Skip to main content

Help us improve the Digital Marketplace - send your feedback

ADELANTE SOFTWARE LTD

SmartPay

SmartPay by Adelante Software is a secure payments and income management service for public sector organisations. It enables online, telephone and recurring payments, integrates with finance systems, automates reconciliation and reporting, and reduces PCI scope. The service is modular, UK hosted, and supported by specialist teams.

Features

  • Fully hosted SaaS platform accessed through standard web browsers
  • Central management of multiple payment channels within a single platform
  • Validation rules enforced before payments are accepted
  • Configurable funds, VAT rules and payment methods
  • Configurable imports and exports for finance systems
  • Flexible report writer for real time and scheduled reporting
  • Centralised administration portal for users, roles and permissions
  • Advanced search tools for locating payments and customer records
  • Full audit trail for payments, configuration and user actions
  • Secure staff access using MFA or Single Sign-On

Benefits

  • Configure payment channels, funds, and VAT rules without supplier involvement
  • Create, edit, and schedule bespoke reports using built in reporting
  • Build and maintain imports and exports for finance systems internally
  • Prevent payment submission unless validation and balance rules are met
  • Manage payment exceptions and apply rules to support automatic correction
  • Allocate, transfer, and journal income directly within the system
  • Search and locate payments quickly to support customer enquiries
  • Customer administrators control user access through role-based permissions
  • Handle PCI compliant call centre payments securely and consistently
  • Accept operator assisted payments using integrated third party forms

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@adelante.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 5 0 6 7 8 9 8 9 0 3 7 6 3 0

Contact

ADELANTE SOFTWARE LTD Alison Rodwell
Telephone: 01628 820600
Email: sales@adelante.co.uk

About your service

Service categories

Applications

Enterprise resource management

Financial

  • Accounts Receivable Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
No.

The service has no known operational constraints that materially limit buyer use. Infrastructure maintenance is performed as part of routine patching and update cycles, using a resilient and redundant architecture. These activities are designed to avoid service disruption and do not require customer downtime.
System requirements
  • Modern, security-updated web browser
  • Internet access

User support

Email or online ticketing support
Yes
Support response times
Support requests submitted by email or the online ticketing system are acknowledged within 4 business hours during UK business hours, Monday to Friday, excluding public holidays.

In practice, the current average first response time is within one hour.

Out of hours requests are logged and responded to during the next business day.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
The service includes a single standard support level, provided through the Adelante helpdesk during UK business hours, Monday to Friday, excluding public holidays.

Standard support covers incident management, fault resolution, and assistance with normal service operation, delivered in line with published response time targets. The cost of standard support is included within the service price.

Customer support is coordinated by the Helpdesk Manager. Each SmartPay customer is assigned a dedicated Customer Success Manager who supports service oversight and may assist with escalation where appropriate.

A named technical account manager is not provided. Escalated issues are handled by subject matter experts within the technical team, including staff involved in the original implementation who are familiar with the customer’s configuration and processes.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
SmartPay onboarding is delivered as a structured implementation project tailored to the customer’s requirements.

The onboarding process typically includes solution design, configuration of payment channels and funds, integration setup, data validation, user access configuration, and testing. A dedicated, hands on Technical Project Manager coordinates onboarding activity and acts as the primary point of contact throughout delivery.

Training is provided using a train the trainer approach, delivered remotely via Microsoft Teams and supported by user documentation. Hypercare support is provided immediately following go live to support the transition into live service. Additional end user training can be purchased if required.

The scope and duration of onboarding vary depending on the services and modules selected and the complexity of integrations required.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Users cannot directly extract a full copy of their data themselves via the service.

During the contract, users can access and download their data through standard reports available within the SmartPay user interface.

At the end of the contract, customers can request a full data extract from Adelante by submitting a written request. Adelante will perform the extraction on the customer’s behalf.

Data is stored in SQL databases and can be provided in commonly used formats such as CSV or Excel, provided no bespoke development is required.

