Skip to main content

Help us improve the Digital Marketplace - send your feedback

MIGO CONSULT LTD

Learning Management System (LMS) (SaaS)

Migo LMS is a cloud-hosted Learning Management System (SaaS) for rail operators. It supports digital training delivery, assessments, certification, and auditable training records aligned to rail standards and competency frameworks. The service enables structured learning, compliance reporting, and integration with existing competence management systems.

Features

  • Cloud-hosted learning management system designed for rail training
  • Role-based learning plans aligned to competency frameworks
  • Online courses with quizzes and automated assessments
  • Certification and digital badges for competence evidence
  • Audit-ready training records and learner histories
  • Scheduling, notifications, and deadline reminders
  • SCORM and xAPI compliant learning content support
  • Integration with existing competence management systems
  • Secure role-based access for administrators and learners
  • Web-based access with optional mobile learning support

Benefits

  • Improve workforce competence and regulatory compliance
  • Reduce administrative effort through automated training management
  • Provide clear audit evidence for regulators and assurance teams
  • Accelerate rollout of new training programmes
  • Improve learner engagement with structured digital learning
  • Ensure consistent training delivery across the organisation
  • Support role-specific learning and development pathways
  • Maintain complete, searchable training histories
  • Enable scalable training without additional infrastructure
  • Support continuous improvement through accessible training data

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jason.durk@migoconsult.co. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 3 7 2 7 2 1 5 3 7 8 2 5 2 9

Contact

MIGO CONSULT LTD Jason Durk
Telephone: 07767644659
Email: jason.durk@migoconsult.co

About your service

Service categories

Applications

Enterprise resource management

Human capital management

  • Talent Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Migo LMS can integrate with existing competency management and HR systems via APIs. It can also be deployed as a standalone learning management platform without dependency on other software services.
Cloud deployment model
Public cloud
Service constraints
Migo LMS is delivered as a cloud-hosted SaaS solution and requires a modern web browser and internet connectivity. Planned maintenance is carried out outside core business hours where possible, with advance notice provided. Some functionality may require configuration or onboarding support. Performance depends on network connectivity.
System requirements
  • Modern web browser supporting HTML5 and JavaScript
  • Stable internet connection for cloud access
  • User account with appropriate role-based permissions
  • PDF and spreadsheet software for exports
  • API access enabled for system integrations

User support

Email or online ticketing support
Yes
Support response times
Email and ticketing support is provided during UK business hours, Monday to Friday.
Initial response is typically provided within one business day.
Response times may be longer outside business hours, weekends, and UK public holidays.
Priority incidents are triaged and escalated as appropriate.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support is provided across three levels:

Standard Support (included):
Email and ticketing support during UK business hours (09:00–17:00, Monday to Friday). Covers incident logging, user queries, configuration assistance, and first-line issue resolution. Escalation to second-line and vendor support as required.

Enhanced Support (optional, additional cost):
Extended support hours and faster response targets. Includes second-line technical support, configuration troubleshooting, integration support, and coordinated escalation with the software vendor.

Premium Support (optional, additional cost):
Includes all Enhanced Support features plus a named technical account manager. Provides proactive service reviews, change coordination, release planning, and priority escalation management.

A named UK-based service manager or technical account manager can be provided for Enhanced and Premium support tiers. Pricing for Enhanced and Premium support is provided separately and depends on service scope and required response times.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Onboarding is delivered through a structured implementation and training approach tailored to each customer. This typically includes initial service setup, configuration of learning structures, user accounts, roles, and reporting, and migration of training content where required.

Users are supported through remote onboarding workshops, role-based training sessions for administrators and instructors, and guided configuration activities delivered by experienced implementation consultants. Onsite training can be provided where required at additional cost.

Comprehensive user documentation, configuration guides, and reference materials are provided to support day-to-day use and administration of the service. Ongoing support is available via email and online ticketing, with escalation to specialist support where needed.

The onboarding approach is designed to support rapid adoption and ensure users are confident using the service from go-live.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
At the end of the contract, customers can request extraction of their data held within Migo LMS. Data is provided in commonly used, open formats such as CSV, Excel, or other agreed structured formats to support reuse and migration to alternative systems.

Data extracts can be generated via standard export functionality and, where required, through supported API-based exports. Assistance with data extraction and validation can be provided as part of the offboarding process.

The scope of exported data includes customer-owned training records, learning history, certification data, user information, configuration data, and associated audit information where applicable. Personal data is handled in accordance with data protection requirements.

Data extraction is completed within an agreed timeframe following contract termination, subject to any contractual notice periods.
End-of-contract process
At the end of the contract, access to the Migo LMS service is maintained for the duration of any agreed notice period. During this time, customers may request extraction of their data in line with the agreed data export approach.

