Orion
Orion is an intelligence and analytics platform that combines data from multiple sources to identify risk, fraud and complex patterns. It provides visualisation and investigative tools that help users analyse relationships, detect anomalies and support informed operational and investigative decision-making.
Features
- Multi-source data ingestion
- Advanced analytics and pattern detection
- Interactive visualisation dashboards
- Link and network analysis
- Configurable risk indicators
- Search and filtering tools
- Case and investigation management
- Audit trails and evidential capture
- Secure role-based access control
Benefits
- Faster identification of risk and fraud
- Improved investigative efficiency
- Better insight from complex datasets
- More informed decision-making
- Prioritisation of high-risk activity
- Reduced manual analysis effort
- Increased transparency and auditability
- Consistent investigative processes
- Enhanced operational effectiveness
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 0 8 2 4 5 1 6 2 7 6 1 2 8 2
Contact
SYNECTICS SOLUTIONS LIMITED
Louise Williams
Telephone: 0333 234 3409
Email: publicsectorservices@synectics-solutions.com
About your service
- Service categories
-
Applications
Enterprise resource management
Financial
- Treasury and Risk Management Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Orion is not an extension of third-party software. It can be deployed standalone but is commonly used alongside SIRA, extending it with advanced analytics, visualisation and investigative tools to support deeper analysis, insight generation and decision-making.
- Cloud deployment model
- Private cloud
- Service constraints
- Orion is provided as a cloud-hosted SaaS service and requires a supported web browser and network connectivity. The service relies on the availability and quality of customer-provided or third-party data sources. Buyers do not manage underlying infrastructure, and custom functionality beyond configuration may require professional services. Data ingestion volumes and performance are subject to agreed service limits.
- System requirements
-
- Modern, standards-compliant web browser
- Secure internet network connectivity
- HTTPS access enabled
- Supported desktop or laptop device
User support
- Email or online ticketing support
- Yes
- Support response times
- User support responses are provided in line with the customer’s agreed SLA. Under the Synectics standard SLA, response times on working days are: Critical issues within 4 hours, High within 8 hours, Medium within 3 working days, and Low within 5 working days. Synectics also provides reactive support on Saturdays between 9am and 2pm. Additional or enhanced support arrangements can be procured on a case-by-case basis where required.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Synectics Solutions provides structured user support for the Orion service aligned to agreed service level agreements. Orion is supported for 12 hours per day as standard, with 24-hour support available at additional cost. The service is designed to operate for extended periods without manual intervention, ensuring system availability beyond core support hours.
Support is available via telephone and email and is delivered by a dedicated Business Operations function. This comprises an Application Support Team responsible for incident management, operational monitoring, issue tracking and resolution, supported by second-line specialists who also contribute to ongoing service improvement. A separate Problem Management Team investigates underlying issues and works to reduce the likelihood of recurrence.
Application Support and Service Desk hours are 07:00–19:00 GMT, Monday to Friday, excluding public holidays in England and Wales. Severity 1 and 2 incidents may also be reported outside core hours, including early mornings, evenings, weekends and public holidays, within defined escalation windows.
Standard support is included in the service price. Enhanced support options, including extended hours, 24-hour coverage and dedicated technical account management or cloud support engineers, are available at additional cost on a case-by-case basis. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Synectics Solutions supports onboarding through a structured and supported approach. New users and existing customers have access to a dedicated help desk facility that provides training and guidance. A full suite of user guides is provided to support independent use of the service. Training can be delivered through hosted online sessions or on-site where required. Customers are supported by a dedicated service manager who oversees onboarding activities and ensures users are able to start using the service effectively.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- When a contract ends, Synectics Solutions works with the customer to support data extraction in line with the customer’s termination policies and contractual terms. Data is made available in agreed formats and transferred securely to the customer or a nominated third party. The approach, scope and timing of data extraction are agreed during offboarding to ensure a controlled and compliant service exit.
