mycomplaints.ai
Mycomplaints.ai is an AI powered Complaints Management Solution. AI generated output is presented clearly, with context, for human review. The solution enhances the analysis, investigation, root cause identification, remediation and response processes, improving the timeliness, accuracy and efficiency of an organisation’s complaint handling activities.
Features
- AI First, with human in the loop validation
- Management of the complete complaints lifecycle
- Enterprise grade SaaS solution
- Designed and built by experts in complaints management
- Process automation. Converts unstructured emails into structured case data
- AI delivers comprehensive analysis of all key case information
- Explainable outputs require human review and validation
- Automation of proposed plan of action for agent review
- Proposes redress, remedial actions and identifies systemic issues
- Integrated with MS Teams, Microsoft Dynamics 365, Salesforce
Benefits
- Efficient case creation, building a case from unstructured data
- Reduced overhead of triaging case, analysing all relevant data
- Allows agents to add value, reviewing AI analysis
- Automation reduces time to process a case
- Supports compliance, through delivery of timely responses
- Can be tightly integrated with relevant internal systems
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 3 2 4 1 4 3 3 0 0 2 8 2 5 9
Contact
mycomplaints.ai
David Filler
Telephone: 07761 834951
Email: david@mycomplaints.ai
About your service
- Service categories
-
Applications
Customer relationship management
- Contact centre
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Can be integrated with existing line of business systems or CRM solutions (e.g. Salesforce, Microsoft Dynamics 365) to deliver a dedicated complaints module as a component of a broader system.
- Cloud deployment model
- Public cloud
- Service constraints
- None.
- System requirements
-
- Native SaaS solution
- MS-Teams. (The solution is delivered as an app in MS-Teams).
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 4 business hours hours on Working Days (09:00-17:00 Monday to Friday, excluding Bank and Public holidays in England). Tickets may be logged out of hours, but will receive a response on the next Working Day. Infrastructure is monitored and maintained on a 24x7x365 basis.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- We offer support as per our Service Level Agreement (SLA). The support is integral to the service and forms part of the fee that is paid for use of the service (i.e. there is no incremental fee). Support will be provided by a suitably qualified member of the support or development teams, as appropriate.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Remote training and access to online documentation
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Our commitment is that we will return to the Customer (or otherwise make available functionality for the Customer to download) a copy of the Customer Content in a commonly used, machine-readable format.
- End-of-contract process
- At the end of the contract, following the conclusion of any applicable Data Export Period (please see above), we will delete all Customer Content from our systems within the Data Deletion Period specified in the Key Terms of the contract, unless retention is required to comply with legal or regulatory obligations. We will ensure that deletion is performed in a secure and industry-standard-compliant manner.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- None.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
- The API exists principally to integrate the complaints management solution with existing line of business or CRM solutions, to remove the need to duplicate data entry. Please see https://www.mycomplaints.ai/apidocs for more detailed information.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Capture additional attributes, modify AI prompts etc.
Scaling
- Independence of resources
- Ongoing automated monitoring of the hosting environment and scaling of the underlying virtual infrastructure as demand upon resources grows.
Analytics
- Service usage metrics
- Yes
- Metrics types
- A full analytical toolset is to be provided to review workload, internal compliance with SLAs, identify systemic issues etc
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Google Gemeni provides the AI capability
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Degaussing
Data importing and exporting
- Data export approach
- In an industry-standard format.
- Data export formats
- Other
- Other data export formats
- Case by case extraction of data and documents via API
- Data import formats
- Other
- Other data import formats
- Import of data and documents via API
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
-
Data moving between a buyer's network and the AWS infrastructure is protected via:
• Encryption in Transit.
• Protocol Standards. The organisation maintains a minimum standard of TLS v1.2 or higher.
• Trusted Certificates
• End-to-End Application Flow.
The soluton provides mechanisms to restrict the "pathway" between networks:
• IP Address Whitelisting.
• Fixed Egress IP.
