Skip to main content

Help us improve the Digital Marketplace - send your feedback

ARVATO LIMITED

XpertRule Intelligent Decisioning by ArvatoConnect

Our XpertRule Intelligent Decisioning is a no-code platform that combines AI, automation, and human expertise to optimise business decisions. It enables organisations to capture knowledge, integrate predictive analytics, and automate workflows across front, middle, and back-office operations, improving efficiency, compliance, and customer experience through explainable, auditable decision intelligence.

Features

  • No-code platform for rapid decision automation and deployment.
  • Integrates AI, rules, and predictive analytics for intelligent decisions.
  • Supports multi-cloud deployment across AWS, Azure, and Google Cloud.
  • Explainable AI for transparency and regulatory compliance assurance.
  • Real-time decision orchestration across business workflows and processes.
  • Knowledge capture and modelling for complex decision logic.
  • Scalable architecture for enterprise-grade performance and reliability.
  • API integration with existing systems and third-party applications.
  • Personalised decision-making based on dynamic data inputs.
  • Built-in audit trails for governance and accountability.

Benefits

  • Accelerates decision-making through automation and AI-driven insights.
  • Reduces operational costs by streamlining complex workflows efficiently.
  • Improves compliance with explainable, auditable decision processes.
  • Enhances customer experience via personalised, data-driven decisions.
  • Boosts agility with rapid deployment and no-code configuration.
  • Supports scalability for enterprise-wide digital transformation initiatives.
  • Minimises risk through predictive analytics and anomaly detection.
  • Integrates seamlessly with existing systems for smooth adoption.
  • Empowers business users without heavy reliance on IT teams.
  • Drives innovation by combining AI, rules, and human expertise.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at richard.husband@arvatoconnect.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 9 2 9 7 8 1 5 6 7 6 4 8 1 6

Contact

ARVATO LIMITED Richard Husband
Telephone: 07867464428
Email: richard.husband@arvatoconnect.co.uk

About your service

Service categories

Application Development and Deployment

AI platforms

AI software services

  • Generative AI Software Services
  • Anomaly Detection AI Software Services
  • Personalize AI Software Services
  • Forecast AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
XpertRule offers flexible deployment but has important constraints buyers should consider. Integration with complex or fragmented systems may require additional planning and configuration. While multi-cloud is supported, hosting typically occurs in private subnets within the provider’s tenancy.
System requirements
  • Windows Server 2019+ 64-bit
  • MongoDB 5.0 (Community edition)
  • Node.js 16
  • Internet Information Services (IIS) & WebPlatformInstaller
  • PHP 8.1 64-bit (non-thread safe)

User support

Email or online ticketing support
Yes
Support response times
Response times for each level of support are defined below. All specified response times relate to production issues. Response times for non-production issues will be 3 working days:

Priority 1: Standard - 1 Business day; Premium - 2 Business Hours
Priority 2: Standard - 2 Business day; Premium - 4 Business Hours
Priority 3: Standard - 3 Business day; Premium - 4 Business Day

P1 - Represents a complete loss of service or a significant feature that is completely unavailable.
P2 - Includes intermittent issues and reduced quality of service
P3 - Includes product questions, feature requests and development
issues.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
XpertRule offers two structured support levels to meet diverse customer needs:

Standard Support is designed for non-mission-critical deployments. It provides email-based assistance, access to digital resources and XR Academy, and entitlement to new and maintenance releases. Customers receive defined response times: Priority 1 within one business day, Priority 2 within two business days, and Priority 3 within three business days.

Premium Support is tailored for mission-critical and complex applications. It includes live support during business hours (8 hours, 5 days), four nominated contacts, scheduled migration support for cloud-hosted environments, and four one-hour consultation calls with a Viabl.ai product expert. Response times are accelerated: Priority 1 within two hours, Priority 2 within four hours, and Priority 3 within one business day.

Pricing for both support levels is quotation-based, ensuring flexibility to align with customer requirements. While Premium Support offers expert guidance, XpertRule does not provide a dedicated Technical Account Manager or Cloud Support Engineer as part of its standard packages.

These support services ensure customers receive timely assistance, proactive guidance, and access to resources that maintain operational continuity and optimise solution performance.
Support available to third parties
No

Onboarding and offboarding

Getting started
We provide a comprehensive onboarding experience to ensure users can quickly and effectively start using XpertRule. We offer online training through the XpertRule Academy, which includes interactive courses, video tutorials, and self-paced learning modules covering key features, best practices, and advanced configuration. These resources are accessible via a secure portal, enabling users to learn at their convenience.