Standard data extraction, provided in commonly used formats, and account closure are included within the contract price. Reasonable assistance to support data handover and transition is provided where required.

Following confirmation that data extraction has been completed, user access is removed and customer data is securely deleted in accordance with data protection requirements and retention policies.

Additional services, such as extended access periods, bespoke data transformation, migration support, or on-site offboarding assistance, can be provided at additional cost by agreement.

No proprietary tools or licences are required to access exported data, supporting supplier exit and transition to alternative solutions.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Migo LMS provides a responsive, browser-based interface accessible on mobile devices for learning, assessments, and content access. The desktop interface remains the primary environment for administration, configuration, reporting, and content management.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Migo LMS provides a web-based user interface accessed via a modern browser. The interface is role-based and configurable, presenting dashboards, courses, assessments, certifications, and reports relevant to each user’s role. Administrators manage content, users, and reporting, while learners access assigned training and learning records. Secure APIs support integration with external competence or HR systems.
Accessibility standards
None or don’t know
Description of accessibility
Migo LMS is accessed through a modern web browser and does not require local installation. Users can navigate using standard keyboard and mouse controls, with support for browser zoom and responsive layouts. Role-based views reduce interface complexity. The service does not currently provide formal accessibility modes or guaranteed compatibility with all assistive technologies.
Accessibility testing
Formal usability testing with users of assistive technologies has not yet been conducted. Migo LMS has been developed using standard web technologies and is used by a wide range of learners and administrators in live rail training environments. Accessibility considerations are reviewed during ongoing development, and reasonable adjustments can be discussed during implementation or onboarding.
API
Yes
What users can and can't do using the API
Migo LMS provides a secure, documented API that enables authorised systems to integrate with the platform. The API can be used to manage users, roles, courses, enrolments, learning records, and certification data, supporting integration with competency management or HR systems. API access is configured during implementation, subject to role-based permissions and security controls. The API supports automated data exchange and synchronisation where required.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Migo LMS is highly configurable without requiring code changes. Authorised customer administrators can configure courses, learning pathways, assessments, certifications, user roles, permissions, dashboards, reports, and notifications using built-in administration tools.

Customisation is performed through role-based administration interfaces, allowing organisations to align the service with their training, competency, and compliance requirements. Configuration changes can be applied per organisation or business unit without impacting other tenants.

Advanced configuration, integrations, and content structuring can be supported by the supplier during onboarding or change activity. End users cannot alter core platform code or security controls. All customisation is governed by access permissions and audit logging.

Scaling

Independence of resources
Migo LMS is delivered as a multi-tenant SaaS platform with logical separation of customer data and workloads. The service uses cloud-native scalability, resource allocation controls, and performance monitoring to manage demand across tenants. Core services are designed to scale horizontally, and usage is monitored to detect and manage abnormal load. Where required, tenants can be configured with dedicated resources or capacity limits. This approach ensures that demand from one customer does not adversely impact the performance or availability experienced by others.

Analytics

Service usage metrics
Yes
Metrics types
Migo LMS provides service usage and learning metrics through configurable dashboards and reports. Metrics may include user activity, course enrolments, completion status, assessment results, certification status, and content usage across roles and organisational units.

Metrics are available in near real time where supported by underlying data sources and can be filtered by date, course, role, or organisational unit. Data can be viewed within the application, exported for further analysis, or accessed via APIs where enabled.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data directly from the Migo LMS application using built-in reporting and export tools, subject to role-based permissions. Data can also be extracted via the Migo LMS API for integration or bulk export purposes.

Where required, data exports can be supported by the supplier as part of standard off-boarding or by request during the contract. Exports are provided in commonly used, non-proprietary formats to support analysis, archiving, or migration to other systems.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is designed and operated to provide a target availability of 99.5% measured monthly, excluding planned maintenance. Availability is calculated based on core application access and excludes customer-side connectivity issues, third-party network outages, or force majeure events.

Planned maintenance is scheduled outside normal UK business hours wherever possible and customers are given advance notice. Emergency maintenance may be carried out where required to maintain security or service integrity.

Availability is supported by standard cloud hosting resilience measures including monitored infrastructure, automated recovery mechanisms, and regular backup processes.

If the guaranteed availability level is not met in a given month, customers may be entitled to service credits in accordance with the agreed contract terms. Service credits are calculated as a proportion of the monthly service charge and are applied to future invoices. Refunds are not provided as cash payments.

Full details of availability targets, exclusions, and service credit arrangements are defined in the customer contract and service level agreement.
Approach to resilience
The service is designed using standard cloud resilience principles to minimise the impact of component, infrastructure, or service failures. It is hosted on resilient cloud infrastructure with built-in redundancy across compute, storage, and network components.

