Bizzdesign Hopex
Bizzdesign Hopex enables business driven IT decision making by building a clear map of your IT and business landscapes and their dependencies to each other, clear descriptions of your assets, and powerful dashboarding capabilities to pilot your asset portfolios.
Features
- Real Time Collaboration
- Dynamic views generations
- Automatic diagram generations
- Dashboards
- Data collection mechanisms - surveys
- Metamodel configuration
- Attributes configurations
- Data driven insights
- AI powered capability mapping
- MCP Server
Benefits
- Identify applications to rationalise
- Manage obsolescence of applications and technologies portfolios
- Gain clear visibility over the IT landscape
- Plan for IT transformations
- Run multi-layer impact analysis
- Model and assess business processes
- Improve stakeholder contribution
- Facilitate access to IT knowledge
- Manage IT and business risks
- Gather all IT/Business/Risk data in a single repository
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 5 9 9 6 4 3 6 1 0 8 4 6 3 3
Contact
BIZZDESIGN UK LTD.
Eddie Walker
Telephone: 07552 376731
Email: e.walker@bizzdesign.com
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
The HOPEX Cloud service offers robust performance, scalability, and security, with a few operational considerations to keep in mind:
- Planned Maintenance: Scheduled during weekends with a 5-day notice; unscheduled maintenance requires a 1-day notice and is performed outside working hours;
- Support Availability: Service is available 24/7, with a support provided during business hours (9 am to 6 pm) with a 24x7 web-based incident submission system;
- Service Uptime: Guaranteed minimum uptime of 99.4% during business hours, excluding maintenance.
For more details, please refer to the HOPEX Cloud SLA available at https://bizzdesign.com/policies/terms-and-conditions. - System requirements
- Microsoft Edge Chromium (64-bit) Google Chrome (64-bit) Mozilla Firefox (64-bit)
User support
- Email or online ticketing support
- Yes
- Support response times
-
For details please refer to the HOPEX Cloud SLA available at https://bizzdesign.com/policies/terms-and-conditions.
The response time is calculated starting from the day after the client reports the error via the "Case Portal" in the MEGA community. MEGA's technical support may adjust the severity level if the client does not provide the necessary resources or responses to resolve the incident. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Communication with our customers takes place through a dedicated HOPEX Cloud portal and with a physical contact person through various channels: Support portal, email, telephone.
For details please refer to the HOPEX Cloud SLA available at https://bizzdesign.com/policies/terms-and-conditions - Onsite support
- No
- Support levels
-
MEGA provides Maintenance and Support Services for its HOPEX products and HOPEX Cloud Enterprise offering, structured around incident severity rather than commercial tiered plans. Support incidents are classified as Critical, Moderate, or Minor, depending on business impact. Services cover functional and operational incidents, usage questions, and improvement requests. Incidents can be declared 24/7 via the support portal or email, with processing during business hours, and are managed through a formal case lifecycle including analysis, escalation, workaround, or fix .
Support pricing is not published as fixed tiers. The scope, service levels, and associated costs are defined contractually in the customer’s order form or agreement, depending on the deployment model and subscribed options (e.g. Disaster Recovery) .
For HOPEX Cloud Enterprise, support is delivered by MEGA Cloud Services (MCS). Customers benefit from Cloud Support Engineers handling daily operations, monitoring, backups, and incident resolution. In addition, Service Delivery Managers provide customer-facing coordination, SLA oversight, and incident and change management, fulfilling a role comparable to a Technical Account Manager . - Support available to third parties
- No
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- The MEGA University offers training courses on our HOPEX platform. Our experienced trainers provide knowledge of our products and services to assist you in enterprise architecture, business process analysis, risk management, and data governance projects. Our modules are designed to impart MEGA-specific knowledge, encourage new ideas, and share experiences. Our training courses are offered in inter-company, intra-company and e-learning sessions.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
When a contract ends, data extraction is handled through MEGA’s reversibility process, managed by MEGA Cloud Services (MCS).
*Data extraction:* Upon customer request and according to contractual terms, MCS exports the customer’s HOPEX data (e.g. repositories, databases, and related content) in agreed formats.
*Delivery:* Extracted data is securely provided to the customer using controlled transfer mechanisms.
