Skip to main content

Help us improve the Digital Marketplace - send your feedback

mycomplaints.ai

mycomplaints.ai

Mycomplaints.ai is an AI powered Complaints Management Solution. AI generated output is presented clearly, with context, for human review. The solution enhances the analysis, investigation, root cause identification, remediation and response processes, improving the timeliness, accuracy and efficiency of an organisation’s complaint handling activities.

Features

  • AI First, with human in the loop validation
  • Management of the complete complaints lifecycle
  • Enterprise grade SaaS solution
  • Designed and built by experts in complaints management
  • Process automation. Converts unstructured emails into structured case data
  • AI delivers comprehensive analysis of all key case information
  • Explainable outputs require human review and validation
  • Automation of proposed plan of action for agent review
  • Proposes redress, remedial actions and identifies systemic issues
  • Integrated with MS Teams, Microsoft Dynamics 365, Salesforce

Benefits

  • Efficient case creation, building a case from unstructured data
  • Reduced overhead of triaging case, analysing all relevant data
  • Allows agents to add value, reviewing AI analysis
  • Automation reduces time to process a case
  • Supports compliance, through delivery of timely responses
  • Can be tightly integrated with relevant internal systems

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at david@mycomplaints.ai. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 3 2 4 1 4 3 3 0 0 2 8 2 5 9

Contact

mycomplaints.ai David Filler
Telephone: 07761 834951
Email: david@mycomplaints.ai

About your service

Service categories

Applications

Customer relationship management

  • Contact centre
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Can be integrated with existing line of business systems or CRM solutions (e.g. Salesforce, Microsoft Dynamics 365) to deliver a dedicated complaints module as a component of a broader system.
Cloud deployment model
Public cloud
Service constraints
None.
System requirements
  • Native SaaS solution
  • MS-Teams. (The solution is delivered as an app in MS-Teams).

User support

Email or online ticketing support
Yes
Support response times
Within 4 business hours hours on Working Days (09:00-17:00 Monday to Friday, excluding Bank and Public holidays in England). Tickets may be logged out of hours, but will receive a response on the next Working Day. Infrastructure is monitored and maintained on a 24x7x365 basis.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
We offer support as per our Service Level Agreement (SLA). The support is integral to the service and forms part of the fee that is paid for use of the service (i.e. there is no incremental fee). Support will be provided by a suitably qualified member of the support or development teams, as appropriate.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Remote training and access to online documentation
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Our commitment is that we will return to the Customer (or otherwise make available functionality for the Customer to download) a copy of the Customer Content in a commonly used, machine-readable format.
End-of-contract process
At the end of the contract, following the conclusion of any applicable Data Export Period (please see above), we will delete all Customer Content from our systems within the Data Deletion Period specified in the Key Terms of the contract, unless retention is required to comply with legal or regulatory obligations. We will ensure that deletion is performed in a secure and industry-standard-compliant manner.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None.
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
The API exists principally to integrate the complaints management solution with existing line of business or CRM solutions, to remove the need to duplicate data entry. Please see https://www.mycomplaints.ai/apidocs for more detailed information.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Capture additional attributes, modify AI prompts etc.

Scaling

Independence of resources
Ongoing automated monitoring of the hosting environment and scaling of the underlying virtual infrastructure as demand upon resources grows.

Analytics

Service usage metrics
Yes
Metrics types
A full analytical toolset is to be provided to review workload, internal compliance with SLAs, identify systemic issues etc
Reporting types
  • Real-time dashboards
  • Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Google Gemeni provides the AI capability

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Degaussing

Data importing and exporting

Data export approach
In an industry-standard format.
Data export formats
Other
Other data export formats
Case by case extraction of data and documents via API
Data import formats
Other
Other data import formats
Import of data and documents via API

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Data moving between a buyer's network and the AWS infrastructure is protected via:
• Encryption in Transit.
• Protocol Standards. The organisation maintains a minimum standard of TLS v1.2 or higher.
• Trusted Certificates
• End-to-End Application Flow.

The soluton provides mechanisms to restrict the "pathway" between networks:
• IP Address Whitelisting.
• Fixed Egress IP.

