Newcross Healthcare Solutions - Software Platforms
Opserra is a comprehensive service platform that enables clients to efficiently manage their entire workforce solution, including Bank, temporary staffing and rostering. The platform provides robust controls to standardise processes, ensure compliance, and optimise resource allocation. Powerful data insights and analytics support informed decision-making, improved performance, and cost-effective workforce management.
Features
- Real-time reporting delivers instant workforce insights for informed.
- Skill Matching workflows Automated workflows accurately match skills to roles
- Secure web application enables easy access anywhere, supporting efficient workforce.
- User-friendly staff software manages shifts, availability, communication, improving reliability.
- Direct booking features let managers choose specific staff for shifts.
- Two-way API integration streamlines data exchange ensuring accuracy crosssystems
- Remote access enables staff and managers to securely work anywhere.
Benefits
- Instantly view live workforce data to drive faster, smarter decisions.
- Automatically match staff skills to roles, ensuring safe compliant staffing.
- Speed up workflows by automating updates across integrated systems.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 4 5 2 8 7 4 2 1 8 9 7 5 9 9
Contact
NEWCROSS HEALTHCARE SOLUTIONS LIMITED
Alix Ripley
Telephone: 07341440027
Email: tenders@newcrosshealthcare.com
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Robotic process automation
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No constraints. There are currently no constraints buyers need to be aware of. We do not limit support to particular hardware configurations, and we do not have planned maintenance arrangements that would disrupt service access. Our offering is designed to operate reliably without imposing technical or operational restrictions on users.
- System requirements
- Software licenses
User support
- Email or online ticketing support
- Yes
- Support response times
- We monitor our ticketing system with strict SLAs which are as follows: Urgent: 4 hours. BAU: 24 hours. Questions are triaged through automation and assigned to appropriate support agents.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- EN 301 549
- Web chat accessibility testing
-
We are currently working towards WCAG 2.1 certification and compliance awaiting our messenger being re-assessed and certified formally. In the meantime, we have implemented several improvements including:
Keyboard Navigation:
Arrow key navigation in chat windows
Four-directional navigation for emoji/GIF pickers
Updated ESC key behavior
Visible skip links when focused
Screen Reader Support:
Logical heading hierarchies
Proper status message announcements
Accessible names for reactions and language controls
Accurate alt attributes for non-text content - Onsite support
- Yes
- Support levels
- Support is provided via email, ticketing, phone, web chat and online services. These are monitored and performance managed via robust SLAs and operate 24/7. Included in the pricing, a technical account manager and access to could support engineers will be provided. They will perform necessary maintenance, issue resolution or change requests to uphold service quality and ensure a positive user experience. Client specific requests that are beyond the scope of the call off contract will be quoted accordingly with estimates for completion advised.
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
A comprehensive implementation plan will be designed and launched to set up their organisation within the platform.
This includes tasks such as:
Configuring user roles and permissions: Defining different levels of access and privileges for users
Customising workflows: Tailoring workflows and processes within the platform to match the client's existing organisational practices and requirements.
Integrating with existing systems: Connecting with other software systems or databases used by the client's organisation to ensure interoperability.
Setting up reporting and analytics: Configuring reporting tools and dashboards within the platform to track key performance indicators (KPIs) and performance.
Training administrators: Providing training and guidance to administrators within the client's organisation.
User Onboarding: Our user onboarding process for ensures seamless adoption and maximises user proficiency through comprehensive support measures.
Platform Demos: We offer personalised platform demos conducted by our dedicated customer success team.
New User Online Tutorial: Upon first login, users are greeted with an intuitive new user online tutorial. This tutorial, comprised of interactive wayfinders, guides users through the platform's functionalities step-by-stepand covers all essential tasks.
In-App Help Centre: Our platform features an in-app help centre accessible from every page, providing users with instant access to contextualised FAQ and support content. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- During the offboarding procedure a project plan including data capture and handoffs will be produced in full consultation with the customer. This will include data handoff points, formats, ownership, governance and any other considerations required. We will work with the customer to design tailored/custom reporting downloads and access to any reporting required. Furthermore, post the contract end date and exit strategy, there will be a latency period whereby we can facilitate any reports for a period which will be agreed upon within the offboarding procedure. The main format for data download will be via CSV but we can work to a clients requirements within reason.
