Bramble Hub - Digital Asset Delivery (DAD)
Bluestar's DAD provides a secure, controlled portal for sharing evidential files with authorised partners. It streamlines publishing, enforces time limited access, reduces administrative burden and ensures full auditability. With flexible security, automated indexing and caseworking support, DAD enables efficient, compliant, reliable delivery of digital assets across policing and partner agencies.
Features
- Secure portal for sharing evidential files with authorised recipients
- Publisher controlled sender, recipient and security configuration
- Time limited access windows for downloadable asset bundles
- Email notifications with direct secure download links
- Integrated content player for immediate evidence viewing
- Extensive search across published digital materials
- Full audit trail for complete compliance assurance
- Flexible privilege and security model for granular control
- Automatic indexing and data extraction for shared assets
- Supports industry standard data exchange formats
Benefits
- Enables secure sharing of evidential files with trusted partners
- Reduces administrative workload for publishing and distributing assets
- Ensures controlled, time limited access to sensitive material
- Improves compliance with full audit trails
- Speeds evidence delivery through automated notifications
- Strengthens security with granular privilege controls
- Supports efficient case working with integrated tools
- Enhances accessibility via a simple, secure download portal
- Minimises risk of data loss or unauthorised sharing
- Delivers cost savings through streamlined digital distribution
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 3 0 7 6 3 2 3 1 4 5 3 4 2 1
Contact
BRAMBLE HUB LIMITED
Geoff Couling
Telephone: +44 (0) 2077350030
Email: contact@bramblehub.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
Content services
- Content Sharing and Collaboration Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Corvus integrates with all our modules, as well as third party Record Management Systems
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- None
- System requirements
- Chromium based browser
User support
- Email or online ticketing support
- Yes
- Support response times
- We respond from one hour to 28 days depending on the priority of the question which is covered in our Service Level Agreements (SLAs).
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support is offered at two levels - standard office hours and extended 24 x 7 (available at additional cost). Typically, customers operate a first line support function with Bluestar delivering a second line capability. Customers can opt for Bluestar to carry out first line support but this is subject to an additional charge. All customers are assigned a technical lead and support manager.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Initial handover to the customer's representatives is typical. A user manual is provided as part of the product, and is accessible to all users. The service is designed to be as easy to use as possible, with tool tips and pointers in order to help new users. Formal training courses are provided at an additional cost.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Multiple formats can be offered depending on the customer requirements
- Including presentations and on-site training
- End-of-contract data extraction
- Data can be provided in a CSV format on request.
- End-of-contract process
- Bluestar can develop an exit management plan based on specific customer requirements
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Standard user guides developed with customers
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- Yes
- Description of customisation
- Bluestar offer a large variety of ways in which the applications can be customised both for the context of the buyer, and with branding and specific functionality/fields etc. The application itself can be configured and customised during initial configuration exercise. End users have ability to have customise various elements e.g. the widgets on their home screen, saved searches and differing functionality depending on the modules purchased. Admins/team leads have additional customisation options.
Scaling
- Independence of resources
- The provision of resources scales in line with demand. As demand increases, the provision goes up.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide the number of transactions performed by the users against the date and time
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- By request
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- A range of attachments covered in the majority of modules
- Most image formats, document formats and videos
- Data import formats
-
- CSV
- Other
- Other data import formats
- Common formats: PDF, DOCX, XLSX for formatting documents
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Service levels are discussed on a per customer basis. As a general guide, Bluestar offers 99.95% availability for the main service.
- Approach to resilience
- The system is deployed using a distributed service architecture, that is to say the system has built-in redundancy by locating the same service capability across multiple physical machines. This is combined with load balancing so that a particular service location operates effectively. Using these (patented) techniques, we have no single point of failure within the system itself and therefore achieves extremely high levels of availability as standard.
- Outage reporting
- Bluestar uses the Check MK monitoring application. This is used to implement monitors and metrics linked to the main service. Monitoring checks a range and variety of conditions such as capacity, network access, performance of individual processes etc. Alerts are immediately visible on screen and sent via email (and SMS) to administrators and (optionally) customer representatives.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Management interfaces are typically setup on specific management networks and are only available to specific whitelisted IP ranges used for support purposes. Separate credentials are used and are limited to specific administrators/support staff, separate to their usual login, and are used just for the purposes of managing the system. Strong authentication is required with management interfaces typically setup with a username/password/MFA, or other controls are established. Management interfaces are integrated to log centrally.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Less than 1 month
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
- We comply with the following governance standards: Cyber Essentials, Cyber Essentials Plus, ISO 270001:2022.
- Information security policies and processes
- Bluestar hold ISO 27001 accreditation which establishes an Information Security Management System (ISMS) with a framework document and policies, covering the secure design and development of complex systems.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Typically the change management process is agreed with customers to suit their preferred model. In all cases, customer representatives authorise work to be carried out and will be asked to participate in the acceptance testing on a suitable test platform
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Bluestar considers all aspects of vulnerability including the physical location and access controls. Software configurations utilise an automated patching process (run daily as a minimum) to ensure that any potential threats are mitigated as quickly as possible, adhering to a patch management policy. At the outset, all builds are established with a 'known' and approved benchmark which is independently verified. Bluestar maintain a list of threat intelligence sources as part of their ISO 27001.
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- Bluestar adopts compliance with recognised standards covered by agreements with our hosting providers. A vulnerability management policy will detail the detection, and a defined incident response plan will be in place. Response times will be determined as part of contract with 24/7 options available.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Incident management is a built-in element of our Support-Link and automatic monitoring systems and is defined within our business process management workflow. Any incidents (including security) reported, or identified, are passed on to our support team and if sufficiently serious in nature, are immediately notified to our dedicated Support Manager. The Support Manager will escalate to the Senior Management Team (Director level), if the incident is either deemed sufficiently serious, or there are specific customer circumstances , or if the SLA is compromised.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Police National Network (PNN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- UKAS
- ISO/IEC 27001 accreditation date
- Tuesday 31 December 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- UKAS
- ISO 9001 accreditation date
- Tuesday 31 December 2024
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 94c671e6-823b-4c1b-9e66-be61b04e765c
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 3b271556-6f71-40cd-bd60-169f03c35f6e
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-