Extracted data is supplied securely to the customer via an SFTP folder or another agreed secure transfer method if requested by the customer.
End-of-contract process
The return of customer data at contract end and the decommissioning of the service are included within the price of the contract, provided no bespoke development is required to meet the requested data format.

If the customer wishes to retain access to the system after the contract end date, for example to continue querying transactional data or processing refunds through the user interface, this can be provided for an agreed extension period. Any such extension is chargeable and would be priced and agreed in advance.

Once the agreed extension period ends, the data extraction and decommissioning process is completed.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Service documentation, including technical, onboarding, and operational materials, is supplied as PDF documents.

The documentation is not formally certified against a specific accessibility standard such as WCAG 2.2 or EN 301 549. However, reasonable steps are taken to ensure accessibility and usability.

PDF documents are created using structured content, including headings, tags, and bookmarks, to support navigation and use with assistive technologies. Documents are reviewed using the Adobe Accessibility Checker to identify and address common accessibility issues.

Onboarding and offboarding documentation is written in clear, plain language and structured logically, with consistent layouts and clearly labelled sections to aid comprehension.

Where required, reasonable adjustments or alternative formats can be provided on request to support accessibility needs.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
It is a desktop first service that has been designed to scale to mobile applications. We do have a mobile app for staff to be able to take payments only. The mobile app is an optional component designed to support staff-initiated payments and does not provide full administrative functionality.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
SmartPay is accessed through a secure, browser based web interface. The service provides role-based access to administrative, operational, and reporting functions through a central portal. Authorised users can manage funds, payment channels, validation rules, reports, imports, and exports using structured configuration screens. Operational users can search for transactions, review payment status, manage exceptions, and initiate permitted actions in line with their assigned permissions. Customer facing payment journeys are delivered through secure hosted payment pages designed for desktop and mobile use.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Formal user testing with assistive technology users has not yet been carried out. Accessibility is assessed using recognised browser-based evaluation tools.

Accessibility considerations are incorporated into ongoing development and improvement of the service, and feedback from customers is reviewed where accessibility concerns are raised.
API
Yes
What users can and can't do using the API
The API allows users to initiate and manage payment transactions from third party applications.

Users can set up use of the service by integrating with Adelante’s REST API using credentials provided by Adelante. Once credentials are issued, users can call the API to create payment requests and generate secure hosted payment links.

Using the API, users can initiate customer self service and operator assisted payment transactions, pass customer and order line information, and redirect users to secure card entry pages hosted by Adelante. Users can retrieve payment results by querying the API using a unique transaction identifier and can optionally receive server to server postbacks for successful payments.

Users can make changes at a transaction level only. They can create new payment requests and query transaction status. They cannot modify SmartPay configuration, payment channels, funds, merchant accounts, security settings, or completed transactions.

The API does not expose card data and does not return real time payment results in the initial request. All configuration, credential management, and behavioural settings are managed within SmartPay by authorised users or Adelante support.

It is designed for secure payment processing and transaction querying, not for system administration or configuration.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
SmartPay provides extensive configuration to meet organisational and service specific requirements.

Example areas include customer facing payment pages, which are branded and configured by Adelante. Funds can be configured with VAT treatment, balance rules, mandatory fields, and availability by payment method or department. IVR call trees, receipt templates, batch entry templates, reports, imports, and exports can be tailored. Payment channels and balance lookup behaviour can also be configured.

Most configuration is completed through the SmartPay administration interface using configuration tools, report writers, schedulers, and template management features. Changes do not require software development.

Authorised system administrators within the customer organisation can configure funds, reports, templates, payment channels, and validation rules. Branding of customer facing payment pages is managed by Adelante. Adelante can support or complete additional configuration where requested.

Scaling

Independence of resources
Each SmartPay customer is provided with a separate service instance, with customer data and configuration logically isolated hosted within a SQL Server cluster.

Customer data and configuration are logically isolated at both application and database level. This ensures that activity, configuration changes, or data access for one customer does not affect other customers.