- End-of-contract process
-
Our off-boarding process ensures a seamless transition for clients, adhering to contractual terms and data protection regulations while accommodating specific client needs.
We collaborate with the client throughout the offboarding process, liaising with all appointed stakeholders and 3rd parties as instructed by the client, ensuring clear communication and alignment with the clients expectations and requirements.
Using Prince-2 methodology, tailored project plans would be created and signed off, with clear milestones including data sharing, communication packages, system hand-offs and workforce transition, ensuring no impact on patient care and a seamless transition.
Our standard off-boarding process is simple and straightforward. It involves extracting data from the platform and providing it to the client in an accessible format. Additionally, we secure closure of all client user accounts within an agreed timeframe, in compliance with Call-Off contract terms and Data Protection Laws.
We ensure that clients can effectively transition out of our services while safeguarding their data and meeting contractual obligations. Our commitment to collaboration and support helps minimise disruptions and facilitates a smooth exit for clients. - Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The product is optimised for use on a desktop device (laptop/mac/PC), but is accessible on a mobile browser. Due to the nature of some interactions, some features are better accessed on web, such as reporting and analytics, due to the usage of large data sets.
- Service interface
- Yes
- User support accessibility
- EN 301 549
- Description of service interface
- The interface is easy to use and accessible to the highest standard. We conduct usability testing throughout the design and implemtation phases to ensure the product is easy to understand and use.
- Accessibility standards
- EN 301 549
- Accessibility testing
- N/A
- API
- No
- Customisation available
- Yes
- Description of customisation
- The design and color scheme can be customised to the clients branding. This will be applied at a global level in the product.
Scaling
- Independence of resources
- The scalability of cloud infrastructure ensures that users aren't impacted by any increases of demand in users on the service. The system has been tested for 5000 concurrect same actions with no service impact.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide real-time dashboarding within the product, giving histroical and future views. Top line metrics such as booking status, coverage, agency performance, cancellations, compliance and financial performance are all available in real time. Invoicing and statement generation is available within the product. Custom date filters can be set, to generate on demand data for your desired time frames.
- Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Other
- Other data at rest protection approach
- Data at rest is protected using AES-256 encryption across all AWS storage services (S3, EBS, RDS). Encryption keys are managed through AWS Key Management Service (KMS) with strict access controls and audit logging. Physical media in AWS data centres is encrypted and subject to rigorous security standards, including ISO 27001 and CSA CCM. This ensures confidentiality and compliance with recognised security frameworks.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Real time dashboards, downloadable reports (CSV and PDF) and access to a full reporting suite and BI dashboard.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
-
- CSV
- Other
- Other data import formats
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Our production services under the framework guarantee 99.95% availability, measured monthly. Services are hosted on Amazon Web Services (AWS), leveraging its highly available infrastructure. The SLA covers all core components, including compute, storage, and networking. Availability is monitored continuously using automated systems across redundant infrastructure. If availability falls below the guaranteed level, customers are eligible for service credits, calculated based on downtime and applied to the next billing cycle. Services are deployed in the AWS London region as the primary location, with failover capability to AWS Dublin to ensure continuity during regional disruptions. Planned maintenance is communicated in advance, and we aim to perform updates without service interruption. In the rare event of an outage, our incident response team works to restore service promptly while keeping customers informed. Full SLA details, including refund mechanisms, are available upon request.
- Approach to resilience
- Our production services are designed for resilience through AWS’s multi-region architecture. The primary hosting location is AWS London, with a tested failover capability to AWS Dublin in the event of a major incident or regional outage. This ensures continuity even if the primary region becomes unavailable. AWS data centres meet Tier 3 or higher standards and provide redundant power, cooling, and network connectivity. Data is replicated in real time across availability zones within the London region, and backups are encrypted and stored in separate locations. Disaster recovery plans include automated failover and are tested regularly to meet strict Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). This architecture ensures our production services maintain integrity under adverse conditions, including hardware failures or regional outages.