Secure Integration and Messaging is implemented via:
• OAuth 2.0
• Electronic Messaging
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Service Availability of 99.9%. Service Credit regime for failure to achieve stated Service Availability - please see Service Level Agreement that forms part of our Terms & Conditions document.
Approach to resilience
Mycomplaints Ltd uses the capabilities of the AWS public cloud architecture to configure a resilient solution. Further details can be provided upon request.
Outage reporting
A series of alarms and monitoring options exist for Mycomplaints Ltd operational staff. A public facing service availability monitor is made available to customers via the web.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
We restrict personnel access to customer systems through a comprehensive framework governed by the Principle of Least Privilege and a Need to Know basis. We employ effective:
• Personnel Vetting and Onboarding
• Technical Access Controls
• Single Sign-On (SSO) and MFA
• Role-Based Access Control (RBAC):
• Production Environment Isolation:
• AWS IAM Roles

Governance and Monitoring is achieved through:
• Segregation of Duties.
• Periodic Access Reviews.
• Automated Monitoring.

In the event of a role change or employment termination, a formal offboarding process is triggered.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
ISO 27001
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Mycomplaints ltd. employs a formalised framework for change and configuration management

The organisation categorises changes into two main types: planned (scheduled) and unplanned (emergency).

• All software developed for the platform is managed using Git.
• Changes must be tested in a staging environment prior to implementation.
• Changes undergo peer review and approval
• Access to implement changes in the production environment is strictly restricted.

Configuration Management

The organisation maintains established configuration baselines for critical infrastructure, including server hardening, endpoint device hardening, and firewall configurations.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Internal Vulnerability Assessments: We conduct regular internal vulnerability assessments, particularly after significant code releases or infrastructure updates. This includes checks for input validation flaws, common injection vulnerabilities, broken authentication/session management, insecure direct object references, and CSRF vulnerabilities.
Independent External Testing: We engage accredited third-party security firms to conduct annual penetration tests of our platform. Quarterly ASV (Approved Scanning Vendor) vulnerability scans are also performed in line with PCI DSS requirements. Findings from these tests are reviewed, prioritised, and remediated accordingly.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Audit Logging for Cloud Resources (AWS CloudTrail): All AWS management API calls are meticulously recorded. This is crucial for audit, compliance, and security analysis.
Network Traffic Logging (VPC Flow Logs): Provides detailed insights into IP traffic patterns to and from network interfaces in our virtual private cloud.
Threat Detection Service (AWS GuardDuty): This service continuously monitors for malicious activity and unauthorised behaviour.
Centralised Logging and Alerting (Amazon CloudWatch): System, application and security logs are consolidated in a centralised logging service.
Incident management type
Supplier-defined controls
Incident management approach
A structured framework exists for incident management to ensure that information security events are identified, communicated, and resolved in a timely manner.

Incidents are identified through two primary channels:
• Automated Threat Detection: The organisation uses services like AWS GuardDuty.
• Staff Reporting: All staff members, contractors, and third parties are required to report discovered security weaknesses or incidents promptly.

Specific protocols are in place for incidents involving sensitive or personal data.

Following the resolution of critical incidents, a post-mortem is conducted to determine the root cause and lessons learned.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
25%
Between £250,000 and £500,000
27.5%
Between £500,001 and £1,000,000
30%
Between £1,000,001 and £2,500,000
32.5%
Between £2,500,001 and £5,000,000
35%
Over £5,000,001
35%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
InterCert
ISO/IEC 27001 accreditation date
Thursday 14 August 2025
What the ISO/IEC 27001 doesn’t cover
The following areas of the Mycomplaints Ltd business operations are documented as falling outside the scope of ISO 27001:

Physical Office Premises: Because the organisation is cloud-native and does not host production servers or customer data on-site, the physical office buildings are excluded from the Information Security Management System (ISMS) scope.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
155615e9-e4d1-405d-a861-7dee487d5d4d
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
  • SOC2 Type 2 Report
  • We host with AWS who have Cyber Essentials Plus (CE+).

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at david@mycomplaints.ai. Tell them what format you need. It will help if you say what assistive technology you use.