- End-of-contract process
-
At the end of the contract, Synectics Solutions works with the customer to agree the service exit approach, including data extraction, service shutdown and data deletion, in line with contractual terms and customer policies. The service is then disabled and fully decommissioned, and customer data is securely deleted in accordance with agreed processes.
Standard offboarding activities, including coordination of service termination, data extraction in agreed formats and confirmation of service decommissioning, are included in the contract price. Any additional support, such as bespoke data transformation, extended access periods or non-standard exit activities, may be provided at additional cost subject to agreement. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding documentation is provided in standard digital formats that can be accessed using commonly available devices and software. Where required, Synectics Solutions can provide documentation in alternative formats or offer additional guidance through the help desk to support users with specific accessibility needs.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service interface for user support is provided through direct communication with the Synectics Solutions support team. Users interact with the service via telephone calls and online meetings, such as GoToMeeting or Webex, to report issues, discuss incidents and receive assistance. This approach enables real-time interaction, effective troubleshooting and collaborative resolution of support queries with appropriate technical specialists.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service interface is delivered through telephone calls and online meetings, making it accessible without requiring users to interact with a bespoke digital interface. Users can report issues, discuss incidents, receive guidance and participate in troubleshooting sessions through verbal communication and screen sharing. Users can apply their own accessibility settings and assistive technologies within the conferencing tools they use. Users cannot self-serve through an online portal or ticketing interface; all support interactions are mediated by Synectics Solutions support staff, with reasonable adjustments made where required.
- Accessibility testing
- Formal interface testing with users of assistive technology has not been undertaken for the service interface, as support is delivered via telephone and third-party online meeting platforms rather than a bespoke user interface. Accessibility is addressed through the use of widely adopted conferencing tools that support assistive technologies and user-controlled accessibility features. Informal feedback from users is considered, and reasonable adjustments to communication methods are made where required to accommodate individual accessibility needs.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Users can customise the service by selecting and combining modules to create a solution that best meets their business needs.
Users can choose which service modules are enabled, allowing functionality to be tailored to specific operational, analytical or support requirements.
Module selection is agreed during onboarding or through change requests and is configured within the service by Synectics Solutions.
Customisation is requested by authorised customer representatives, such as service managers or contract owners, and implemented by Synectics Solutions in line with the agreed service scope.
Scaling
- Independence of resources
- Synectics Solutions ensures users are not adversely affected by demand from other users through a resilient, scalable service architecture. Capacity and performance are regularly tested to validate headroom and identify scaling requirements. The service uses load balancing to distribute demand efficiently, supported by multiple internet connections and redundant components to maintain performance and availability. This approach provides isolation and resilience, ensuring consistent service levels as demand fluctuates across users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- A full suite of standard and bespoke reports are available from within the system
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Independent review of processes (for example CESG CPA Build Standard, Cyber Essentials , ISO/IEC 27001 )
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Through CSV or excel
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- JPEG
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XLS
- XLSX
- .TXT
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Synectics Solutions guarantees a service availability level of 98% or higher, measured over the agreed service period. All planned development, upgrades and maintenance activities are performed within scheduled maintenance windows and are executed outside of normal operating hours to minimise impact on users.
Availability commitments and measurement criteria are defined within the customer’s SLA. If guaranteed availability levels are not met, service credits or refunds are applied in accordance with the terms set out in the SLA. These remedies are proportionate to the level and duration of service unavailability and are agreed contractually with the customer. - Approach to resilience
-
The service is designed with resilience built in at both the application and infrastructure levels to maintain availability and protect customer data. The underlying systems are engineered to be highly fault tolerant, using dual power supplies and redundant network connections to reduce single points of failure. Load balancing and capacity planning are used to maintain service continuity under varying demand.
