Skip to main content

Help us improve the Digital Marketplace - send your feedback

NEWCROSS HEALTHCARE SOLUTIONS LIMITED

Newcross Healthcare Solutions - Software Platforms

Opserra is a comprehensive service platform that enables clients to efficiently manage their entire workforce solution, including Bank, temporary staffing and rostering. The platform provides robust controls to standardise processes, ensure compliance, and optimise resource allocation. Powerful data insights and analytics support informed decision-making, improved performance, and cost-effective workforce management.

Features

  • Real-time reporting delivers instant workforce insights for informed.
  • Skill Matching workflows Automated workflows accurately match skills to roles
  • Secure web application enables easy access anywhere, supporting efficient workforce.
  • User-friendly staff software manages shifts, availability, communication, improving reliability.
  • Direct booking features let managers choose specific staff for shifts.
  • Two-way API integration streamlines data exchange ensuring accuracy crosssystems
  • Remote access enables staff and managers to securely work anywhere.

Benefits

  • Instantly view live workforce data to drive faster, smarter decisions.
  • Automatically match staff skills to roles, ensuring safe compliant staffing.
  • Speed up workflows by automating updates across integrated systems.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@newcrosshealthcare.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 4 5 2 8 7 4 2 1 8 9 7 5 9 9

Contact

NEWCROSS HEALTHCARE SOLUTIONS LIMITED Alix Ripley
Telephone: 07341440027
Email: tenders@newcrosshealthcare.com

About your service

Service categories

Application Development and Deployment

Application platforms

  • Robotic process automation
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
No constraints. There are currently no constraints buyers need to be aware of. We do not limit support to particular hardware configurations, and we do not have planned maintenance arrangements that would disrupt service access. Our offering is designed to operate reliably without imposing technical or operational restrictions on users.
System requirements
Software licenses

User support

Email or online ticketing support
Yes
Support response times
We monitor our ticketing system with strict SLAs which are as follows: Urgent: 4 hours. BAU: 24 hours. Questions are triaged through automation and assigned to appropriate support agents.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
EN 301 549
Web chat accessibility testing
We are currently working towards WCAG 2.1 certification and compliance awaiting our messenger being re-assessed and certified formally. In the meantime, we have implemented several improvements including:
Keyboard Navigation:
Arrow key navigation in chat windows
Four-directional navigation for emoji/GIF pickers
Updated ESC key behavior
Visible skip links when focused
Screen Reader Support:
Logical heading hierarchies
Proper status message announcements
Accessible names for reactions and language controls
Accurate alt attributes for non-text content
Onsite support
Yes
Support levels
Support is provided via email, ticketing, phone, web chat and online services. These are monitored and performance managed via robust SLAs and operate 24/7. Included in the pricing, a technical account manager and access to could support engineers will be provided. They will perform necessary maintenance, issue resolution or change requests to uphold service quality and ensure a positive user experience. Client specific requests that are beyond the scope of the call off contract will be quoted accordingly with estimates for completion advised.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
A comprehensive implementation plan will be designed and launched to set up their organisation within the platform.
This includes tasks such as:
Configuring user roles and permissions: Defining different levels of access and privileges for users
Customising workflows: Tailoring workflows and processes within the platform to match the client's existing organisational practices and requirements.
Integrating with existing systems: Connecting with other software systems or databases used by the client's organisation to ensure interoperability.
Setting up reporting and analytics: Configuring reporting tools and dashboards within the platform to track key performance indicators (KPIs) and performance.
Training administrators: Providing training and guidance to administrators within the client's organisation.
User Onboarding: Our user onboarding process for ensures seamless adoption and maximises user proficiency through comprehensive support measures.
Platform Demos: We offer personalised platform demos conducted by our dedicated customer success team.
New User Online Tutorial: Upon first login, users are greeted with an intuitive new user online tutorial. This tutorial, comprised of interactive wayfinders, guides users through the platform's functionalities step-by-stepand covers all essential tasks.
In-App Help Centre: Our platform features an in-app help centre accessible from every page, providing users with instant access to contextualised FAQ and support content.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
During the offboarding procedure a project plan including data capture and handoffs will be produced in full consultation with the customer. This will include data handoff points, formats, ownership, governance and any other considerations required. We will work with the customer to design tailored/custom reporting downloads and access to any reporting required. Furthermore, post the contract end date and exit strategy, there will be a latency period whereby we can facilitate any reports for a period which will be agreed upon within the offboarding procedure. The main format for data download will be via CSV but we can work to a clients requirements within reason.
End-of-contract process
Our off-boarding process ensures a seamless transition for clients, adhering to contractual terms and data protection regulations while accommodating specific client needs.
We collaborate with the client throughout the offboarding process, liaising with all appointed stakeholders and 3rd parties as instructed by the client, ensuring clear communication and alignment with the clients expectations and requirements.
Using Prince-2 methodology, tailored project plans would be created and signed off, with clear milestones including data sharing, communication packages, system hand-offs and workforce transition, ensuring no impact on patient care and a seamless transition.
Our standard off-boarding process is simple and straightforward. It involves extracting data from the platform and providing it to the client in an accessible format. Additionally, we secure closure of all client user accounts within an agreed timeframe, in compliance with Call-Off contract terms and Data Protection Laws.
We ensure that clients can effectively transition out of our services while safeguarding their data and meeting contractual obligations. Our commitment to collaboration and support helps minimise disruptions and facilitates a smooth exit for clients.
Documentation accessibility standard
EN 301 549

