XpertRule Intelligent Decisioning by ArvatoConnect
Our XpertRule Intelligent Decisioning is a no-code platform that combines AI, automation, and human expertise to optimise business decisions. It enables organisations to capture knowledge, integrate predictive analytics, and automate workflows across front, middle, and back-office operations, improving efficiency, compliance, and customer experience through explainable, auditable decision intelligence.
Features
- No-code platform for rapid decision automation and deployment.
- Integrates AI, rules, and predictive analytics for intelligent decisions.
- Supports multi-cloud deployment across AWS, Azure, and Google Cloud.
- Explainable AI for transparency and regulatory compliance assurance.
- Real-time decision orchestration across business workflows and processes.
- Knowledge capture and modelling for complex decision logic.
- Scalable architecture for enterprise-grade performance and reliability.
- API integration with existing systems and third-party applications.
- Personalised decision-making based on dynamic data inputs.
- Built-in audit trails for governance and accountability.
Benefits
- Accelerates decision-making through automation and AI-driven insights.
- Reduces operational costs by streamlining complex workflows efficiently.
- Improves compliance with explainable, auditable decision processes.
- Enhances customer experience via personalised, data-driven decisions.
- Boosts agility with rapid deployment and no-code configuration.
- Supports scalability for enterprise-wide digital transformation initiatives.
- Minimises risk through predictive analytics and anomaly detection.
- Integrates seamlessly with existing systems for smooth adoption.
- Empowers business users without heavy reliance on IT teams.
- Drives innovation by combining AI, rules, and human expertise.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 9 2 9 7 8 1 5 6 7 6 4 8 1 6
Contact
ARVATO LIMITED
Richard Husband
Telephone: 07867464428
Email: richard.husband@arvatoconnect.co.uk
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI software services
- Generative AI Software Services
- Anomaly Detection AI Software Services
- Personalize AI Software Services
- Forecast AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- XpertRule offers flexible deployment but has important constraints buyers should consider. Integration with complex or fragmented systems may require additional planning and configuration. While multi-cloud is supported, hosting typically occurs in private subnets within the provider’s tenancy.
- System requirements
-
- Windows Server 2019+ 64-bit
- MongoDB 5.0 (Community edition)
- Node.js 16
- Internet Information Services (IIS) & WebPlatformInstaller
- PHP 8.1 64-bit (non-thread safe)
User support
- Email or online ticketing support
- Yes
- Support response times
-
Response times for each level of support are defined below. All specified response times relate to production issues. Response times for non-production issues will be 3 working days:
Priority 1: Standard - 1 Business day; Premium - 2 Business Hours
Priority 2: Standard - 2 Business day; Premium - 4 Business Hours
Priority 3: Standard - 3 Business day; Premium - 4 Business Day
P1 - Represents a complete loss of service or a significant feature that is completely unavailable.
P2 - Includes intermittent issues and reduced quality of service
P3 - Includes product questions, feature requests and development
issues. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
XpertRule offers two structured support levels to meet diverse customer needs:
Standard Support is designed for non-mission-critical deployments. It provides email-based assistance, access to digital resources and XR Academy, and entitlement to new and maintenance releases. Customers receive defined response times: Priority 1 within one business day, Priority 2 within two business days, and Priority 3 within three business days.
Premium Support is tailored for mission-critical and complex applications. It includes live support during business hours (8 hours, 5 days), four nominated contacts, scheduled migration support for cloud-hosted environments, and four one-hour consultation calls with a Viabl.ai product expert. Response times are accelerated: Priority 1 within two hours, Priority 2 within four hours, and Priority 3 within one business day.
Pricing for both support levels is quotation-based, ensuring flexibility to align with customer requirements. While Premium Support offers expert guidance, XpertRule does not provide a dedicated Technical Account Manager or Cloud Support Engineer as part of its standard packages.
These support services ensure customers receive timely assistance, proactive guidance, and access to resources that maintain operational continuity and optimise solution performance. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
We provide a comprehensive onboarding experience to ensure users can quickly and effectively start using XpertRule. We offer online training through the XpertRule Academy, which includes interactive courses, video tutorials, and self-paced learning modules covering key features, best practices, and advanced configuration. These resources are accessible via a secure portal, enabling users to learn at their convenience.
In addition to online training, XpertRule provides detailed user documentation and developer guides, available in HTML and PDF formats. These include step-by-step instructions, API references, and troubleshooting tips to support both business users and technical teams. For organisations requiring tailored support, we offer remote onboarding sessions with product experts to assist with initial setup, configuration, and integration.
