Parchment Digitary Services
Parchment Digitary Services is a secure, globally accessible platform enabling institutions, employers, and government agencies to certify, issue, accept, and verify academic credentials. Learners access and share digital academic documents, including transcripts and badges, supporting efficient records management, fraud prevention, and trusted verification worldwide.
Features
- Secure digital credential issuance with cryptographic signatures
- Real-time reporting and analytics dashboard for administrators
- Single sign-on integration with EduGate and SAML providers
- API integration with Student Information Systems
- Automated batch document issuance and scheduled delivery
- GDPR-compliant, ISO 27001 certified secure cloud hosting
- 24/7 web-based access across mobile and desktop devices
- Document revocation, access control, and audit logging
- Digital badge issuance compliant with Open Badges standards
- Credential verification support for document share recipients
Benefits
- Reduce administrative workload through automated document processing
- Eliminate credential fraud with tamper-proof digital verification
- Enable students to access credentials anytime, anywhere securely
- Speed up document delivery and verification for employers
- Improve student experience through self-service credential sharing
- Streamline integrations with existing student record systems
- Lower printing, postage, and manual handling costs
- Support sustainability goals by reducing paper-based processes
- Enhance institutional reputation with trusted global credential network
- Simplify compliance with GDPR, accessibility, and security standards
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 0 3 0 5 2 4 1 3 5 3 5 7 4 8
Contact
INSTRUCTURE GLOBAL LIMITED
G-Cloud Contact
Telephone: 020 3514 6223
Email: gclouduk@instructure.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Education
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
-
- An internet connection
- A browser-enabled desktop or mobile device.
User support
- Email or online ticketing support
- Yes
- Support response times
- Parchment Digitary provides user support via an online ticketing portal and email, with defined SLA response times based on issue priority. Critical Priority 1 issues receive a first response within 30 minutes, with resolution targeted within 4 hours. Priority 2 issues receive a response within 2 hours. Priority 3 issues receive a response within 4 hours, and Priority 4 issues within 1 business day. Support operates during business hours (9am–5pm, Mon–Fri), with 24/7/365 system monitoring and escalation pathways in place
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Parchment Digitary provides a tiered managed support model delivered through its Support Portal and Customer Success function.
Level 0 – Self-Service: Knowledge base, FAQs, user guides, and documentation to resolve common issues.
Level 1/2 – Support Portal & Email: Ticket-based incident and service request handling with defined SLAs.
Level 3 – Customer Support Manager: Escalation point for complex or unresolved issues.
Level 4 – Senior Leadership Escalation: Director-level oversight for critical matters.
Each institution receives 5 days (40 hours) of support annually, covering post-go-live incidents, troubleshooting, and how-to requests. Additional support hours are available at extra cost if the allocation is exceeded.
A dedicated Customer Success Manager (CSM) is assigned as the primary relationship and technical coordination contact. The CSM provides service reviews, training, roadmap updates, usage reporting, and quarterly business reviews.
24/7/365 system monitoring, 99.95% uptime, and priority-based SLA response targets are included. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Parchment Digitary supports onboarding through training, documentation, and guided implementation. Training is provided during onboarding and User Acceptance Testing (UAT), covering end-to-end platform workflows. Institutions receive user manuals, operations documentation, and knowledge-base resources for both staff and learners.
A Customer Success Manager (CSM) is assigned to support onboarding, training, adoption, and ongoing use. Additional training sessions may be provided, including on-site training where required. Test environments are available to allow institutions to validate processes and new features.
The Support Portal provides access to FAQs, release notes, troubleshooting guides, and help articles, and users can raise support requests via the portal. Learners also have access to a built-in “Take a Tour” feature within the Learner Portal to guide them through platform functionality.
Ongoing support includes quarterly business reviews, feature updates, and continuous improvement feedback loops to ensure successful long-term adoption. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- We will deliver the latest customer data backup in a format that is readily and easily accessible to the Customer as outlined in the contract exit clauses agreed with the Customer. Customer data, metadata and configuration data will be deleted following contract termination using Amazon AWS best practice processes and procedures and in compliance with applicable laws and regulations including ISO 27001 and SOC2.
- End-of-contract process
-
In the unlikely event that a user chooses to leave Parchment Digitary Services, we will support them throughout the process, giving them the assistance you need to successfully transition to their new provider.
A Customer Success Manager will continue to support the user throughout the phase-out process. Tasks and timescales will depend on the size of the organisation and the number of institutions. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Documentation is delivered through a web-based Support Portal, making it accessible via standard browsers across desktop and mobile devices. Materials include operations manuals, FAQs, troubleshooting guides, release notes, and training resources, supporting both institutional staff and learners. The online format enables searchable content, structured navigation, and responsive viewing, improving usability across devices.
