Insytful - The digital accessibility, website improvement and QA platform
Insytful is a single platform for monitoring accessibility, content quality and UX across websites and intranets. Continuous QA audits identify WCAG nonconformities, PDF accessibility, SEO concerns, broken links, misspellings, readability problems, page speed and other performance issues. Insytful’s dashboard helps organisations prioritise fixes, track improvements, and meet compliance requirements.
Features
- Automated website QA audits for accessibility, content quality and SEO
- Accessibility checks for HTML and PDFs against WCAG 2.2
- CMS deeplink integrations, plus Google Analytics and Web Risk API
- Custom policies and reports based on keywords, HTML snippets, size
- Identify misspellings, broken or malicious links, broken images and readability
- Interdepartmental collaboration with assigned issues workflow, sections and Jira
- View all email addresses, phone numbers, documents with the inventory
- Monitor your carbon footprint and environmental impact of your website
- Track AI search conversations for content gap analysis
- https://www.insytful.com/social/gcloud
Benefits
- Ongoing monitoring with alerts for compliance, quality and performance issues
- Meet WCAG 2.2 requirements and deliver accessible web experiences
- Resolve issues quickly using CMS deep-linking and integrated workflows
- Improve content quality through continuous audits and readability checks
- Gain visibility of links, documents, contacts and site content inventory
- Receive automated scores with prioritised actionable recommendations
- Enhance technical SEO, crawlability and site health automatically
- Monitor website performance, page size and speed impacting user experience
- Audit HTML and PDFs to identify and fix accessibility issues
- Get started immediately with minimal training and technical implementation required
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 6 7 9 8 4 6 3 5 2 3 2 2 9 1
Contact
ZENGENTI LIMITED
Stef Robinson / Ola Andersson
Telephone: 01584 824202
Email: tenders@zengenti.com
About your service
- Service categories
-
Applications
Content workflow and management
Content services
- Content Sharing and Collaboration Applications
Persuasive content management
- Website Software
- Digital Adoption Platform
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Insytful is a standalone product, but it also integrates with the Contensis Digital Experience Platform (DXP) and Content Management System (CMS). It also integrates with other popular CMS platforms.
- Cloud deployment model
- Private cloud
- Service constraints
- Insytful is a browser-based application provided as software-as-a-service (SaaS), and can only be accessed via the internet. Planned maintenance on the Insytful platform is carried out by our engineers outside business hours and should not directly affect our customers.
- System requirements
-
- Google Chrome (latest)
- Safari (latest)
- Firefox (latest)
- Microsoft Edge (latest)
User support
- Email or online ticketing support
- Yes
- Support response times
- We aim to respond to all support queries for Insytful promptly via our help desk portal, email and our dedicated Slack channel. Support is unlimited for any technical issues. Service availability issues can expect a response within 1 hour, with resolution targeted within 8 hours. Non-critical queries can expect a response within 8 business hours, with resolution typically within 3 working days. Support for Insytful is available Monday to Friday, 9am–5pm (GMT). Additional support can be provided on an ad-hoc basis where required.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- All plans include unlimited support for technical issues with Insytful via our help desk portal, email, and dedicated Slack channel. Support is available Monday to Friday, 9am-5pm (GMT). While the service is not classified as business-critical, any issues affecting availability receive a response within one hour, with resolution targeted within eight hours. Non-critical queries are typically responded to within eight business hours of ticket submission and resolved within three working days. Where required, we can also work with customers on an ad-hoc basis to provide additional support outside standard arrangements.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Insytful is designed for users to start using the service quickly and confidently, regardless of their technical experience. From the moment users are added to the system, the onboarding process is simple and guided, with help configuring scans, single sign-on (SSO) and integrations from the Insytful support team. To further support onboarding, we provide detailed user guides and documentation that explain features, terminology, and workflows. These resources are written in plain language and are easy to access directly from Insytful. In addition, our support team is readily available to answer questions, provide clarification, and assist users during their early stages, ensuring they can begin using Insytful effectively and gain value as quickly as possible. The interface is intuitive, uncluttered, and visually clear, allowing new users to navigate the platform easily without prior training.The main dashboard provides immediate value by presenting snapshots of website scans and audits, including at-a-glance scores for current and previous scans. Key insights such as worst-performing pages, accessibility issues, SEO, performance, and content quality are surfaced clearly, helping users prioritise actions straight away. Progress-over-time scores also help users understand improvements and next steps.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Customers can request that our engineers export their historical scan data in JSON format.