In addition to online training, XpertRule provides detailed user documentation and developer guides, available in HTML and PDF formats. These include step-by-step instructions, API references, and troubleshooting tips to support both business users and technical teams. For organisations requiring tailored support, we offer remote onboarding sessions with product experts to assist with initial setup, configuration, and integration.

While onsite training is not part of the standard offering, it can be arranged as an optional service for enterprise customers with complex requirements. Our approach ensures flexibility, combining self-service resources with expert guidance to accelerate adoption and maximise value.

This structured onboarding process empowers users to configure workflows, integrate systems, and leverage decision automation capabilities confidently and efficiently.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
When a contract with XpertRule ends, customers can securely extract their data before access is revoked. The process is initiated by contacting our support or the account manager within the agreed notice period. Data is provided in structured formats such as CSV, XML, or JSON, making it suitable for migration to other platforms. For API-enabled deployments, customers can use the REST API to export decision models, workflows, and associated datasets prior to termination.

It is important to complete extraction before the contract end date, as access to the platform ceases immediately after termination, and data may be deleted according to retention policies. Buyers cannot extract system-level configurations or proprietary logic beyond what is contractually permitted. For complex migrations or large datasets, optional Professional Services support may be required.
This approach ensures customers retain control of their data while maintaining compliance and security throughout the offboarding process.
End-of-contract process
When the contract ends, XpertRule follows an agreed Exit Plan to ensure an orderly transition. This includes maintaining service continuity during the handover period, providing supervised access for the buyer or new provider, and ensuring minimum disruption. Buyers are given a reasonable period (typically at least 90 days) to extract their data from XpertRule’s environment. Data is provided in structured formats such as CSV, XML, or JSON, and API access can be used for exporting decision models and workflows. After the notice period, access is revoked, and data is deleted according to retention policies.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
XpertRule is built on a cloud-native architecture accessible via standard web browsers (Chrome, Edge, Firefox, Safari) without requiring additional plugins. It provides a user-friendly interface for decision automation and supports customisable dialogs for data capture and reporting. For integration, XpertRule offers REST APIs, enabling seamless connectivity with external systems and automation workflows. This ensures flexibility, scalability, and ease of use for both end users and technical teams.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
XpertRule is committed to delivering an inclusive and accessible service interface that meets UK Government accessibility requirements and aligns with WCAG 2.1 AA standards. Our approach combines automated and manual testing to ensure compliance and usability for all users, including those relying on assistive technologies.

Automated testing is integrated into our development lifecycle using industry-standard tools such as axe-core-based solutions to identify machine-detectable issues early. Manual testing complements this by validating real-world scenarios, including screen reader compatibility, keyboard-only navigation, logical tab order, and colour contrast checks. These tests confirm that interactive elements are operable without a mouse and that content is perceivable and understandable.

We also conduct iterative reviews with accessibility specialists to ensure compliance with the Public Sector Bodies Accessibility Regulations and the Government Service Standard. While automated tools provide technical assurance, manual checks ensure practical usability for individuals using assistive technologies such as screen readers and magnifiers.

This dual approach guarantees that XpertRule’s web-based interface remains robust, inclusive, and compliant, supporting equal access for all users and meeting the expectations of G-Cloud buyers.
API
Yes
What users can and can't do using the API
XpertRule provides a REST-based API that enables integration and automation of decision logic and workflows. Through the API, users can set up the service by authenticating with secure credentials and configuring endpoints to connect external systems. This includes initial provisioning tasks such as creating decision models, defining input/output parameters, and linking data sources.

Users can make changes via the API by updating model configurations, triggering workflows, and submitting data for real-time decision processing. The API supports operations such as deploying new versions of models, adjusting business rules, and retrieving execution results programmatically.

However, there are limitations. Users cannot fully configure the platform’s infrastructure or perform administrative tasks such as user management through the API; these require access to the web interface or support team. Additionally, complex model development and advanced UI customisation must also be performed using the web interface rather than the API. The API is designed for integration and operational updates, not for complete service setup or environment migration.

This approach ensures flexibility for automation while maintaining governance and security for critical configuration tasks.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
XpertRule is a highly configurable, no-code decision intelligence platform designed to meet diverse organisational needs. Buyers can customise the service extensively through its intuitive interface and tools. Key customisation options include creating and modifying decision models, workflows, and business rules to reflect unique operational processes. The platform also supports integration with external systems via REST APIs, enabling seamless connectivity with CRM, ERP, and other enterprise applications. Additionally, buyers can personalise user interfaces, dashboards, and branding using WYSIWYG tools and CSS for accessibility and corporate identity alignment. While the service offers significant flexibility, certain limitations apply. Buyers cannot alter core infrastructure, hosting environments, or multi-cloud architecture, as these are managed by XpertRule to ensure security and compliance. Advanced model development and complex logic may require vendor assistance. Service-level changes, such as subscription tier adjustments or SLA modifications, must be agreed contractually and cannot be self-administered through the platform. This approach ensures buyers retain control over functional and operational aspects while XpertRule maintains governance over critical infrastructure and compliance, delivering a secure, scalable, and customisable solution.

