AutoMutatio Data Discovery: Unify your data. Search and report fast.
AutoMutatio offers a sophisticated data discovery platform that automatically transforms vast and unstructured datasets into actionable intelligence. By combining your data into one clear view, AutoMutatio mitigates risks and unlocks cost savings. AutoMutatio makes searching intuitive, accelerating decision-making by extracting insights and surfacing what matters most in your data.
Features
- Automatically synchronise, searchable and deduplicated datasets.
- Understanding numerical and textual data by linking individual records.
- Preserve file metadata, with all original associations to source data.
- Virtual referencing allows disconnected data to become associated data.
- Navigate any language, including European, Arabic and Asian (CJKV).
- Navigate the version history of every document and conversation.
- Explore the timeline of emails by sender or recipient.
- Unpack and analyse file archives, including .pst, .zip and attachments.
- Continuously analyse new information and provide metrics on data volume.
- Convert machine-readable files to text for full content discovery.
Benefits
- Use keyword based tagging for powerful filtering from keyword lists.
- Perform advanced search and filtering on unstructured and structured data.
- Navigate visualisations, understand timelines and charts, analyse pivot tables.
- Conduct advanced data analysis at scale, beyond Excel’s capacities.
- Detect new language patterns and emerging issues.
- Highlight critical risks and assess their impact on your projects.
- Trace communication threads by topic and export communication threads.
- Mitigate risks, investigate records, substantiate claims and solve disputes.
- Generate tailored and customised reports for your use case.
- Visualise words and summarise numbers and metadata using Pivot tables.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 4 4 7 6 2 1 2 6 8 7 0 5 2 1
Contact
AUTOMUTATIO LTD
Mark John Austin
Telephone: 07793047124
Email: info@automutatio.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Advanced and predictive analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- AutoMutatio is designed to work in any modern browser. We recommend 8GB of RAM for optimum performance. All upgrades are deployed between 1800 and 0700 UK time to avoid any potential issues with deployments during the working day.
- System requirements
- Any modern browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Please submit all queries to support@automutatio.com. We aim to provide an initial response within one hour and a complete response within 24 hours. Our email helpline is open from 0800-1800 GMT/BST Monday to Friday. All tickets regarding bugs or issues should have “AM-CM-BUG” in the subject, or “AM-CM-MOD” if they relate to a modification to an existing feature. This ensures that our system directs them to the relevant pipeline.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Bronze, Silver or Gold SaaS application training and support is included within the mobilisation fee. Additional training, telephone and email support is also available. In the first instance, please submit all queries to support@automutatio.com. We aim to provide an initial response within one hour and a complete response within 24 hours.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Our Onboarding and mobilisation phase follows our standard process. Upon receipt of a Purchase Order (sent to support@automutatio.com with the Project Reference (e.g., GCLOUD-001) and Project Name (e.g., GCLOUD)), we will send a link to the onboarding Wizard to the Buyer. The Buyer then completes the configuration in the Wizard, including Users, Agreed Feeds to Sync Data to the app. Instructions for feed log-ins are then issued. Tags that have been agreed during mobilisation will then be added via the Tag Import function. Thereafter, we will host an introduction meeting and training session, and provide links to our Online User Guide.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Buyers can extract their data at any time as a ZIP file or via our API. Alternatively, for an additional charge, we can extract Buyer data at the end of the contract and transfer it to a SharePoint site of their choice.
- End-of-contract process
- At the end of the contract, all data is retained for 12 months, included in the service price. Additional storage can be provided for up to 12 years post-contract at 25% of the standard monthly charge, payable annually in advance. This service will allow login and full read-only access to the data for up to 3 user accounts, providing a cost-effective, flexible service and archive solution. New feeds will be unavailable, and if required during this storage period, the normal service rate will resume for app use during those months.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- We have tested our service using the standard features available with modern browsers, such as Microsoft Edge Accessibility.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Our user interface provides different visualisations for data to suit the user's preferred way of working, such as List and Kanban views. AutoMutatio includes an onboarding section, featuring User Access, Feeds, Tag and a general description of the service, which can be updated at any time by an administrator. This is created during onboarding and can be updated at any time by a user who has administration rights. There is also an error checker built into the App that allows administrators to identify where errors in files might be.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service is fully accessible from any web browser, with all the usual accessibility features available within the App. For example, in Edge, pressing Ctrl+Shift+U will read the page aloud.
- Accessibility testing
- We have tested our service using the standard features available with modern browsers, such as Microsoft Edge Accessibility.
- API
- Yes
- What users can and can't do using the API
- We provide an OData-compliant API with read-only access for authorised accounts.
- API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- Where Buyers have significant volumes of data, we provide a dedicated environment. Alternatively, a tiered approach is available. Here, data is split between a shared tier and a dedicated tier. The shared tier automatically scales to additional servers to manage load, whereas the dedicated tier provides Buyers with dedicated resources. Data is partitioned daily to reduce operational overhead and manage Buyer costs.
Analytics
- Service usage metrics
- Yes
- Metrics types
- On request, we generate a user report to enable Buyer actions to make the most of their subscription. The metrics in that report include web logs that track web user requests, the number and durations of tasks within the application, user usage, monthly data volume and file count, the number of feeds, and the number of tags.
