Skip to main content

Help us improve the Digital Marketplace - send your feedback

Evotix

Evotix Assure Environmental Assessment Software

Evotix Assure Environmental Assessment health and safety software features sub-modules capturing environmental performance information. Create components outlining environmental aspects, the potential impact of aspects and consistent control measures to manage that impact. These components then allow both the simple creation of an aspects and impacts register.

Features

  • Assessments and waste registers that record and manage environmental compliance
  • Easy attachment tool for permits & policies
  • Monitoring quantity and source of waste with waste materials register
  • Waste handlers register ensures only registered contractors remove waste
  • Handling companies' details are directly linked to waste transfer record
  • Create, record and monitor all waste assessments with preconfigured templates
  • Stores results, conclusion notes and review dates for all records
  • Built-in approvals and action tracking process

Benefits

  • Delivers clear visibility of environmental performance
  • Improved environmental focus across the organisation
  • Supports continuous improvement and development of more effective controls
  • Live environmental information across the organisation
  • Ability to link aspects to relevant legislation and policies
  • Reduces administrative burden associated with environmental reporting
  • Action Management – assign work and track to completion
  • Maintains a full audit trail for every assessment

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@evotix.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 7 7 0 9 2 9 5 7 7 6 7 8 0 3

Contact

Evotix Tristan Alden
Telephone: 03003033657
Email: gcloud@evotix.com

About your service

Service categories

Applications

Content workflow and management

Enterprise portals and digital workspaces

  • Multi-Audience Portals
  • Integrated Employee Workspaces
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
The Assure health and safety management solution from Evotix is modular. This means each Assure module works standalone, but integrates powerfully with others to provide you with a complete solution.
Cloud deployment model
Public cloud
Service constraints
Application support availability is situated in EMEA, the US, and Australia. The standard support hours in the EMEA region are 08:30 -17:00 local UK time, Mon-Fri on Business Days.
On-premise deployment is not supported.
Customers cannot stay on a specific version of the software, all customers are upgraded to the latest software version whenever there is an update.
Microsoft Internet Explorer is not supported.
No separate staging/testing/training environment is provided however, a discrete segmented area of the system is made available in order to cover these aspects.
The core Assure system is not fully compliant with WCAG Accessibility standards.
System requirements
  • Officially supported browsers recommended (Edge / Chrome)
  • AssureGO+ Web App tested/compatible with Edge, Chrome. Android OS/Apple iOS

User support

Email or online ticketing support
Yes
Support response times
For support tickets, our SLA response times are as follows:

Critical severity errors - 30 mins
High severity errors - 2 hrs
Medium severity errors - 4 hrs
Our solutions are architected with integrity and availability as part of the design our SLA is to provide 99.9% uptime with an RTO within 2 hours and an RPO of a maximum of 1 hour.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Our customers prize our expert and friendly support both during implementation and ongoing. 95% of our customers renew every year.

Our UK based customer services team answer support requests promptly and resolve problems quickly whether they relate to training or configuration. We follow a 6 stage case management process. All cases, issues, or requests for change are, in the first instance, reported to the Help Desk as the central point of contact.

As first line support, the Help Desk can be contacted via our online ticketing service Monday to Friday 8:30-17:30. Requests are recorded and monitored in our case management system which ties the request to your customer account to provide a complete history. Where first line support is unable to solve the customer issue, the case is escalated to second line support. Here, our system experts will work to understand the customer issue and diagnose the problem. Once derived, the solution is communicated to the customer in our outlined SLA. If second line support cannot resolve the customer issue, the case is escalated to third line support for root cause analysis and/or data fix.
Support available to third parties
No

Onboarding and offboarding

Getting started
We have a robust implementation methodology, which we have honed through over 500 customer implementations. One of our Customer Implementation Consultants will meet remotely with the customer weekly throughout the course of their onboarding, and they will guide them through the 6 key steps of the implementation journey (Setup/Initiation, Orientation, Configuration, Testing, Training, Go Live), analysing their requirements, recommending solutions, delivering training, and offering support through UAT and Go Live. They will set tasks and actions to accelerate and sustain progress throughout the project as needed.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
Video
End-of-contract data extraction
Data can be downloaded to CSV using the data extract tools within the product.
End-of-contract process
Upon receipt of a notice of termination, the Customer Success Manager initiates the customer offboarding experience. This involves notification to Finance and Engineering teams and confirmation to the customer of receipt of the termination notice.
Following acceptance of the termination, the following work streams are started:

Customer Success:
The Customer Success Manager will reach out to the customer to agree the customer's needs as part of the exit from the contract, including whether the customer requires support with the extraction of their data from Evotix's products using the built in tools. Evotix can extract information on behalf of the customer, but there may be a cost associated with this.