- Outage reporting
- All AWS-hosted production services under the framework provide transparent and timely outage reporting through multiple channels. Outages are categorised by severity, and updates include root cause analysis, estimated resolution times, and mitigation steps. Our communication process ensures initial notification within 30 minutes of detection, followed by regular updates until resolution. A detailed post-incident report is published within 72 hours, outlining the cause, impact, and corrective actions taken. Historical incident reports remain accessible via the dashboard for audit and compliance purposes. This multi-channel approach ensures customers have accurate, timely information to manage their operations effectively during service disruptions.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Other
- Other user authentication
- Role-based controls, least privilege, and encrypted channels.
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels for AWS-hosted production services is strictly controlled using role-based access control (RBAC) and the principle of least privilege. All administrative access requires Multi-Factor Authentication (MFA) and encrypted connections (TLS). Privileged accounts are segregated and monitored through AWS IAM policies and CloudTrail logging. Support channels are restricted to authorised personnel, with identity verification before any action is taken. Access rights are reviewed regularly and revoked immediately upon role changes or termination. Automated alerts and periodic audits ensure compliance and prevent unauthorised access, maintaining the integrity and security of management operations.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Our production services operate under a comprehensive set of information security policies and procedures aligned with and certified to ISO/IEC 27001. These policies cover all aspects of security governance, including access control, data protection, incident management, vulnerability management, and secure development practices. The framework ensures that responsibilities are clearly defined, with escalation paths up to board level for security oversight. Compliance is enforced through mandatory staff training, regular audits, and automated monitoring controls. Policies are reviewed annually and updated to reflect emerging threats and regulatory requirements. Reporting structures ensure that any deviation or security event is escalated promptly to the appropriate authority. Continuous improvement is achieved through internal audits, penetration testing, and lessons learned from incidents. This approach guarantees that security policies are not only documented but actively implemented and monitored across all AWS-hosted production services, maintaining confidentiality, integrity, and availability of customer data
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Our AWS-hosted production services follow a structured configuration and change management process aligned with recognised standards. All service components are tracked throughout their lifecycle. Changes undergo formal assessment for security, compliance, and operational impact before approval. High-risk changes require additional security review and rollback plans. All changes are logged, version-controlled, and tested in staging environments prior to deployment. Emergency changes follow expedited but documented procedures. This approach ensures traceability, accountability, and minimises risk to service integrity while maintaining compliance with industry best practices.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Our AWS-hosted production services follow a proactive vulnerability management process. We utilise AWS Inspector for continuous scanning of cloud workloads and GitHub Advanced Security for code-level vulnerability detection. Threat intelligence is sourced from NCSC advisories, CVE databases, and vendor feeds. Identified vulnerabilities are assessed for severity and potential impact, with critical patches deployed within 24 hours and others following a risk-based schedule. All patches are tested in staging environments before production rollout. Regular penetration testing and compliance audits validate our approach, ensuring rapid response to emerging threats and maintaining a secure environment.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Our AWS-hosted production services implement continuous monitoring aligned with ISO 27001 standards. We leverage AWS CloudTrail, Security Hub, and GuardDuty for real-time log analysis, anomaly detection, and threat intelligence. These feeds are integrated into our UK-based 24/7 Security Operations Centre (SOC), which provides round-the-clock monitoring and incident response. Alerts are triaged immediately, and suspected compromises trigger predefined workflows. Critical incidents are responded to within 30 minutes, with containment and remediation actions documented. This layered approach ensures rapid detection, proactive threat management, and compliance with recognised security standards.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Our services follow a formal Incident Management Policy and Process aligned with ISO 27001 and industry best practices. We maintain predefined playbooks for common events such as service outages, security breaches, and DDoS attacks. Incidents are detected through automated monitoring. The UK-based 24/7 SOC coordinates triage and response, ensuring containment within defined SLAs. Customers receive timely updates and a detailed incident report within 72 hours, including root cause analysis and corrective actions. Regular reviews and simulations ensure continuous improvement of our incident response capability.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2%
- Between £250,000 and £500,000
- 6%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO
- ISO/IEC 27001 accreditation date
- Saturday 20 May 2023
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 00bb5d87-8f14-4b2e-b85f-f4f9dc9149e2
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-