Skip to main content

Help us improve the Digital Marketplace - send your feedback

BEST COMPANIES LIMITED

Employee engagement service

Best Companies is the UK’s leading employee engagement specialist, known for setting the standard in workplace excellence. Our data-driven platform, expert consultancy, and nationally recognised accreditation system help organisations measure, understand and improve employee engagement, driving higher performance, stronger collaboration and sustainable organisational success.

Features

  • Tailored Engagement Surveys
  • Insightful Reporting & Benchmarking
  • Accreditation System
  • Leadership & Culture Consultancy
  • Data Insight Workshops
  • Pulse Surveys & Real-Time Feedback
  • Manager Dashboards
  • Recognition Tools
  • Inclusive Participation

Benefits

  • Designed to uncover what matters most to your people
  • Detailed analytics including engagement scores and sector comparisons
  • Celebrate progress with our respected 1 to 3 Star ratings
  • Expert support to interpret results and drive change
  • Facilitated manager sessions that transform survey data into strategic actions
  • Stay connected with flexible, continuous listening tools
  • Equip people leaders with actionable insights to improve engagement
  • Reinforce values and celebrate success across your organisation
  • Accessible formats and multilingual support to hear every voice

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at enquiries@b.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 1 9 6 0 5 4 0 1 2 8 6 8 5 4

Contact

BEST COMPANIES LIMITED Head of Client Success
Telephone: 01978 851220
Email: enquiries@b.co.uk

About your service

Service categories

Applications

Customer relationship management

  • Customer service
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Our products support the following browsers:

Microsoft Edge
Google Chrome
Mozilla Firefox
Apple Safari

We no longer support Internet Explorer version 10 and earlier, as some of our products may not appear as designed.
System requirements
Microsoft Edge, Google Chrome, Mozilla Firefox, Apple Safari supported

User support

Email or online ticketing support
Yes
Support response times
Within 48 hours
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Standard Support included for all plans:

Available during UK business hours (09:00–17:00, Monday–Friday, excluding public holidays)
Technical support is also available by email or phone if required.

For those who opt for the Improve or Elevate plans, a dedicated Account Manager for support and guidance is assigned.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We support users to start using our service through a structured guided onboarding process backed by dedicated client support training and documentation.

Each client is assigned a strategic point of contact, either a Client Outcomes Manager or a Client Experience Specialist, who leads onboarding and acts as the primary point of contact throughout the engagement.

Onboarding begins with a strategic kick off call where we introduce Best Companies, outline the end to end journey, agree success metrics, and confirm the client’s survey objectives. This is followed by a survey setup call with our Client Experience team, who provide a full guided walkthrough of the survey dashboard. This includes configuration of employment groups, survey statements, and guidance on the employee data required.

As clients progress, we offer an insights strategy call to support their rollout approach and help them maximise value from our platforms, including Elevate and Workplace Insight. The Client Experience team also provides live demonstrations of these platforms.

In addition, users have access to supporting user documentation and video demonstrations, enabling them to use the service confidently at their own pace. Ongoing support is available throughout the contract to help clients achieve the best possible outcomes from the service.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
PowerPoint
End-of-contract data extraction
With regards to the reporting generated through the services, should the contract end and the services lapse, the Client will have a 30 day grace period during which all reporting can be downloaded from the Workplace Insight Tool.
With regards to the data shared for the delivery of the services, we retain personal data in accordance with our Terms of Service for a period of up to three years following the lapse of the subscription term. During this period, all personal identifiers, including employee name, email address, and any information that could directly or indirectly identify an individual, are permanently deleted. This process anonymises the remaining statistical data. Our approach is consistent with the Information Commissioners Office (ICO) Anonymisation Code of Practice. In line with the UK General Data Protection Regulation (GDPR), data that has been anonymised so that the data subject is no longer identifiable is not considered personal data.
We retain anonymised survey responses and demographic information for ongoing research purposes. Once all identifying data has been removed, the remaining statistical data is no longer deemed personal data within the meaning of the UK GDPR.
End-of-contract process
At the end of the contract, the Agreement continues until the end of the Initial Subscription Term and will then automatically renew for successive periods of twelve months unless the client elects not to renew. The client may choose not to renew at the end of the Initial Subscription Term or any Renewal Period, in which case the Agreement will terminate at the expiry of that term. A Grace Period of thirty days may be applied following expiry, during which the client may still elect to renew. During this period, Services remain accessible but with reduced functionality. If the client renews during the Grace Period, the Renewal Period is treated as having commenced at the start of that Grace Period.
The contract price covers the Services included within the agreed Subscription Term. Any additional services or deliverables outside the agreed scope, such as optional consultancy, extra survey cycles or enhanced reporting, would be treated as additional costs.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Our documentation is made accessible through our CRM Knowledge Base, where clients can access detailed articles relating to both the onboarding and offboarding. These articles can be view offline if preferred. To support users who may have difficulty reading or engaging with written documentation, we also offer virtual run throughs of all onboarding and offboarding materials. During these sessions, our team provides a verbal, guided walkthrough of the processes, ensuring that clients with accessibility needs receive the same level of understanding and support as those using the written guides.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is delivered as a responsive web application. Functionality remains consistent across mobile and desktop devices, while the layout adapts for smaller screens: navigation collapses into a menu, content flows into a single column, tables use stacked or scrollable views, and touch-friendly controls and spacing are applied. No separate native mobile application is required; users access the service via a mobile browser.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Users access the service through a browser-based web interface. The interface supports core user journeys, including sign-in, data entry, viewing reports and dashboards, and administration. It is designed to be fully responsive across desktop, tablet, and mobile viewports. Where integrations are provided, they are delivered via authenticated endpoints; there is no separate public-facing API portal.
Accessibility standards
None or don’t know
Description of accessibility
Accessibility Guidelines (WCAG) 2.1 AA standard to which we believe we meet. Below outlines some of the steps towards this:

• Inclusive Design for Neurodivergent Users:

The platform has been designed with a clean, distraction-free layout, clear visual hierarchy, the use of plain language, and carefully chosen, readable fonts to support neurodivergent individuals.

• Screen Reader Compatibility:

The survey platform works with screen readers, making it accessible to users with visual impairments.

• Keyboard Navigation Support:

Users can navigate the entire survey using just a keyboard, ensuring inclusivity for those with motor impairments or who prefer non-mouse input methods.
Accessibility testing
We have tested our survey portal for accessibility against WCAG 2.1 AA standards using screen readers and keyboard-only navigation. Testing includes verifying correct use of headings and landmarks, form labels and error messages, logical focus order and visible focus indicators, accessible names for controls, and ensuring content remains usable with zoom and reflow.
API
No
Customisation available
No

Scaling

Independence of resources
Our systems are designed to handle much higher load than what we typically expect to receive. We also have monitoring setup to alert us if utilisation of infrastructure resources is reaching thresholds we set so we can make decisions about scaling infrastructure to give us more capacity or we may use our monitoring products to investigate and push performance improvements out in our products to reduce inefficiencies.

Analytics

Service usage metrics
Yes
Metrics types
Survey‑related metrics are available, including response and completion rates broken down by employment group and by manager. In addition to survey analytics, a range of service usage metrics can be provided on request, such as logins, page views, feature‑usage patterns, and other engagement indicators. Further or more detailed data can be supplied as required.
Reporting types
Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
NCSC approved service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Data Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can export their data directly from the client dashboard. Only the data they have provided for the services can be downloaded. Survey responses, while used to create reporting, do not become part of the client dataset. This ensures respondents can answer honestly without any risk of reprisal. We are the sole data controller for all information provided directly by data subjects. This data is used by our research team, acting as a separate data controller, to conduct statistical research and to produce benchmarking statistics at sector, regional and national levels. The research database is pseudo anonymised to protect individuals.
Data export formats
Other
Other data export formats
Excel
Data import formats
Other
Other data import formats
Excel

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
When developing or altering systems we always do so with failover and redundancy in mind. The server setup we use has failover options at every stage, which come into effect automatically should a service or piece of hardware encounter an issue. We have real time monitoring in place which is configured to report when there is an issue with one or more sites. Once alerted, a staff member will respond accordingly and escalate where required to avoid issues or resolve them as quickly as possible.

Most of our services are handled by external hosting providers. For our internal systems, we aim to restore services as soon as possible if an issue occurs. We have a one hour response agreement with our hosting providers for any issues that cannot be resolved in house.

The majority of our client services are automated and self serve. Our services are not considered business critical to our customers. While an unplanned outage may be frustrating, our services do not impact critical infrastructure or the provision of continuity services.
Approach to resilience
All data is stored within the United Kingdom or the European Union and is processed in compliance with applicable data protection legislation.

Our services are delivered using Microsoft infrastructure. Microsoft manages and operates the datacentre environments that support the services and is responsible for the physical security and resilience of those datacentres, including redundancy, availability and fault tolerance controls. Further information on Microsoft datacentre resilience is available on request.

All physical assets are encrypted using built in functionality such as BitLocker or are managed through a mobile device management profile that allows remote wiping where required.

