MailCentral
MailCentral is a 'best of breed', non proprietary middleware platform that enables your desktop, departmental and/or corporate applications to seamlessly integrate with your preferred digital communication channels such as SMS, email, web portal and App without changes to existing formats or workflow.
Features
- Inhouse or outsourced Hybrid Mail (Non-Proprietary solution)
- Integrated Customer (Patient Portal)
- Email and Secure Email Integration
- Interactive (two-way) SMS
- Non Proprietary Middleware
- Intuitive simple user interfaces
- Detailed Management reporting for auditability and compliance
- Detailed Track and trace capabilities (Detailed Audit Trail)
- Digitally transforms any printed (i.e. Physical) communication
- Intelligent workflows - least cost communications workflow
Benefits
- Dynamically publish on-line communications from any application
- Eliminates manual processes - delivering significant workplace efficiencies
- Delivers significant cost savings across all forms of communication
- Eliminates postage costs
- Maximises auditability and Compliance
- Simplifies Digital Transformation workflows
- Quick and Easy integration with your preferred digital platforms
- Centralises, optimises and digitises your outbound communications
- Simple, Accessible Self Serve implementation workflows
- Enhances your options to deliver a 'digital first' strategy
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 5 1 4 7 7 3 9 3 9 7 1 6 1 4
Contact
QUADIENT UK LIMITED
Adam Smith
Telephone: 07725 826750
Email: bids.uk@quadient.com
About your service
- Service categories
-
Applications
Content workflow and management
- Document
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Office 365 and other cloud based applications such as Digital Health Records and back end systems
- Cloud deployment model
- Private cloud
- Service constraints
- N/A
- System requirements
- Only requires download and installation on to desktop clients
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 4 hours (excluding weekends)
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We will provide a technical account manager for each customer to liaise and co-ordinate responses if required. Standard Support levels Severity 1 (Response 30 minutes, response 1 Day) - is usually when the problem is detrimental to the business and is impacting the business directly as a result of software, i.e.: if the business could lose a significant amount of money caused by whatever problem there may be. Severity 2 (Response 60 minutes, response 2 Days) - is usually if a server, network, application, database goes down which is causing a business impact to users and the business. Severity 3 - (Response 4 Hours, response 5 Days) - Where a bug is raised as part of the support process, Quadient will liaise with the development team and provide a synopsis of the problem within 2 working days and a proposed timescale for its resolution, within a reasonable time frame. Severity 4 (Response 4 Hours, No SLA) - Where issues are caused by non Quadient software or environments, some advice will be given and support offered, but with no guarantee of resolution
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Users can download the MailCentral clients from the SaaS based service Training can be delivered on-site, remotely or through on line videos and tutorials. User guides, training documentation is delivered in a digital (PDF) format.
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- PostMan
- End-of-contract data extraction
- MailCentral provides simple export facilities enabling customers to extract their data when the contract ends
- End-of-contract process
- Self Serve data extraction is provided in the price of the contract. Any consultancy or customised outputs will incur an additional cost
- Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
- The MailCentral User interface allows users to view manage and control the documents they have submitted and manage their associated digital workflows. The web interface provides detailed 'track and trace' capabilities for each document that is submitted. Full management reporting is available The interface offers multi level access rights enabling users access to be restricted based on pre-defined workflows.
- Accessibility standards
- None or don’t know
- Description of accessibility
- User can submit documents from virtually any application using a simple, intuitive print driver Users are then able to view, manage and control the documents they (or their workgroup have submitted) The system provides a detailed audit trail and feedback regarding how the document has been communicated (i.e. post, SMS. email, portal App etc) Full Administration and management interface for authorised users enabling simple set up and configuration of the system. Seamless integration with either our own or the customers preferred digital communication channels via documents API interfaces.
- Accessibility testing
- User Interface has been implemented with due consideration of assistive technology
- API
- Yes
- What users can and can't do using the API
- Documents can be submitted via a simple API interface (rather than being printed or dropped into hot folders) The API interface provides a fully featured interactive gateway to all the standard MailCentral management reporting interfaces Integration with Active Directory, SAML and SSO Platforms
- API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- The interface can be customised using your logo and details. The system can submit hybrid mail outputs to virtually any supplier on the CCS framework ensuring the technology is owned and managed by the customer (and not a third party) The API interfaces enable the customer to integrate the digital outputs with their preferred in-house or third party digital communication channels
Scaling
- Independence of resources
- If required a server can be dedicated to a specific client ensuring the platform is both scalable and independent of other organisations transactional requirements.
Analytics
- Service usage metrics
- Yes
- Metrics types
- MailCentral provides a fully integrated management reporting interface. MailCentral enables this data to be delivered in PDF or CSV format MailCentral reports on documents that have been submitted into the system per user, workgroup or department MailCentral details the time a document was submitted into the system and the time it was then output via the relevant physical (i.e. print and post) or physical channel MailCentral provides full closed loop reporting and details each document and whether it has been processed within the agreed SLA. MailCentral provides a simple intuitive dashboard with which to manage your digital transformation processes
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users are able to export their data using a simple reporting interface
- Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XML
- Postscript
- ASCII
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- The Servers are hosted in Azure Microsoft guarantee that API Management Service instances running in the Consumption Tier, Basic Tier, Standard Tier, and Premium Tier deployments scaled within a single region will respond to requests to perform operations at least 99.95% of the time
- Approach to resilience
- Available on request
- Outage reporting
- E-mail alerts and dashboard
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Access in management interfaces and support channels is restricted by the 'roles' associated with each users login credentials
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Documented in our ISO27001 policy - this can be made available on request
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Documented in our ISO27001 policy - This can be made available on request
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Information from potential threats gathered from Anti Virus supplier, and development channels for each of the toolkits being implemented Ensuring toolkits and database engines are up to date Patches (if required) applied at least once every month
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Anti Virus Scans Vulnerability reporting Penetration testing Cyber Essentials plus accreditation If a potential compromise is identified, its severity is assessed and a plan of action put in place to mitigate or eliminate the risk. Any Incident regarding data is treated as a P1 and our SLA for an initial response is 30 minutes
- Incident management type
- Supplier-defined controls
- Incident management approach
- Documented as part of our ISO 27001 policies - available on request User report incidents via the on-line help desk Full and detailed incident reports are provided via the Job Ticket and as a specific physical document (if required)
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
Basic platform configuration
3 month trial limit
Subject to application
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- DNV
- ISO/IEC 27001 accreditation date
- Saturday 1 November 2025
- What the ISO/IEC 27001 doesn’t cover
-
This certificate is valid for the following site scope:
The security and privacy of all information and data assets Quadient use for the delivery of all core activities surrounding the provision of a range of communication solutions in accordance with the Quadient UKI & CEI Statement of Applicability version 1.0 - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- DNV
- ISO 9001 accreditation date
- Tuesday 3 June 2025
- What the ISO 9001 doesn’t cover
-
This certificate is valid for the following scope:
The marketing, sales, provision, installation and maintenance of mailing and document handling equipment and parcel lockers. The marketing, sales and support of customer communication solutions - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- C795b54f-685b-4494-91c1-4ccb64625516
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-