The application is designed to tolerate the failure of individual components through automated recovery, monitoring, and alerting. Core services are monitored continuously, with automated restarts and escalation where issues are detected.

Data is protected through regular, automated backups and recovery procedures, enabling restoration in the event of data corruption or loss. Backups are tested periodically to ensure recoverability.

Planned maintenance and updates are managed to minimise disruption to users, with changes introduced in a controlled manner. Where appropriate, maintenance is scheduled outside normal UK business hours.

The underlying datacentre infrastructure is managed by a specialist third-party cloud provider and benefits from physical security, power redundancy, environmental controls, and network resilience. Detailed datacentre resilience information is available to customers on request.
Outage reporting
Service availability is monitored continuously using automated monitoring and alerting. Where an outage or service degradation is identified, affected customers are notified promptly via email.

Customers can also report issues through the service support channels, which are monitored during UK business hours, with escalation for critical incidents. Status updates are provided to affected customers during an outage and following resolution, including confirmation of service restoration.

Where appropriate, outage information and incident summaries can be provided on request. There is currently no public outage dashboard; however, customers are kept informed directly through agreed communication channels.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using role-based access control and the principle of least privilege. Administrative access is limited to authorised personnel only and protected using strong authentication, including multi-factor authentication where supported. Access rights are reviewed periodically and removed promptly when no longer required. Support channels are restricted to authenticated users and controlled internal teams, with sensitive actions logged and auditable. Production access is limited and segregated from standard user access to reduce risk.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Security governance is managed through defined policies, roles and responsibilities, with oversight at senior management level. The organisation follows recognised best practice aligned to the UK Government’s Cyber Essentials controls, including access control, secure configuration, patch management, malware protection and incident response. The organisation is actively working towards Cyber Essentials certification, with formal controls and evidence in place and final assessment planned. Security risks are reviewed regularly and governance processes are continually improved.
Information security policies and processes
The organisation follows a defined set of information security policies and operational processes covering access control, data protection, incident management, secure development, change management and supplier assurance. Policies are aligned with UK Government Cyber Essentials guidance and relevant NCSC best practice.

Responsibility for information security sits with senior management, with day-to-day implementation managed by designated technical and operational leads. Security risks, incidents and exceptions are reported through an established escalation process and reviewed at management level.

Compliance with policies is enforced through role-based access controls, documented procedures, peer review, and regular operational checks. Staff and contractors are required to follow security policies as part of their engagement, and security considerations are embedded into system design, development and deployment activities.

Policies and processes are reviewed regularly and updated as the service evolves, with ongoing improvements driven by risk assessment, operational experience and external guidance.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and change management is managed through defined internal processes. All service components, including application code, infrastructure and third-party dependencies, are version-controlled and tracked throughout their lifecycle. Changes are proposed, reviewed and approved before implementation, with consideration given to security, availability and data protection impacts. Changes are tested in non-production environments prior to deployment and can be rolled back if required. Security-relevant changes are subject to additional review by senior technical staff, and changes are logged to provide an auditable record of configuration and release history.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerabilities are managed through a risk-based process covering infrastructure, platform and application components. Potential threats are assessed using a combination of supplier security advisories, cloud platform notifications, CVE databases, and guidance from NCSC and Cyber Essentials. Vulnerabilities are triaged based on severity and exposure, with critical patches deployed as soon as practicable, and high-risk issues addressed within defined timescales. Patching and updates are tested prior to deployment and applied through controlled change processes. Ongoing monitoring and periodic reviews ensure emerging threats are identified and mitigated promptly.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is implemented through a combination of cloud platform monitoring, application logging, and alerting. Logs are collected for access, authentication, configuration changes, and application activity, and reviewed for anomalous or suspicious behaviour. Automated alerts are configured for security-relevant events, with escalation to technical staff for investigation. Where a potential compromise is identified, access can be restricted, credentials rotated, and affected components isolated as required. Incidents are assessed promptly, with initial response typically within hours, and corrective actions tracked to resolution.
Incident management type
Supplier-defined controls
Incident management approach
The service operates a defined incident management process covering common operational and security events. Incidents can be reported by users via a dedicated support email or service desk, and are logged, prioritised, and triaged according to severity and potential impact.

Pre-defined response procedures are in place for common incident types, including service availability issues and security events. Customers are kept informed during incidents and provided with post-incident reports outlining cause, impact, and corrective actions where appropriate.

Incident handling and escalation are overseen by senior technical staff, with lessons learned fed back into service improvement and risk management activities.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
4%
Between £1,000,001 and £2,500,000
6%
Between £2,500,001 and £5,000,000
8%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jason.durk@migoconsult.co. Tell them what format you need. It will help if you say what assistive technology you use.