Skip to main content

Help us improve the Digital Marketplace - send your feedback

CITRUS SUITE LTD

AppiHealth

AppiHealth is an SaaS framework for rapidly deploying bespoke, DTAC-compliant mobile health apps and web platforms. Supports remote patient monitoring, self-management, and digital therapeutics. Features include symptom tracking, medication reminders, and interoperable clinical dashboards. Scalable from simple support tools to integrated systems for NHS trusts and healthcare providers.

Features

  • Rapid deployment of branded iOS and Android health apps.
  • Secure web-based clinical dashboard for real-time patient support.
  • Symptom tracking, health metric logging, and mood monitoring tools.
  • Scalable Content Management System for educational health resources.
  • Configurable framework supporting diverse therapeutic areas and conditions.
  • Encryption ensuring secure sensitive health data management.
  • Patient engagement tools including medication reminders and gamification.

Benefits

  • Improve patient adherence with intuitive, gamified self-management tools.
  • Alleviate pressure on NHS resources via digital self-help tools.
  • Accelerate recovery through structured digital rehabilitation programmes.
  • Reduce clinical workload through effective remote patient support.
  • Support patients on waiting lists with digital pre-hab interventions.
  • Accelerate recovery through structured digital rehabilitation programmes.
  • Scale effortlessly from local pilots to enterprise-wide deployment.
  • Drive decisions with real-time health data and analytics.
  • Significantly reduce costs compared to bespoke software development.
  • Rapidly deploy branded apps to accelerate digital transformation.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@citrussuite.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 9 9 8 2 8 4 5 7 7 1 1 4 5 5

Contact

CITRUS SUITE LTD Chris Morland
Telephone: 0151 345 1979
Email: hello@citrussuite.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Planned maintenance is scheduled outside standard UK business hours with prior notification. The service requires an active internet connection for data synchronization. The web dashboard is optimised for modern browsers (Chrome, Edge, Safari). Mobile applications require currently supported versions of iOS and Android.
System requirements
  • Modern web browser: Chrome, Edge, Safari, or Firefox.
  • IOS device running currently supported operating system version.
  • Android device running currently supported operating system version.
  • Active internet connection required for real-time data synchronization.
  • Standard HTTPS internet access (Port 443) for connectivity.
  • No local server hardware or software installation required.

User support

Email or online ticketing support
Yes
Support response times
Availability 10am to 5pm Monday to Friday (UK time zone, BST / GMT), excluding UK bank holidays & Xmas.
Service level response targets:
• 1 hour for all critical issues
• 24 hours response for non-critical issues
• 5-working days for other items (feedback/suggestions, quotes, schedules and business discussion).
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Support overview:
• Enquiries from project team, Client staff, authorised Client contacts.
• Second line support (technical IT issues)
• Please contact your Citrus Suite representatives by email or telephone to log support requests, support time will be calculated by the hours used per intervention.
Dedicated support, bespoke quote.
Support available to third parties
No

Onboarding and offboarding

Getting started
We work with client to customise and set up app: Getting started:

Our approach to customisation and setup is client-centric, designed to ensure a smooth, efficient deployment and a high degree of user confidence. The process is collaborative and tailored to your organisational structure and specific project needs.

Customisation Workshop:
We begin with a detailed workshop to finalise the bespoke elements of your chosen package (Silver, Gold, or Diamond). This includes feature configuration, branding requirements, integration points, and data flows.

Staging and Deployment:
The customised app is deployed to a staging environment for your testing and validation before final release to the public app stores (iOS and Android).
Training and Documentation:
To ensure immediate productivity and adoption, we provide tiered support and documentation:
Online Training:
Virtual sessions are provided for key administrative and clinical staff, covering the Web-based Portal CMS, data analytics dashboards, and feature configuration. These are recorded for future reference.
Onsite Training (subject to quote):
For larger deployments or complex integrations, we can arrange onsite sessions with your teams.
User Documentation:
We supply role-specific documentation.
Direct Support:
Our technical support team is available during the setup phase and throughout your annual subscription to assist with any queries.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
The contract ensures that you retain ownership of all patient data and analytics generated through AppiHealth.