- End-of-contract process
- At the end of the contract, there is no automatic renewal unless otherwise agreed. Customers are downgraded to Insytful’s free plan, allowing continued access to the platform within the limits of that plan. This ensures users can retain visibility of their account and results without any immediate loss of access. No exit fees are applied at contract end. During the contract term, the agreed price includes access to the Insytful platform at the contracted plan level, including core features such as website scanning, dashboards, reporting, historical comparisons, and access to user documentation. The price also includes platform updates, maintenance, and access to our support team for assistance and guidance. Additional costs only apply where customers choose to extend beyond the scope of the agreed contract. This may include upgrading to a higher usage tier beyond contracted limits, requesting consultancy services, or adding on features or enhanced support arrangements. Any additional costs are clearly scoped, agreed in advance, and confirmed in writing before being incurred. This approach provides customers with transparency and certainty, ensuring there are no unexpected charges during or after the contract and that exiting the service is straightforward and low risk.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The full range of Insytful features is available across both mobile and desktop devices. However, for the best experience, we recommend a minimum screen width of at least 1024px on a tablet or desktop. This screen size will provide users with a seamless experience when using Insytful to analyse their scan data.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
- The Insytful service is accessed through a browser-based interface, designed for self-service use. Users are presented with a central dashboard that provides a clear overview of accessibility, content quality, SEO, and performance for each website, alongside a site inventory and issue status by severity and frequency. Insytful is role-based and organisation administrators can manage users, permissions, site sections, policies and billing through dedicated administration screens. Users with appropriate permissions can review findings, track progress and assign issues to team members. Scans are managed through the interface, allowing administrators to configure and monitor scheduled activities.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The Insytful user interface is designed to be accessible. Accessible design elements, including colour contrast and keyboard navigation, have been built into Insytful, making it accessible to users of the software. We regularly review user journeys and interactions with accessibility in mind, considering the needs of users with different assistive technologies. We manually test all user interfaces using assistive technology, including JAWS, NVDA and VoiceOver.
- API
- Yes
- What users can and can't do using the API
- Insytful has its own API. It is not currently available to users, but it will be available in the near future. We can work with a customer to make the API available, allowing them to use most features available in Insytful. The most common use cases would be to provide scan data and results, allowing customers to surface this data in their own reporting tools, such as Microsoft Power BI, and initiate single-page scans to integrate Insytful scans with their tools and CMS platforms. We use industry-standard REST API architecture and can work with clients to surface the data they need through our service.
- API documentation
- No
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Insytful offers flexible custom configuration options to meet organisational needs. Administrators can create a custom brand global dictionary in Insytful, which is used for spell checking specific terminology, product names, or acronyms used by your organisation. Creating a custom dictionary is an ideal way to capture any words that would otherwise get flagged as spelling mistakes. The custom dictionary can be used across multiple sites, even with multiple languages. In addition to custom brand dictionaries, users can create custom reports and policies based on various criteria, such as looking for specific words, phone numbers on pages or pages exceeding a certain size. Sections allow site admins to split the site up into different areas, making large web estates easier to manage. Sections can be configured by path, author, metatag, regex and value. Administrators can also customise their scanning schedules and frequency, specifying the time and day when the website scans occur. As a result, Insytful can be configured to support an organisation’s content standards, governance policies and complex web estates.
Scaling
- Independence of resources
- To ensure users aren’t affected by additional demand on the service, Insytful has active monitoring, rate limiting, and scans are scheduled to run outside peak periods. The Insytful service operates on a highly specified and elastic infrastructure that is capable of sustaining website scanning traffic at least 30% beyond normal demand. Users benefit from our hosting platform, which provides automatic scaling for Insytful’s scanning technology, allowing it to manage any spikes in demand with minimal impact on business operations.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Customers can request that our engineers export their historical scan data in JSON format.
- Data export formats
- Other
- Other data export formats
- JSON
- Data import formats
- Other
- Other data import formats
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Insytful provides a high level of service availability appropriate to its intended use. The service is designed to deliver a minimum uptime availability of 99.9%, measured on a monthly basis. Availability is calculated as the percentage of total time in which the service is operational and accessible to users during the measurement period. Service availability is monitored continuously. Service credits are calculated on the basis of the difference between the actual availability achieved for the month and the SLA. Insytful is not positioned as a business-critical system. However, it is supported by defined operational and support processes. Support requests are acknowledged within 8 business hours of submission, with a target resolution time of three working days, depending on issue severity.
