FFT Aspire
FFT Aspire is a comprehensive online reporting and data analysis tool which is widely used by schools, LAs, academy trusts, diocese and government to analyse performance and improve educational outcomes. It encompasses self-evaluation, pupil tracking and collaboration and makes use of statistical models developed by researchers in FFT's Education Datalab.
Features
- Reports and dashboard for schools, academy trusts and LAs
- Estimates and predictions of future performance for pupils
- Set challenging and aspirational targets for pupils
- Identify strengths and areas for improvement
- Direct link to school MIS to synchronise data
- Benchmark school, LA and academy trust performance
- Monitor and track progress for current pupils
- Match and process pupil data
- Compare performance to other schools
- Measure value-added pupil progress in all subjects
Benefits
- Dashboard reports analysing school performance and education data
- Analyse data for pupil, school, academy trust and LA
- Aggregate reports analysing performance for local area or region
- Value-added analysis of education performance (results and pupil progress)
- Estimates (predictions) of future performance to help set challenging targets
- Improve school performance
- Raise pupil achievement
- Data processing: collect, match and process pupil data
- Data is synchronised from school MIS with FFT's national datasets
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 5 3 6 7 3 3 2 1 6 1 5 8 1 2
Contact
FFT EDUCATION LIMITED
Peter Collison
Telephone: 01446 776 262
Email: peter.collison@fft.org.uk
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Advanced and predictive analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- There are no constraints that buyers need be aware of
- System requirements
-
- Aspire requires a computer or tablet (Microsoft, Apple or Android/Chrome)
- Aspire requires a compatible browser: Edge, Chrome, Safari, Firefox
User support
- Email or online ticketing support
- Yes
- Support response times
- Response times are between 1 and 3 business days depending on the severity of the issue. Tickets are not responded to during weekends or outside of support hours.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Access to web chat is embedded within the FFT Aspire portal and connects users with the FFT support team. They can chat directly to a support agent, securely provide screenshots of issues/error messages and receive guidance on what to do to resolve the issue.
- Web chat accessibility testing
- None
- Onsite support
- Yes, at extra cost
- Support levels
-
Support is provided by FFT as part of the Aspire subscription with no additional charge. FFT treats all calls as important and does not offer different support levels.
Some local authorities prefer to support their schools themselves (where the schools are being provided access to Aspire through the local authority) and this is catered for. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
All new customers are assigned a dedicated onboarding contact who will guide them through the set-up and configuration stage of adopting FFT Aspire. As part of this users will be able to access our online customer knowledge hub which includes a wide range of on-demand training videos and "how-to" articles.
All operational customers are also appointed a named account handler who is available throughout the duration of the contract to ensure client success in the long term. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Users are provided with facilities to take copies of their data at any point during the course of the project. FFT will delete user data, other than that which provides an audit trail of activity, in line with retention guidelines outlined in the FFT privacy notice.
- End-of-contract process
-
The contract grants customers a license to access the Aspire portal for any number of staff. It also covers the provision of help guides and email and phone support.
FFT runs free training courses for some users from time to time, but for the most part training courses are not covered by the contract.
For local authorities, LA events covering developments in education and the most recent research using educational data are provided as part of the contract. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Documents are available to view online, in either PDF or HTML format, via a browser or other compatible application. The PDF versions are also available to download and can be viewed locally using any compatible application, allowing the use of screen magnifiers and contrast changing as needed.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
All system functionality is available from mobile tablet devices.
The service operates within a responsive layout. The navigation when accessing the service through a mobile device collapses at smaller screen sizes and content reflows to fit available space. On-screen tools maintain a persistent position where space is available. Typography and spacing adjusts to take advantage of available space. - Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
- Aspire is a flexible service which provides customers and users a range of areas where they can customise the service to meet their particular needs. Administrators can create unique accounts for each user, and each user can be assigned a role and privileges. This makes it possible, for example, to limit the level of access to only allow aggregate data to be viewed. Administrators can also decide the default level of challenge at which a schools wants to work. Users can customise the reports they view with an array of settings: set persistent Key Stage settings and apply filters that are carried from report to report. Uses can set email preferences about whether to receive email updates. Each user can save to a list of reports through a bookmarking system and assign descriptions to each report. Certain users can achieve custom interfaces by accessing the system through a BI interface.
