Skip to main content

Help us improve the Digital Marketplace - send your feedback

TESTFYRA LIMITED

Custom Framework Development & Automation Services

Bespoke framework development for specialized requirements including AI ML Automation, log management platforms, DHCP infrastructure, connected car testing ecosystems, CI/CD observability automation, and telecom end-to-end test automation frameworks. Three-to-five-month development timeline with collaborative design, iterative testing, and comprehensive knowledge transfer. Tailored solutions avoiding generic product limitations.

Features

  • Custom AI workflow automation developed using advanced RAG agents.
  • Cloud‑native log management frameworks delivering scalable IP allocation.
  • Connected‑car testing frameworks validating eSIM, telematics, infotainment systems.
  • CI/CD observability automation integrating seamlessly with major pipelines.
  • Telecom end‑to‑end automation supporting RAN, Core, OSS, BSS.
  • Protocol‑level automation covering SIP, Diameter, HTTP, RRC, NAS.
  • Network element simulation enabling comprehensive testing without hardware.
  • Automated regression frameworks preventing defects during continuous upgrades.
  • Custom dashboards providing real‑time visibility into operations.
  • Comprehensive documentation detailing architectures, APIs, and user guides.

Benefits

  • Avoid vendor lock‑in using customised frameworks meeting requirements.
  • Reduce operational costs through automation removing repetitive tasks.
  • Accelerate deployment cycles using CI/CD automation ensuring compliance.
  • Improve system reliability with comprehensive logging and detection.
  • Scale infrastructure efficiently managing IP addresses and resources.
  • Future‑proof technology stacks using frameworks supporting ongoing evolution.
  • Ensure regulatory compliance via audit trails and retention.
  • Enhance troubleshooting using detailed logs and telemetry correlation.
  • Lower total ownership costs compared to commercial products.
  • Gain competitive advantage with unique capabilities beyond generic solutions.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at contact@testfyra.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 2 9 9 4 7 8 2 9 9 0 2 9 1 9

Contact

TESTFYRA LIMITED Kam Sangha
Telephone: 07814
Email: contact@testfyra.com

About your service

Service categories

Application Development and Deployment

Application development

  • Development languages, environments and tools
  • Software construction components
  • Business rules management

Modelling and architecture

  • Object Modelling Tools
  • Business Process Modelling Tools
  • Enterprise Architecture Tools
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
Custom framework development typically requires three to five months, depending on complexity, and accelerated delivery may reduce quality or testing depth. Successful implementation relies on clear requirements, stakeholder availability for reviews, and timely feedback. Clients must provide access to infrastructure, systems, and representative test data to enable realistic validation. Integrations with legacy systems depend on documentation and API accessibility, with poorly documented environments extending timelines. Frameworks are delivered as source code, requiring client maintenance capability or support contracts. Initial deployments may need performance tuning, while high‑volume workloads or AI training may require additional infrastructure capacity.
System requirements
  • Modern server infrastructure providing sufficient CPU, memory, storage.
  • Linux‑based operating systems preferred for reliable framework deployment.
  • Container platforms enable scalable framework deployment and orchestration.
  • Database systems support required framework data storage needs.
  • Network connectivity with firewall rules permitting authorised framework access.
  • API endpoints and credentials enabling integration with existing systems.
  • Git repositories manage framework source code and configurations.
  • CI/CD pipelines automate framework deployment and testing processes.
  • Monitoring and logging infrastructure track framework health continuously.
  • Administrative permissions required for installation, configuration, integration tasks

