Skip to main content

Help us improve the Digital Marketplace - send your feedback

DIREK LTD

D-XPERT: Space Utilisation & Occupancy Management

Real-time space management software that uses sensor data to optimize desk, meeting room, and zone usage. Provides heatmaps and utilization trends to help estates teams rationalize portfolios, reduce cleaning costs, and improve "people-per-square-meter" efficiency.

Features

  • Real-time floorplan heatmaps: Shows live occupancy and dead zones.
  • Granular utilisation analytics: Metrics for zones, floors, buildings, portfolios.
  • Automated rightsizing reporting: AI reports for consolidation and lease breaks.
  • Hybrid working validation: Peak vs average occupancy validates policies.
  • Sensor & system agnostic: Supports API, BACnet, MQTT, CSV, sensors.
  • AI reporting suite: Role-specific summaries for FM, ESG, directors.
  • Ranked recommender backlog: Prioritised space optimisation recommendations.
  • Configurable alerts: Notifies overcrowding, under-use, anomalies.
  • Calendar & booking integration: Detects ghost bookings and utilisation.
  • Omni-channel access: Access insights on web, email, WhatsApp.

Benefits

  • Data-driven rightsizing: Evidence supports lease rationalisation and consolidation.
  • Optimise soft services: Align cleaning, security with actual occupancy.
  • Validate hybrid policies: Defensible occupancy data confirms policy adherence.
  • Reduce overcrowding risk: Density monitoring matches demand to capacity.
  • Stakeholder intelligence: Decision-ready reports with drill-down details.
  • Reduce operational effort: Automated reports and alerts save time.
  • Reduce tech lock-in: Uses existing sensors, no hardware dependency.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at enquiry@direkltd.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 8 4 2 0 7 4 0 6 6 5 4 4 8 4

Contact

DIREK LTD Amir Taba
Telephone: 07426498545
Email: enquiry@direkltd.co.uk

About your service

Service categories

Application Development and Deployment

AI platforms

  • Search and knowledge discovery

AI life cycle

  • Data Labeling Software
  • Trustworthy AI Software

AI software services

  • Conversational AI Software Services
  • Generative AI Software Services
  • Document AI Software Services
  • Anomaly Detection AI Software Services
  • Personalize AI Software Services
  • Forecast AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Service requires a secure internet connection (outbound HTTPS/MQTT) from the client site to the cloud to deliver real-time analytics and access to the platform. Where occupancy or space-usage data is sourced from existing sensor or workplace systems (such as people-counting sensors, Wi-Fi analytics, room booking systems, or building systems), these systems must provide data via accessible APIs or standard data export formats. Planned maintenance is scheduled outside core UK business hours with advance notice, during which brief, non-disruptive service interruptions may occur.
System requirements
  • Modern web browser required
  • Active internet connection
  • Secure outbound internet connection to the cloud
  • Existing systems require to support standard open protocols or APIs

User support

Email or online ticketing support
Yes
Support response times
Support is provided via a dedicated email helpdesk and online ticketing system. Tickets are triaged based on severity:

Priority 1 (Critical System Outage): Response within 1 hour.

Priority 2 (Major Functionality Issue): Response within 4 hours.

Priority 3 (General Enquiries/Minor Issues): Response within 1 business day.

Support operates during standard UK business hours (09:00 – 17:00, Monday to Friday, excluding Public Holidays). All tickets are tracked with unique reference numbers for full traceability and status updates.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Our web chat service is powered by Zoho SalesIQ, which is designed and tested to meet WCAG 2.1/2.2 AA standards. Testing with assistive technology includes:

Screen Reader Compatibility: Verified compatibility with major screen readers (JAWS, NVDA, VoiceOver) to ensure chat announcements and incoming messages are audible.

Keyboard Accessibility: The chat widget supports full keyboard-only navigation (Tab/Shift+Tab keys) for opening the window, typing messages, and navigating the conversation history without a mouse.