Engineering: The notification to Engineering allows a formal contract termination date to be placed against the customer's tenant. Access to data is maintained for the customer for 30 days post formal termination date to allow the customer the opportunity to export their own data before the data is securely deleted from Evotix's systems, and a further 14 days later, all backups holding that customer's data are cycled out and have been securely deleted. If the customer requests, Evotix can provide confirmation in writing of the deletion of data.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
The Evotix Implementation team share onboarding/offboarding materials (presentations, templates (PDFs)) with customers via secure web links, with the documentation saved in a shared Sharepoint folder.
Customers have access to the Evotix Knowledge Base, which features documentation to support their onboarding, such as written articles and video guidance. Video Content is available in multiple languages, and features captions to support user accessibility.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Assure (desktop) is a gated service requiring login and internet access. It enables full management of health and safety records, platform configuration, and analytics.

Assure Go+ (mobile) allows anyone to report incidents or complete health and safety tasks from anywhere. It can be ungated for easy access and supports sharing key documents like risk assessments with frontline staff. It also provides offline functionality, letting users complete forms without connectivity to sync later.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Assure is heralded by customers as ‘straightforward’ and ‘easy to use.’ We understand the importance of our solution to be simple and intuitive, requiring little or no training. One of our design mantras is "Keep it Stupidly Simple", key to driving user engagement and culture change across an organisation.

The repetition of common design components throughout the application (e.g., Record list views and header bars) make the UI consistent and decreases cognitive load. Assure does not rely on a thin UI layer to conceal variations in underlying software and navigations, it is designed top to bottom as an integrated whole.
Accessibility standards
None or don’t know
Description of accessibility
Our progressive web app, Assure GO+ is WCAG 2.1 AA compliant - not Assure Core.

Assure and Assure GO+ services can be accessed by users via modern web browsers, either via a URL or QR code
Accessibility testing
Use of automated Accessibility checkers on Assure GO+.
API
Yes
What users can and can't do using the API
Assure features two inbound RESTful API's facilitating create/update/ delete options for maintaining the systems Organisation Unit hierarchy and Users information - this alleviates administrative overhead and ensures that Assure keeps up-to-date with organisation and personnel changes.

In addition to the two system based API's, there are 5 inbound API's available, which facilitate data to be created/updated/deleted into 5 areas of Assure:

People Register
Equipment Register
Claims Management
Incident Analysis (Headcount hours)
Contractor Register

Assure features 64 outbound APIs, which facilitate data extraction from the target modules.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Evotix Assure is built with configurability at its core, enabling organisations to adapt the platform to their exact EHS and ESG requirements without requiring code changes. Configuration can be applied across workflows, forms, fields, risk matrices, permissions, and reporting, ensuring the system mirrors how your business actually operates.

This flexibility allows teams to respond quickly to regulatory changes, operational shifts, or business growth while maintaining control and consistency.

Scaling

Independence of resources
The Assure service is delivered using various AWS services using a combination of capacity planning, scheduled scaling and auto scaling to ensure capacity is in place to handle variable throughput.

Proactive monitoring is in place to alert our teams when a metric breaches set thresholds.

Analytics

Service usage metrics
Yes
Metrics types
Service metrics are provided in relation to user usage of the platform
Reporting types
Regular reports
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
Other
Other data at rest protection approach
Encryption of all Data at Rest. Control of hardware is outsourced to AWS.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Users can download their data in a variety of ways:

• On individual records; in formatted reports (Word, PDF, CSV)

• On multiple records; using configurable (logic) filters and configurable tabular CSV/JSON reports. Additionally, via the integrated BI tool (Insights+) in PDF, CSV, Excel, JPG formats.

