Digital Financial Support and Fund Management Platform
Lightning Reach provides local authorities with a configurable digital platform to administer ongoing financial support and local funds. The service enables online applications, assessment, vouchers, warm referrals, and access to a wider support ecosystem. This helps councils streamline administration, maximise impact and deliver consistent support across multiple schemes.
Features
- Digital applications for financial support and local funds
- Configurable eligibility rules and application forms
- Identity verification and secure document upload
- Open Banking integration for financial assessment
- Voucher issuance and delivery for direct financial support
- Warm referrals to advice and support services
- Access to additional financial support through Lightning Reach ecosystem
- Shared case records across support journeys
- Real-time outcome and demographic reporting dashboards
- Supports API integration with existing council systems
Benefits
- Provides a single platform for administering financial support
- Reduces administrative effort across multiple funds and schemes
- Improves consistency across financial support decisions
- Enables faster access to financial support for residents
- Maximises impact through access to wider support ecosystem
- Reduces duplicate applications and repeated information collection
- Supports warm handovers between services and partners
- Improves visibility of demand, spend, and outcomes
- Supports flexible delivery across changing policy priorities
- Scales easily across departments and funding streams
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 4 5 0 5 1 6 5 2 8 0 5 8 4 2
Contact
LIGHTNING SOCIAL VENTURES LTD
Dave Farquharson
Telephone: +447361583244
Email: partnerships@lightningreach.org
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service will not auto-renew grants, does not guarantee success in applications and requires accurate input from the user.
- System requirements
-
- Device to access the internet
- Access to internet
User support
- Email or online ticketing support
- Yes
- Support response times
- The average response time for user support is less than 2 hours.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
- The support helpdesk is available to support customers and their clients with any difficulties using the Lightning Reach portal. For certain tiers, a dedicated account manager will be assigned to provide personal support.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- The onboarding process includes personal support in setting up your organisation on the Lightning Reach portal. This includes dedicated online training for all members of staff that will be using the portal.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Extracting data is a bespoke service, which will be available on request
- End-of-contract process
- The offboarding process is bespoke, based on the customer's needs. If necessary, the customer can arrange continued access to end-user data.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Onboarding is supported through a combination of guided setup, direct support and accessible documentation. Customers receive personal support from an onboarding specialist, alongside online training sessions for staff who will use the platform. Supporting guides, forms and reference materials are provided throughout the onboarding process and made available in digital formats that can be accessed using standard assistive technologies. Documentation is designed to be clear, structured and easy to navigate, and can be adapted to align with a customer’s own systems or preferred ways of working where required.
For offboarding, a clear process and timeline is agreed with the customer. Written guidance is provided to support offboarding activities and additional support is available where needed to ensure a smooth transition.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service has been designed to work on a wide range of devices, primarily mobile phones. There are no differences in using the service.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The Lightning Reach portal uses trusted and secure technology to make it easy to find and apply for financial support. We’re collaborating with a range of partners across the UK so you can apply for personalised support from multiple providers, whenever you need it.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The portal is very simple, with large, easy to read buttons and graphics enabling users to access the wide variety of services Lightning Reach offers.
- Accessibility testing
-
We aim to meet WCAG 2.1 AA accessibility standards and have measures in place to support inclusive access. The application portal is fully responsive across devices, supporting readability through scalable font sizes, responsive layouts and appropriate image handling. Colour contrast ratios are designed in line with WCAG AA guidance.
We use automated accessibility testing tools, including Google Lighthouse, to assess accessibility across the platform, with typical scores ranging between 80–90 depending on page content.
Accessibility considerations are embedded into our design and development processes, with ongoing review to support compatibility with commonly used assistive technologies such as screen readers. - API
- Yes
- What users can and can't do using the API
- Users can enable automated data transfer through Lightning Reach to their own CRM system.
- API documentation
- No
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
What can be customised:
Buyers can configure user roles and permissions, eligibility criteria, application forms, custom statuses, reporting fields, and branding elements such as logos and copy.
How users can customise:
Authorised users can make changes directly within the platform using administrative settings. Configuration changes can be applied and updated at any time.
Where preferred, buyers can request configuration changes via their account manager. Where additional custom features or integrations are required beyond standard configuration, these can be delivered as optional services, scoped and agreed in advance.
Who can customise:
Buyer-appointed administrators can manage configuration within the platform. Configuration support can also be provided by the supplier’s account manager on request. Any additional custom services are delivered by the supplier following buyer approval and agreed pricing.
Scaling
- Independence of resources
- Services are running on GCP Cloud Run, with autoscaling enabled. Different parts of the system are decoupled via PubSub messaging. Persistence layer runs on a High Availability cluster.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Service utilisation, API error rates, response times, user engagement, drop-off rates.
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Extracting data is a bespoke service, which will be available on request
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- SLA for portal availability is 99.9%. Refunds can be agreed on case by case.
- Approach to resilience
- Our service is built on Google Cloud Platform, utilising multiple availability zones for resilience and leveraging serverless technologies for efficient scaling. High availability configuration is used for databases, to ensure automatic failover and minimal service disruption.
- Outage reporting
- Customers will be alerted as soon as practically possible of any notable outages or significant incidents. Notifications will be via email through the account manager or support team.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- We use two-factor authentication (2FA) wherever possible to enhance access security. Additionally, we maintain separate accounts for administrators distinct from their daily work accounts, ensuring a clear separation of roles and responsibilities. Permissions to cloud resources are managed using identity and access management principles, strictly adhering to the least privilege principle.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Our security governance is certified to Cyber Essentials. We maintain a valid Cyber Essentials certification and operate security controls aligned with its requirements.
- Information security policies and processes
- Our information security policies and processes are guided by principles from ISO/IEC 27001. We maintain a comprehensive cybersecurity security policy, which is reviewed annually. Our Data Protection Policy complies with GDPR, the UK Data Protection Act 2018, and the Privacy and Electronic Communications Regulations. Our security governance structure involves the CTO, COO, and Data Protection Officer (DPO), all reporting directly to the CEO. This structure ensures that information security is integrated into our top-level management and decision-making processes. To ensure adherence to our policies, we engage in active monitoring and conduct annual security audits, to evaluate the effectiveness of our security measures and identify areas for improvement.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Our configuration and change management process ensures strict environment segregation with dedicated development, testing and production environments. Components of our services are tracked throughout their lifecycle via automated CI/CD pipelines. Changes undergo peer reviews to assess potential security impacts and maintain separation of duties.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Our vulnerability management process involves continuous monitoring and assessment of potential threats through automated scanning and peer reviews. We complement these with annual penetration tests conducted by third-party vendors. Once a vulnerability requiring remediation has been identified, it is logged and prioritized according to severity.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Our protective monitoring processes involve comprehensive logs and audit trails to identify potential security issues. We use alerts based on log severity and system metrics to detect unusual activity quickly. Potential compromised is promptly triaged and response prioritized according to severity.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Incidents can be reported through our support channels or identified automatically by alerts. Upon detection, we follow a standardised process to evaluate the severity, determine necessary communications, and implement mitigation strategies. Playbooks are available for common events to ensure efficient incident resolution. Incident reports are available upon request.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 18%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 99ff5841-0c5e-4614-a192-dfbd73110504
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-