Scaling
- Independence of resources
- Service capacity, scalability, availability and performance is managed by separation of services and scale up/down based on service needs. Services are monitored on a per minute active monitoring of server availability, performance and load. Servers are Load Balanced to evenly distribute load and where additional capacity is needed, this is managed automatically. Capacity is distributed across different UK availability zones for additional resilience. Database server capacity is over provisioned ahead of time to ensure capacity requirements are met.
Analytics
- Service usage metrics
- Yes
- Metrics types
- FFT provides metrics to Local Authorities and multi-academy trusts with information about how the service is being used by schools. Metrics include information about number of users, user logins, page views and functional areas of service used.
- Reporting types
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export pupil and school data from FFT Aspire for use by the organisation in other management information systems, including FFT's estimates of future performance. Dashboard reports can be exported for use offline and printing (PDF or Excel).
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- TSV
- Data import formats
-
- CSV
- Other
- Other data import formats
- Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We offer a 99.5% availability SLA (excluding scheduled downtime) which operates 24 hours a day, 7 days a week. We do not offer automatic refunds on the event of SLA failure but will use commercially reasonable endeavours to maintain adherence to this SLA.
- Approach to resilience
- Information available on request
- Outage reporting
- Outages are reported via email alerts to users and via messages on our helpdesk.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- FFT Aspire uses role-based permissions to grant users access to the relevant areas of service. Customers are responsible for granting access to their users based on the standard roles available.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- FFT adopts all the information security controls identified under ISO27001:2013. Policies are reviewed and updated to a defined schedule. Training on information security is given to staff on induction and through frequent workshops and training sessions. FFT has put in place a governance structure which includes responsibilities for SMT, SIRO, DPO, Information Security Officer and a wider Information Security Forum. Internal and external audits are carried out to a defined schedule. Surveillance and recertification audits are carried out annually on a 3 year cyclical basis.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- A risk assessment covering information security is carried out before embarking on any new developments or significant changes. Azure DevOps is used for source control of code and for managing development and change/configuration. Requirements are logged and tracked through user stories, product backlog items and tasks. All changes are assessed against the FFT change management policy and the FFT Secure development policy with consideration being given to scale, scope, security and testing requirements of code and components before release to a production environment.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Potential threats are monitored and assess through a range of processes including vulnerability testing, external penetration testing and third party vulnerability management systems. The service undergoes an annual IT Health Check (ITHC) by a Crest Approved Security Tester. This includes a code review. In addition, up to date information on potential threats is obtained through security forums and from information provided by technical bodies and vendors. Patches are deployed as a matter of course on a monthly basis with more frequent patching when required.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Industry standard vulnerability management, threat management and antivirus solutions are used to monitor the infrastructure from which Aspire is delivered. In addition, AWS provide a multi layered defence in depth monitoring service. Active monitoring is in place for the firewall. System log monitoring is carried out. Any alerts or risks identified are managed through an internal helpdesk system with processes to escalate serious threats and ensure prompt resolution.
- Incident management type
- Supplier-defined controls
- Incident management approach
- FFT has a defined process for managing security events as defined in its security event policies. Events are reported and managed through a help desk system. Prioritisation and escalation of events is established by FFT's information security manager with escalation to SMT as needed. All events are reported internally to FFT's information security forum. The classification of information security incidents is defined by FFT's information security policies. In the event of a breach, processes are in place to inform affected users, the relevant Data Controllers and the ICO.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Schools interested in purchasing a subscription to Aspire can request access to a free trial version of the FFT Aspire dashboards and pupil tracking tool for a time limited period.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA Certification Ltd
- ISO/IEC 27001 accreditation date
- Tuesday 13 April 2010
- What the ISO/IEC 27001 doesn’t cover
-
We do not exclude any controls, clauses, or areas from our ISO 27001:2022 certification. Our Information Security Management
System (ISMS) covers the full scope of the standard with no exclusions. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 642b1b65-9c2c-416a-8dfe-bbe11a28eb97
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 9d68b579-6d32-48dc-8219-c31845809095
- Other security certifications
- Yes
- Any other security certifications
- ITHC (June 2025)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-