Skip to main content

Help us improve the Digital Marketplace - send your feedback

VIRTUAL MAIL ROOM LIMITED

Corporate Hybrid Mail Communications

Virtual Mail Room specialises in the provision of corporate hybrid and bulk mail solutions either by post, email, SMS or web.

Features

  • 24/7 automated processing
  • Dynamic data merge
  • Comprehensive delivery reporting
  • Multi-medium delivery support
  • Secure attachment management
  • Certified data security controls
  • UK-hosted infrastructure
  • Message archiving and audit trail

Benefits

  • Send GDPR-compliant messages securely with assured data protection
  • Manage all transactional messages from a single centralised service
  • Track every message with complete end-to-end audit visibility
  • Adapt integrations and workflows quickly to changing business requirements
  • Reduce manual effort and accelerate transactional communication processes

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tmoloney@vmailroom.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 6 0 5 0 0 3 6 7 1 0 9 9 9 0

Contact

VIRTUAL MAIL ROOM LIMITED Tina Moloney
Telephone: 07557908576
Email: tmoloney@vmailroom.co.uk

About your service

Service categories

Applications

Content workflow and management

  • Document

Content services

  • Enterprise Content Management Applications
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Integration into legacy ERP systems - SAP, Oracle, JD Edwards, SAGE
Cloud deployment model
Hybrid cloud
Service constraints
The service requires internet connectivity via a browser or HTTPS access. Planned maintenance is infrequent, scheduled in advance, and designed to avoid service interruption.
Physical print requirements limited to windowed enevlopes or postcards.
System requirements
Internet connectivity with outbound HTTPS access

User support

Email or online ticketing support
Yes
Support response times
Priority 1 (S1) service is “down” response within 30 mins, Priority 2 (S2) service severely degraded response within 1 hour, Priority 3 (S3) non-essential features impaired response within 4 hours. Response times are during business hours. Weekend support available on negotiation.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
EN 301 549
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
As standard and for no extra cost, all clients have a nominated Account Manager who provides support with setup/implementation and then ongoing delivery and technical queries thereafter.

The Account Manager is supported by a technical team (including an external cloud support engineer) who are available to undertake any technical tasks following escalation.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Users are supported through a structured onboarding process that includes comprehensive API documentation, integration guidance, and configuration support. Setup assistance is provided to help users authenticate, configure templates, and test email delivery. Ongoing support is available remotely to assist with integration queries and operational use. Onsite training is not required due to the API-driven nature of the service.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
At the end of the contract, users can extract their data through the service via an agreed secure export process. Message metadata, delivery reports, audit logs, and retained message content (where applicable) can be provided in standard, machine-readable formats. Data extraction is supported during the contract exit period, after which all customer data is securely deleted in accordance with contractual and data protection requirements
End-of-contract process
At the end of the contract, the service enters a managed off-boarding period. During this time, users retain access to the service for agreed data extraction, including delivery reports, audit logs, and retained message content where applicable. Following successful data extraction or at the end of the agreed exit period, all customer data is securely deleted in accordance with contractual terms and data protection requirements, and access credentials are revoked.

The contract price includes standard service operation, portal access, routine support, and assistance with end-of-contract data extraction and data deletion. Additional costs may apply for non-standard exit activities, such as bespoke data formats, extended data retention beyond contract terms, or additional support effort outside standard exit arrangements.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and offboarding documentation is provided via email. Ensuring its accessibility, documents are provided in PDF formats and can be provided in larger font with a colour contrast ration of 4:5:1

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
System administration on mobile platform limited to user permissions only. System wide changes not available on mobile platform.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service interface is for client administrtators to provide user, template, and forms management. User management includes assigning billing groups as well as limiting service levels on a per user or group basis.
Accessibility standards
EN 301 549
Accessibility testing
None - have applied best practice and rules,
API
Yes
What users can and can't do using the API
Users will need to be authorised to use the API and will need credentials prior to setting up the service. The API is for sending and reporting on jobs with their preferences only. Preferences will depend on the application/service required i.e. mono or colour where printing is involved, timed delivery of email/SMS. No user management can be done via the API.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
All content, layouts, forms, and templates are fully customisable. User preferences can be set at a group or organistaional level. These are for administrators only. Users cannot customise the service. Bespoke customisation can be applied as a chargebale service. Customisation is controlled and does not extend to underlying infrastructure or core security controls.

Scaling

Independence of resources
The service is designed to operate safely in a multi-tenant environment. User workloads are logically isolated through per-client authentication, rate limiting, and queue-based processing to prevent one user’s demand from impacting others. Capacity is monitored continuously and scaled to maintain performance and availability, ensuring consistent service levels across all users.

Analytics

Service usage metrics
Yes
Metrics types
The service provides usage metrics through the portal, including message volumes, delivery status, success and failure rates, and processing timestamps. These metrics support operational monitoring, reporting, and audit requirements.
Reporting types
Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data through an agreed managed export process. Exported data includes delivery reports, audit logs, and retained message content where applicable, provided in standard, machine-readable formats. Data export is supported during the contract term and as part of the contract exit process.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • XML
  • JSON
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • PDF
  • DOCX
  • XLSX

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
The service is designed for high availability and is operated on resilient cloud infrastructure. We target a minimum service availability of 99.9% per calendar month, excluding planned maintenance. Availability is measured at the service Portal level.