User support

Email or online ticketing support
Yes, at extra cost
Support response times
TestFyra offers flexible support tailored to testing project needs. Standard Support provides business‑hours remote assistance, monitoring, defect triage, and troubleshooting, with 4‑hour critical and 24‑hour non‑critical responses. Enhanced Support extends hours with a dedicated Manager, priority defect handling, analytics, automation support, and strategy reviews, with 2‑hour and 8‑hour response targets. Premium Support delivers 24/7 coverage with Technology Lead, real‑time dashboards, immediate incident response, proactive monitoring, and continuous improvement, with 1‑hour and 4‑hour response times. All tiers include documentation, knowledge transfer, and access to TestFyra’s provided platforms.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
TestFyra provides structured software and AI development support across the full project lifecycle, delivered through three service tiers. Standard Support offers business‑hours coverage (9am–5pm, Monday to Friday) via email and phone during active development. It includes bug fixes, minor enhancements, and technical guidance for delivered applications. Monthly progress meetings cover project updates and sprint planning. Response times are four hours for critical issues and twenty‑four hours for non‑critical. A ninety‑day post‑deployment warranty provides continued bug‑fix support. Pricing is £850 per developer per day, plus £400 per month for post‑deployment assistance. Enhanced Support extends coverage to 8am–8pm, Monday to Saturday, with a dedicated Technical Lead providing architectural guidance, code reviews, and quality assurance. This tier includes bi‑weekly sprint reviews, documentation, priority bug resolution, performance optimisation. Response times are two hours for critical issues and eight hours for non‑critical. Pricing is £1,200 per day, plus £800 per month post‑deployment. Premium Support provides 24/7 production coverage with an embedded Solution Architect offering strategic direction, technical leadership, and stakeholder engagement. It includes continuous development, rapid feature delivery, proactive monitoring, AI model performance tracking, and a twelve‑month warranty. Pricing is £2,200 per day, plus £1,500 per month for managed support. include source‑code ownership, documentation, knowledge‑transfer
Support available to third parties
No