Data held within Microsoft services, Barracuda, Jira and HubSpot is encrypted at rest.

We have the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident.
Equipment disposal is managed securely. Hard drives are wiped onsite using Blancco prior to being collected by an IT asset disposal company, where they are physically shredded.
Outage reporting
We would handle an outage differently depending on what part(s) of our service were affected. Our company website www.b.co.uk runs in Webflow and not Azure, this gives us the ability to put a message on this website if we experience serious product issues with our Azure based products. We’d also consider emails or calls from our Customer Success team depending on what was most appropriate.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Processes are in place for joiners, leavers, and movers. Active Directory and Microsoft 365 membership groups restrict access to departmental folders and resources, with all activity logged in our ticket management software. The allocation of privileged rights is restricted and controlled, with authorisation jointly provided by the system owner and the IT department. Technical teams guard against issuing privileged rights to entire teams to prevent loss of confidentiality. Access rights follow the principles of least privilege and need to know. Event logs are regularly reviewed for suspicious activity or account lockouts. Two step authentication is in place for all users.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Best Companies follows a comprehensive set of information security policies and processes that are reviewed regularly and supported at board level. We maintain an Information Security Policy that is reviewed annually and signed off by a director, along with a wide range of supporting policies including acceptable use, access control, remote access, anti virus, patch management, vulnerability management, password, firewall, data classification, change management, retention, disaster recovery, business continuity, incident response and data breach reporting. GDPR compliance is overseen by our Data Protection Officer who reports directly to senior management and is involved in all matters relating to data protection. Regular internal audits, monthly and six monthly reviews, and an annual GDPR audit ensure policies are followed. Staff receive mandatory training on data protection, data handling, company policy and cyber security on induction and at least annually. All employees are required to report any suspected security weaknesses and all incidents are logged, investigated and signed off by senior management. Security responsibilities are clearly defined and reported through senior management meetings and board reporting, ensuring strong oversight and accountability across the organisation.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
The components of our services are tracked through their lifetime using established configuration management processes. All changes go through a formal change management process where they are assessed for potential security impact before implementation.

Vulnerability Assessment and Penetration Testing is conducted by an external organisation at least annually, and all Best Companies applications including the survey code, servers, and infrastructure networks are covered in the scan.

An incident management process is in place, along with the ability to restore availability and access to data in a timely manner.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We operate a multi‑layered vulnerability‑management process aligned with ISO 27001. We conduct annual external VAPT with an independent provider and perform quarterly scans of our public IPs. We use Mend.io to continuously monitor software components for known vulnerabilities and SecurityScorecard to track externally visible risks.

Patches to operating systems and supporting services are deployed weekly, with accelerated patching for any critical vulnerabilities disclosed by vendors.

Vulnerabilities identified through scanning, VAPT, Mend.io, or SecurityScorecard are risk‑assessed and prioritised for remediation according to severity.

We receive vulnerability intelligence from sources including our VAPT partner, Mend.io, SecurityScorecard, vendor advisories, and Microsoft Azure guidance.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We operate ISO 27001‑aligned protective‑monitoring processes supported by logging and alerting. We identify potential compromises through centralised log monitoring, external attack‑surface monitoring (SecurityScorecard), continuous software‑dependency scanning (Mend.io).

Our services run on Microsoft Azure, which provides multi‑layer physical and operational monitoring, such as surveillance, access control, continuous system monitoring, and security reviews, to detect anomalies at the infrastructure layer.

When a potential compromise is detected, we follow a structured incident‑response process: triage, containment, investigation, eradication, recovery, and post‑incident review.

We respond to high‑severity incidents and escalate any confirmed threat without delay, applying a risk‑based prioritisation model for medium and low‑severity events.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We have established clear roles, responsibilities and documented procedures to ensure a quick, effective and orderly response to information security incidents. All employees are trained to recognise and report any observed or suspected information security weaknesses, and reporting procedures are also in place with our processors. Incidents are assessed and classified according to likelihood and severity, logged in all cases including near misses, and investigated with findings reviewed and signed off by senior management. Where clients are affected, we notify them without undue delay and provide detailed incident reports outlining the nature, consequences and remedial actions taken.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
7.5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
UKAS Management Systems
ISO/IEC 27001 accreditation date
Thursday 11 December 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
UKAS Management Systems
ISO 9001 accreditation date
Thursday 11 December 2025
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Self-Certification
PCI DSS accreditation date
Monday 4 August 2025
What the PCI DSS doesn’t cover
N/A
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at enquiries@b.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.