If service availability falls below the guaranteed level, users may be eligible for service credits in accordance with the contractual service level agreement. Service credits are calculated as a percentage of the monthly service charge and applied to future invoices. Planned maintenance is scheduled in advance and does not count toward availability calculations.
Approach to resilience
The service is designed using a distributed, cloud-native architecture to ensure resilience and continuity of operation. Both front-end and back-end components operate as distributed services across multiple layers, avoiding single points of failure. The platform uses managed cloud services provided by Amazon Web Services (AWS) and Microsoft Azure to deliver datacentre and geographic resilience within the UK.

Ini addition to the data centre resilience, back-end physicla processing is supported across three UK production locations, with controlled failover arrangements to maintain service continuity. Service components are replicated, and all data is encrypted and backed up daily to secure cloud storage.

The service is continuously monitored, with automated alerts and defined escalation procedures to detect and respond to service degradation or failure. Network resilience is supported through layered security controls, including external and internal firewalls. All resilience controls and escalation procedures are governed and reviewed at Director level.
Outage reporting
Service outages are monitored continuously and managed through defined incident response procedures. Where an outage or service degradation occurs, affected users are notified via email alerts using registered service contact details. Status information and incident updates can also be provided through agreed support communications. The service does not provide a public status dashboard; outage information is communicated directly to users.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Other
Other user authentication
API access is authenticated using securely issued API credentials and tokens over HTTPS. Administrative and support access is protected using role-based access controls and multi-factor authentication
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is tightly restricted. Administrative access is controlled using Amazon Cognito with strong authentication policies, including enforced password standards, IP-based restrictions, and monitoring for suspicious login activity. Access is granted on a least-privilege basis and restricted to authorised personnel only.

All access is logged and monitored, with alerts for anomalous activity. User and administrator access rights are reviewed regularly and updated as required. Support access is controlled and auditable, and actions taken through support channels are logged to ensure accountability.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Description of management access authentication
Management access is authenticated using centrally managed identities via Amazon Cognito, with enforced password policies, multi-factor authentication, and role-based access controls. Access is restricted to authorised personnel and monitored continuously.

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
VMR operates a formal information security management framework supported by documented policies and defined operational processes. Key information security policies include Acceptable Use, Access Control, Account Administration, Backup, Business Continuity, Change Control, Data Breach Management, Encryption, Information Classification, Password Management, Records Management, Supplier Management, and Visitor Security.

All staff are required to review and adhere to relevant information security policies as part of induction and ongoing employment. Policy awareness and compliance are reinforced through training and operational controls.

Information security governance is overseen at Director level. Compliance with policies is monitored through a structured quality assurance programme, including regular spot checks and formal internal audits. Audit findings are reviewed to identify root causes, and corrective actions are implemented to support continual improvement.

Information security incidents are reported through a defined escalation process. Incidents are raised to senior management and investigated by the information security function, with appropriate remedial actions taken and affected customers notified in line with contractual and regulatory requirements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and change management are governed by formal processes aligned with VMR’s ISO 9001 and ISO 27001 management systems. All service components are identified, version-controlled, and tracked throughout their lifecycle using a configuration management database. Change requests are logged and assessed by the Head of IT for operational and information security impact. Identified risks and mitigations are reviewed at Director level. Approved changes are implemented in a controlled manner, tested, verified, and documented to ensure service integrity, security, and availability.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
In line with ISO27001, our Head of IT undertakes regular vulnerability assessments to define, identify, classify, prioritise vulnerabilities within our operating system, network, IT security policies/processes. This is supported by scans via installed software.

Following each assessment/scan, a report is produced detailing any present vulnerabilities/security risks, and risk mitigating solutions/actions e.g. installation of new software, deploying of patches etc. These solutions are immediately implemented by the Director. In addition to the vulnerability assessments, the Head of IT will also undertake regular penetration testing and run regular scans using our antivirus software; ensuring a wealth of accurate data on potential threats.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is used to identify potential security compromises through anti-malware controls, log review, vulnerability scanning, and regular vulnerability assessments and penetration testing. When a potential compromise is detected, the issue is immediately triaged by the Head of IT and appropriate containment and remediation actions are implemented, including patching, configuration changes, or policy updates. Incidents and corrective actions are reviewed at Director level to ensure lessons learned. Security incidents are responded to immediately upon detection.
Incident management type
Supplier-defined controls
Incident management approach
VMR operates a documented incident management process aligned with ISO 27001. Pre-defined procedures for common incident types are set out in the IRP. Users and staff report incidents through a managed ticketing system or via their account contact, with escalation to the Head of IT and Director level.

Incidents are triaged and contained promptly by the Head of IT, including isolating affected systems, preserving logs, and suspending processing where required. Following resolution, services are restored in a controlled manner. Incident reports are produced detailing the impact, root cause, corrective actions, and lessons learned, and shared with affected users as appropriate.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0.5%
Between £500,001 and £1,000,000
1%
Between £1,000,001 and £2,500,000
2%
Between £2,500,001 and £5,000,000
3%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Sunday 15 December 2013
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau
ISO 9001 accreditation date
Wednesday 22 July 2015
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
5a9179f0-3a66-48fe-aeb3-a3f7dd5690d0
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tmoloney@vmailroom.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.