Melo
Melo is a digital platform built in collaboration with NHS Trusts and clinical experts which helps make complex behavioural data more accessible and actionable for clinical teams looking after patients with neurological conditions.
Features
- Clinical behavioural assessment forms
- Real-time patient reporting
- Dynamic risk levels and tracking
- Accessible across all devices and modern browsers
- Meets DTAC security standards
- Digital audit trail of patient assessments
- Replaces the need for paper-based assessments and reporting
Benefits
- Standardised collection of clinical data
- Improves clinical decision making
- Allows users to prioritise resources and interventions
- Can be used on mobile, tablet and desktop
- All patient data is secured to current NHS standards
- Provides a legal record of all behavioural assessments
- Saves time for busy clinicians
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 2 6 5 7 5 5 1 2 2 2 3 1 6 9
Contact
DECENTLY LIMITED
James Chapman
Telephone: 07555401212
Email: jc@decently.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- We notify users in advance of any planned maintenance, scheduled for off‑peak times. The service is fully hosted (SaaS) and only needs a modern, compatible web browser. We run on Laravel Cloud’s managed platform hosted on AWS for core infrastructure. This includes CDN, HTTPS, DDoS protection, autoscaling and built‑in redundancy to minimise any impact from infrastructure issues.
- System requirements
-
- Modern browers inc. Chrome, Microsoft Edge
- Internet connection
- Modern mobile & tablet devices
User support
- Email or online ticketing support
- Yes
- Support response times
- Initial response within 1-2 business days
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Decently offers our standard level of support available as part of the licence fee.
All customers will have access to their account manager and the Decently support helpdesk.
Business Hours: 09:00 to 17:00 (Monday-Friday, not including UK Bank holidays)
Support Email: support@decently.co.uk
Emails received outside of these hours will be viewed and assessed the next available business day.
More detail available in the full Support SLA contained within the attached Service Definition document - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
We will provide online training (onsite if necessary) to the initial group of admins and super users in a "train the trainer model". In addition we will provide quick reference help guide and access to support help desk.
From here the Admins and Super users will set up subsequent users and conduct the training - Service documentation
- No
- End-of-contract data extraction
- In the event of Melo licence not being renewed, repatriation of data will be discussed between Melo Admin and Melo support team at Decently.
- End-of-contract process
- In the event of Melo licence not being renewed, removal of access to the system will be discussed between Melo Admin and Melo support team at Decently.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Functionality across screensizes is identical. The only differences are UI layouts which in some areas involves progressive disclosure of less common functionality e.g. demoting non-essential content into sub-menus.
- Service interface
- Yes
- User support accessibility
- EN 301 549
- Description of service interface
- Web based interface accessed through a modern browser on phones and on screen.
- Accessibility standards
- EN 301 549
- Accessibility testing
- None
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Laravel Cloud lets us scale quickly during busy periods, with web traffic and background jobs handled separately. Capacity can be increased on infrastructure provided by AWS. We run regular performance tests, optimise our application and database, and use edge caching so traffic spikes are absorbed without affecting other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- User access and usage metrics will be provided through the dashboards available to the Admin user. Reasonable requests for additional metrics may be requested from the support team as bespoke exports - these will be responded to on a "best endeavours".
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- All customer data is encrypted at rest. We use PostgreSQL as our relational database on Laravel Cloud on AWS, with encryption and automated backups supporting point in time recovery within a defined retention window. Platform storage (files and volumes) is also encrypted. Access is restricted using least privilege credentials, role based access, network controls, and securely managed environment secrets. Physical data centre security is provided by Laravel Cloud’s underlying providers, and data in transit is protected with TLS end to end.
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Decently support team will do this on their behalf
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- .We use Laravel Cloud’s managed infrastructure hosted on AWS—with load balancing, regional redundancy and zero‑downtime deployments—to keep the service available. Laravel Cloud relies on AWS for underlying compute, networking and storage. Our target availability is 99.5% or higher, excluding planned maintenance, supported by proactive monitoring and alerts.
- Approach to resilience
-
Our service is designed for high resilience on Laravel Cloud’s managed platform, which leverages Cloudflare for global edge networking and protection, and established cloud provider Amazon Web Services (AWS) for core compute, storage and databases. This provides globally distributed, redundant infrastructure with load balancing, autoscaling, and an edge CDN. Application servers and databases are deployed across multiple availability zones to avoid single points of failure. All traffic is encrypted with HTTPS and protected by Cloudflare’s DDoS mitigation and web application firewall. Data, file storage and backups are encrypted and replicated, with recovery points regularly verified. Deployments run through automated pipelines with zero‑downtime releases.