*Data destruction:* After confirmation of successful data delivery and in line with the contract and data protection requirements, MCS **formally deletes and destroys the customer’s data from the cloud environment.
Customers do not perform data extraction themselves via API or self-service tools; the process is managed and executed by MEGA to ensure data integrity, security, and compliance with contractual and regulatory obligations.
For details please refer to the HOPEX Cloud SLA available at https://bizzdesign.com/policies/terms-and-conditions - End-of-contract process
- At the end of the contract, customer data is retained for 3 months to allow reversibility. After this period, data is permanently erased, and proof of deletion is provided. Customers can request extended retention or reversibility services, including Basic Reversibility (data backup restoration) or Complex Reversibility (XML export, documentation, and skill transfer), which are subject to additional costs.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- HOPEX web front-end can be displayed through mobiles devices in "consultation mode" thanks to the adaptative design (PWA) architecture (smartphones & tablets).
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- As part of the SaaS-based HOPEX Cloud service, a dedicated web interface is available to access the service and take advantage of the solution.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
-
MEGA follows RGAA regulations on accessibility and usability, in the development of our standard products. We have started the project for our compliance with the RGAA standard in 2022 for a first batch planned for 2024 as part of our next major version.
In June 2022 , an assessment of the tool compliance to the WCAG was carried out. With the result of a compliance score equal to 75%. - API
- Yes
- What users can and can't do using the API
-
Only the authorised customer's public address can access the service through IP filtering.
*Service setup through the API:*
Users cannot set up the service through an API. Provisioning of HOPEX Cloud Enterprise environments (infrastructure, environments, security, backups, DR) is performed exclusively by MEGA Cloud Services.
*Making changes through the API:*
Users cannot make platform or service changes through an API. Any changes to environments, configuration, or operations are handled via formal service requests and change management. Where licensed, users may use application-level APIs only to access or integrate HOPEX business data.
*Limitations:*
API usage is strictly limited to application data and integrations. Infrastructure provisioning, configuration, security controls, availability settings, and lifecycle actions are not exposed via API and remain under MEGA’s operational control to ensure security, availability, and compliance. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- ODF
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Customisations are carried out with the help of Bizzdesign's professional services.
Scaling
- Independence of resources
- HOPEX Cloud services are deployed on dedicated environments based on a Single-tenant architecture. This provides a very high level of security since each customer’s data is completely separated from any other customer’s data (e.g. dedicated nodes, storage, IP whitelisting, VNet and firewall).
Analytics
- Service usage metrics
- Yes
- Metrics types
- MEGA provides monthly service metrics focused on availability, incident management, and service quality. Service availability is continuously monitored and measured against contractual SLAs. Support metrics track incidents by severity, status, and resolution progress. Operational metrics include platform health, backup execution, and restore capability, with Disaster Recovery metrics available when subscribed. SLA compliance, incidents, and major events are reviewed with customers during service review or steering meetings, coordinated by Service Delivery Managers.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
HOPEX allows to import file in EXCEL format, XML, Visio, BPMN, and to export in XML, BPMN, EXCEL, WORD, PowerPoint, JPEG, PNG, SVG, HTML (web portal).
The solution is embedded with secured REST API. You can also build JSON queries to populate or query the solution. - Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- XML
- BPMN
- EXCEL
- WORD
- PowerPoint
- JPEG
- PNG
- SVG
- HTML
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- EXCEL
- XML
- Visio
- BPMN
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
HOPEX Cloud service relies on Microsoft Azure infrastructure that guarantees the highest levels of availability and security. The service is available 24/7, with a support provided over business hours from 9am-6pm and a 24x7 web-based incident submission.
Backups are performed at regular intervals and our service offers at the minimum, 99.4% uptime (During business hours. Excluding maintenance downtime).