• Assure features 64 outbound APIs which facilitate data extraction from the target modules including any associated iQ data. These 64 outbound API's span across all modules within Evotix Assure. Through the outbound API's data can be extracted in JSON, CSV or Snappy Compressed Parquet format.
Data export formats
  • CSV
  • Other
Other data export formats
  • Word
  • Excel
  • PDF
  • JSON
  • Snappy Compressed Parquet
Data import formats
  • CSV
  • Other
Other data import formats
  • API
  • JSON object

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Our solutions are architected with integrity and availability as part of the design. Our SLA is to provide 99.9% uptime with an RTO within 2 hours and an RPO of a maximum of 1 hour.
Approach to resilience
The service is designed to be highly resilient by spanning multiple Availability Zones in any given Region. An Availability Zone (AZ) is one or more discrete data centres with redundant power, networking, and connectivity in an AWS Region.

In the event of an Availability Zone being impacted, additional capacity is automatically initialised in another AZ until the issue is resolved, ensuring the service remains unaffected.
Outage reporting
Details of any scheduled maintenance and unscheduled outages will be published via the Evotix status page.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Other user authentication
Single Sign On
Access restrictions in management interfaces and support channels
Assure uses a role-based permissions model aligned to organisational hierarchy, allowing customers to define and control user access across the platform. Permissions are managed through two configurable sets:

Supervisor Privileges: Reserved for system administrators, these control configuration capabilities, including module settings, system settings, user management, and role permissions.
Role Permissions: Determine access to core system functionality (read, write, edit, approve records) and can be applied to specific organisational units or sub-modules. Users can be assigned a single role or multiple roles across different areas, ensuring access aligns precisely with their responsibilities.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Description of management access authentication
Single Sign On

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
SOC 2
Information security policies and processes
Evotix has in place a Certified ISO 27001 Information Security Management system including all applicable Policies, processes and procedures.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Change requests are subject to the Change management process with different authorisation requirements for standard, minor and major and emergency changes.

Standard changes are logged and completed without approval, these are changes which happen regularly which have robust processes in place and are low risk. Minor changes require formal approval from the requestor's manager, major changes require formal approval from the CAB. Emergency changes require verbal approval from the Head of Business Technology or the Head of Risk & Compliance with details formally logged once the situation is dealt with.

Changes to the product are managed through the SDLC.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Known vulnerabilities within the service are identified via continuous scanning for security issues.

Once identified, vulnerabilities are tracked, assigned a severity level (based on CVSS scores and business context) and triaged. remediation SLAs have the following targets:

Zero Day – 14 Days
Critical - 30 days
High - 30 days,
medium - 90 days
Low – As possible
All patches are tested before release.

Mitigations are implemented via our standard change management process. Tooling includes Snyk and Rapid7. All actions are logged for auditability.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Evotix monitors threats, vulnerability, and exploitation technique information through a structured approach:

Annual penetration testing is conducted using both automated and manual techniques to identify and validate vulnerabilities. This helps assess the depth and business impact of vulnerabilities and ensures findings are not false positives

Evotix tracks vulnerabilities across its infrastructure via vendor-issued advisories. These updates are reviewed to assess urgency and initiate remediation or mitigation. These  include threat-aware scoring models such as Rapid7’s Active Risk, integrating CVSS data with threat intelligence feeds enables prioritisation of vulnerabilities that are the highest risk.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Where an Incident or potential incident is identified, an Incident Response team is convened to contain the incident and complete any immediate remediation. Internal escalation happens simultaneously.

Further required remediation is identified with actions planned to mitigate the potential for recurrence and the investigation is commenced.

Affected customers are informed without undue delay, but within 48 hours, of Evotix becoming aware of the incident with relevant information as available at that point and ongoing updates

A full investigation will be conducted and a summary report will be issued to any affected customer upon completion of the investigation.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Upon request, we offer a free limited trial for a maximum period of two weeks. This will be limited to a maximum of 10 users, unless agreed otherwise. Critical success factors must be agreed before commencement to allow the customer to measure success and guide users in what they're testing.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2.5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
7.5%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Sirim QAS
ISO/IEC 27001 accreditation date
Wednesday 30 July 2025
What the ISO/IEC 27001 doesn’t cover
The only exclusions from the certification are Cabling Security (Annex A 7.12) and Supporting utilities (Annex A 7.11)
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
IS Quality Services Liimited
ISO 9001 accreditation date
Tuesday 17 June 2025
What the ISO 9001 doesn’t cover
There are no exclusions
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
0ea6b1f6-b54a-45a7-bda1-60e6299cbc93
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
SOC 2 Type II Attestation

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@evotix.com. Tell them what format you need. It will help if you say what assistive technology you use.