While onsite training is not part of the standard offering, it can be arranged as an optional service for enterprise customers with complex requirements. Our approach ensures flexibility, combining self-service resources with expert guidance to accelerate adoption and maximise value.
This structured onboarding process empowers users to configure workflows, integrate systems, and leverage decision automation capabilities confidently and efficiently. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
When a contract with XpertRule ends, customers can securely extract their data before access is revoked. The process is initiated by contacting our support or the account manager within the agreed notice period. Data is provided in structured formats such as CSV, XML, or JSON, making it suitable for migration to other platforms. For API-enabled deployments, customers can use the REST API to export decision models, workflows, and associated datasets prior to termination.
It is important to complete extraction before the contract end date, as access to the platform ceases immediately after termination, and data may be deleted according to retention policies. Buyers cannot extract system-level configurations or proprietary logic beyond what is contractually permitted. For complex migrations or large datasets, optional Professional Services support may be required.
This approach ensures customers retain control of their data while maintaining compliance and security throughout the offboarding process. - End-of-contract process
- When the contract ends, XpertRule follows an agreed Exit Plan to ensure an orderly transition. This includes maintaining service continuity during the handover period, providing supervised access for the buyer or new provider, and ensuring minimum disruption. Buyers are given a reasonable period (typically at least 90 days) to extract their data from XpertRule’s environment. Data is provided in structured formats such as CSV, XML, or JSON, and API access can be used for exporting decision models and workflows. After the notice period, access is revoked, and data is deleted according to retention policies.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- XpertRule is built on a cloud-native architecture accessible via standard web browsers (Chrome, Edge, Firefox, Safari) without requiring additional plugins. It provides a user-friendly interface for decision automation and supports customisable dialogs for data capture and reporting. For integration, XpertRule offers REST APIs, enabling seamless connectivity with external systems and automation workflows. This ensures flexibility, scalability, and ease of use for both end users and technical teams.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
XpertRule is committed to delivering an inclusive and accessible service interface that meets UK Government accessibility requirements and aligns with WCAG 2.1 AA standards. Our approach combines automated and manual testing to ensure compliance and usability for all users, including those relying on assistive technologies.
Automated testing is integrated into our development lifecycle using industry-standard tools such as axe-core-based solutions to identify machine-detectable issues early. Manual testing complements this by validating real-world scenarios, including screen reader compatibility, keyboard-only navigation, logical tab order, and colour contrast checks. These tests confirm that interactive elements are operable without a mouse and that content is perceivable and understandable.
We also conduct iterative reviews with accessibility specialists to ensure compliance with the Public Sector Bodies Accessibility Regulations and the Government Service Standard. While automated tools provide technical assurance, manual checks ensure practical usability for individuals using assistive technologies such as screen readers and magnifiers.
This dual approach guarantees that XpertRule’s web-based interface remains robust, inclusive, and compliant, supporting equal access for all users and meeting the expectations of G-Cloud buyers. - API
- Yes
- What users can and can't do using the API
-
XpertRule provides a REST-based API that enables integration and automation of decision logic and workflows. Through the API, users can set up the service by authenticating with secure credentials and configuring endpoints to connect external systems. This includes initial provisioning tasks such as creating decision models, defining input/output parameters, and linking data sources.
Users can make changes via the API by updating model configurations, triggering workflows, and submitting data for real-time decision processing. The API supports operations such as deploying new versions of models, adjusting business rules, and retrieving execution results programmatically.
However, there are limitations. Users cannot fully configure the platform’s infrastructure or perform administrative tasks such as user management through the API; these require access to the web interface or support team. Additionally, complex model development and advanced UI customisation must also be performed using the web interface rather than the API. The API is designed for integration and operational updates, not for complete service setup or environment migration.
This approach ensures flexibility for automation while maintaining governance and security for critical configuration tasks. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- XpertRule is a highly configurable, no-code decision intelligence platform designed to meet diverse organisational needs. Buyers can customise the service extensively through its intuitive interface and tools. Key customisation options include creating and modifying decision models, workflows, and business rules to reflect unique operational processes. The platform also supports integration with external systems via REST APIs, enabling seamless connectivity with CRM, ERP, and other enterprise applications. Additionally, buyers can personalise user interfaces, dashboards, and branding using WYSIWYG tools and CSS for accessibility and corporate identity alignment. While the service offers significant flexibility, certain limitations apply. Buyers cannot alter core infrastructure, hosting environments, or multi-cloud architecture, as these are managed by XpertRule to ensure security and compliance. Advanced model development and complex logic may require vendor assistance. Service-level changes, such as subscription tier adjustments or SLA modifications, must be agreed contractually and cannot be self-administered through the platform. This approach ensures buyers retain control over functional and operational aspects while XpertRule maintains governance over critical infrastructure and compliance, delivering a secure, scalable, and customisable solution.