Learners also benefit from an integrated “Take a Tour” feature in the Learner Portal, guiding users through key platform functions. Where additional assistance is needed, users can raise support requests via the Support Portal or receive guidance through the Customer Success Manager.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Parchment Digitary Services is fully web-based and responsive, designed to work across desktop, tablet, and mobile devices using standard browsers on iOS and Android. The mobile experience provides the same core functionality as desktop, including viewing, sharing, and managing digital credentials and badges. Differences are limited to screen layout and navigation optimised for smaller displays, ensuring usability and accessibility while maintaining full security, verification, and sharing features. Organisation Portal (staff members) typically use a laptop/desktop when using the service
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Digitary provides a web-based service interface consisting of an Organisation Portal for institutional staff and a Learner Portal for students and graduates. The interface enables secure document issuance, search, reporting, sharing, badge management, and administrative controls. It is browser-accessible, requires no local installation, supports role-based access, and is designed to be intuitive and responsive for all users.
- Accessibility standards
- WCAG 2.2 AAA
- Accessibility testing
- The platform is engineered for universal inclusivity, maintaining strict adherence to WCAG 2.2 AA standards through a continuous validation cycle. We conduct regular automated accessibility scans and manual audits. We treat accessibility as a core functional requirement ensuring that every learner - regardless of ability, can navigate, interact with, and celebrate their achievements in a fully perceivable and robust digital environment.
- API
- Yes
- What users can and can't do using the API
-
Parchment Digitary Services provides a RESTful API that enables integration with Student Information Systems (SIS) and other institutional platforms. The API allows institutions to automate document issuance, upload structured XML data, populate document templates, and trigger credential creation and delivery. It supports data mapping, custom schemas, and standards such as PESC and the Digitary Learner Profile (DLP).
Users can push student records, credentials, and metadata, configure automated workflows based on system flags or criteria, and manage batch issuance processes through API-driven integrations. The API supports document rendering, secure signing workflows, and integration for receiving and sharing credentials within the Digitary network.
System configuration changes, major template logic changes, schema modifications, and new document type creation are typically managed through formal change requests rather than unrestricted API calls. API use is therefore primarily focused on data exchange, document creation, and automation, while platform governance, security controls, and structural changes remain managed through Digitary’s support and change management processes. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Parchment Digitary Services allows institutions to customise multiple aspects of the service. Universities can configure document types, document templates, branding (logos, fonts, layout), data fields, and presentation formats for different cohorts (e.g., undergraduate vs postgraduate). Institutions control what data is uploaded, how it is structured, and when documents are issued, including batch or individual issuance.
Customisation is also supported for email templates, user roles and permissions, sharing settings, authentication methods (SSO), and API data schemas (e.g., PESC or Digitary Learner Profile). Minor template updates (e.g., signature image changes) can be handled as support requests, while more complex changes (e.g., logic or schema updates, new document types) are managed through formal change requests.
The platform is fully customizable to meet the specific needs of individual institutions. Key features include support for diverse document types, options for both print and digital fulfillment, digital badges, and the ability to share documents in bulk with third parties.
Customisation is typically carried out by institutional administrators, supported by Parchment Support and the Customer Success Manager, ensuring governance, security, and consistency across the platform.
Scaling
- Independence of resources
-
The platform operates on highly available, scalable AWS infrastructure, deployed across multiple availability zones to ensure resilience and consistent performance. The platform maintains a 99.95% availability target.
24/7/365 system monitoring and recovery proactively detects and mitigates performance issues.
Architecture supports load balancing, redundancy, and failover to reduce the risk of service degradation under peak demand. Institutions are provisioned with their own Organisation Portal Instance shielding it from other institutions' usage. The platform is performance tested with every release, 6 times yearly, at usage levels over and above peak usage, ensuring it's provisioned to perform well at very-high peak time usage.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Parchment Digitary provides service usage metrics and operational reporting, including platform availability, performance monitoring, support ticket SLA metrics, and service desk performance reports. Institutions receive usage statistics such as credential issuance volumes, learner engagement, access and sharing activity, and adoption trends. Metrics are reviewed during Quarterly Business Reviews, alongside insights on platform usage, improvement recommendations, and roadmap updates. Security monitoring and system health metrics are also tracked through continuous infrastructure monitoring.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- The platform supports data export through comprehensive, multi-format capabilities designed for effective interoperability. Users can execute bulk exports of document repositories, including high-fidelity PDFs, XML files, and detailed CSV metadata, alongside granular CSV extracts for badge attributes, metadata, and recipient records. Additionally, all system-level reports are exportable in standard spreadsheet formats (XLSX), ensuring that administrative data remains accessible, machine-readable, and ready for ingestion into downstream environments.
- Data export formats
-
- CSV
- Other
- Other data export formats
- XLSX
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XML
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Parchment Digitary Services guarantees 99.95% monthly application availability, measured using external monitoring tools that perform continuous HTTP/TLS health checks. Availability is calculated monthly and assessed against the 99.95% uptime target. The platform runs in a multi-availability-zone AWS environment, supporting high availability and fault tolerance.