We continuously monitor uptime, performance and error rates using Laravel Cloud’s real‑time metrics and alerts, alongside our own logs and health checks. Incidents are triaged immediately via on‑call notifications, and our incident response plan defines clear escalation, communication and rollback steps to ensure recovery is planned, not ad hoc. We test resilience with controlled failover and load simulations, perform periodic backup‑restore and disaster‑recovery drills, and keep versioned configuration snapshots for rapid restoration. These practices ensure the service is robust in the face of failure, and able to recover quickly while maintaining high availability for all users. - Outage reporting
- Email and in-house messaging alerts when production servers meet a threshold. After initial investigation by the technical team users and customers are informed as required by the situation.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
We use cloud services to host and support the Melo application and we don't have an internal network.
All cloud accounts have MFA and strong passwords. Where possible admin accounts and standard accounts are separate, users with access to cloud apps have the least privilege access and super user/admin accounts are not used for daily "normal" activity. We use VPN software with a dedicated fixed IP to reduce the risk of a cyber event. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- NHS DTAC
- Information security policies and processes
-
Our information security policies align to guidance detailed in the NHS DTAC assessment
DTAC is focused on 5 core areas. Sections 1 to 4 form the assessed criteria, with a separate conformity rating provided around usability and accessibility:
1. Clinical safety
Products are assessed to ensure that clinical safety measures are in place and that organisations undertake clinical risk management activities to manage this risk.
2. Data protection
Aligned to GDPR requirements, our products are assessed to ensure that data protection and privacy is ‘by design’ and the rights of individuals are protected.
3. Technical assurance
Products are assessed to ensure that products are secure and stable.
4. Interoperability
Products are assessed to ensure that data is communicated accurately and quickly whilst staying safe and secure.
5. Usability and accessibility
Products are allocated a conformity rating having been benchmarked against good practice and the NHS service standard.
The DTAC includes company information and value proposition sections for context. Each of the scored and assessed sections contain:
a reference code for each question
the question for the developer to respond to
whether evidence is required and is so the evidence
response options or free text
supporting information and guidance
scoring criteria - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We follow a secure development approach based on OWASP, with safety checklists at design and build stages. We maintain separate Test, Pre‑Production and Production environments. Changes to Production are peer‑reviewed, require director approval, and are deployed through automated pipelines with full audit trails. Configuration changes and releases are recorded in our internal channels and tracked in Laravel Cloud’s deployment history. Where relevant, changes consider the underlying provider environments from AWS used by Laravel Cloud.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We hold Cyber Essentials and follow guidance on secure setup, access control and anti‑malware. We regularly scan our software and third‑party components for security issues, carry out code reviews, and complete an annual OWASP‑based penetration test. High‑risk issues are fixed as a priority, and we can release patches quickly via our deployment process. We use Laravel Cloud’s monitoring and protection features hosted on AWS for core infrastructure, and we run automated checks in our build pipeline to spot problems early.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use Laravel Cloud’s built in logs, metrics and alerts to monitor uptime, performance and errors across environments. The service is fronted by Laravel Cloud’s edge network (via Cloudflare), which provides DDoS protection and a managed web application firewall based on the OWASP ruleset. Application and infrastructure activity is logged for investigation and audit. High risk incidents are triaged the same working day, following a documented process for escalation, containment and post incident review.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
We have an inhouse Data Protection Officer (James Burch) and an external DPO from a Cyber Security and Compliance specialist NaqCyber.com
In addition through our Cyber insurance with CFC (market leading Cyber insurance specialists) we have a managed incident response plan in place.
Our systems and policies covering GDPR and Data Security are in place should there be any form of incident involving users or customer data.
Users can report an incident through our support helpdesk (see attached Service Definition document) and the resolution time / incident reports will depend on the nature of the incident. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
One months free trial, limited to;
- 30 assessments
- base version / functionality (as is)
- one ward/unit
- 5 users
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 046de138-84ee-47a8-8b18-ffb9dcdbc41f
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- NHS DPST
- DTAC
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-