support Engineers (CSEs) & Technical Account Manager (TAM)
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
We offer a white glove onboarding service that supports clients throughout the setup and implementation process. This service can include tailored on-site or remote training and client specific user documentation, to ensure effective and confident use of the platform.
Service documentation
No
End-of-contract data extraction
It will be deleted
End-of-contract process
The contract can be renewed or cancelled

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
For the end user none. Administration area to manage content can only be accessed via desktop
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Yes via a web application
Accessibility standards
None or don’t know
Description of accessibility
Users can ask natural language questions by text queries or voice.
Accessibility testing
We recognise the value of testing with real users of assistive technology and are planning to include this as part of future usability testing to further improve accessibility and user experience.
API
No
Customisation available
Yes
Description of customisation
We can provide custom data and content connectors

Scaling

Independence of resources
Our architecture is distributed and autoscales using common cloud deisgn patterns

Analytics

Service usage metrics
Yes
Metrics types
Usage
Reporting types
Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Degaussing
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
At the moment this is done by requesting via helpdesk and we provide. This process is on the roadmap for automation via tehir priofie
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We aim to provide a reliable and highly available SaaS platform for all users. The service is designed to achieve 99.9% uptime per calendar month, excluding scheduled maintenance and events outside of our reasonable control (including force majeure, internet outages, or third-party service failures).

Availability is measured as the percentage of total minutes in a month during which the core platform is operational and accessible. Scheduled maintenance, where possible, will be communicated in advance and conducted during off-peak hours.

If monthly availability falls below the 99.9% target, affected customers may request service credits as compensation. Credits are applied to future subscription fees and are calculated on a pro-rata basis depending on the level of downtime experienced. Service credits are the sole and exclusive remedy for failure to meet availability commitments.

Refund requests must be submitted within 30 days of the end of the affected billing period, along with reasonable evidence of impact. This SLA applies only to paid subscription plans.
Approach to resilience
We use aws / azure with two availability zones for all 'in time' services and load balanced auto scaled instances (or lambda functions where approriate). For overnight processes we use queues and FIFO processing with fault detection and auto replacement
Outage reporting
At the moment we use email alerts. in immediate roadmap is a public dashboard and in the longer roadmap is an api

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is based on the principle of least privilege. Admin and operational access is granted only to authorised personnel, and all accounts are unique and require MFA. Role-based access controls ensure users have the minimum permissions required to perform their roles and responsibilities. Regular access audits ensure permissions are routinely reviewed and removed where no longer required.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We are iso 270001 approved and SOC 2. we have a compliance officer who sits at board level and are audited and inspected every year as well as having ongoing team training and education
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Our configuration and change management processes are aligned with ISO 27001 principles, and our services are delivered using cloud-native components. Configuration and code is managed through Azure DevOps repositories and pipelines. Changes are tracked through their lifecycle from development through to deployment. Changes are initiated through change requests, with resulting code and config changes reviewed and approved before being deployed through automated pipelines. Security impacts are assessed as part of the change review process, with releases subject to rollback where required.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We follow a risk-based vulnerability management process aligned with recognised standards including ISO 27001, SOC 2 and Cyber Essentials. Potential threats are identified and assessed using a combination of vulnerability scanning and review of system configurations. Identified risks are triaged based on severity and exposure, with patches and mitigations prioritised according to their criticality, and deployed through the standard change control process. Advisories and security sources are leveraged to keep abreast of emerging threats.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Our protective monitoring processes are tailored to detect and respond to security events across cloud-hosted systems and services. Cloud-native monitoring and logging functionality provided by AWS and Azure are used to track potential security incidents. Alerts are escalated according to severity and reviewed by the cloud engineering team. If a security incident is detected, documented incident response procedures are followed to investigate and remediate the issue, with appropriate documentation and communication procedures.
Incident management type
Supplier-defined controls
Incident management approach
Our incident management processes are risk-based with predefined procedures for common security events. Users can report incidents via ticketing portals, email or support channels. AWS and Azure monitoring and alerting services provide oversight and notify on infrastructure or application events, which are then triaged by the technical team. Incident reports summarise the cause, actions taken, impact and any further recommendations. Incident postmortems aim to identify learnings which can be fed back into improvements in the continuous monitoring practices.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
30 - 90 day free trial with upto 5 to 100 users depending on usecase

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Monday 17 September 2018
What the ISO/IEC 27001 doesn’t cover
Nothing is stated on our certification.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
SOC 2 Type II

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at connect@thevirtualforge.com. Tell them what format you need. It will help if you say what assistive technology you use.