Onboarding and offboarding

Getting started
TestFyra ensures successful framework development through a structured and collaborative delivery approach that maintains alignment and reduces implementation risk.
Phase 1: Requirements Discovery (Weeks1–2)
A focused discovery workshop defines business objectives, technical requirements, integration needs, and success criteria. The team reviews existing infrastructure, workflows, and operational pain points, while assessing data volumes, performance expectations, scalability demands, and compliance obligations. Stakeholder interviews refine understanding. Outputs include a requirements document, architecture proposal, development roadmap, resource plan, and fixed‑price quotation.
Phase 2: Design & Prototyping (Weeks2–4)
Design sessions establish the architecture, data models, API specifications, and user interfaces. Low‑fidelity prototypes validate the approach and gather early feedback. The development environment is prepared, including version control, CI/CD pipelines, testing infrastructure, and collaboration tools. The technical design is reviewed and approved before development begins.
Phase 3: Iterative Development (Weeks4–14)
Two‑week sprint cycles deliver incremental functionality with regular demonstrations. Stakeholder feedback shapes priorities,weekly progress meetings maintain alignment. Staging deployments enable parallel testing and validation.
Phase 4: Testing & Refinement (Weeks 14–16)
Functional, performance, security, and integration testing is completed, including load testing,user acceptance testing.
Phase 5: Deployment & Training (Weeks16–18)
Production deployment support, administrator training, documentation handover, operational transition ensure teams can operate the framework independently.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
TestFyra ensures complete framework ownership and seamless data extraction through transparent delivery, open standards, and fully portable artefacts. All source code is transferred via a Git repository with full commit history, documentation, and architectural diagrams, and clients retain 100% intellectual property rights for all custom‑developed components. The codebase includes inline comments, API documentation, deployment guides, troubleshooting runbooks, and a complete dependency list with version and licensing details.
Data export is fully supported across all frameworks. Log Management Framework data is provided in syslog, JSON, or compressed text formats with timestamps and metadata preserved. DHCP Management Framework data, including leases, reservations, and configuration records, is exported as CSV, JSON, or SQL dumps with IPAM integration supported. Test Automation Framework assets—test cases, scripts, results, and historical metrics—are delivered in industry‑standard formats. CI/CD Framework exports include pipeline definitions, deployment scripts, and observability data for recreation on alternative platforms.
All configurations are delivered as code in YAML, JSON, or XML, alongside comprehensive technical documentation. Deployment artefacts such as Docker images, Kubernetes manifests, and Terraform templates enable independent operation. Frameworks use open‑source technologies, ensuring no vendor lock‑in.
End-of-contract process
TestFyra manages software development contract closure ensuring smooth operational transition:
30 Days Before Contract End: Final sprint planning completing remaining user stories and addressing outstanding issues. Comprehensive code review ensuring quality standards and best practices adherence. Final security audit and penetration testing validating application security posture. Schedule knowledge transfer sessions and documentation handover.
Final Weeks: Complete all deliverables including source code, documentation, training materials, and deployment artifacts. Conduct extensive handover sessions with technical teams covering architecture, codebase navigation, deployment procedures, troubleshooting, and maintenance. Deliver administrator and user training ensuring operational readiness.
Contract End Date: Transfer complete source code repository with full commit history to client-owned Git platform. Deliver comprehensive documentation package including technical architecture, API specifications, deployment guides, and user manuals. Provide AI model exports, training datasets, and performance benchmarking reports. Remove TestFyra access credentials from client systems and infrastructure.
Warranty Period: Post-deployment warranty support (90 days standard, 6-12 months enhanced/premium) continues providing bug fixes and technical assistance. Critical security patches prioritised throughout warranty period.
Optional Transition Support: extended support contracts for ongoing maintenance, feature enhancements,technical consulting. Flexible retainer arrangements available for ad-hoc development needs.
Final Deliverables: Project closure report documenting delivered features, technical decisions, lessonslearned,recommendations for future development roadmap.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Some services may work better on desktop version.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
TestFyra offers role-based access through four intuitive interfaces. The Web-Based Dashboard provides a responsive browser platform (Chrome, Firefox, Safari, Edge) for managing test projects, monitoring real-time execution, and generating reports. The TestFyra Accelerator Portal specializes in load test configuration, bulk call generation, and live KPI tracking. The UEX Mobile App, installed on test devices, enables automated mobile network testing with remote control. RESTful APIs allow programmatic test execution, result retrieval, and CI/CD integration. Finally, the Admin Console centralizes user permissions, project setup, and reporting, secured via SSO authentication. Each interface ensures seamless, efficient testing tailored to user needs.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
TestFyra has not conducted formal user testing with assistive technology users to date. However, our web-based interfaces are developed following WCAG 2.1 Level AA guidelines including semantic HTML markup, keyboard navigation support, ARIA attributes for dynamic content, sufficient color contrast ratios (4.5:1 minimum), and alternative text for non-text content. Automated accessibility scanning performed using Axe and WAVE tools during development identifying and addressing common accessibility barriers. We are committed to conducting formal accessibility testing with assistive technology users for future releases and welcome feedback from users requiring accessibility accommodations to improve service inclusivity.
API
Yes
What users can and can't do using the API
TestFyra provides custom API implementations tailored to client requirements rather than standardized product APIs. Typical capabilities include programmatic test execution, real-time status monitoring, automated result retrieval, performance data extraction, and CI/CD integration. Users can automate testing workflows, integrate with DevOps pipelines, and generate custom reports.
API limitations defined collaboratively based on security and operational requirements, typically including rate limiting, authentication token expiration, restricted production environment access, and read-only access for sensitive configurations. Specific API capabilities, endpoints, authentication methods, and constraints documented in project-specific specifications ensuring APIs match exact client needs and security policies.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
TestFyra services are highly customisable to match specific organisational requirements, workflows, and technical environments.
What Can Be Customised: Dashboards and reporting formats tailored to stakeholder preferences, alert thresholds and notification rules matching operational priorities, integration points with existing systems (ITSM, monitoring, CI/CD tools), user roles and permissions reflecting organisational structure, automated workflows and business logic specific to client processes, data retention policies meeting compliance requirements, branding elements including logos and colour schemes, and API endpoints for custom integrations.
How Users Customise: Configuration performed through web-based administrative interfaces for standard customisations including dashboard layouts, alert rules, user management, and reporting preferences. Complex customisations requiring code changes (custom integrations, workflow logic, API extensions) delivered through change request process with TestFyra development team implementing modifications. Infrastructure-as-code configurations enable version-controlled customisation management.
Who Can Customise: Administrative users with appropriate permissions can perform standard customisations through web interface including dashboard modifications, alert configurations, user management, and report generation. Technical customisations requiring code changes restricted to designated administrators submitting formal change requests. TestFyra provides training enabling client teams to perform routine customisations independently while supporting complex modifications through professional services engagements.

