endev-o Information Management Platform
endev-o is a UK-hosted, cloud-native information management platform for public sector asset owners. It integrates with common CDE's and supports structured data capture, validation and assurance across projects and operational assets, enabling compliant digital handover, risk and HSEQ management, and auditable information governance aligned to ISO 19650 and regulatory requirements
Features
- Validated data capture aligned to industry standards
- Defined governance embedded within configurable workflows
- Integration with project and asset CDE platforms
- Structured digital handover and acceptance management
- Automated tasks, triggers and role-based notifications
- Immutable version history and submission snapshots
- Real-time dashboards and portfolio reporting
- Standardised templates across projects and programmes
- Secure, role-based access controls
- Simple, spreadsheet-style user experience
Benefits
- Trust information used for critical project and asset decisions
- Reduce time spent chasing, checking and reworking data
- Improve assurance at project and asset handover
- Maintain a single, reliable version of the truth
- Strengthen governance without increasing user burden
- Enable faster, more confident decision-making
- Improve visibility of risks, issues and trends
- Reduce duplication across projects and supply chains
- Support consistent outcomes across projects, programmes and asset portfolios
- Build confidence in data used by senior leaders
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 3 6 8 7 2 1 0 4 2 9 8 6 0 5
Contact
AMODAL LIMITED
Jacqueline Lynch
Telephone: 0330 320 1000
Email: jlynch@amodal.co.uk
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- We have scheduled planned maintenance arrangements which are communicated in advance to all users of the service
- System requirements
- Modern web browsers (Edge, Chrome, Safari etc)
User support
- Email or online ticketing support
- Yes
- Support response times
-
P1 Urgent - respond within 1 h, resolution with 4h
P2 High - respond within 4 h, resolution with 12h
P3 Medium - respond within 8 h, resolution with 3d
P4 Low - respond within 24 h, resolution with 7d - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Amodal provides a three-level support service to ensure reliable operation, adoption and continuous improvement of its software and managed services.
Level 1 – Standard Support
Provides business-hours access to Amodal’s UK-based support team for end-user queries, incident logging and basic configuration guidance. This level includes issue triage, access to guidance materials and standard service updates. Suitable for organisations requiring stable, day-to-day operational support.
Level 2 – Enhanced Support
Includes all Standard Support services, plus proactive system monitoring, configuration support, dashboard and workflow adjustments, and priority response times. Enhanced Support also provides scheduled service reviews and adoption support to meaningfully improve outcomes.
Level 3 – Managed Service
Provides a fully managed service, including platform administration, data quality checks, workflow optimisation, reporting support and continuous improvement. This level is suited to asset owners seeking assured information management outcomes without maintaining in-house specialist capability.
Support is delivered primarily remotely, with on-site support available by agreement. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Once the order/Agreement is received, Amodal will email the principle client contacts a new customer onboarding form to allow the setup of user accounts, apps and workspaces. Training is delivered online and tailored to suit the requirements. Training can also be delivered onsite on request at an additional cost.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
Amodal provides automated export functionality for all table data in CSV, JSON or XML.
Amodal can also provide digital archives on external hard drives to be shipped directly to the Buyer on request, at an additional cost. - End-of-contract process
-
Upon termination of the Software-as-a-Service subscription, the following option is available for archiving of data (subject to contract):
At an additional cost, all data can be exported from endev-o and provided in a standardised format to the Customer via an external hard drive compatible with Windows or OSX operating systems. The hard drive can be encrypted as an additional option if required.
In the absence of any specific archiving instructions, customer data will be retained for a period of 12 calendar months after the subscription termination date before being securely sanitised and destroyed. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Documentation is distributed by secure link. This provides access to well formatted PDF documents that have been checked to ensure accessibility and readability.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The User Interface is responsively designed to suit the browser's screen resolution.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is entirely web browser-based and has many user interfaces to access, build, navigate, store, process, track and download data and information.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Accessibility is embedded into the design and delivery of our service interface to ensure it can be used effectively by a wide range of users. The platform supports keyboard-only navigation, clear and consistent layouts, readable text and appropriate contrast. The interface is responsive across devices and avoids unnecessary motion or visual distraction. Accessibility is reviewed as part of our ongoing product development and improvement cycle, and we work with clients to accommodate specific accessibility needs where reasonable.
- Accessibility testing
-
We have undertaken practical usability testing of the interface, alongside internal accessibility reviews.
Testing has been carried out during development and prior to major releases, with findings logged and addressed through our normal product backlog and release process. In addition, feedback from users with accessibility needs has been incorporated where the platform is used within client organisations.