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- Data held in Azure infrastructure is always encrypted at rest. All end-user devices are configured with BitLocker at rest encryption. No removable storage media is permitted and is blocked via hardware configuration policy.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- We provide CSV and ZIP functionality for limited data exports (up to 1,000 files). Significant exports can be conducted using our API.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Full unpacking and extraction of data from .zip files
- Full unpacking and extraction of data from .pst files
- Full text extraction from .xls and xlsx files
- Full text extraction from .doc & .docx files
- Full text extraction from machine-readable .pdf formats
- Full text extraction from .ppt and pptx files
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Data transmission is protected by virtual private network subnet separation for resources and transmitted through a reverse proxy application. Network and application security groups define firewall rules, and access is only available through authorised user accounts. Administrative data is transmitted via a secure bastion connection and private VNet peering; there is no external access to the application or data. The default for all our resources is TLS 1.2 or later, with all data at rest and in transit encrypted.
Availability and resilience
- Guaranteed availability
- Our operations are maintained by our IT and Development teams to maintain infrastructure integrity and timely deployment of critical resources. The considerations we have made to ensure data availability and redundancy include regular backups to separate physical locations, to ensure no single point of failure. In combination with infrastructure as code deployed as standard, our systems can be flexibly, quickly and reliably recreated and deployed. A combination of automated monitoring systems and regular manual review provides us with a reliable environment that needs little manual intervention and which offers minimal downtime. All upgrades are deployed between 1800 and 0700 UK time to avoid any potential issues with deployments during the working day.
- Approach to resilience
- Data is stored in multiple locations with regular backups providing redundancy in case of a disaster recovery scenario. Numerous instances of the App running provide service redundancy, and all of our infrastructure is run as infrastructure-as-code, allowing fast and reliable redeployment. Testing and development environments are separated for best practice. Networking is secured via approved firewall rules, Azure scan functions, and the setup of a reverse proxy to prevent malicious connections and maintain a high level of availability, as well as subnet separation of resources.
- Outage reporting
- Outages are avoided by maintaining multiple replicas of the services with failed node detection and replacement. Users can use system dashboards and alerts to detect outages.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- Management interfaces are only accessible through a secured Azure bastion connection to the virtual private management network via a director-approved management account secured with MFA and complex passwords, to be used only for administrative tasks and not for day-to-day use. Additional security credentials are stored in Azure Key Vaults to separate role-based account permissions further.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Other
- Description of management access authentication
- Management access is only possible through a secured Azure bastion connection to the virtual private management network via a director-approved management account secured with MFA and complex passwords, to be used only for administrative tasks and not for day-to-day use.
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- We comply with many recognised governance standards, including Cyber Essentials, Cyber Essentials Plus, NCSC Cyber Assurance, the United Utilities Risk Ledger and Once for All.
- Information security policies and processes
- Our organisation follows a comprehensive set of information security policies aligned with industry standards, including Cyber Essentials and Cyber Essentials+, as well as the IASME Cyber Assurance Framework. These policies cover data protection, access control, incident response, risk management, and secure use of technology. We ensure our policies are followed through annual training, regular audits, continuous monitoring, and documented procedures that guide day-to-day and essential operations. Issues or incidents are formally reviewed, with corrective actions tracked to maintain the security of infrastructure and personnel. Compliance is overseen through logging, monitoring and IT department intervention, allowing employees to escalate security concerns to the appropriate level based on severity.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our configuration and change management processes ensure all assets are documented and tracked from deployment through retirement. We maintain an asset and register that records ownership, status, service numbers and relevant configuration information throughout each component’s lifecycle. Proposed changes follow an approval process where technical, operational, and security impacts are considered before approval. Regular reviews evaluate potential vulnerabilities, data exposure risks, and compliance issues. Approved changes are tested in controlled environments and monitored after implementation to confirm stability and detect any unforeseen issues.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Our vulnerability management process uses continuous monitoring via the Microsoft and Azure management portals, along with regular scheduled scanning and risk-based assessments, to identify and prioritise potential threats to our services. We evaluate vulnerabilities based on severity, exploitability, and impact. We monitor trusted threat intelligence sources, vendor security advisories, industry feeds, and recognised vulnerability databases. All critical security and zero-day patches are automatically pushed or remediated within 14 days, in accordance with Cyber Essentials standards.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Our protective monitoring processes combine log collection and analysis, automated alerting, and anomaly detection to identify potential issues. If a suspicious event is detected, it will be addressed immediately, investigated by our security team, and escalated according to severity. Confirmed or high-risk compromises trigger our incident response procedures, including containment, remediation, and post-incident review. We aim to respond to incidents as quickly as possible, addressing critical issues immediately and notifying the affected parties.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We follow a policy-based incident response procedure to resolve operational issues by severity. Users should report issues to support@automutatio.com with details of the incident, and they will be assigned to a team member for resolution as soon as possible. Upon resolution of an incident, the relevant parties will be notified of the resolution steps and actions in the future.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 57df9e63-611f-4dd8-a9ae-187de3ef401a
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 5201e388-c541-41a7-8bce-998b6efd1684
- Other security certifications
- Yes
- Any other security certifications
-
- United Utilities Risk ledger
- IASME Cyber Assurance
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
-