This separation provides controlled access to resources and prevents cross customer impact at the SmartPay service level

Analytics

Service usage metrics
Yes
Metrics types
SmartPay provides service usage metrics based on payment activity. Metrics include transaction volumes and values, usage by fund codes or other customer defined references, service or department, location, payment method, user, till, and activity over defined time periods.

Customers can use the built in report writer to define metrics using multiple criteria. Reports can be run ad hoc or scheduled and delivered by email or to a secure location such as an SFTP folder.

Defined reports can be used as a consistent data set for regular service review meetings.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
SmartPay supports both user initiated and automated data exports during service operation.

At service setup, Adelante configures automated exports so that existing exports from the customer’s previous system are recreated in the same format, supporting continuity with third party and finance systems.

Authorised users can view, modify, and create exports within SmartPay, define export content, and configure schedules for when exports run.

Users can also search for data within the SmartPay user interface and download results as CSV files, including transactions, users, funds, and batches.

This supports ad hoc reporting and scheduled data transfers to third party systems.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • HTML
  • Plain text
Data import formats
  • CSV
  • Other
Other data import formats
  • Fixed Length Text record
  • XML

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
The Supplier uses reasonable endeavours to make the Hosted Services available on a 99.5% basis, measured per calendar month. Availability is assessed by reference to whether any Priority 0 or Priority 1 incidents remain outstanding during the measurement period.

The 99.5% availability target excludes planned maintenance windows and any agreed installation or implementation periods for new products or releases. Planned maintenance is managed in accordance with contractual provisions and communicated in advance where practicable.

Availability commitments and remedies are defined in the applicable Call Off Contract. Any service credits, availability related remedies, or refund mechanisms are agreed as part of the Call Off Contract and documented in the relevant Call Off Schedule.

These arrangements are considered and agreed on a case by case basis at contract finalisation, reflecting the customer’s requirements and the scope of services being provided.
Approach to resilience
The SmartPay service is hosted in a resilient data centre environment operated by a third party hosting partner.

The hosting environment is designed to support high availability and recovery from infrastructure failures. The data centre operates with resilient power, cooling, and network connectivity, and is designed to Tier 3 standards to reduce the risk of single points of failure.

Disaster recovery arrangements are in place to support service continuity in the event of a data centre incident. These include a geographically separate disaster recovery site within the UK. The disaster recovery environment is PCI DSS Level 1 compliant, consistent with the requirements for payment processing.

Data is protected through regular backups and replication between primary and disaster recovery environments, enabling recovery to a known good state in the event of data loss or corruption. Recovery objectives are designed to minimise both service interruption and data loss.

The availability commitments for the service are defined contractually, and resilience measures are designed to support those commitments.

Further technical detail regarding resilience design, recovery arrangements, and backup processes can be made available to customers on request to support assurance and risk assessment activities.
Outage reporting
Service outages are communicated directly to customers by email.

During onboarding, customers are asked to provide the details of key operational and emergency contacts who should be notified in the event of a service incident. These contacts are recorded for the purpose of outage and incident communications.

If an outage or significant service issue occurs, notifications are sent by email to the nominated contacts to advise them of the issue, its impact, and progress updates where appropriate.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Users authenticate to the service using a unique email address and password. Multi factor authentication is enforced for user access.

Where customers choose to implement it, the service supports identity federation using the customer’s existing identity provider to enable Single Sign-On.

Access to data hosted within the hosting environment, including the card data environment, is restricted to authorised Adelante personnel only. Access is via a VPN protected by multi factor authentication and controlled through formal change management processes. These controls are audited annually as part of Adelante’s PCI DSS Level 1 assessment by an independent external QSA.
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted through authenticated user access and permission controls within the service. Customer administrators are responsible for assigning and managing user access for their organisation. Adelante does not override or manage customer user permissions.

Administrative access by Adelante is restricted to authorised personnel only and protected using strong authentication controls, including multi factor authentication. Access is granted on a least privilege basis and managed through joiners and leavers processes.

Support channels are open for queries, but only authorised customer contacts can approve actions affecting configuration, data, or third party access.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
Management access to the service is restricted to authorised Adelante personnel only.