Visual Standards: The interface is tested for high-contrast visibility and supports browser-based zoom without breaking layout, ensuring readability for visually impaired users.
Onsite support
Yes, at extra cost
Support levels
Support Levels provided: We provide two tiers of support:

Standard Support: Covers UK business hours (09:00–17:00, Monday to Friday) via email, online ticketing, and phone support. Includes remote troubleshooting, bug reporting, and access to the knowledge base.

Enterprise Support: Designed for mission-critical deployments and includes priority ticket handling, quarterly service review meetings, and proactive system health monitoring. Onsite support can be provided where required.

Technical Account Manager & Cloud Support Engineer:

Cloud Support Engineers are available to all customers via the helpdesk for technical triage and issue resolution.

A Technical Account Manager (TAM) acts as a named point of contact for strategic planning, roadmap alignment, and escalation management for customers requiring enhanced service engagement.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Onboarding & Provisioning:

Digital Setup: Users receive an automated email invitation to create a secure account. Access is provisioned instantly upon contract signature.

Data Migration: We provide standard templates and API tools to assist with the bulk import of building metadata, space hierarchies, and historical occupancy or utilisation datasets where available.

Training Options:

Agentic AI Guidance (In-App): Our unique "Co-pilot" interface allows users to learn by doing. Users can ask the AI how to perform tasks (e.g., "How do I generate a report?"), and the system provides instant, conversational guidance, significantly reducing the learning curve.

Online Training: We provide remote "Train the Trainer" sessions via video conference (Teams/Zoom) and regular webinars for general users at no extra cost.

Onsite Training: Bespoke onsite training workshops are available as a chargeable option (based on SFIA rate card).

Documentation:

Knowledge Base: Access to a searchable, secure online help center containing video tutorials, user guides, and FAQs.

API Documentation: Full technical documentation (Swagger/OpenAPI) is provided for developers and integrators.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Extraction Methods:

Self-Service (UI): Users can export all historical datasets (occupancy logs, utilisation trends, space metadata, and derived performance metrics) directly from the dashboard at any time. Reports can be downloaded as PDF or Excel.

Bulk API Export: For large datasets, users can utilize the REST API to programmatically retrieve raw data in machine-readable formats (JSON/CSV) prior to contract termination.

Data Formats:

Raw Data: CSV, JSON.

Processed Reports: PDF, XLSX.

Asset Registers: CSV.

Cost & Conditions:

Standard Exit: There is no charge for standard self-service data extraction or API retrieval during the contract term or notice period.

Bespoke Extraction: If the buyer requests a custom database dump or manual data migration assistance from our engineering team, this is chargeable based on the SFIA Rate Card.

Data Deletion: Upon contract termination, all customer data is retained in a "read-only" state for 30 days to allow for final retrieval, after which it is permanently and securely deleted in accordance with GDPR and ISO 27001 standards.
End-of-contract process
End of Contract Process:

Termination Notice: Upon expiry or termination, the service remains fully active until the final day of the contract.

Data Extraction: The buyer is responsible for extracting their data via the self-service API or dashboard export tools during the notice period.

Access Revocation: On the day following contract expiry, user access is revoked. Data is moved to "cold storage."

Secure Deletion: Data is retained for a grace period of 30 days to allow for accidental non-renewal recovery. After 30 days, all client data (including backups) is permanently and securely deleted in accordance with ISO 27001 standards.

Included in the Price:

Self-Service Export: Full access to export data via CSV, JSON, or API is included at no cost.

Standard Offboarding: Automated account deactivation and standard confirmation of data destruction.

Additional Costs:

Bespoke Extraction: Manual engineering support to extract data in non-standard formats or to migrate data to a new provider is chargeable based on the SFIA Rate Card.

Extended Retention: Requests to retain data beyond the standard 30-day grace period are chargeable.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Mobile (Agentic AI): The D-XPERT Co-pilot is fully mobile-optimized via WhatsApp Business integration, allowing users to query occupancy and space utilisation metrics, receive alerts, request reports, manage issue notes, and, where enabled, request booking-related actions using natural language on any mobile device without installing a proprietary app.

Mobile (Reporting): Critical alerts and PDF reports are delivered via email, optimized for mobile viewing.