Accessibility testing is treated as an ongoing activity rather than a one-off exercise, and we continue to refine the interface as new features are introduced or user needs evolve - API
- Yes
- What users can and can't do using the API
- The endev-o RESTful API is not available by default to users. It can be made available to the Buyer for specific purposes to be agreed with the supplier in writing. These purposes are usually regarding an integration with third party software.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Endev-o is customised by the Buyer to meet the requirements of each individual project, asset or estate need. Specifically, the Buyer can customise the following:
+Tables
+Forms
+Workflows
+Views
+Pages (incl. interface layouts with customised branding/logo)
Scaling
- Independence of resources
- The service supports a split-tier architecture, separating the application layer (Laravel web and queue workers via Horizon/Supervisor with Redis) from the database layer. This separation isolates database performance from application and background processing workloads and allows each tier to be scaled independently. Monitoring is in place for system health and queue processing (CPU, memory, disk, database performance, and queue depth) to ensure one component does not degrade the others.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
A number of usage metrics are available for example:
+Number of users
+User details
+All data metrics from within apps e.g. Number of MIDPs/TIDPs - Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Users can export data from the platform via the interface by following means:
+Export table views e.g. an asset register to CSV
+Export all documents in their native format - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Internal traffic protected by network boundary
Availability and resilience
- Guaranteed availability
- We offer a 99.5% service level agreement, but we do not offer a credit system to customers if SLAs are not met. Note that our 99.5% service availability has always been met.
- Approach to resilience
-
Endev-o is delivered as a UK-hosted, cloud-native service operated by a managed service provider, with resilience and continuity built into the hosting and operational model. The service uses automated, monitored backups stored in secure UK locations, ensuring data can be recovered in the event of service disruption, system failure or data corruption.
As a minimum acceptable resilience capability, endev-o is designed to support restoration of service from a verified backup within four hours (Recovery Time Objective), with backups no more than one hour old (Recovery Point Objective). This approach provides a proportionate level of resilience aligned to the service’s role as an information management and data assurance platform, while avoiding unnecessary complexity.
Disaster recovery and business continuity procedures are documented and managed by the service provider, with defined responsibilities for incident response, escalation and recovery. Backup integrity and restore processes are tested periodically to provide confidence in recoverability.
This approach ensures endev-o remains available, recoverable and reliable, supporting the Users expectations for continuity, data protection and operational assurance - Outage reporting
- Users can sign up and receive e-mail alerts in the event of the system experiencing an outage or degraded performance.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- Identity federation with Microsoft Entra ID (Azure Active Directory) using Microsoft Authenticator for MFA
- Access restrictions in management interfaces and support channels
- A user cannot access a project without being a member of it; they must temporarily add themselves. This is an administrative function that is audited so we can know which of our staff had access to which projects at which time. Any changes that user made to the project would also be audited.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- CyberEssentials. Currently progressing CyberEssentials+
- Information security policies and processes
- At Amodal, safeguarding the integrity and confidentiality of our software and services is paramount. We are committed to meeting industry standards for information security, ensuring compliance through comprehensive policies and procedures encompassing information security, acceptable use, privacy and incident reporting. Our dedication to maintaining the highest standards is evidenced by our annual independent audits and maintaining accreditations including ISO 27001, Cyber Essentials and actively progressing Cyber Essentials +. These measures demonstrate our commitment to protecting the data entrusted to us and maintaining the trust of our clients and stakeholders. Copies of these policies are available on request
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Changes are requested either by a customer or internally. The product team meets every fortnight in line with our sprint cycle to review requests and discuss the next fortnight's work, and what features should be prioritised. A technical specification is prepared by the product management lead and signed off by the technical director. After a developer prepares the changes, they are code reviewed reviewed by the technical director and Head of Development. During the code review, we identify potential security risks and mitigate them wherever possible. We use the same approach for changes to servers, patches or configurations.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We monitor operating system and platform security advisories through maintained Ubuntu and Windows security alert mailing lists and feeds, which are reviewed daily to identify any relevant vulnerabilities. Security patches are normally deployed first to a staging environment and tested for stability over two to three days before release to production. For critical or widely exploited issues, this process is accelerated and patches are prioritised, typically within 24 hours or less. We maintain a security risk register that is reviewed regularly to track risks, mitigations and residual exposure, ensuring continued visibility of our security posture.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We operate continuous protective monitoring using automated alerts and logging to identify anomalous activity or indicators of potential compromise across our environments. Where an alert is raised, it is triaged immediately to determine whether it reflects expected behaviour, configuration error or unintended developer activity.
If a potential compromise is suspected, the affected system is isolated from the network for investigation, with broader containment controls applied if required. Alerts trigger SMS notifications to senior technical staff and are reviewed within minutes, enabling rapid assessment, containment and remediation in line with the severity of the incident. - Incident management type
- Supplier-defined controls
- Incident management approach
- We operate defined incident management processes for common operational and security events, supported by automated monitoring and alerting. Users can report incidents through our online support ticketing system or via their account manager. In most cases, monitoring detects potential issues, such as abnormal resource usage, before users are impacted, allowing proactive resolution without downtime. Where incidents occur, updates and incident reports are communicated to customers through our service status web page, with additional follow-up provided as appropriate.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 4%
- Between £1,000,001 and £2,500,000
- 6%
- Between £2,500,001 and £5,000,000
- 8%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Monday 18 August 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A - the whole business was covered as part of the review
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Monday 18 August 2025
- What the ISO 9001 doesn’t cover
- N/A - the whole business was covered as part of the review
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B315ae37-d443-4d81-a325-3143f67b4431
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-