Scaling

Independence of resources
TestFyra ensures complete project isolation to maintain development quality, protect intellectual property, and guarantee resource availability. Each framework project is assigned dedicated developers, architects, and DevOps engineers, preventing conflicts across concurrent engagements. All development, testing, and staging environments are isolated per client with separate repositories, CI/CD pipelines, and deployment infrastructure. Capacity is reserved according to contractual commitments, and new projects are accepted only when specialist resources are available. Client‑specific code is never reused across engagements. SLAs define minimum resource allocation with financial penalties for shortfalls, while premium‑tier clients receive priority scheduling for specialist expertise.

Analytics

Service usage metrics
Yes
Metrics types
TestFyra provides comprehensive service metrics enabling performance monitoring and continuous improvement. Metrics include availability percentages, incident response times,resolution times, ticket volumes by severity, service request fulfillment rates, and SLA compliance percentages. Real-time dashboards display current service health, performance trends, and capacity utilisation. Monthly reports deliver detailed analytics covering incident patterns, root cause analysis, service quality trends,improvement recommendations. Custom metrics tailored to client requirements including business-specific KPIs, user satisfaction scores, and operational efficiency indicators. Historical data retention enables trend analysis and forecasting. All metrics accessible via web dashboards, automated email reports, and API exports for integration with client analytics platforms.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export all framework data and assets through comprehensive delivery mechanisms. Source code is transferred as a complete Git repository with full commit history, branches, and tags to client‑owned platforms. Automated export scripts generate data dumps in standard formats such as JSON, CSV, SQL, and syslog, with APIs supporting bulk extraction. Infrastructure‑as‑code templates and configuration files in YAML or JSON enable full framework recreation. Technical documentation is provided in editable formats, including Markdown, PDF, and Confluence exports. Deployment packages include Docker images, Kubernetes manifests, and scripts for independent operation.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)

