Skip to main content

Help us improve the Digital Marketplace - send your feedback

BIZZDESIGN UK LTD.

Bizzdesign Hopex

Bizzdesign Hopex enables business driven IT decision making by building a clear map of your IT and business landscapes and their dependencies to each other, clear descriptions of your assets, and powerful dashboarding capabilities to pilot your asset portfolios.

Features

  • Real Time Collaboration
  • Dynamic views generations
  • Automatic diagram generations
  • Dashboards
  • Data collection mechanisms - surveys
  • Metamodel configuration
  • Attributes configurations
  • Data driven insights
  • AI powered capability mapping
  • MCP Server

Benefits

  • Identify applications to rationalise
  • Manage obsolescence of applications and technologies portfolios
  • Gain clear visibility over the IT landscape
  • Plan for IT transformations
  • Run multi-layer impact analysis
  • Model and assess business processes
  • Improve stakeholder contribution
  • Facilitate access to IT knowledge
  • Manage IT and business risks
  • Gather all IT/Business/Risk data in a single repository

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at e.walker@bizzdesign.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 5 9 9 6 4 3 6 1 0 8 4 6 3 3

Contact

BIZZDESIGN UK LTD. Eddie Walker
Telephone: 07552 376731
Email: e.walker@bizzdesign.com

About your service

Service categories

Applications

Collaborative

  • Team collaboration
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The HOPEX Cloud service offers robust performance, scalability, and security, with a few operational considerations to keep in mind:

- Planned Maintenance: Scheduled during weekends with a 5-day notice; unscheduled maintenance requires a 1-day notice and is performed outside working hours;

- Support Availability: Service is available 24/7, with a support provided during business hours (9 am to 6 pm) with a 24x7 web-based incident submission system;

- Service Uptime: Guaranteed minimum uptime of 99.4% during business hours, excluding maintenance.

For more details, please refer to the HOPEX Cloud SLA available at https://bizzdesign.com/policies/terms-and-conditions.
System requirements
Microsoft Edge Chromium (64-bit) Google Chrome (64-bit) Mozilla Firefox (64-bit)

User support

Email or online ticketing support
Yes
Support response times
For details please refer to the HOPEX Cloud SLA available at https://bizzdesign.com/policies/terms-and-conditions.

The response time is calculated starting from the day after the client reports the error via the "Case Portal" in the MEGA community. MEGA's technical support may adjust the severity level if the client does not provide the necessary resources or responses to resolve the incident.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Communication with our customers takes place through a dedicated HOPEX Cloud portal and with a physical contact person through various channels: Support portal, email, telephone.
For details please refer to the HOPEX Cloud SLA available at https://bizzdesign.com/policies/terms-and-conditions
Onsite support
No
Support levels
MEGA provides Maintenance and Support Services for its HOPEX products and HOPEX Cloud Enterprise offering, structured around incident severity rather than commercial tiered plans. Support incidents are classified as Critical, Moderate, or Minor, depending on business impact. Services cover functional and operational incidents, usage questions, and improvement requests. Incidents can be declared 24/7 via the support portal or email, with processing during business hours, and are managed through a formal case lifecycle including analysis, escalation, workaround, or fix .

Support pricing is not published as fixed tiers. The scope, service levels, and associated costs are defined contractually in the customer’s order form or agreement, depending on the deployment model and subscribed options (e.g. Disaster Recovery) .

For HOPEX Cloud Enterprise, support is delivered by MEGA Cloud Services (MCS). Customers benefit from Cloud Support Engineers handling daily operations, monitoring, backups, and incident resolution. In addition, Service Delivery Managers provide customer-facing coordination, SLA oversight, and incident and change management, fulfilling a role comparable to a Technical Account Manager .
Support available to third parties
No
AI chatbot
No

Onboarding and offboarding

Getting started
The MEGA University offers training courses on our HOPEX platform. Our experienced trainers provide knowledge of our products and services to assist you in enterprise architecture, business process analysis, risk management, and data governance projects. Our modules are designed to impart MEGA-specific knowledge, encourage new ideas, and share experiences. Our training courses are offered in inter-company, intra-company and e-learning sessions.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
When a contract ends, data extraction is handled through MEGA’s reversibility process, managed by MEGA Cloud Services (MCS).

*Data extraction:* Upon customer request and according to contractual terms, MCS exports the customer’s HOPEX data (e.g. repositories, databases, and related content) in agreed formats.