Scaling
- Independence of resources
- XpertRule ensures users aren’t impacted by others’ demand through a scalable, multi-cloud architecture and intelligent resource orchestration. Its platform isolates workloads using private subnets and secure integrations, while leveraging elastic cloud resources across AWS, Azure, and Google Cloud. Real-time decision orchestration and API-based integration allow dynamic scaling without performance degradation. Explainable AI and audit trails maintain transparency and compliance, ensuring consistent, reliable outcomes even under high concurrent usage.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
XpertRule does provide mechanisms to capture and analyse service usage data, primarily through its Intelligent Decisioning platform and associated analytics tools. These metrics include:
Operational Data: Tracks decision execution, workflow performance, and user interactions.
Efficiency Metrics: Measures success rates, agent guidance effectiveness, and self-service adoption.
Audit Trails: Built-in logging for governance and compliance, ensuring transparency in decision-making processes - Reporting types
- API access
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- XpertRule
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Data Export Options API-Based Export Users can utilise XpertRule’s interface to extract decision models, workflows, and associated datasets. API endpoints allow exporting data in structured formats such as JSON or XML, suitable for integration or migration. Platform Tools Data can be exported directly from the XpertRule interface using built-in export functions. Common formats include CSV, XML, and JSON, ensuring compatibility with other systems.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XML
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XML
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- XpertRule guarantees high availability through AWS multi-AZ architecture, continuous monitoring, and robust backup strategies. While exact uptime percentages are not explicitly stated, the design aligns with industry standards (≈99.9%). SLA terms focus on support responsiveness: critical issues receive a 2-hour response under Premium support, with lower priorities handled within defined timeframes. If XpertRule fails to meet these commitments, customers are compensated via service credits, ensuring accountability and trust.
- Approach to resilience
-
XpertRule is built on a cloud-native architecture designed for high availability and operational resilience. The platform is deployed within secure environments using multiple availability zones, ensuring continuity in the event of localised outages. Private subnet isolation and strict access controls minimise exposure to external threats, while encryption at rest and in transit safeguards data integrity.
Business Continuity (BC) and Disaster Recovery (DR) plans are embedded into operations, with regular testing to validate readiness. These include multi-site operational flexibility and remote working capabilities to maintain service delivery during major incidents. The infrastructure supports hybrid deployment models, combining on-premises and cloud resources for added resilience and scalability.
Datacentre design follows UK government guidance for Critical National Infrastructure (CNI), incorporating redundancy across power, cooling, and connectivity systems. Resilience-by-design principles ensure failover capability through active-active or active-passive configurations. Regular penetration testing and IT health checks underpin compliance with National Cyber Security Centre (NCSC) standards.
This approach ensures XpertRule delivers secure, reliable, and uninterrupted service, even under adverse conditions. Detailed technical specifications on resilience and datacentre setup are available on request. - Outage reporting
-
XpertRule provides a structured approach to outage communication, ensuring transparency and timely updates for customers. The service does not currently offer a public-facing dashboard for outage status. Instead, it relies on direct communication channels to keep stakeholders informed.
Email Alerts
Automated email notifications are the primary method for reporting outages. These alerts include incident summaries, status updates, and estimated resolution times. Emails are routed dynamically to customer-specific addresses using pre-configured templates, ensuring relevant and accurate information reaches the right recipients promptly.
API Integration
For organisations requiring automated monitoring, XpertRule supports API integration. This enables customers to extract incident data programmatically for inclusion in their own dashboards or IT service management tools. The API provides structured data for outage events, escalation status, and resolution progress.
Escalation and Monitoring
Internally, XpertRule uses live dashboards for operational teams to track incident volumes, sentiment, and escalation workflows. While these dashboards are not public, they underpin the service’s ability to maintain 24/7 availability and rapid response.