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The product is optimised for use on a desktop device (laptop/mac/PC), but is accessible on a mobile browser. Due to the nature of some interactions, some features are better accessed on web, such as reporting and analytics, due to the usage of large data sets.
Service interface
Yes
User support accessibility
EN 301 549
Description of service interface
The interface is easy to use and accessible to the highest standard. We conduct usability testing throughout the design and implemtation phases to ensure the product is easy to understand and use.
Accessibility standards
EN 301 549
Accessibility testing
N/A
API
No
Customisation available
Yes
Description of customisation
The design and color scheme can be customised to the clients branding. This will be applied at a global level in the product.

Scaling

Independence of resources
The scalability of cloud infrastructure ensures that users aren't impacted by any increases of demand in users on the service. The system has been tested for 5000 concurrect same actions with no service impact.

Analytics

Service usage metrics
Yes
Metrics types
We provide real-time dashboarding within the product, giving histroical and future views. Top line metrics such as booking status, coverage, agency performance, cancellations, compliance and financial performance are all available in real time. Invoicing and statement generation is available within the product. Custom date filters can be set, to generate on demand data for your desired time frames.
Reporting types
Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Other
Other data at rest protection approach
Data at rest is protected using AES-256 encryption across all AWS storage services (S3, EBS, RDS). Encryption keys are managed through AWS Key Management Service (KMS) with strict access controls and audit logging. Physical media in AWS data centres is encrypted and subject to rigorous security standards, including ISO 27001 and CSA CCM. This ensures confidentiality and compliance with recognised security frameworks.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Real time dashboards, downloadable reports (CSV and PDF) and access to a full reporting suite and BI dashboard.
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
  • CSV
  • Other
Other data import formats
PDF