*Delivery:* Extracted data is securely provided to the customer using controlled transfer mechanisms.

*Data destruction:* After confirmation of successful data delivery and in line with the contract and data protection requirements, MCS **formally deletes and destroys the customer’s data from the cloud environment.

Customers do not perform data extraction themselves via API or self-service tools; the process is managed and executed by MEGA to ensure data integrity, security, and compliance with contractual and regulatory obligations.

For details please refer to the HOPEX Cloud SLA available at https://bizzdesign.com/policies/terms-and-conditions
End-of-contract process
At the end of the contract, customer data is retained for 3 months to allow reversibility. After this period, data is permanently erased, and proof of deletion is provided. Customers can request extended retention or reversibility services, including Basic Reversibility (data backup restoration) or Complex Reversibility (XML export, documentation, and skill transfer), which are subject to additional costs.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
HOPEX web front-end can be displayed through mobiles devices in "consultation mode" thanks to the adaptative design (PWA) architecture (smartphones & tablets).
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
As part of the SaaS-based HOPEX Cloud service, a dedicated web interface is available to access the service and take advantage of the solution.
Accessibility standards
WCAG 2.2 A
Accessibility testing
MEGA follows RGAA regulations on accessibility and usability, in the development of our standard products. We have started the project for our compliance with the RGAA standard in 2022 for a first batch planned for 2024 as part of our next major version.
In June 2022 , an assessment of the tool compliance to the WCAG was carried out. With the result of a compliance score equal to 75%.
API
Yes
What users can and can't do using the API
Only the authorised customer's public address can access the service through IP filtering.

*Service setup through the API:*
Users cannot set up the service through an API. Provisioning of HOPEX Cloud Enterprise environments (infrastructure, environments, security, backups, DR) is performed exclusively by MEGA Cloud Services.

*Making changes through the API:*
Users cannot make platform or service changes through an API. Any changes to environments, configuration, or operations are handled via formal service requests and change management. Where licensed, users may use application-level APIs only to access or integrate HOPEX business data.

*Limitations:*
API usage is strictly limited to application data and integrations. Infrastructure provisioning, configuration, security controls, availability settings, and lifecycle actions are not exposed via API and remain under MEGA’s operational control to ensure security, availability, and compliance.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • ODF
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Customisations are carried out with the help of Bizzdesign's professional services.

Scaling

Independence of resources
HOPEX Cloud services are deployed on dedicated environments based on a Single-tenant architecture. This provides a very high level of security since each customer’s data is completely separated from any other customer’s data (e.g. dedicated nodes, storage, IP whitelisting, VNet and firewall).

Analytics

Service usage metrics
Yes
Metrics types
MEGA provides monthly service metrics focused on availability, incident management, and service quality. Service availability is continuously monitored and measured against contractual SLAs. Support metrics track incidents by severity, status, and resolution progress. Operational metrics include platform health, backup execution, and restore capability, with Disaster Recovery metrics available when subscribed. SLA compliance, incidents, and major events are reviewed with customers during service review or steering meetings, coordinated by Service Delivery Managers.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
HOPEX allows to import file in EXCEL format, XML, Visio, BPMN, and to export in XML, BPMN, EXCEL, WORD, PowerPoint, JPEG, PNG, SVG, HTML (web portal).
The solution is embedded with secured REST API. You can also build JSON queries to populate or query the solution.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • XML
  • BPMN
  • EXCEL
  • WORD
  • PowerPoint
  • JPEG
  • PNG
  • SVG
  • HTML
Data import formats
  • CSV
  • Other
Other data import formats
  • EXCEL
  • XML
  • Visio
  • BPMN

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
HOPEX Cloud service relies on Microsoft Azure infrastructure that guarantees the highest levels of availability and security. The service is available 24/7, with a support provided over business hours from 9am-6pm and a 24x7 web-based incident submission.
Backups are performed at regular intervals and our service offers at the minimum, 99.4% uptime (During business hours. Excluding maintenance downtime).