Secure Integration and Messaging is implemented via:
• OAuth 2.0
• Electronic Messaging - Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Service Availability of 99.9%. Service Credit regime for failure to achieve stated Service Availability - please see Service Level Agreement that forms part of our Terms & Conditions document.
- Approach to resilience
- Mycomplaints Ltd uses the capabilities of the AWS public cloud architecture to configure a resilient solution. Further details can be provided upon request.
- Outage reporting
- A series of alarms and monitoring options exist for Mycomplaints Ltd operational staff. A public facing service availability monitor is made available to customers via the web.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
We restrict personnel access to customer systems through a comprehensive framework governed by the Principle of Least Privilege and a Need to Know basis. We employ effective:
• Personnel Vetting and Onboarding
• Technical Access Controls
• Single Sign-On (SSO) and MFA
• Role-Based Access Control (RBAC):
• Production Environment Isolation:
• AWS IAM Roles
•
Governance and Monitoring is achieved through:
• Segregation of Duties.
• Periodic Access Reviews.
• Automated Monitoring.
In the event of a role change or employment termination, a formal offboarding process is triggered. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- ISO 27001
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Mycomplaints ltd. employs a formalised framework for change and configuration management
The organisation categorises changes into two main types: planned (scheduled) and unplanned (emergency).
• All software developed for the platform is managed using Git.
• Changes must be tested in a staging environment prior to implementation.
• Changes undergo peer review and approval
• Access to implement changes in the production environment is strictly restricted.
Configuration Management
The organisation maintains established configuration baselines for critical infrastructure, including server hardening, endpoint device hardening, and firewall configurations. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Internal Vulnerability Assessments: We conduct regular internal vulnerability assessments, particularly after significant code releases or infrastructure updates. This includes checks for input validation flaws, common injection vulnerabilities, broken authentication/session management, insecure direct object references, and CSRF vulnerabilities.
Independent External Testing: We engage accredited third-party security firms to conduct annual penetration tests of our platform. Quarterly ASV (Approved Scanning Vendor) vulnerability scans are also performed in line with PCI DSS requirements. Findings from these tests are reviewed, prioritised, and remediated accordingly. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Audit Logging for Cloud Resources (AWS CloudTrail): All AWS management API calls are meticulously recorded. This is crucial for audit, compliance, and security analysis.
Network Traffic Logging (VPC Flow Logs): Provides detailed insights into IP traffic patterns to and from network interfaces in our virtual private cloud.
Threat Detection Service (AWS GuardDuty): This service continuously monitors for malicious activity and unauthorised behaviour.
Centralised Logging and Alerting (Amazon CloudWatch): System, application and security logs are consolidated in a centralised logging service. - Incident management type
- Supplier-defined controls
- Incident management approach
-
A structured framework exists for incident management to ensure that information security events are identified, communicated, and resolved in a timely manner.
Incidents are identified through two primary channels:
• Automated Threat Detection: The organisation uses services like AWS GuardDuty.
• Staff Reporting: All staff members, contractors, and third parties are required to report discovered security weaknesses or incidents promptly.
Specific protocols are in place for incidents involving sensitive or personal data.
Following the resolution of critical incidents, a post-mortem is conducted to determine the root cause and lessons learned. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 25%
- Between £250,000 and £500,000
- 27.5%
- Between £500,001 and £1,000,000
- 30%
- Between £1,000,001 and £2,500,000
- 32.5%
- Between £2,500,001 and £5,000,000
- 35%
- Over £5,000,001
- 35%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- InterCert
- ISO/IEC 27001 accreditation date
- Thursday 14 August 2025
- What the ISO/IEC 27001 doesn’t cover
-
The following areas of the Mycomplaints Ltd business operations are documented as falling outside the scope of ISO 27001:
Physical Office Premises: Because the organisation is cloud-native and does not host production servers or customer data on-site, the physical office buildings are excluded from the Information Security Management System (ISMS) scope. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 155615e9-e4d1-405d-a861-7dee487d5d4d
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- SOC2 Type 2 Report
- We host with AWS who have Cyber Essentials Plus (CE+).
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-