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Our production services under the framework guarantee 99.95% availability, measured monthly. Services are hosted on Amazon Web Services (AWS), leveraging its highly available infrastructure. The SLA covers all core components, including compute, storage, and networking. Availability is monitored continuously using automated systems across redundant infrastructure. If availability falls below the guaranteed level, customers are eligible for service credits, calculated based on downtime and applied to the next billing cycle. Services are deployed in the AWS London region as the primary location, with failover capability to AWS Dublin to ensure continuity during regional disruptions. Planned maintenance is communicated in advance, and we aim to perform updates without service interruption. In the rare event of an outage, our incident response team works to restore service promptly while keeping customers informed. Full SLA details, including refund mechanisms, are available upon request.
Approach to resilience
Our production services are designed for resilience through AWS’s multi-region architecture. The primary hosting location is AWS London, with a tested failover capability to AWS Dublin in the event of a major incident or regional outage. This ensures continuity even if the primary region becomes unavailable. AWS data centres meet Tier 3 or higher standards and provide redundant power, cooling, and network connectivity. Data is replicated in real time across availability zones within the London region, and backups are encrypted and stored in separate locations. Disaster recovery plans include automated failover and are tested regularly to meet strict Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). This architecture ensures our production services maintain integrity under adverse conditions, including hardware failures or regional outages.
Outage reporting
All AWS-hosted production services under the framework provide transparent and timely outage reporting through multiple channels. Outages are categorised by severity, and updates include root cause analysis, estimated resolution times, and mitigation steps. Our communication process ensures initial notification within 30 minutes of detection, followed by regular updates until resolution. A detailed post-incident report is published within 72 hours, outlining the cause, impact, and corrective actions taken. Historical incident reports remain accessible via the dashboard for audit and compliance purposes. This multi-channel approach ensures customers have accurate, timely information to manage their operations effectively during service disruptions.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Other
Other user authentication
Role-based controls, least privilege, and encrypted channels.
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels for AWS-hosted production services is strictly controlled using role-based access control (RBAC) and the principle of least privilege. All administrative access requires Multi-Factor Authentication (MFA) and encrypted connections (TLS). Privileged accounts are segregated and monitored through AWS IAM policies and CloudTrail logging. Support channels are restricted to authorised personnel, with identity verification before any action is taken. Access rights are reviewed regularly and revoked immediately upon role changes or termination. Automated alerts and periodic audits ensure compliance and prevent unauthorised access, maintaining the integrity and security of management operations.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Our production services operate under a comprehensive set of information security policies and procedures aligned with and certified to ISO/IEC 27001. These policies cover all aspects of security governance, including access control, data protection, incident management, vulnerability management, and secure development practices. The framework ensures that responsibilities are clearly defined, with escalation paths up to board level for security oversight. Compliance is enforced through mandatory staff training, regular audits, and automated monitoring controls. Policies are reviewed annually and updated to reflect emerging threats and regulatory requirements. Reporting structures ensure that any deviation or security event is escalated promptly to the appropriate authority. Continuous improvement is achieved through internal audits, penetration testing, and lessons learned from incidents. This approach guarantees that security policies are not only documented but actively implemented and monitored across all AWS-hosted production services, maintaining confidentiality, integrity, and availability of customer data
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Our AWS-hosted production services follow a structured configuration and change management process aligned with recognised standards. All service components are tracked throughout their lifecycle. Changes undergo formal assessment for security, compliance, and operational impact before approval. High-risk changes require additional security review and rollback plans. All changes are logged, version-controlled, and tested in staging environments prior to deployment. Emergency changes follow expedited but documented procedures. This approach ensures traceability, accountability, and minimises risk to service integrity while maintaining compliance with industry best practices.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Our AWS-hosted production services follow a proactive vulnerability management process. We utilise AWS Inspector for continuous scanning of cloud workloads and GitHub Advanced Security for code-level vulnerability detection. Threat intelligence is sourced from NCSC advisories, CVE databases, and vendor feeds. Identified vulnerabilities are assessed for severity and potential impact, with critical patches deployed within 24 hours and others following a risk-based schedule. All patches are tested in staging environments before production rollout. Regular penetration testing and compliance audits validate our approach, ensuring rapid response to emerging threats and maintaining a secure environment.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Our AWS-hosted production services implement continuous monitoring aligned with ISO 27001 standards. We leverage AWS CloudTrail, Security Hub, and GuardDuty for real-time log analysis, anomaly detection, and threat intelligence. These feeds are integrated into our UK-based 24/7 Security Operations Centre (SOC), which provides round-the-clock monitoring and incident response. Alerts are triaged immediately, and suspected compromises trigger predefined workflows. Critical incidents are responded to within 30 minutes, with containment and remediation actions documented. This layered approach ensures rapid detection, proactive threat management, and compliance with recognised security standards.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Our services follow a formal Incident Management Policy and Process aligned with ISO 27001 and industry best practices. We maintain predefined playbooks for common events such as service outages, security breaches, and DDoS attacks. Incidents are detected through automated monitoring. The UK-based 24/7 SOC coordinates triage and response, ensuring containment within defined SLAs. Customers receive timely updates and a detailed incident report within 72 hours, including root cause analysis and corrective actions. Regular reviews and simulations ensure continuous improvement of our incident response capability.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
2%
Between £250,000 and £500,000
6%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Citation ISO
ISO/IEC 27001 accreditation date
Saturday 20 May 2023
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
None of the criteria
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
00bb5d87-8f14-4b2e-b85f-f4f9dc9149e2
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@newcrosshealthcare.com. Tell them what format you need. It will help if you say what assistive technology you use.