Availability and resilience

Guaranteed availability
TestFyra guarantees both development team availability and high delivered‑framework uptime through structured delivery models and resilient architectural patterns.
Development Phase Availability
Standard Delivery provides development team access during business hours (9am–5pm, Monday–Friday) for collaboration, reviews, and support, with responses to client queries within four business hours and a 95% on‑time sprint delivery rate. Accelerated Delivery extends availability to 8am–8pm, Monday–Saturday, enabling faster development cycles and flexible stakeholder engagement, with two‑hour response times and a 98% sprint completion rate. Premium Delivery offers a dedicated team with near 24/7 availability for urgent requirements, one‑hour responses to critical blockers, and a 99% sprint commitment achievement.
Delivered Framework Availability (Post‑Deployment)
Frameworks are architected for high availability based on deployment requirements. Standard Architecture provides 99.5% uptime using load balancing, database replication, automated health monitoring, and failover mechanisms. Enhanced Architecture delivers 99.7% uptime through active‑passive configurations, automated recovery, and comprehensive monitoring alerts. Premium Architecture achieves 99.9% uptime with geo‑distributed deployments, active‑active configurations, advanced disaster recovery, and zero‑downtime updates.
Measurement
Availability is measured monthly, excluding scheduled maintenance windows. All frameworks include built‑in uptime monitoring, historical performance metrics, and reporting dashboards to ensure transparency and operational assurance.
Approach to resilience
TestFyra’s development methodology and application architecture are designed to ensure resilience across the full software lifecycle, reducing operational risk and maintaining consistent performance under varying conditions.
Development Process Resilience
Agile delivery using two‑week sprints provides incremental releases that minimise big‑bang deployment risks. Regular stakeholder reviews enable early correction, while continuous integration prevents late‑stage integration issues. Team redundancy ensures no single point of knowledge, with cross‑trained engineers, peer code reviews, and continuous documentation maintaining shared understanding. Git‑based version control with feature branches supports safe experimentation, and tagged releases allow rapid rollback if issues arise.
Application Architecture Resilience
Cloud‑native design principles use microservices, containerisation, and orchestration to deliver component‑level resilience, with failed services automatically restarted without affecting the wider system. Database resilience is achieved through replication, automatic failover, regular backups, and point‑in‑time recovery, supported by connection pooling and retry logic for transient failures. API resilience incorporates circuit breakers, timeouts, exponential backoff, and graceful degradation to maintain essential functionality during dependency issues. Infrastructure resilience is delivered through multi‑availability‑zone deployments, load balancing, health checks, and automatic removal of unhealthy instances. AI model resilience includes versioning for rapid rollback, A/B testing to validate new models, and fallback mechanisms to maintain responses when models are unavailable.
Outage reporting
TestFyra maintains fully transparent communication throughout development delays and production application outages, ensuring stakeholders remain informed, aligned, and able to make timely decisions.
Development Phase Reporting
Sprint progress is tracked through real‑time Jira dashboards showing user story status, blockers, and velocity trends, supported by daily stand‑ups that surface impediments immediately. Risk alerts are issued proactively whenever technical challenges, requirement ambiguities, or resource constraints threaten sprint commitments, with mitigation strategies presented at once. If sprint deliverables are delayed, stakeholders receive immediate email notification outlining cause, revised timelines, and recovery actions. Formal change requests are raised for required scope or schedule adjustments.
Production Application Outages
Each application includes a real‑time status page displaying system health, component availability, and historical uptime metrics. Monitoring systems detect outages within 60 seconds and trigger automated alerts via email, SMS, webhook integrations. During active incidents, updates are issued every 30 minutes through email, the status page, Teams channels, detailing investigation progress and expected resolution times. Within 24 hours of resolution, a comprehensive post‑incident report is delivered, documenting the timeline, root cause, corrective actions, and preventive measures. Support is available through a 24/7 emergency hotline for premium clients, with email and ticketing channels for non‑urgent issues.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
TestFyra enforces strict access controls to protect application administration and development resources. Mandatory multi‑factor authentication is required for all access to code repositories, cloud consoles, CI/CD pipelines, production systems, and client data. Role‑based access control limits developers to assigned projects, with production access restricted to authorised operations staff. Administrative interfaces are accessible only from corporate networks or approved VPNs, with further IP restrictions for production. Sensitive credentials are stored in secure vaults with time‑limited access. All administrative actions are immutably logged, including commits, deployments, configuration changes, and data access.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
TestFyra has established a comprehensive security governance framework in preparation for ISO 27001 certification. A designated Information Security Manager oversees governance with senior management involvement, quarterly security reviews. A full policy suite is in place covering information security, secure development, access control, data protection, incident response, and business continuity aligned to ISO 27001. Risks are identified and mitigated through structured assessments, vulnerability management, and penetration testing. Cyber Essentials Plus certification provides validated baseline controls. Secure development follows OWASP guidance with code reviews and automated testing. GDPR procedures are documented. Staff receive quarterly training. Internal audits complete, certification expected in 2026.
