Employee engagement service
Best Companies is the UK’s leading employee engagement specialist, known for setting the standard in workplace excellence. Our data-driven platform, expert consultancy, and nationally recognised accreditation system help organisations measure, understand and improve employee engagement, driving higher performance, stronger collaboration and sustainable organisational success.
Features
- Tailored Engagement Surveys
- Insightful Reporting & Benchmarking
- Accreditation System
- Leadership & Culture Consultancy
- Data Insight Workshops
- Pulse Surveys & Real-Time Feedback
- Manager Dashboards
- Recognition Tools
- Inclusive Participation
Benefits
- Designed to uncover what matters most to your people
- Detailed analytics including engagement scores and sector comparisons
- Celebrate progress with our respected 1 to 3 Star ratings
- Expert support to interpret results and drive change
- Facilitated manager sessions that transform survey data into strategic actions
- Stay connected with flexible, continuous listening tools
- Equip people leaders with actionable insights to improve engagement
- Reinforce values and celebrate success across your organisation
- Accessible formats and multilingual support to hear every voice
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 1 9 6 0 5 4 0 1 2 8 6 8 5 4
Contact
BEST COMPANIES LIMITED
Head of Client Success
Telephone: 01978 851220
Email: enquiries@b.co.uk
About your service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
Our products support the following browsers:
Microsoft Edge
Google Chrome
Mozilla Firefox
Apple Safari
We no longer support Internet Explorer version 10 and earlier, as some of our products may not appear as designed. - System requirements
- Microsoft Edge, Google Chrome, Mozilla Firefox, Apple Safari supported
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 48 hours
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Standard Support included for all plans:
Available during UK business hours (09:00–17:00, Monday–Friday, excluding public holidays)
Technical support is also available by email or phone if required.
For those who opt for the Improve or Elevate plans, a dedicated Account Manager for support and guidance is assigned. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We support users to start using our service through a structured guided onboarding process backed by dedicated client support training and documentation.
Each client is assigned a strategic point of contact, either a Client Outcomes Manager or a Client Experience Specialist, who leads onboarding and acts as the primary point of contact throughout the engagement.
Onboarding begins with a strategic kick off call where we introduce Best Companies, outline the end to end journey, agree success metrics, and confirm the client’s survey objectives. This is followed by a survey setup call with our Client Experience team, who provide a full guided walkthrough of the survey dashboard. This includes configuration of employment groups, survey statements, and guidance on the employee data required.
As clients progress, we offer an insights strategy call to support their rollout approach and help them maximise value from our platforms, including Elevate and Workplace Insight. The Client Experience team also provides live demonstrations of these platforms.
In addition, users have access to supporting user documentation and video demonstrations, enabling them to use the service confidently at their own pace. Ongoing support is available throughout the contract to help clients achieve the best possible outcomes from the service. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- PowerPoint
- End-of-contract data extraction
-
With regards to the reporting generated through the services, should the contract end and the services lapse, the Client will have a 30 day grace period during which all reporting can be downloaded from the Workplace Insight Tool.
With regards to the data shared for the delivery of the services, we retain personal data in accordance with our Terms of Service for a period of up to three years following the lapse of the subscription term. During this period, all personal identifiers, including employee name, email address, and any information that could directly or indirectly identify an individual, are permanently deleted. This process anonymises the remaining statistical data. Our approach is consistent with the Information Commissioners Office (ICO) Anonymisation Code of Practice. In line with the UK General Data Protection Regulation (GDPR), data that has been anonymised so that the data subject is no longer identifiable is not considered personal data.
We retain anonymised survey responses and demographic information for ongoing research purposes. Once all identifying data has been removed, the remaining statistical data is no longer deemed personal data within the meaning of the UK GDPR. - End-of-contract process
-
At the end of the contract, the Agreement continues until the end of the Initial Subscription Term and will then automatically renew for successive periods of twelve months unless the client elects not to renew. The client may choose not to renew at the end of the Initial Subscription Term or any Renewal Period, in which case the Agreement will terminate at the expiry of that term. A Grace Period of thirty days may be applied following expiry, during which the client may still elect to renew. During this period, Services remain accessible but with reduced functionality. If the client renews during the Grace Period, the Renewal Period is treated as having commenced at the start of that Grace Period.
