Corporate Hybrid Mail Communications
Virtual Mail Room specialises in the provision of corporate hybrid and bulk mail solutions either by post, email, SMS or web.
Features
- 24/7 automated processing
- Dynamic data merge
- Comprehensive delivery reporting
- Multi-medium delivery support
- Secure attachment management
- Certified data security controls
- UK-hosted infrastructure
- Message archiving and audit trail
Benefits
- Send GDPR-compliant messages securely with assured data protection
- Manage all transactional messages from a single centralised service
- Track every message with complete end-to-end audit visibility
- Adapt integrations and workflows quickly to changing business requirements
- Reduce manual effort and accelerate transactional communication processes
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 6 0 5 0 0 3 6 7 1 0 9 9 9 0
Contact
VIRTUAL MAIL ROOM LIMITED
Tina Moloney
Telephone: 07557908576
Email: tmoloney@vmailroom.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
- Document
Content services
- Enterprise Content Management Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Integration into legacy ERP systems - SAP, Oracle, JD Edwards, SAGE
- Cloud deployment model
- Hybrid cloud
- Service constraints
-
The service requires internet connectivity via a browser or HTTPS access. Planned maintenance is infrequent, scheduled in advance, and designed to avoid service interruption.
Physical print requirements limited to windowed enevlopes or postcards. - System requirements
- Internet connectivity with outbound HTTPS access
User support
- Email or online ticketing support
- Yes
- Support response times
- Priority 1 (S1) service is “down” response within 30 mins, Priority 2 (S2) service severely degraded response within 1 hour, Priority 3 (S3) non-essential features impaired response within 4 hours. Response times are during business hours. Weekend support available on negotiation.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
As standard and for no extra cost, all clients have a nominated Account Manager who provides support with setup/implementation and then ongoing delivery and technical queries thereafter.
The Account Manager is supported by a technical team (including an external cloud support engineer) who are available to undertake any technical tasks following escalation. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Users are supported through a structured onboarding process that includes comprehensive API documentation, integration guidance, and configuration support. Setup assistance is provided to help users authenticate, configure templates, and test email delivery. Ongoing support is available remotely to assist with integration queries and operational use. Onsite training is not required due to the API-driven nature of the service.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- At the end of the contract, users can extract their data through the service via an agreed secure export process. Message metadata, delivery reports, audit logs, and retained message content (where applicable) can be provided in standard, machine-readable formats. Data extraction is supported during the contract exit period, after which all customer data is securely deleted in accordance with contractual and data protection requirements
- End-of-contract process
-
At the end of the contract, the service enters a managed off-boarding period. During this time, users retain access to the service for agreed data extraction, including delivery reports, audit logs, and retained message content where applicable. Following successful data extraction or at the end of the agreed exit period, all customer data is securely deleted in accordance with contractual terms and data protection requirements, and access credentials are revoked.
The contract price includes standard service operation, portal access, routine support, and assistance with end-of-contract data extraction and data deletion. Additional costs may apply for non-standard exit activities, such as bespoke data formats, extended data retention beyond contract terms, or additional support effort outside standard exit arrangements. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding documentation is provided via email. Ensuring its accessibility, documents are provided in PDF formats and can be provided in larger font with a colour contrast ration of 4:5:1
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- System administration on mobile platform limited to user permissions only. System wide changes not available on mobile platform.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service interface is for client administrtators to provide user, template, and forms management. User management includes assigning billing groups as well as limiting service levels on a per user or group basis.
- Accessibility standards
- EN 301 549
- Accessibility testing
- None - have applied best practice and rules,
- API
- Yes
- What users can and can't do using the API
- Users will need to be authorised to use the API and will need credentials prior to setting up the service. The API is for sending and reporting on jobs with their preferences only. Preferences will depend on the application/service required i.e. mono or colour where printing is involved, timed delivery of email/SMS. No user management can be done via the API.
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- All content, layouts, forms, and templates are fully customisable. User preferences can be set at a group or organistaional level. These are for administrators only. Users cannot customise the service. Bespoke customisation can be applied as a chargebale service. Customisation is controlled and does not extend to underlying infrastructure or core security controls.
Scaling
- Independence of resources
- The service is designed to operate safely in a multi-tenant environment. User workloads are logically isolated through per-client authentication, rate limiting, and queue-based processing to prevent one user’s demand from impacting others. Capacity is monitored continuously and scaled to maintain performance and availability, ensuring consistent service levels across all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides usage metrics through the portal, including message volumes, delivery status, success and failure rates, and processing timestamps. These metrics support operational monitoring, reporting, and audit requirements.
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export their data through an agreed managed export process. Exported data includes delivery reports, audit logs, and retained message content where applicable, provided in standard, machine-readable formats. Data export is supported during the contract term and as part of the contract exit process.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XML
- JSON
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- DOCX
- XLSX
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
The service is designed for high availability and is operated on resilient cloud infrastructure. We target a minimum service availability of 99.9% per calendar month, excluding planned maintenance. Availability is measured at the service Portal level.