The service includes 24/7/365 remote monitoring and recovery, enabling proactive detection and resolution of system issues. A daily maintenance window (00:00–03:00 GMT) is used for updates and platform maintenance, with advance notification provided when applicable. - Approach to resilience
-
The Digitary platform is deployed in a secure, highly scalable AWS environment across multiple availability zones, supporting resilience, redundancy, and high availability. The architecture includes load balancing, multi-node deployment, and failover capability to reduce service disruption risk.
A 24/7/365 monitoring and recovery capability proactively detects system issues and automatically restarts affected components where required. Performance is continuously monitored using remote monitoring tools, with a target that 80% of transactions complete in under 2.5 seconds.
The platform follows a controlled release and maintenance process, with scheduled upgrades, UAT environments, and change validation prior to production deployment. Backup, recovery testing, and security monitoring are in place to support operational continuity. - Outage reporting
-
Parchment Digitary provides a public platform status page that displays real-time availability and service health information: https://status.digitary.net/
.
Outages, incidents, and maintenance events are communicated through status updates and institutional notifications. Planned maintenance and significant changes are announced in advance, including release notes and scheduled maintenance alerts.
Availability and incident performance are also reviewed through service reporting, SLA tracking, and Quarterly Business Reviews, providing transparency on uptime, performance, and operational issues.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to Digitary’s management interfaces and Support Portal is restricted through authenticated user accounts, role-based permissions, and controlled support escalation pathways. Institutional administrators manage access to organisational portals, while Digitary support staff operate under defined support roles and escalation tiers. Support requests are submitted via a secure ticketing portal, and sensitive actions are limited to authorised personnel. Platform access is monitored using 24/7/365 operational monitoring, and incidents are handled through formal escalation procedures.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Parchment Digitary operates formal security, access control, incident management, change management, and data protection processes, supported by AWS cloud security controls. The platform uses 24/7/365 monitoring, vulnerability scanning, patch management, and controlled release procedures.
Data protection includes TLS encryption in transit, AES-256 encryption at rest on AWS S3, and secure storage media sanitisation aligned with NIST SP 800-88 and DoD 5220.22-M. Incident response follows defined escalation paths, including SOC monitoring and Customer Support leadership.
Compliance and performance are reviewed through service reporting, SLA monitoring, and Quarterly Business Reviews, ensuring accountability and continuous improvement. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Digitary follows a controlled configuration and change management process supported by defined release, testing, and approval workflows. System changes are planned, tested in User Acceptance Testing (UAT) environments, and validated prior to production deployment. Scheduled releases occur approximately every two months, with advance communication to customers where applicable.
Service components are monitored throughout their lifecycle using 24/7/365 remote monitoring, uptime tools, and performance tracking. Changes are reviewed for operational stability and potential security impact, and incidents or issues are managed through formal support escalation processes. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Digitary manages vulnerabilities through continuous security monitoring, AWS security controls, and regular patching and platform updates. Potential threats are identified via remote monitoring tools, infrastructure alerts, and AWS security advisories. Software updates and fixes are deployed through a controlled release process, with testing in UAT environments prior to production rollout. Scheduled releases occur approximately every two months, with critical fixes applied as required. Threat intelligence is sourced from AWS security services, internal monitoring, and platform performance tools.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Digitary uses 24/7/365 remote monitoring and recovery, supported by AWS infrastructure monitoring and external uptime and performance tools (e.g., Site24x7). Monitoring tracks availability, performance, errors, and potential security incidents. Alerts trigger incident response and escalation procedures, enabling rapid investigation and remediation. Support SLAs define priority-based response targets, including 30-minute response for critical incidents. Monitoring insights are reviewed through service reporting and quarterly business reviews, supporting continuous improvement and proactive risk management.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Digitary manages incidents through a formal support and escalation process via its Support Portal and ticketing system. Users report incidents by submitting support tickets, which are prioritised according to defined P1–P4 severity levels with SLA response targets (e.g., 30-minute response for critical incidents). Incidents are monitored through 24/7/365 remote monitoring, and escalated to the Customer Support Manager and senior leadership when required. Incident progress and outcomes are tracked within the support system, and service performance is reviewed through regular reporting and Quarterly Business Reviews.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 3%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 8%
- Between £1,000,001 and £2,500,000
- 12%
- Between £2,500,001 and £5,000,000
- 17%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Moss Adams Certifications LLC, Ansi National Accreditations Board, IAF
- ISO/IEC 27001 accreditation date
- Wednesday 16 October 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Wednesday 9 February 2022
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
- N/A
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- PCI Security Standards Council
- PCI DSS accreditation date
- Tuesday 10 June 2025
- What the PCI DSS doesn’t cover
- We have PCI certification for Catalog and Parchment, since these are the only areas PCI is applicable to.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 4a4bc4ae-3c41-470d-97a4-ebc10f592d2a
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 2d0362aa-3ec2-4529-b07e-cc167d357a7b
- Other security certifications
- Yes
- Any other security certifications
-
- SOC2 Type II
- SOC3
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-