Upon the conclusion of your contract, the process for data extraction and offboarding is as follows:
Data Provision: Copy of your data and analytics, including patient records, health metrics and system logs, in a standard, secure, and easily transferrable format (e.g., CSV).
Data Transfer: Data is typically transferred via a secure method, such as an encrypted file transfer protocol (SFTP) or a secure physical storage medium, as mutually agreed upon in the contract's terms for termination.
Data Sanitisation: Following successful data transfer and confirmation of receipt, all of your associated data will be securely and permanently deleted from our servers and backup systems, adhering to strict data sanitisation protocols and compliance standards like DTAC, to ensure no patient data remains on our platform.
Timing: The contract will specify the timeline for data extraction and deletion, typically completed within a defined period (e.g., 30-90 days) after the contract end date.
End-of-contract process
App Decommissioning: The AppiHealth apps will be taken offline as the Annual Subscription is no longer active, ceasing all ongoing services (hosting, maintenance, etc.) plus Data Transfer if agreed.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
No
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Mobile first for end users
Service interface
No
User support accessibility
None or don’t know
API
No
Customisation available
Yes
Description of customisation
Core System and Functionality: The product is designed to be customisable and scalable, allowing it to be swiftly reconfigured to support various health conditions and patient groups. The top-tier Diamond Package offers a highly customised system with tailored functionalities, advanced features, and integrations.
Health Conditions: A bespoke app can be created to support any health condition.
Branding: The Gold Package includes your own branded iOS & Android apps (in contrast to the Silver Package which is AppiHealth branded).
Content: Educational content can be updated.

Scaling

Independence of resources
AppiHealth is designed to maintain consistent performance, regardless of demand spikes from other users. While the specific architecture details, such as the use of AWS, are not publicly disclosed in the product specification, the platform is built on a modern, tried and tested tech stack and engineered to be scalable.

Analytics

Service usage metrics
Yes
Metrics types
We provide usage metrics and data analytics, as this is a core component of both the Gold and Diamond packages. The connected versions included in these packages feature a web backend specifically for administration and data analytics, which allows the client to track how the app is being used by patients, monitor engagement, and measure adoption of resources.
Reporting types
  • Real-time dashboards
  • Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
Other
Other data at rest protection approach
AppiHealth is hosted in a standalone AWS environment. Data at rest is encrypted using industry-standard encryption provided by AWS-managed services. Physical access to underlying infrastructure is controlled by AWS in accordance with internationally recognised data centre security standards. Access to data is restricted through role-based permissions and least-privilege principles. Administrative access is protected using strong authentication and multi-factor authentication. Systems are maintained in line with Cyber Essentials & DSP Toolkit principles, including secure configuration, patching, and malware protection where applicable.
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
AppiHealth does not include a patient-facing feature for individual users to directly export their data (e.g., via a "Download My Data" button within the app).
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection between networks
Data is protected in transit between the buyer’s network and AppiHealth using industry-standard encryption (HTTPS/TLS). AppiHealth is hosted in a standalone AWS environment, logically isolated from Citrus Suite’s internal network and from NHS or buyer networks. There is no direct network connectivity between these environments. Access is restricted through authentication and role-based controls, and network boundaries are protected using AWS security groups and firewalls. This approach ensures secure data transfer while maintaining clear separation between networks.
Data protection within supplier network
Other
Other protection within supplier network
Data within our network is protected in line with Cyber Essentials principles. AppiHealth is hosted in a standalone AWS environment using network segmentation, firewalls, and security groups to restrict access to authorised services only. Data is encrypted at rest. Access is limited through role-based permissions, strong passwords, and multi-factor authentication for administrative accounts. Systems are kept up to date with security patches, and anti-malware protections are in place where applicable. Access is logged and reviewed, ensuring least-privilege access and separation from Citrus Suite’s internal systems.