Desktop (Deep Analytics): Complex visualisations, heatmaps, and portfolio utilisation dashboards are optimized for desktop web browsers to ensure data clarity, though they remain accessible via mobile browsers.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Description of the Service Interface

D-XPERT provides a comprehensive API and integration layer to facilitate interoperability with workplace and property management systems.

RESTful API: A documented HTTPS API allows authorized third-party systems to retrieve historical and real-time occupancy, utilisation, booking, and space metadata, along with processed workplace efficiency and portfolio performance reports programmatically.

Real-Time Data Streams: Supports secure MQTT and WebSockets for live occupancy and utilisation data ingestion, alerting, and event triggering from connected workplace or sensor systems.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Interface testing is currently conducted by our internal QA team using assistive technology tools to simulate the experience of users with disabilities. This includes:

Screen Reader Compatibility: We test the dashboard and reporting pages using NVDA (Windows) and VoiceOver (Mac) to ensure ARIA labels and semantic HTML are correctly interpreted.

Keyboard-Only Navigation: We verify that all core user journeys (logging in, viewing dashboards, downloading reports) can be completed using only the keyboard (Tab/Enter/Space), ensuring no "keyboard traps" exist.

Platform Inheritance: For our mobile interface, we leverage WhatsApp's native accessibility features (which are rigorously tested with diverse user groups by Meta), ensuring our "Agentic AI" interface is immediately accessible to users of assistive technology.
API
Yes
What users can and can't do using the API
What users CAN do (Read & Intelligence): The API is designed for high-granularity data consumption and reporting:

Granular Reporting (GET): Users can programmatically request tailored reports filtered by hierarchy:

Scope: Single Building, entire Portfolio, or specific Space Types (e.g., "All Meeting Rooms").

Audience: Data can be formatted for specific roles (e.g., technical engineering logs vs. high-level Manager/ESG summaries).

Recommendations & Insights: Fetch the live backlog of AI-generated space optimisation recommendations, including predicted efficiency gains, utilisation improvements, and cost-avoidance insights.

Real-Time Alerts: Subscribe to live alert streams (via Webhooks/JSON) to trigger notifications in external systems.

How users set up/configure via API:

Report Configuration: Users can define reporting parameters (frequency, granularity, metric selection) via API payloads to automate the generation of monthly or quarterly ESG evidence packs.

Metadata Management: Users can update space definitions and asset tags (e.g., re-classifying a zone from "Office" to "Breakout").

What users CAN’T do:
The API does not capture or expose personally identifiable information (PII), nor does it provide individual-level tracking. The service is designed for aggregated, anonymous occupancy insights only.

Users cannot modify or delete historical data points or generated audit logs, ensuring that all ESG reporting remains defensible and traceable.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
What can be customised Users can tailor the platform to their specific role and building portfolio:

Dashboards: Configure personal views by selecting widgets for Occupancy rate by zone, Desk utilisation %, Meeting room overbooking, or Peak vs off-peak usage.

Reporting: Define custom schedules (Daily/Monthly) and formats (PDF/Excel) for specific standards (e.g., Space efficiency benchmarks) or granular scopes (Single Asset vs. Portfolio).

Alerts: Notify if meeting room utilisation < 30% for 4 weeks. Alert when desk utilisation exceeds target density. Identify underutilised zones suitable for consolidation

Metadata: Rename zones, re-classify space types, and update occupancy targets to reflect layout changes.

How users can customise

GUI: Drag-and-drop interface for rearranging dashboard widgets and toggling heatmap layers.

Agentic AI: Uniquely, users can customize outputs via natural language (e.g., "Update my Monday report to include meeting room utilisation and desk occupancy trends."). The AI automatically reconfigures backend settings.

Who can customise

Administrators: Full control to configure global settings, site hierarchies, and organization-wide compliance targets.

Standard Users: Can customize personal dashboards, report subscriptions, and notification preferences without affecting the global configuration.

Scaling

Independence of resources
Elastic Auto-Scaling: Our Google Cloud Platform (GCP) infrastructure automatically scales compute resources to match demand. High usage by one client triggers instant capacity expansion, preventing performance degradation for others.

Asynchronous Queues: Intensive tasks (e.g., AI reporting) are offloaded to background queues, ensuring the main user interface remains responsive at all times.