For details please refer to the HOPEX Cloud SLA available at https://bizzdesign.com/policies/terms-and-conditions
Approach to resilience
MEGA has chosen the following Microsoft paired regions to host its HOPEX Cloud services and best serve British customers’ business needs and locations:
o UK South (London)
o UK West (Cardiff) - Secondary region dedicated to HOPEX data replication

Automatic daily encrypted backups containing customer’s data are performed and replicated to the paired region (Georedundant storage) allowing to recover customer’s production data in case of incident. Their retention period is defined below:
- Daily: 7 days
- Weekly: 4 weeks
- Monthly: 6 months

The defined Recovery Point Objective (RPO) is 24 hours, and the Recovery Time Objective (RTO) is 7 days, which can be reduced to 1 day with the Advanced Disaster Recovery Plan.
Outage reporting
Email alerts and public dashboard.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Client poublic IP address filtering; SSO (SAML2 or OpenID)
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted to MCS engineers via a secure bastion host, using SSL/TLS sessions and IP whitelisting. All administrative actions are logged (logs and video). Multi-Factor Authentication (MFA) is enforced for external access. Support channels are limited to authorized customer representatives, who report incidents through a dedicated portal. Temporary access for support is granted only with customer approval, and all actions are logged
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
Management access to HOPEX Cloud is authenticated via a secure bastion host using SSL/TLS sessions and IP whitelisting. Multi-Factor Authentication (MFA) is enforced for external access. Passwords comply with MEGA's strong password policy and are managed securely on the CyberArk platform, ensuring they are never visible to users. All administrative actions are logged (logs and video) for accountability.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
MEGA (a Bizzdesign company) is audited at least annually against the SOC 2 reporting framework by an independent third-party. The audit for MEGA SaaS covers controls for data security, availability, and confidentiality as applicable to in-scope trust principles for each service.
Information security policies and processes
SOC2 type 2.
The SOC2 report can be provide upon request.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
MEGA implemented an Incident Management Process to mitigate the adverse impact on business and restore normal service operation as quickly as possible; an IS Vulnerability Management Process to constantly monitor security of its services; and a Change Management Process is in place to ensure the use of standardized methods and procedures to promptly and efficiently handle change and minimize impact on service quality.
A weekly Change Advisory Board (CAB) ensures that any change to the Production instance is properly assessed by the MCS team, tested in UAT instance, and validated by the Customer.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Vulnerability audits of our solution and infrastructures are performed, such as:
• ALTIUS, IT cyber security expert, carries out annual vulnerability scans on MEGA software (e.g. API vulnerabilities, Cross Site Scripting Attacks, Authentication Attacks, Client-Side Attacks);
• Continuous anti-virus and anti-malware protection with Microsoft Defender;
• Periodic scans (infrastructure and software) based on Vulnerability Scanners (Tenable Nessus) carried out by the IT Dept. and MCS team (reference framework for vulnerability is CVSS 3.1).

Below the timeframes for vulnerability remediation objectives based on CVSS 3.1:
Critical: 5 business days
High: one month
Medium: a quarter
Low: a semester
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Potential compromises are identified via log monitoring, Azure Security Center, and periodic vulnerability scans . Incidents are escalated to the CISO, with immediate customer notification within 1 business hour if impacted . The MCS team leads resolution, defines a remediation plan, and may use temporary test environments for fixes . Response times depend on severity: critical incidents are addressed within a day, high within a week, medium within a month, and low within six months .
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
MEGA has a predefined incident management process to mitigate impacts and restore services quickly. Customers report incidents via a dedicated portal, accessible by up to three representatives, including the functional administrator. The MCS team leads resolution, defines a remediation plan, and communicates it to the customer. For security incidents, customers are notified within 1 business hour. Detailed reports are shared as part of the resolution process, and temporary test environments may be created for issue reproduction and fixes, with customer approval.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Free HOPEX trials are available for 30 days and include selected HOPEX products (e.g., BPA, EA, DATA GOV, GRC).
Link to free trial
https://bizzdesign.com/request-demo

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
20%
Between £500,001 and £1,000,000
30%
Between £1,000,001 and £2,500,000
40%
Between £2,500,001 and £5,000,000
50%
Over £5,000,001
60%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Brand Compliance B.V.
ISO/IEC 27001 accreditation date
Monday 19 May 2025
What the ISO/IEC 27001 doesn’t cover
Sales and Marketing
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
C2294408-b3c6-473d-8a4d-06e0b23d3fc8
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
50216479-1555-473a-8d44-77acd67ba783
Other security certifications
Yes
Any other security certifications
SOC2 - Type 2

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at e.walker@bizzdesign.com. Tell them what format you need. It will help if you say what assistive technology you use.