The service is hosted in highly resilient data centres. These facilities are supported by uninterruptible power supplies and backup generators to maintain power continuity, alongside FM200 fire suppression systems for physical asset protection. Data centres are served by multiple internet service provider connections to ensure network resilience. Further details of the data centre resilience architecture can be provided on request. - Outage reporting
- Service outages are reported directly to customers in line with contractual agreements. Where an outage exceeds the client’s contractual targets, Synectics Solutions notifies the client directly, providing details of the issue, estimated resolution times and proposed remediation. Notifications are typically delivered via direct communication channels such as email or telephone. The service does not provide a public status dashboard or outage reporting API.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is tightly controlled. Orion users can only access the service from authorised, allow-listed IP addresses. Each client accesses its own isolated service instance, identified by a unique domain. All users authenticate using unique user IDs verified by the application. Role-based access controls are enforced, and client-managed administrator accounts are provided to control user provisioning, permissions and access levels within their organisation.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Synectics Solutions operates a formal Information Security Management System (ISMS) certified to ISO/IEC 27001:2013, supported by documented security policies and procedures.
Overall responsibility for information security rests with the Chief Information Security Officer (CISO), who reports to the Legal & Compliance Director. An ISMS Review Committee, including at least one Director, meets twice annually to review security posture, risks and compliance. A Security Strategy Group meets fortnightly to oversee security direction and ongoing improvements. Day-to-day operational security is managed by a dedicated IT Security team, with physical security managed by the Facilities team.
Synectics adheres to Cyber Essentials and follows established Security Operating Procedures (SyOPS). Protective monitoring controls are selected from GPG13, informed by IS1 risk assessments, and are designed to protect OFFICIAL information. An assessment against GPG43 (RSDOPS) has been completed, and the platform has been continuously accredited since 2009. All 14 government cloud security principles are met in the secure delivery of services. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management processes are operated in line with ITIL V3.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Synectics Solutions operates a structured vulnerability management process aligned to its ISO/IEC 27001–certified ISMS. Potential threats are assessed through annual penetration and vulnerability testing, continuous monitoring and risk-based analysis. Where significant issues are identified, the Business Continuity Plan is invoked and a dedicated project team manages remediation. Patch deployment follows a defined patching policy, with prioritisation based on risk and severity. The IT Security team monitors multiple threat intelligence sources, including NCSC guidance, vendor advisories, AlienVault Open Threat Exchange and industry feeds, and participates in the NCSC Cyber Security Information Sharing Partnership (CiSP).
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Synectics Solutions operates protective monitoring in line with documented security policies and accredited RMADS. Potential compromises are identified through continuous monitoring using IPS/IDS and a SIEM solution, supported by annual penetration and vulnerability testing. Alerts are reviewed to detect anomalous or suspicious activity. When a potential compromise is identified, incidents are assessed and managed in accordance with the Information Security Incident Management policy, including containment, investigation and remediation. Response actions are prioritised by severity, with prompt escalation and resolution in line with defined security procedures and incident response times.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Synectics Solutions operates a formal incident management process aligned with NCSC guidance, industry best practice and ISO/IEC 27035. Pre-defined processes are in place for common security and service incidents, supported by documented playbooks and escalation procedures. Users report incidents through dedicated helpdesk facilities via telephone or email. All incidents are managed in line with the Security Incident Management Policy, with remediation supported by departmental Business Continuity Plans where required. Incident reports, including impact, actions taken and outcomes, are provided to customers as appropriate.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- The service does not provide a free production version. A time-limited proof of concept can be offered to demonstrate how the service applies to existing processes and potential operational uplift. The proof of concept is scoped with the customer and excludes full production functionality.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI Assurance UK Ltd
- ISO/IEC 27001 accreditation date
- Sunday 14 December 2025
- What the ISO/IEC 27001 doesn’t cover
- There are no exclusions, it covers the entire organisation
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5481ad36-f8b8-4fbf-a885-0fc0b874aed6
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 45d04f71-6b83-45f8-a067-3157e440a657
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-