This multi-channel approach ensures outages are communicated effectively, with options for integration into customer systems. Detailed technical specifications and API documentation are available on request.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- XpertRule enforces strict access controls across management interfaces and support channels to maintain security and integrity. Administrative functions are protected by role-based access control (RBAC), ensuring only authorised personnel can perform configuration or system changes. Multi-factor authentication (MFA) is mandatory for privileged accounts, reducing the risk of unauthorised access. Support channels operate under verified identity protocols, with all requests authenticated before action. Sensitive operations, such as data changes or escalations, require documented approval and are logged for audit purposes. Continuous monitoring and periodic reviews ensure compliance with ISO 27001 and NCSC security principles.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Information Security Policies and Processes:
We adhere to robust information security policies aligned with ISO 27001, GDPR, and UK Government NCSC Cloud Security Principles. Our framework is based on the Bertelsmann Information Security Management System (ISMS), supported by ArvatoConnect-specific policies. These cover key areas such as access control, cryptographic measures, data security, vulnerability management, incident response, and personnel security.
Reporting Structure:
Information security governance is overseen by the Head of Security and Information Assurance, with accountability through the Information Security Management Forum. Policies are reviewed annually or as required, ensuring continuous compliance and improvement.
Policy Enforcement:
Compliance is maintained through mandatory training, role-based access controls, and regular IT Health Checks (ITHC), penetration testing, and audits. Incident management processes are in place for security breaches, supported by forensic readiness and monitoring tools.
Our approach ensures confidentiality, integrity, and availability of information assets, with clear escalation paths and documented assurance evidence. These measures demonstrate our commitment to secure-by-design principles and proactive risk management.
Detailed policy documents and governance frameworks are available on request. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- XpertRule follows structured configuration and change management processes aligned with industry standards. All service components are tracked throughout their lifecycle using a central configuration management database (CMDB), ensuring accurate records of versions, dependencies, and ownership. Changes undergo formal assessment, including risk and impact analysis, with specific focus on potential security implications such as data integrity, access control, and vulnerability exposure. Authorisation is required before implementation, and rollback plans are documented for contingency. Continuous monitoring, audit trails, and periodic reviews ensure compliance and accountability, maintaining a secure and controlled environment for all updates.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- XpertRule operates a proactive vulnerability management process to safeguard services. Potential threats are assessed through continuous monitoring, automated scans, and risk analysis, prioritising critical vulnerabilities based on severity and potential impact. Patches and security updates are deployed promptly, typically within 24–72 hours for high-risk issues, following rigorous testing and change control procedures. Threat intelligence is sourced from trusted feeds, including vendor advisories, NCSC alerts, and industry vulnerability databases such as CVE. Regular penetration testing and IT health checks complement this process, ensuring rapid identification and remediation of emerging risks while maintaining compliance with security standards.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- XpertRule employs continuous protective monitoring to detect and respond to potential compromises. Automated tools and security information and event management (SIEM) systems analyse logs, network traffic, and user activity for anomalies or indicators of compromise. When a potential threat is identified, it is escalated through our incident response process, which includes verification, containment, and remediation steps. Critical incidents are addressed immediately, with initial response typically within one hour and full resolution prioritised based on severity. Alerts are supported by 24/7 monitoring and threat intelligence feeds, ensuring rapid detection and mitigation to maintain service integrity and compliance.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- XpertRule maintains pre-defined incident management processes for common events, including security breaches, service outages, and data integrity issues. These processes follow structured workflows for identification, containment, eradication, and recovery, ensuring rapid and consistent response. Users can report incidents via dedicated service desk channels, email, or integrated ticketing systems, which trigger immediate triage and escalation based on severity. Incident reports are provided to customers through formal communication, including root cause analysis, resolution steps, and preventive measures. Regular reviews and post-incident assessments ensure continuous improvement and compliance with ISO 27001 and NCSC best practices.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Wednesday 7 September 2022
- What the ISO/IEC 27001 doesn’t cover
- While it is not practicable to list exclusions in isolation, our ISO 27001 certification supports all contracted services to ArvatoConnect customers, including contact centre, back-office and IT services.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Monday 16 January 2023
- What the ISO 9001 doesn’t cover
- While it is not practicable to list exclusions in isolation, our ISO 9001 certification supports business process outsourcing, delivering a comprehensive range of front and back office services. This includes customer experience services and administrative services.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Fbb5c636-5561-4d78-b819-3360c25ffe07
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- A774e5a5-9ad4-4cbf-a7a3-e47ea2c0ef05
- Other security certifications
- Yes
- Any other security certifications
-
- Tisax
- ISO 20000-1:2018
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
-