Availability and resilience

Guaranteed availability
AppiHealth is provided on a best-endeavours basis using resilient cloud infrastructure hosted on AWS. We do not offer a fixed percentage availability guarantee unless explicitly agreed in writing. Service availability is supported through use of managed cloud services, monitoring, and planned maintenance. No automatic service credits or refunds apply if availability targets are not met. Where availability commitments or service levels are required, these can be agreed as part of a specific contract or Statement of Work. Any remedies for failure to meet agreed availability levels will be set out in that agreement.
Approach to resilience
AppiHealth is designed to be resilient through the use of managed cloud infrastructure hosted on AWS. The service is deployed in a standalone environment with redundancy at the infrastructure and platform level, including resilient storage and managed backups. AWS data centres provide physical security, power, cooling, and network resilience as standard. Regular backups support recovery from data loss or system failure. The service is monitored to identify availability issues. Further detail on infrastructure resilience and data centre arrangements can be provided to buyers on request.
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using standard access controls. Administrative interfaces are accessible only to authorised Citrus Suite staff with role-based permissions. Strong passwords and multi-factor authentication are used where supported. Access is granted on a least-privilege basis and reviewed when roles change or staff leave. Support requests are handled through controlled communication channels, and sensitive information is not shared unless identity and authority are confirmed. All administrative access and support activity is logged where available to support audit and incident investigation.
Access restriction testing frequency
Less than once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
No audit information available
Access to supplier activity audit information
No audit information available
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
DSP Toolkit, UK Cyber Essentials.
Information security policies and processes
Citrus Suite follows documented information security policies covering data protection, access control, incident management, change management, and acceptable use. Policies are approved and overseen by senior management, including the Data Protection Officer and technical leads. Responsibilities for information security are clearly defined, with escalation routes for incidents and risks. Compliance is supported through staff training, role-based access controls, logging, and periodic reviews of access and systems. Policies are communicated to staff and contractors, and adherence is monitored through audits, incident reviews, and management oversight, with corrective actions taken where required.
Software Security Code of Practice
No

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Citrus Suite uses a defined configuration and change management process to maintain security and service stability. Service components such as source code, infrastructure configuration, from development to retirement. Changes are planned, recorded, and approved by senior staff. Changes are assessed for potential security and data protection impact, including effects on access controls, authentication, data handling, and availability. Higher-risk changes receive additional review and testing before release, with logs maintained to support traceability and incident investigation.
Vulnerability management type
Undisclosed
Vulnerability management approach
Citrus Suite operates a proportionate vulnerability management process aligned with industry good practice. Potential threats are assessed through routine risk reviews, technical monitoring, and consideration of how vulnerabilities could impact confidentiality, integrity, or availability of services. Security patches and updates are applied promptly, with higher-risk vulnerabilities prioritised for faster remediation. We obtain threat and vulnerability information from trusted sources including software vendors, cloud and hosting providers, the National Cyber Security Centre (NCSC), and use a platform to give an overview on software patching. This information informs patching, configuration updates, and ongoing risk management activities.
Protective monitoring type
Undisclosed
Protective monitoring approach
Citrus Suite uses protective monitoring appropriate to its services and size to detect potential security incidents. We identify potential compromises through system logs, access monitoring, hosting provider alerts, and notifications from security services such as the NCSC Early Warning service. When a potential compromise is identified, access may be restricted, affected systems isolated, and an initial assessment carried out by senior technical staff. Incidents are investigated and managed in line with our incident response process, with higher-risk incidents escalated immediately. Initial response actions are taken promptly, typically within hours of detection.
Incident management type
Undisclosed
Incident management approach
Citrus Suite has defined incident management processes proportionate to our services. We maintain pre-defined procedures for common events such as data breaches, unauthorised access, malware, and service disruption. Incidents can be reported by users or clients via agreed contact points, including email or direct contact with project leads. All incidents are logged, assessed, and managed by senior technical staff in line with our incident response process. Where appropriate, incident reports would be produced outlining the issue, impact, actions taken, and lessons learned, and are shared with affected clients in a timely manner.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Citrus Suite provides a free demonstration of a generic AppiSpaces application. This includes access to a sample app and a high-level discussion to assess requirements. The free version excludes bespoke development, customisation, integrations, data migration, and support. The demo is for evaluation only and is time-limited.
Link to free trial
https://www.citrussuite.com/software/appihealth/

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
10%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
F5480c78-e92b-442c-b3b7-71d4c23b44e5
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@citrussuite.com. Tell them what format you need. It will help if you say what assistive technology you use.