Rate Limiting: We enforce strict API limits per tenant to prevent "noisy neighbor" issues and system flooding.

Token Logic: Our token consumption model naturally regulates the volume of intensive AI computations, ensuring fair resource distribution across the platform.

Analytics

Service usage metrics
Yes
Metrics types
Token Monitoring: Users can track their "Token Balance" and "Burn Rate" in real-time. Tokens are consumed when generating complex reports or requesting AI-driven space utilisation insights and optimisation recommendations.

Activity Logs: Detailed breakdown of which users or departments are consuming tokens, allowing for internal cost allocation.

Threshold Alerts: Admins receive automated notifications when their token balance falls below a set percentage, preventing service interruption.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
We built on Open Data philosophy for seamless and secure data extraction:

Self-Service Dashboard: Users can download data tables, charts, and reports directly from the interface in standard formats (CSV, Excel, PDF) for immediate use in other tools.

API Retrieval: For large-scale or automated extraction, users can query the REST API to retrieve raw historical datasets in machine-readable formats (JSON), enabling integration with third-party BI tools or data lakes.

Report Generation: Standard compliance reports (e.g., ESG summaries) can be generated on-demand and exported as comprehensive PDF packages.

Standard data export via these methods is free and included in the service.
Data export formats
  • CSV
  • Other
Other data export formats
JSON
Data import formats
  • CSV
  • Other
Other data import formats
JSON

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We provide a Service Level Agreement (SLA) guaranteeing 99.9% uptime calculated on a monthly basis.

Financial Recompense (Service Credits): If availability falls below this threshold, customers are eligible for Service Credits applied to their next billing cycle. We do not offer cash refunds.

99.0% – 99.9%: 10% Service Credit

95.0% – 99.0%: 25% Service Credit

Below 95.0%: 50% Service Credit

Exclusions: Downtime calculations strictly exclude:

Scheduled Maintenance: Planned updates notified 48+ hours in advance.

Force Majeure: Events beyond reasonable control (e.g., GCP region-wide failure, ISP outages).

Client Fault: Issues arising from the customer’s own network configuration or misuse of the API.
Approach to resilience
Our solution is hosted in the Google Cloud Platform (GCP) London Region (europe-west2), utilizing a high-availability regional architecture to guarantee resilience:

Physical Redundancy: The service is distributed across three physically isolated zones within the London region. If one zone fails (due to power, cooling, or physical disaster), traffic is instantly re-routed to the remaining healthy zones.

Database Resilience: We utilize Cloud SQL High Availability. Data is synchronously replicated to a standby instance in a different zone. In the event of a primary zonal failure, the database automatically fails over to the standby with zero data loss.

Self-Healing Compute: Application logic runs on stateless virtual machines within Managed Instance Groups (MIGs). If a VM becomes unhealthy or a zone goes offline, the MIG automatically repairs the group by provisioning new instances in available zones.

Traffic Distribution: Cloud Load Balancing distributes traffic across the healthy instances in all three zones, ensuring seamless operation during maintenance or outages.
Outage reporting
Public Dashboard: We maintain a dedicated, publicly accessible Status Page (e.g., status.ourdomain.com). This page is hosted on independent infrastructure (separate from our primary GCP environment) to ensure it remains available and accurate even during a total platform outage. It displays real-time health for all core services (UI, API, Reporting Engine, Ingestion).

Email Alerts: Users can subscribe to the Status Page to receive proactive notifications. Alerts are triggered immediately upon incident detection, providing updates on investigation progress, identified root causes, and final resolution.

API: The Status Page exposes a public JSON API. This allows client IT teams to programmatically query current system status and integrate our service health data directly into their own internal monitoring dashboards or ticketing systems.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
We enforce a strict "Least Privilege" for all interfaces:

Identity & MFA: Access requires a corporate Google Workspace identity protected by mandatory hardware-backed MFA.

Network Access: Management interfaces are protected by Google Identity-Aware Proxy (IAP). We verify user identity and device context before granting access, removing direct public internet exposure.

RBAC: Permissions are assigned via Google Cloud IAM on a strict need-to-know basis. Access rights are reviewed quarterly.