Scaling

Independence of resources
XpertRule ensures users aren’t impacted by others’ demand through a scalable, multi-cloud architecture and intelligent resource orchestration. Its platform isolates workloads using private subnets and secure integrations, while leveraging elastic cloud resources across AWS, Azure, and Google Cloud. Real-time decision orchestration and API-based integration allow dynamic scaling without performance degradation. Explainable AI and audit trails maintain transparency and compliance, ensuring consistent, reliable outcomes even under high concurrent usage.

Analytics

Service usage metrics
Yes
Metrics types
XpertRule does provide mechanisms to capture and analyse service usage data, primarily through its Intelligent Decisioning platform and associated analytics tools. These metrics include:

Operational Data: Tracks decision execution, workflow performance, and user interactions.
Efficiency Metrics: Measures success rates, agent guidance effectiveness, and self-service adoption.
Audit Trails: Built-in logging for governance and compliance, ensuring transparency in decision-making processes
Reporting types
API access
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
XpertRule

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Data Export Options API-Based Export Users can utilise XpertRule’s interface to extract decision models, workflows, and associated datasets. API endpoints allow exporting data in structured formats such as JSON or XML, suitable for integration or migration. Platform Tools Data can be exported directly from the XpertRule interface using built-in export functions. Common formats include CSV, XML, and JSON, ensuring compatibility with other systems.
Data export formats
  • CSV
  • Other
Other data export formats
  • XML
  • JSON
Data import formats
  • CSV
  • Other
Other data import formats
  • XML
  • JSON

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
XpertRule guarantees high availability through AWS multi-AZ architecture, continuous monitoring, and robust backup strategies. While exact uptime percentages are not explicitly stated, the design aligns with industry standards (≈99.9%). SLA terms focus on support responsiveness: critical issues receive a 2-hour response under Premium support, with lower priorities handled within defined timeframes. If XpertRule fails to meet these commitments, customers are compensated via service credits, ensuring accountability and trust.
Approach to resilience
XpertRule is built on a cloud-native architecture designed for high availability and operational resilience. The platform is deployed within secure environments using multiple availability zones, ensuring continuity in the event of localised outages. Private subnet isolation and strict access controls minimise exposure to external threats, while encryption at rest and in transit safeguards data integrity.

Business Continuity (BC) and Disaster Recovery (DR) plans are embedded into operations, with regular testing to validate readiness. These include multi-site operational flexibility and remote working capabilities to maintain service delivery during major incidents. The infrastructure supports hybrid deployment models, combining on-premises and cloud resources for added resilience and scalability.
Datacentre design follows UK government guidance for Critical National Infrastructure (CNI), incorporating redundancy across power, cooling, and connectivity systems. Resilience-by-design principles ensure failover capability through active-active or active-passive configurations. Regular penetration testing and IT health checks underpin compliance with National Cyber Security Centre (NCSC) standards.

This approach ensures XpertRule delivers secure, reliable, and uninterrupted service, even under adverse conditions. Detailed technical specifications on resilience and datacentre setup are available on request.
Outage reporting
XpertRule provides a structured approach to outage communication, ensuring transparency and timely updates for customers. The service does not currently offer a public-facing dashboard for outage status. Instead, it relies on direct communication channels to keep stakeholders informed.

Email Alerts
Automated email notifications are the primary method for reporting outages. These alerts include incident summaries, status updates, and estimated resolution times. Emails are routed dynamically to customer-specific addresses using pre-configured templates, ensuring relevant and accurate information reaches the right recipients promptly.

API Integration
For organisations requiring automated monitoring, XpertRule supports API integration. This enables customers to extract incident data programmatically for inclusion in their own dashboards or IT service management tools. The API provides structured data for outage events, escalation status, and resolution progress.

Escalation and Monitoring
Internally, XpertRule uses live dashboards for operational teams to track incident volumes, sentiment, and escalation workflows. While these dashboards are not public, they underpin the service’s ability to maintain 24/7 availability and rapid response.

This multi-channel approach ensures outages are communicated effectively, with options for integration into customer systems. Detailed technical specifications and API documentation are available on request.