If service availability falls below the guaranteed level, users may be eligible for service credits in accordance with the contractual service level agreement. Service credits are calculated as a percentage of the monthly service charge and applied to future invoices. Planned maintenance is scheduled in advance and does not count toward availability calculations. - Approach to resilience
-
The service is designed using a distributed, cloud-native architecture to ensure resilience and continuity of operation. Both front-end and back-end components operate as distributed services across multiple layers, avoiding single points of failure. The platform uses managed cloud services provided by Amazon Web Services (AWS) and Microsoft Azure to deliver datacentre and geographic resilience within the UK.
Ini addition to the data centre resilience, back-end physicla processing is supported across three UK production locations, with controlled failover arrangements to maintain service continuity. Service components are replicated, and all data is encrypted and backed up daily to secure cloud storage.
The service is continuously monitored, with automated alerts and defined escalation procedures to detect and respond to service degradation or failure. Network resilience is supported through layered security controls, including external and internal firewalls. All resilience controls and escalation procedures are governed and reviewed at Director level. - Outage reporting
- Service outages are monitored continuously and managed through defined incident response procedures. Where an outage or service degradation occurs, affected users are notified via email alerts using registered service contact details. Status information and incident updates can also be provided through agreed support communications. The service does not provide a public status dashboard; outage information is communicated directly to users.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Other
- Other user authentication
- API access is authenticated using securely issued API credentials and tokens over HTTPS. Administrative and support access is protected using role-based access controls and multi-factor authentication
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is tightly restricted. Administrative access is controlled using Amazon Cognito with strong authentication policies, including enforced password standards, IP-based restrictions, and monitoring for suspicious login activity. Access is granted on a least-privilege basis and restricted to authorised personnel only.
All access is logged and monitored, with alerts for anomalous activity. User and administrator access rights are reviewed regularly and updated as required. Support access is controlled and auditable, and actions taken through support channels are logged to ensure accountability. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- Management access is authenticated using centrally managed identities via Amazon Cognito, with enforced password policies, multi-factor authentication, and role-based access controls. Access is restricted to authorised personnel and monitored continuously.
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
VMR operates a formal information security management framework supported by documented policies and defined operational processes. Key information security policies include Acceptable Use, Access Control, Account Administration, Backup, Business Continuity, Change Control, Data Breach Management, Encryption, Information Classification, Password Management, Records Management, Supplier Management, and Visitor Security.
All staff are required to review and adhere to relevant information security policies as part of induction and ongoing employment. Policy awareness and compliance are reinforced through training and operational controls.
Information security governance is overseen at Director level. Compliance with policies is monitored through a structured quality assurance programme, including regular spot checks and formal internal audits. Audit findings are reviewed to identify root causes, and corrective actions are implemented to support continual improvement.
Information security incidents are reported through a defined escalation process. Incidents are raised to senior management and investigated by the information security function, with appropriate remedial actions taken and affected customers notified in line with contractual and regulatory requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management are governed by formal processes aligned with VMR’s ISO 9001 and ISO 27001 management systems. All service components are identified, version-controlled, and tracked throughout their lifecycle using a configuration management database. Change requests are logged and assessed by the Head of IT for operational and information security impact. Identified risks and mitigations are reviewed at Director level. Approved changes are implemented in a controlled manner, tested, verified, and documented to ensure service integrity, security, and availability.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
In line with ISO27001, our Head of IT undertakes regular vulnerability assessments to define, identify, classify, prioritise vulnerabilities within our operating system, network, IT security policies/processes. This is supported by scans via installed software.
Following each assessment/scan, a report is produced detailing any present vulnerabilities/security risks, and risk mitigating solutions/actions e.g. installation of new software, deploying of patches etc. These solutions are immediately implemented by the Director. In addition to the vulnerability assessments, the Head of IT will also undertake regular penetration testing and run regular scans using our antivirus software; ensuring a wealth of accurate data on potential threats. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is used to identify potential security compromises through anti-malware controls, log review, vulnerability scanning, and regular vulnerability assessments and penetration testing. When a potential compromise is detected, the issue is immediately triaged by the Head of IT and appropriate containment and remediation actions are implemented, including patching, configuration changes, or policy updates. Incidents and corrective actions are reviewed at Director level to ensure lessons learned. Security incidents are responded to immediately upon detection.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
VMR operates a documented incident management process aligned with ISO 27001. Pre-defined procedures for common incident types are set out in the IRP. Users and staff report incidents through a managed ticketing system or via their account contact, with escalation to the Head of IT and Director level.
Incidents are triaged and contained promptly by the Head of IT, including isolating affected systems, preserving logs, and suspending processing where required. Following resolution, services are restored in a controlled manner. Incident reports are produced detailing the impact, root cause, corrective actions, and lessons learned, and shared with affected users as appropriate. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0.5%
- Between £500,001 and £1,000,000
- 1%
- Between £1,000,001 and £2,500,000
- 2%
- Between £2,500,001 and £5,000,000
- 3%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Sunday 15 December 2013
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Wednesday 22 July 2015
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5a9179f0-3a66-48fe-aeb3-a3f7dd5690d0
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-