Administrative access requires individual credentials protected by multi factor authentication. Access to the hosting environment and card data environment is via a secure VPN and limited to staff with an approved operational need.

Access to development, build, and deployment systems is similarly restricted to authorised personnel using strong authentication controls. Access is granted on a least privilege basis and managed through joiners and leavers processes.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Security governance is managed at group level with board oversight. The Group CTO and General Counsel hold executive responsibility for information security and risk.

Security policies and standards are defined centrally and apply across the organisation. These are supported by regular security audits, risk registers, and documented incident response procedures.

Staff are required to complete mandatory annual security and data protection training, with compliance monitored centrally. Staff must acknowledge and sign off policies each year.

Security policies, guidance, and procedures are made available to all staff via a central intranet to support consistent awareness and adherence across the organisation.
Information security policies and processes
Information security policies and processes are defined and managed at group level and apply across the organisation. The Group CTO and General Counsel hold executive responsibility for information security and risk.

Policies cover areas including information security, data protection, access control, incident management, and acceptable use. These policies are supported by documented processes, including incident response procedures.

Compliance is enforced through mandatory annual training for all staff. This includes information security, PCI DSS, data protection, cyber awareness, phishing, social engineering, fraud awareness, and recognising risks associated with generative AI. Completion and policy acknowledgement are monitored centrally.

Line managers receive regular updates identifying staff who are due or overdue training, and timely completion of mandatory training forms part of individual performance objectives. Policies, procedures, and guidance are available to all staff via a central intranet.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and change management processes are defined and applied across the service. Service components, including application versions and configuration items, are tracked throughout their lifecycle. Changes are recorded and versioned to maintain visibility of what is deployed at any point in time.

Changes follow a controlled change management process. Changes are assessed, approved, tested, and implemented in line with procedures, with separation between development, testing, and production environments. The potential security impact of changes is considered, including security, data protection, and access control implications.

Only authorised personnel can implement changes, and changes are recorded in line with agreed procedures.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerability management is applied across the hosting environment and the application.

Potential threats are assessed through secure development practices, vulnerability scanning, monitoring, and review of reported issues.

Operating systems, platform components, and security software within the hosting environment are vendor supported, in line with PCI DSS requirements, ensuring security updates are available.

Patches are prioritised based on risk and severity. Critical vulnerabilities are addressed as a priority following testing, with routine updates deployed through planned release cycles.

Information about potential threats is obtained from vulnerability scanning, vendor and hosting partner advisories, PCI DSS updates, industry guidance, and internal security reviews.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is applied across the hosting environment and the application.

The hosting environment is monitored by our hosting partners to identify potential compromises, including abnormal activity and security events. Alerts are reviewed and escalated in line with their operational security procedures.

At the application level, potential issues are identified through monitoring of system behaviour and reported incidents.

When a potential compromise is identified, incidents are managed through documented incident response procedures, including investigation, containment where required, and communication with relevant stakeholders.

Response times are prioritised based on severity, with critical incidents escalated and addressed as a priority.
Incident management type
Supplier-defined controls
Incident management approach
Incident management processes are defined and applied across the service.

Pre defined procedures are in place for managing common incident types, including service availability issues, security incidents, and operational faults. These procedures cover incident logging, assessment, escalation, investigation, and resolution.

Users report incidents by contacting the Adelante support desk using the agreed support channels. Incidents are logged and managed in line with priority and severity definitions.

Where required, incident updates are communicated to customers during resolution. Following significant incidents, incident reports can be provided to customers, outlining the nature of the issue, impact, actions taken, and any corrective measures implemented.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Pen Test Partners LLP
PCI DSS accreditation date
Wednesday 25 June 2025
What the PCI DSS doesn’t cover
The PCI DSS certification applies to the Adelante Service Provider Environment only. It does not cover third-party hosting infrastructure, external payment gateways or acquirers, merchant services, card schemes, or customer internal systems, networks, or end-user devices.
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
2568d44d-7ecc-447d-94ec-5eb461e414dc
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Volunteering opportunities for staff
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@adelante.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.