Support Isolation: Support agents use a segregated ticketing system with no direct access to production data. Emergency debugging requires a temporary, time-bound "Break Glass" approval from a senior engineer, ensuring full auditability.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Information Security Management System (ISMS): Our security framework is built in strict alignment with ISO 27001:2022 standards. We are currently in the final stages of the external certification process. Our ISMS governs all aspects of data privacy, risk management, and operational security.

Reporting Structure: Security governance flows from the top down:

Board Level: The CEO retains ultimate accountability for information security.

Security Steering Committee: Meets monthly to review risks and compliance.

Data Protection Officer (DPO): Responsible for GDPR compliance and acts as the liaison for data subjects.

Enforcement & Assurance: We ensure policy adherence through a "Trust but Verify" approach:

Automated Compliance: We utilize Google Cloud Security Command Center to automatically monitor our infrastructure against CIS Benchmarks and ISO controls in real-time. Violations trigger immediate alerts.

Internal Audits: We conduct quarterly internal reviews of access logs, user privileges, and policy acceptance.

Staff Training: All employees must complete mandatory security and GDPR training upon hire and annually thereafter. Failure to comply results in disciplinary action.

Key Policies: Our ISMS includes valid policies for: Access Control, Incident Management, Business Continuity, Asset Management, and Secure Development.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Description: While pending formal certification, our processes strictly follow ITIL and ISO 27001 objectives:

Peer Review: All code requires mandatory peer review via Pull Request before merging.

Automation: Automated CI/CD pipelines run tests before deployment, preventing human error.

Segregation: We strictly separate Development, Staging, and Production; developers cannot access live databases.

Audit Trail: Every production change is logged and attributed to a user for full traceability
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Our vulnerability management process aligns with NCSC guidelines and ISO 27001 controls:

Automated Scanning: We utilise Google Cloud Artifact Registry and Security Command Center to automatically scan container images and infrastructure for known CVEs daily.

Dependency Analysis: We employ Software Composition Analysis (SCA) tools (e.g., Dependabot or Snyk) to detect vulnerabilities in third-party libraries before code is merged.

Patching SLAs: We enforce strict remediation timelines based on CVSS severity:

Critical (CVSS 9-10): < 48 hours.

High (CVSS 7-8.9): < 7 days.

Medium: < 30 days.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Identification: We employ a dual-detection strategy using Google Security Command Center for automated real-time anomaly detection and a dedicated security email for manual reporting.

Response Process: We strictly follow the NCSC Incident Management lifecycle:

Triage: Verify severity immediately.

Containment: Isolate affected resources to prevent spread.

Eradication: Patch vulnerabilities and remove threats.

Recovery: Restore services from clean backups.

Notification: Inform customers and regulators within 72 hours (GDPR).

Speed: We guarantee a 1-hour response time for Critical/High severity incidents (24/7) and 4 hours for Medium/Low issues.
Incident management type
Supplier-defined controls
Incident management approach
We operate a formal Incident Management framework aligned with NCSC guidelines.

Pre-defined Processes: We utilize standardized Runbooks for common scenarios (e.g., DDoS, service outage, data breach) to ensure rapid, consistent execution without decision fatigue.

User Reporting: Users submit incidents via our Support Portal or emergency email (support@domain.com). Critical issues trigger immediate 24/7 paging to our engineering team via PagerDuty.

Incident Reports: We provide a transparent Post-Incident Review (PIR) for all Critical/High severity events. The PIR details the root cause, remediation steps, and future preventative measures. It is shared with affected customers within 5 working days of resolution.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
We offer a structured 30-day Sandbox Pilot.

Included:

Full access to all premium modules.

Synthetic test data for immediate insights.

A 1-hour engineering kick-off call.

Excluded:

Production SLAs (uptime guarantees).

Live PII data ingestion.

Priority telephone support.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
IoT Cyber Assurance: 0f6c7e2c-7909-411b-9adb-2717c94fc09d

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
    • Plans for positive actions with community groups.
    • Measures for making facilities used in the delivery of the contract available for community groups, education or training
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at enquiry@direkltd.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.