Information security policies and processes
TestFyra maintains comprehensive information security governance aligned with international standards to ensure the confidentiality, integrity, and availability of all client data and systems. Its Information Security Management System is progressing toward ISO/IEC 27001:2022 certification, covering all testing services and supporting infrastructure. Annual surveillance audits maintain compliance, while the policy framework is reviewed quarterly and updated for emerging threats.
The Secure Development Policy Framework governs all engineering activity. Secure coding standards address OWASP Top 10 risks, input validation, output encoding, strong authentication, and encryption of sensitive data. Mandatory peer reviews ensure security‑focused scrutiny of authentication, authorisation, data handling, and cryptographic components. Security testing includes SAST, DAST, dependency scanning, and pre‑deployment penetration testing. Data protection controls enforce AES‑256 encryption at rest, TLS 1.3 in transit, GDPR compliance, and privacy‑by‑design principles. AI security measures protect against model poisoning, adversarial attacks, and insecure model deployment.
Development environments use MFA‑protected version control, branch protection rules, secrets vaults, and isolated per‑project environments. TestFyra is Cyber Essentials certified, GDPR compliant, and subject to regular independent audits. Third‑party risk is managed through vendor assessments, strict sub‑processor requirements, and annual external security audits.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
TestFyra applies disciplined configuration and change management across all development activities. All code, configurations, and infrastructure‑as‑code are maintained in Git repositories with atomic commits, descriptive messages, and branch protection rules. Feature branches, pull requests, and tagged releases ensure controlled progression. Environments are managed through Terraform or CloudFormation, maintaining parity across development, staging, and production. Production changes require approval from the technical lead and product owner, with automated pipelines enforcing manual gates. An emergency hotfix process supports critical security patches. All configuration changes are logged with timestamps, users, and rationale, with regular drift detection ensuring alignment with desired states.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
TestFyra proactively identifies ,remediates security vulnerabilities:
Continuous Scanning - Automated vulnerability scanning performed weekly across all infrastructure, applications, and dependencies. Critical vulnerabilities flagged immediately.
Patch Management - Critical security patches applied within 48 hours; high-severity within 7 days; medium within 30 days. Emergency patching process for zero-day exploits.
Penetration Testing - Independent third-party penetration testing conducted annually with remediation of identified issues before re-testing.
Threat Intelligence - Subscription to threat intelligence feeds providing early warning of emerging vulnerabilities affecting our technology stack Remediation Tracking - Vulnerability management system tracks findings through complete remediation lifecycle with management reporting on security posture.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
TestFyra maintains continuous 24/7 security monitoring to detect and respond to threats. A centralised SIEM aggregates security events from all systems, using machine‑learning analytics to identify anomalous behaviour and potential compromises. Real‑time alerts notify the security team immediately. Failed logins, unusual access patterns, data‑exfiltration indicators, malware signatures, and network anomalies automatically trigger investigations. The SOC responds to critical alerts within 15 minutes, with automated containment isolating affected systems to prevent lateral movement. Forensic analysis determines attack vectors and impact. Response times are defined: critical incidents receive 15‑minute response and one‑hour containment; high‑severity incidents receive one‑hour response and four‑hour containment.
Incident management type
Supplier-defined controls
Incident management approach
TestFyra follows ITIL‑based incident management to ensure rapid and consistent resolution. Pre‑defined runbooks outline response procedures for outages, performance issues, and security incidents. Users can report incidents via a 24/7 hotline, email, web portal, or Teams, while automated monitoring creates incidents proactively. Severity levels are classified by business impact: Critical, High, Medium, and Low. Engineers investigate with regular status updates, and post‑incident reports are issued within 48 hours. Unresolved incidents escalate automatically at 30 minutes, two hours, and four hours respectively
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
TestFyra offers a complimentary 2-hour discovery workshop to assess current testing, infrastructure, or development practices. It includes gap analysis, challenge identification, and initial recommendations. Excludes full discovery assessment, implementation, or detailed documentation. Limited to one session per organization, providing insight into TestFyra’s approach and service fit before commitment.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
4%
Between £250,000 and £500,000
7%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
11%
Between £2,500,001 and £5,000,000
12%
Over £5,000,001
14%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
F591209e-cfca-49d7-9cbd-1b984b5acee9
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
    • Plans for positive actions with community groups.
    • Measures for making facilities used in the delivery of the contract available for community groups, education or training
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Introducing transparency to pay and reward processes
    • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at contact@testfyra.com. Tell them what format you need. It will help if you say what assistive technology you use.