Skip to main content

Help us improve the Digital Marketplace - send your feedback

QUADIENT UK LIMITED

MailCentral

MailCentral is a 'best of breed', non proprietary middleware platform that enables your desktop, departmental and/or corporate applications to seamlessly integrate with your preferred digital communication channels such as SMS, email, web portal and App without changes to existing formats or workflow.

Features

  • Inhouse or outsourced Hybrid Mail (Non-Proprietary solution)
  • Integrated Customer (Patient Portal)
  • Email and Secure Email Integration
  • Interactive (two-way) SMS
  • Non Proprietary Middleware
  • Intuitive simple user interfaces
  • Detailed Management reporting for auditability and compliance
  • Detailed Track and trace capabilities (Detailed Audit Trail)
  • Digitally transforms any printed (i.e. Physical) communication
  • Intelligent workflows - least cost communications workflow

Benefits

  • Dynamically publish on-line communications from any application
  • Eliminates manual processes - delivering significant workplace efficiencies
  • Delivers significant cost savings across all forms of communication
  • Eliminates postage costs
  • Maximises auditability and Compliance
  • Simplifies Digital Transformation workflows
  • Quick and Easy integration with your preferred digital platforms
  • Centralises, optimises and digitises your outbound communications
  • Simple, Accessible Self Serve implementation workflows
  • Enhances your options to deliver a 'digital first' strategy

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bids.uk@quadient.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 5 1 4 7 7 3 9 3 9 7 1 6 1 4

Contact

QUADIENT UK LIMITED Adam Smith
Telephone: 07725 826750
Email: bids.uk@quadient.com

About your service

Service categories

Applications

Content workflow and management

  • Document
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Office 365 and other cloud based applications such as Digital Health Records and back end systems
Cloud deployment model
Private cloud
Service constraints
N/A
System requirements
Only requires download and installation on to desktop clients

User support

Email or online ticketing support
Yes
Support response times
Within 4 hours (excluding weekends)
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AAA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We will provide a technical account manager for each customer to liaise and co-ordinate responses if required. Standard Support levels Severity 1 (Response 30 minutes, response 1 Day) - is usually when the problem is detrimental to the business and is impacting the business directly as a result of software, i.e.: if the business could lose a significant amount of money caused by whatever problem there may be. Severity 2 (Response 60 minutes, response 2 Days) - is usually if a server, network, application, database goes down which is causing a business impact to users and the business. Severity 3 - (Response 4 Hours, response 5 Days) - Where a bug is raised as part of the support process, Quadient will liaise with the development team and provide a synopsis of the problem within 2 working days and a proposed timescale for its resolution, within a reasonable time frame. Severity 4 (Response 4 Hours, No SLA) - Where issues are caused by non Quadient software or environments, some advice will be given and support offered, but with no guarantee of resolution
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Users can download the MailCentral clients from the SaaS based service Training can be delivered on-site, remotely or through on line videos and tutorials. User guides, training documentation is delivered in a digital (PDF) format.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
PostMan
End-of-contract data extraction
MailCentral provides simple export facilities enabling customers to extract their data when the contract ends
End-of-contract process
Self Serve data extraction is provided in the price of the contract. Any consultancy or customised outputs will incur an additional cost
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
Yes
Compatible operating systems
Windows
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AAA
Description of service interface
The MailCentral User interface allows users to view manage and control the documents they have submitted and manage their associated digital workflows. The web interface provides detailed 'track and trace' capabilities for each document that is submitted. Full management reporting is available The interface offers multi level access rights enabling users access to be restricted based on pre-defined workflows.
Accessibility standards
None or don’t know
Description of accessibility
User can submit documents from virtually any application using a simple, intuitive print driver Users are then able to view, manage and control the documents they (or their workgroup have submitted) The system provides a detailed audit trail and feedback regarding how the document has been communicated (i.e. post, SMS. email, portal App etc) Full Administration and management interface for authorised users enabling simple set up and configuration of the system. Seamless integration with either our own or the customers preferred digital communication channels via documents API interfaces.
Accessibility testing
User Interface has been implemented with due consideration of assistive technology
API
Yes
What users can and can't do using the API
Documents can be submitted via a simple API interface (rather than being printed or dropped into hot folders) The API interface provides a fully featured interactive gateway to all the standard MailCentral management reporting interfaces Integration with Active Directory, SAML and SSO Platforms
API documentation
Yes
API documentation formats
  • HTML
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The interface can be customised using your logo and details. The system can submit hybrid mail outputs to virtually any supplier on the CCS framework ensuring the technology is owned and managed by the customer (and not a third party) The API interfaces enable the customer to integrate the digital outputs with their preferred in-house or third party digital communication channels

Scaling

Independence of resources
If required a server can be dedicated to a specific client ensuring the platform is both scalable and independent of other organisations transactional requirements.

Analytics

Service usage metrics
Yes
Metrics types
MailCentral provides a fully integrated management reporting interface. MailCentral enables this data to be delivered in PDF or CSV format MailCentral reports on documents that have been submitted into the system per user, workgroup or department MailCentral details the time a document was submitted into the system and the time it was then output via the relevant physical (i.e. print and post) or physical channel MailCentral provides full closed loop reporting and details each document and whether it has been processed within the agreed SLA. MailCentral provides a simple intuitive dashboard with which to manage your digital transformation processes
Reporting types
  • Real-time dashboards
  • Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users are able to export their data using a simple reporting interface
Data export formats
CSV
Data import formats
  • CSV
  • Other
Other data import formats
  • XML
  • PDF
  • Postscript
  • ASCII

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
The Servers are hosted in Azure Microsoft guarantee that API Management Service instances running in the Consumption Tier, Basic Tier, Standard Tier, and Premium Tier deployments scaled within a single region will respond to requests to perform operations at least 99.95% of the time
Approach to resilience
Available on request
Outage reporting
E-mail alerts and dashboard

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Access in management interfaces and support channels is restricted by the 'roles' associated with each users login credentials
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Documented in our ISO27001 policy - this can be made available on request
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Documented in our ISO27001 policy - This can be made available on request
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Information from potential threats gathered from Anti Virus supplier, and development channels for each of the toolkits being implemented Ensuring toolkits and database engines are up to date Patches (if required) applied at least once every month
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Anti Virus Scans Vulnerability reporting Penetration testing Cyber Essentials plus accreditation If a potential compromise is identified, its severity is assessed and a plan of action put in place to mitigate or eliminate the risk. Any Incident regarding data is treated as a P1 and our SLA for an initial response is 30 minutes
Incident management type
Supplier-defined controls
Incident management approach
Documented as part of our ISO 27001 policies - available on request User report incidents via the on-line help desk Full and detailed incident reports are provided via the Job Ticket and as a specific physical document (if required)
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Basic platform configuration
3 month trial limit
Subject to application

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
DNV
ISO/IEC 27001 accreditation date
Saturday 1 November 2025
What the ISO/IEC 27001 doesn’t cover
This certificate is valid for the following site scope:
The security and privacy of all information and data assets Quadient use for the delivery of all core activities surrounding the provision of a range of communication solutions in accordance with the Quadient UKI & CEI Statement of Applicability version 1.0
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
DNV
ISO 9001 accreditation date
Tuesday 3 June 2025
What the ISO 9001 doesn’t cover
This certificate is valid for the following scope:
The marketing, sales, provision, installation and maintenance of mailing and document handling equipment and parcel lockers. The marketing, sales and support of customer communication solutions
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
None of the criteria
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
C795b54f-685b-4494-91c1-4ccb64625516
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bids.uk@quadient.com. Tell them what format you need. It will help if you say what assistive technology you use.