For details please refer to the HOPEX Cloud SLA available at https://bizzdesign.com/policies/terms-and-conditions - Approach to resilience
-
MEGA has chosen the following Microsoft paired regions to host its HOPEX Cloud services and best serve British customers’ business needs and locations:
o UK South (London)
o UK West (Cardiff) - Secondary region dedicated to HOPEX data replication
Automatic daily encrypted backups containing customer’s data are performed and replicated to the paired region (Georedundant storage) allowing to recover customer’s production data in case of incident. Their retention period is defined below:
- Daily: 7 days
- Weekly: 4 weeks
- Monthly: 6 months
The defined Recovery Point Objective (RPO) is 24 hours, and the Recovery Time Objective (RTO) is 7 days, which can be reduced to 1 day with the Advanced Disaster Recovery Plan. - Outage reporting
- Email alerts and public dashboard.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- Client poublic IP address filtering; SSO (SAML2 or OpenID)
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted to MCS engineers via a secure bastion host, using SSL/TLS sessions and IP whitelisting. All administrative actions are logged (logs and video). Multi-Factor Authentication (MFA) is enforced for external access. Support channels are limited to authorized customer representatives, who report incidents through a dedicated portal. Temporary access for support is granted only with customer approval, and all actions are logged
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- Management access to HOPEX Cloud is authenticated via a secure bastion host using SSL/TLS sessions and IP whitelisting. Multi-Factor Authentication (MFA) is enforced for external access. Passwords comply with MEGA's strong password policy and are managed securely on the CyberArk platform, ensuring they are never visible to users. All administrative actions are logged (logs and video) for accountability.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- MEGA (a Bizzdesign company) is audited at least annually against the SOC 2 reporting framework by an independent third-party. The audit for MEGA SaaS covers controls for data security, availability, and confidentiality as applicable to in-scope trust principles for each service.
- Information security policies and processes
-
SOC2 type 2.
The SOC2 report can be provide upon request. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
MEGA implemented an Incident Management Process to mitigate the adverse impact on business and restore normal service operation as quickly as possible; an IS Vulnerability Management Process to constantly monitor security of its services; and a Change Management Process is in place to ensure the use of standardized methods and procedures to promptly and efficiently handle change and minimize impact on service quality.
A weekly Change Advisory Board (CAB) ensures that any change to the Production instance is properly assessed by the MCS team, tested in UAT instance, and validated by the Customer. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Vulnerability audits of our solution and infrastructures are performed, such as:
• ALTIUS, IT cyber security expert, carries out annual vulnerability scans on MEGA software (e.g. API vulnerabilities, Cross Site Scripting Attacks, Authentication Attacks, Client-Side Attacks);
• Continuous anti-virus and anti-malware protection with Microsoft Defender;
• Periodic scans (infrastructure and software) based on Vulnerability Scanners (Tenable Nessus) carried out by the IT Dept. and MCS team (reference framework for vulnerability is CVSS 3.1).
Below the timeframes for vulnerability remediation objectives based on CVSS 3.1:
Critical: 5 business days
High: one month
Medium: a quarter
Low: a semester - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Potential compromises are identified via log monitoring, Azure Security Center, and periodic vulnerability scans . Incidents are escalated to the CISO, with immediate customer notification within 1 business hour if impacted . The MCS team leads resolution, defines a remediation plan, and may use temporary test environments for fixes . Response times depend on severity: critical incidents are addressed within a day, high within a week, medium within a month, and low within six months .
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- MEGA has a predefined incident management process to mitigate impacts and restore services quickly. Customers report incidents via a dedicated portal, accessible by up to three representatives, including the functional administrator. The MCS team leads resolution, defines a remediation plan, and communicates it to the customer. For security incidents, customers are notified within 1 business hour. Detailed reports are shared as part of the resolution process, and temporary test environments may be created for issue reproduction and fixes, with customer approval.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Free HOPEX trials are available for 30 days and include selected HOPEX products (e.g., BPA, EA, DATA GOV, GRC).
- Link to free trial
- https://bizzdesign.com/request-demo
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 20%
- Between £500,001 and £1,000,000
- 30%
- Between £1,000,001 and £2,500,000
- 40%
- Between £2,500,001 and £5,000,000
- 50%
- Over £5,000,001
- 60%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Brand Compliance B.V.
- ISO/IEC 27001 accreditation date
- Monday 19 May 2025
- What the ISO/IEC 27001 doesn’t cover
- Sales and Marketing
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- C2294408-b3c6-473d-8a4d-06e0b23d3fc8
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 50216479-1555-473a-8d44-77acd67ba783
- Other security certifications
- Yes
- Any other security certifications
- SOC2 - Type 2
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-