The contract price covers the Services included within the agreed Subscription Term. Any additional services or deliverables outside the agreed scope, such as optional consultancy, extra survey cycles or enhanced reporting, would be treated as additional costs. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Our documentation is made accessible through our CRM Knowledge Base, where clients can access detailed articles relating to both the onboarding and offboarding. These articles can be view offline if preferred. To support users who may have difficulty reading or engaging with written documentation, we also offer virtual run throughs of all onboarding and offboarding materials. During these sessions, our team provides a verbal, guided walkthrough of the processes, ensuring that clients with accessibility needs receive the same level of understanding and support as those using the written guides.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is delivered as a responsive web application. Functionality remains consistent across mobile and desktop devices, while the layout adapts for smaller screens: navigation collapses into a menu, content flows into a single column, tables use stacked or scrollable views, and touch-friendly controls and spacing are applied. No separate native mobile application is required; users access the service via a mobile browser.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Users access the service through a browser-based web interface. The interface supports core user journeys, including sign-in, data entry, viewing reports and dashboards, and administration. It is designed to be fully responsive across desktop, tablet, and mobile viewports. Where integrations are provided, they are delivered via authenticated endpoints; there is no separate public-facing API portal.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
Accessibility Guidelines (WCAG) 2.1 AA standard to which we believe we meet. Below outlines some of the steps towards this:
• Inclusive Design for Neurodivergent Users:
The platform has been designed with a clean, distraction-free layout, clear visual hierarchy, the use of plain language, and carefully chosen, readable fonts to support neurodivergent individuals.
• Screen Reader Compatibility:
The survey platform works with screen readers, making it accessible to users with visual impairments.
• Keyboard Navigation Support:
Users can navigate the entire survey using just a keyboard, ensuring inclusivity for those with motor impairments or who prefer non-mouse input methods. - Accessibility testing
- We have tested our survey portal for accessibility against WCAG 2.1 AA standards using screen readers and keyboard-only navigation. Testing includes verifying correct use of headings and landmarks, form labels and error messages, logical focus order and visible focus indicators, accessible names for controls, and ensuring content remains usable with zoom and reflow.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Our systems are designed to handle much higher load than what we typically expect to receive. We also have monitoring setup to alert us if utilisation of infrastructure resources is reaching thresholds we set so we can make decisions about scaling infrastructure to give us more capacity or we may use our monitoring products to investigate and push performance improvements out in our products to reduce inefficiencies.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Survey‑related metrics are available, including response and completion rates broken down by employment group and by manager. In addition to survey analytics, a range of service usage metrics can be provided on request, such as logins, page views, feature‑usage patterns, and other engagement indicators. Further or more detailed data can be supplied as required.
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export their data directly from the client dashboard. Only the data they have provided for the services can be downloaded. Survey responses, while used to create reporting, do not become part of the client dataset. This ensures respondents can answer honestly without any risk of reprisal. We are the sole data controller for all information provided directly by data subjects. This data is used by our research team, acting as a separate data controller, to conduct statistical research and to produce benchmarking statistics at sector, regional and national levels. The research database is pseudo anonymised to protect individuals.
- Data export formats
- Other
- Other data export formats
- Excel
- Data import formats
- Other
- Other data import formats
- Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
When developing or altering systems we always do so with failover and redundancy in mind. The server setup we use has failover options at every stage, which come into effect automatically should a service or piece of hardware encounter an issue. We have real time monitoring in place which is configured to report when there is an issue with one or more sites. Once alerted, a staff member will respond accordingly and escalate where required to avoid issues or resolve them as quickly as possible.
Most of our services are handled by external hosting providers. For our internal systems, we aim to restore services as soon as possible if an issue occurs. We have a one hour response agreement with our hosting providers for any issues that cannot be resolved in house.
The majority of our client services are automated and self serve. Our services are not considered business critical to our customers. While an unplanned outage may be frustrating, our services do not impact critical infrastructure or the provision of continuity services. - Approach to resilience
-
All data is stored within the United Kingdom or the European Union and is processed in compliance with applicable data protection legislation.
Our services are delivered using Microsoft infrastructure. Microsoft manages and operates the datacentre environments that support the services and is responsible for the physical security and resilience of those datacentres, including redundancy, availability and fault tolerance controls. Further information on Microsoft datacentre resilience is available on request.
All physical assets are encrypted using built in functionality such as BitLocker or are managed through a mobile device management profile that allows remote wiping where required.
Data held within Microsoft services, Barracuda, Jira and HubSpot is encrypted at rest.
We have the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident.