- Approach to resilience
- The Insytful platform and infrastructure are designed with resilience built in, including operational measures to minimise the impact of component, network, or supplier failures. The service operates from multiple Tier 3 data centres, supported by multiple Tier 1 carriers, with multiple entry points into each data centre. This architecture removes single points of failure and enables continued service delivery if an individual data centre, carrier, or connection becomes unavailable. The platform is designed to support redundancy and failover across its core components, allowing traffic to be rerouted in the event of infrastructure or network issues. We are not dependent on any single supplier or geographic location to deliver the service. Service health is continuously monitored using over 400 monitored data points, providing real-time visibility into performance, capacity, and availability. This monitoring enables early detection of issues and rapid intervention before they affect customers.
- Outage reporting
- Our help desk is the first point of contact for any client issues. Any number of users can be set up to have access to the help desk and raise tickets on your behalf. For any wider outages that affect multiple clients, we have an incident management process which includes additional resources to handle both technical and communication aspects. One of our incident managers will keep all parties informed and provide updates through our Zengenti Cloud Status page, detailing any service outages that may occur. Clients can sign up to receive email notifications of any service outage and status updates. Following the incident, we will also issue an incident report, which will include a detailed description of the problem, a timeline of events, and any potential mitigation measures to prevent a similar issue in the future.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Registering for access to the help desk requires a valid email address associated with your organisation and customer account. Once registered, it can only be accessed by authenticated registered users.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Less than 1 month
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Less than 1 month
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Zengenti operates a comprehensive Information Security Management System (ISMS) which covers Insytful and Contensis, comprising policies, procedures and controls aligned with ISO27001:2022. The ISMS defines how information security risks are identified, assessed, treated and reviewed, and are subject to regular internal reviews and independent external audits to ensure ongoing compliance and continual improvement. Core information security policies cover data protection, access control, asset management, incident management, business continuity, and supplier security. Information security incidents and potential vulnerabilities are managed through a defined incident management process, including investigation, remediation, and lessons learned. Risk assessments are carried out regularly to ensure appropriate controls are in place and remain effective. All staff receive mandatory information security and data protection training as part of their induction, with refresher training delivered annually. Personnel security is further supported through baseline security screening and background checks in line with BS7858:2019.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- The platform is entirely managed using configuration management, so all operations are entirely automated, with no human time required to deploy and configure infrastructure. Any changes related to the underlying shared infrastructure are managed in accordance with Zengenti’s change control processes.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- The platform features multiple layers of security that serve as a barrier against intrusions. These include firewalls, monitoring for DDoS attacks and regular infrastructure patching with security updates. We use internal and external monitoring, and perform vulnerability scans on our central infrastructure and have regular penetration tests too. We assess potential vulnerabilities through proactive monitoring of logs and via security advisories from the security sector. Whenever a vulnerability is recognised, we make an immediate decision about the potential consequences and how it should be addressed. If a patch were critical, we would apply it immediately.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The platform has over 400 monitored data points, which provide early warnings and deep insights into any issues before they impact client environments. We use enterprise network monitoring tools, both internally and externally, and have systems in place to monitor for any increase in website and network traffic over specified thresholds, including DDoS attacks or similar. We proactively monitor logs for any unexpected events too. Any potential compromise would trigger our incident management processes.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The majority of incidents are handled through our help desk, which helps streamline incident management, tracking, and resolution. For critical issues, we have a comprehensive incident management process in place for addressing security incidents, vulnerabilities, and outages. The process ensures that our clients are regularly notified of what is happening and keeps everyone informed. Our incident managers are responsible for client communications through our Zengenti Cloud status page and ensuring the team follows the agreed procedures. As with all our policies and procedures, our incident management process is regularly reviewed and assessed by our ISO27001 auditors.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- The Insytful free plan allows users to evaluate accessibility on up to 100 pages of a single website per month. It provides core scanning functionality for initial insight, while advanced features such as multiple site scans, multi-language support, additional users, section switching, and PDF accessibility are available on paid plans.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Tuesday 1 July 2025
- What the ISO/IEC 27001 doesn’t cover
- Our ISO27001:2022 certification covers all company operations.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- NQA
- ISO 9001 accreditation date
- Tuesday 1 July 2025
- What the ISO 9001 doesn’t cover
- Our ISO9001 certification covers all company operations.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 150a9ced-d172-426e-a0c1-23bcbe2e8af7
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-