Identity and authentication

User authentication needed
Yes
User authentication
Username or password
Access restrictions in management interfaces and support channels
XpertRule enforces strict access controls across management interfaces and support channels to maintain security and integrity. Administrative functions are protected by role-based access control (RBAC), ensuring only authorised personnel can perform configuration or system changes. Multi-factor authentication (MFA) is mandatory for privileged accounts, reducing the risk of unauthorised access. Support channels operate under verified identity protocols, with all requests authenticated before action. Sensitive operations, such as data changes or escalations, require documented approval and are logged for audit purposes. Continuous monitoring and periodic reviews ensure compliance with ISO 27001 and NCSC security principles.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users receive audit information on a regular basis
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users receive audit information on a regular basis
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Information Security Policies and Processes:
We adhere to robust information security policies aligned with ISO 27001, GDPR, and UK Government NCSC Cloud Security Principles. Our framework is based on the Bertelsmann Information Security Management System (ISMS), supported by ArvatoConnect-specific policies. These cover key areas such as access control, cryptographic measures, data security, vulnerability management, incident response, and personnel security.

Reporting Structure:
Information security governance is overseen by the Head of Security and Information Assurance, with accountability through the Information Security Management Forum. Policies are reviewed annually or as required, ensuring continuous compliance and improvement.

Policy Enforcement:
Compliance is maintained through mandatory training, role-based access controls, and regular IT Health Checks (ITHC), penetration testing, and audits. Incident management processes are in place for security breaches, supported by forensic readiness and monitoring tools.

Our approach ensures confidentiality, integrity, and availability of information assets, with clear escalation paths and documented assurance evidence. These measures demonstrate our commitment to secure-by-design principles and proactive risk management.

Detailed policy documents and governance frameworks are available on request.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
XpertRule follows structured configuration and change management processes aligned with industry standards. All service components are tracked throughout their lifecycle using a central configuration management database (CMDB), ensuring accurate records of versions, dependencies, and ownership. Changes undergo formal assessment, including risk and impact analysis, with specific focus on potential security implications such as data integrity, access control, and vulnerability exposure. Authorisation is required before implementation, and rollback plans are documented for contingency. Continuous monitoring, audit trails, and periodic reviews ensure compliance and accountability, maintaining a secure and controlled environment for all updates.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
XpertRule operates a proactive vulnerability management process to safeguard services. Potential threats are assessed through continuous monitoring, automated scans, and risk analysis, prioritising critical vulnerabilities based on severity and potential impact. Patches and security updates are deployed promptly, typically within 24–72 hours for high-risk issues, following rigorous testing and change control procedures. Threat intelligence is sourced from trusted feeds, including vendor advisories, NCSC alerts, and industry vulnerability databases such as CVE. Regular penetration testing and IT health checks complement this process, ensuring rapid identification and remediation of emerging risks while maintaining compliance with security standards.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
XpertRule employs continuous protective monitoring to detect and respond to potential compromises. Automated tools and security information and event management (SIEM) systems analyse logs, network traffic, and user activity for anomalies or indicators of compromise. When a potential threat is identified, it is escalated through our incident response process, which includes verification, containment, and remediation steps. Critical incidents are addressed immediately, with initial response typically within one hour and full resolution prioritised based on severity. Alerts are supported by 24/7 monitoring and threat intelligence feeds, ensuring rapid detection and mitigation to maintain service integrity and compliance.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
XpertRule maintains pre-defined incident management processes for common events, including security breaches, service outages, and data integrity issues. These processes follow structured workflows for identification, containment, eradication, and recovery, ensuring rapid and consistent response. Users can report incidents via dedicated service desk channels, email, or integrated ticketing systems, which trigger immediate triage and escalation based on severity. Incident reports are provided to customers through formal communication, including root cause analysis, resolution steps, and preventive measures. Regular reviews and post-incident assessments ensure continuous improvement and compliance with ISO 27001 and NCSC best practices.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
  • Public Services Network (PSN)
  • Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Wednesday 7 September 2022
What the ISO/IEC 27001 doesn’t cover
While it is not practicable to list exclusions in isolation, our ISO 27001 certification supports all contracted services to ArvatoConnect customers, including contact centre, back-office and IT services.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI
ISO 9001 accreditation date
Monday 16 January 2023
What the ISO 9001 doesn’t cover
While it is not practicable to list exclusions in isolation, our ISO 9001 certification supports business process outsourcing, delivering a comprehensive range of front and back office services. This includes customer experience services and administrative services.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Fbb5c636-5561-4d78-b819-3360c25ffe07
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
A774e5a5-9ad4-4cbf-a7a3-e47ea2c0ef05
Other security certifications
Yes
Any other security certifications
  • Tisax
  • ISO 20000-1:2018

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at richard.husband@arvatoconnect.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.