Equipment disposal is managed securely. Hard drives are wiped onsite using Blancco prior to being collected by an IT asset disposal company, where they are physically shredded. - Outage reporting
- We would handle an outage differently depending on what part(s) of our service were affected. Our company website www.b.co.uk runs in Webflow and not Azure, this gives us the ability to put a message on this website if we experience serious product issues with our Azure based products. We’d also consider emails or calls from our Customer Success team depending on what was most appropriate.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Processes are in place for joiners, leavers, and movers. Active Directory and Microsoft 365 membership groups restrict access to departmental folders and resources, with all activity logged in our ticket management software. The allocation of privileged rights is restricted and controlled, with authorisation jointly provided by the system owner and the IT department. Technical teams guard against issuing privileged rights to entire teams to prevent loss of confidentiality. Access rights follow the principles of least privilege and need to know. Event logs are regularly reviewed for suspicious activity or account lockouts. Two step authentication is in place for all users.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Best Companies follows a comprehensive set of information security policies and processes that are reviewed regularly and supported at board level. We maintain an Information Security Policy that is reviewed annually and signed off by a director, along with a wide range of supporting policies including acceptable use, access control, remote access, anti virus, patch management, vulnerability management, password, firewall, data classification, change management, retention, disaster recovery, business continuity, incident response and data breach reporting. GDPR compliance is overseen by our Data Protection Officer who reports directly to senior management and is involved in all matters relating to data protection. Regular internal audits, monthly and six monthly reviews, and an annual GDPR audit ensure policies are followed. Staff receive mandatory training on data protection, data handling, company policy and cyber security on induction and at least annually. All employees are required to report any suspected security weaknesses and all incidents are logged, investigated and signed off by senior management. Security responsibilities are clearly defined and reported through senior management meetings and board reporting, ensuring strong oversight and accountability across the organisation.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
The components of our services are tracked through their lifetime using established configuration management processes. All changes go through a formal change management process where they are assessed for potential security impact before implementation.
Vulnerability Assessment and Penetration Testing is conducted by an external organisation at least annually, and all Best Companies applications including the survey code, servers, and infrastructure networks are covered in the scan.
An incident management process is in place, along with the ability to restore availability and access to data in a timely manner. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
We operate a multi‑layered vulnerability‑management process aligned with ISO 27001. We conduct annual external VAPT with an independent provider and perform quarterly scans of our public IPs. We use Mend.io to continuously monitor software components for known vulnerabilities and SecurityScorecard to track externally visible risks.
Patches to operating systems and supporting services are deployed weekly, with accelerated patching for any critical vulnerabilities disclosed by vendors.
Vulnerabilities identified through scanning, VAPT, Mend.io, or SecurityScorecard are risk‑assessed and prioritised for remediation according to severity.
We receive vulnerability intelligence from sources including our VAPT partner, Mend.io, SecurityScorecard, vendor advisories, and Microsoft Azure guidance. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
We operate ISO 27001‑aligned protective‑monitoring processes supported by logging and alerting. We identify potential compromises through centralised log monitoring, external attack‑surface monitoring (SecurityScorecard), continuous software‑dependency scanning (Mend.io).
Our services run on Microsoft Azure, which provides multi‑layer physical and operational monitoring, such as surveillance, access control, continuous system monitoring, and security reviews, to detect anomalies at the infrastructure layer.
When a potential compromise is detected, we follow a structured incident‑response process: triage, containment, investigation, eradication, recovery, and post‑incident review.
We respond to high‑severity incidents and escalate any confirmed threat without delay, applying a risk‑based prioritisation model for medium and low‑severity events. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We have established clear roles, responsibilities and documented procedures to ensure a quick, effective and orderly response to information security incidents. All employees are trained to recognise and report any observed or suspected information security weaknesses, and reporting procedures are also in place with our processors. Incidents are assessed and classified according to likelihood and severity, logged in all cases including near misses, and investigated with findings reviewed and signed off by senior management. Where clients are affected, we notify them without undue delay and provide detailed incident reports outlining the nature, consequences and remedial actions taken.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 7.5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- UKAS Management Systems
- ISO/IEC 27001 accreditation date
- Thursday 11 December 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- UKAS Management Systems
- ISO 9001 accreditation date
- Thursday 11 December 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Self-Certification
- PCI DSS accreditation date
- Monday 4 August 2025
- What the PCI DSS doesn’t cover
- N/A
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
-