Skip to main content

Help us improve the Digital Marketplace - send your feedback

INSTRUCTURE GLOBAL LIMITED

Parchment Digitary Services

Parchment Digitary Services is a secure, globally accessible platform enabling institutions, employers, and government agencies to certify, issue, accept, and verify academic credentials. Learners access and share digital academic documents, including transcripts and badges, supporting efficient records management, fraud prevention, and trusted verification worldwide.

Features

  • Secure digital credential issuance with cryptographic signatures
  • Real-time reporting and analytics dashboard for administrators
  • Single sign-on integration with EduGate and SAML providers
  • API integration with Student Information Systems
  • Automated batch document issuance and scheduled delivery
  • GDPR-compliant, ISO 27001 certified secure cloud hosting
  • 24/7 web-based access across mobile and desktop devices
  • Document revocation, access control, and audit logging
  • Digital badge issuance compliant with Open Badges standards
  • Credential verification support for document share recipients

Benefits

  • Reduce administrative workload through automated document processing
  • Eliminate credential fraud with tamper-proof digital verification
  • Enable students to access credentials anytime, anywhere securely
  • Speed up document delivery and verification for employers
  • Improve student experience through self-service credential sharing
  • Streamline integrations with existing student record systems
  • Lower printing, postage, and manual handling costs
  • Support sustainability goals by reducing paper-based processes
  • Enhance institutional reputation with trusted global credential network
  • Simplify compliance with GDPR, accessibility, and security standards

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gclouduk@instructure.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 0 3 0 5 2 4 1 3 5 3 5 7 4 8

Contact

INSTRUCTURE GLOBAL LIMITED G-Cloud Contact
Telephone: 020 3514 6223
Email: gclouduk@instructure.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Education
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
No
System requirements
  • An internet connection
  • A browser-enabled desktop or mobile device.

User support

Email or online ticketing support
Yes
Support response times
Parchment Digitary provides user support via an online ticketing portal and email, with defined SLA response times based on issue priority. Critical Priority 1 issues receive a first response within 30 minutes, with resolution targeted within 4 hours. Priority 2 issues receive a response within 2 hours. Priority 3 issues receive a response within 4 hours, and Priority 4 issues within 1 business day. Support operates during business hours (9am–5pm, Mon–Fri), with 24/7/365 system monitoring and escalation pathways in place
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Parchment Digitary provides a tiered managed support model delivered through its Support Portal and Customer Success function.

Level 0 – Self-Service: Knowledge base, FAQs, user guides, and documentation to resolve common issues.
Level 1/2 – Support Portal & Email: Ticket-based incident and service request handling with defined SLAs.
Level 3 – Customer Support Manager: Escalation point for complex or unresolved issues.
Level 4 – Senior Leadership Escalation: Director-level oversight for critical matters.

Each institution receives 5 days (40 hours) of support annually, covering post-go-live incidents, troubleshooting, and how-to requests. Additional support hours are available at extra cost if the allocation is exceeded.

A dedicated Customer Success Manager (CSM) is assigned as the primary relationship and technical coordination contact. The CSM provides service reviews, training, roadmap updates, usage reporting, and quarterly business reviews.

24/7/365 system monitoring, 99.95% uptime, and priority-based SLA response targets are included.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Parchment Digitary supports onboarding through training, documentation, and guided implementation. Training is provided during onboarding and User Acceptance Testing (UAT), covering end-to-end platform workflows. Institutions receive user manuals, operations documentation, and knowledge-base resources for both staff and learners.

A Customer Success Manager (CSM) is assigned to support onboarding, training, adoption, and ongoing use. Additional training sessions may be provided, including on-site training where required. Test environments are available to allow institutions to validate processes and new features.

The Support Portal provides access to FAQs, release notes, troubleshooting guides, and help articles, and users can raise support requests via the portal. Learners also have access to a built-in “Take a Tour” feature within the Learner Portal to guide them through platform functionality.

Ongoing support includes quarterly business reviews, feature updates, and continuous improvement feedback loops to ensure successful long-term adoption.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
We will deliver the latest customer data backup in a format that is readily and easily accessible to the Customer as outlined in the contract exit clauses agreed with the Customer. Customer data, metadata and configuration data will be deleted following contract termination using Amazon AWS best practice processes and procedures and in compliance with applicable laws and regulations including ISO 27001 and SOC2.
End-of-contract process
In the unlikely event that a user chooses to leave Parchment Digitary Services, we will support them throughout the process, giving them the assistance you need to successfully transition to their new provider.

A Customer Success Manager will continue to support the user throughout the phase-out process. Tasks and timescales will depend on the size of the organisation and the number of institutions.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Documentation is delivered through a web-based Support Portal, making it accessible via standard browsers across desktop and mobile devices. Materials include operations manuals, FAQs, troubleshooting guides, release notes, and training resources, supporting both institutional staff and learners. The online format enables searchable content, structured navigation, and responsive viewing, improving usability across devices.

Learners also benefit from an integrated “Take a Tour” feature in the Learner Portal, guiding users through key platform functions. Where additional assistance is needed, users can raise support requests via the Support Portal or receive guidance through the Customer Success Manager.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Parchment Digitary Services is fully web-based and responsive, designed to work across desktop, tablet, and mobile devices using standard browsers on iOS and Android. The mobile experience provides the same core functionality as desktop, including viewing, sharing, and managing digital credentials and badges. Differences are limited to screen layout and navigation optimised for smaller displays, ensuring usability and accessibility while maintaining full security, verification, and sharing features. Organisation Portal (staff members) typically use a laptop/desktop when using the service
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Digitary provides a web-based service interface consisting of an Organisation Portal for institutional staff and a Learner Portal for students and graduates. The interface enables secure document issuance, search, reporting, sharing, badge management, and administrative controls. It is browser-accessible, requires no local installation, supports role-based access, and is designed to be intuitive and responsive for all users.
Accessibility standards
WCAG 2.2 AAA
Accessibility testing
The platform is engineered for universal inclusivity, maintaining strict adherence to WCAG 2.2 AA standards through a continuous validation cycle. We conduct regular automated accessibility scans and manual audits. We treat accessibility as a core functional requirement ensuring that every learner - regardless of ability, can navigate, interact with, and celebrate their achievements in a fully perceivable and robust digital environment.
API
Yes
What users can and can't do using the API
Parchment Digitary Services provides a RESTful API that enables integration with Student Information Systems (SIS) and other institutional platforms. The API allows institutions to automate document issuance, upload structured XML data, populate document templates, and trigger credential creation and delivery. It supports data mapping, custom schemas, and standards such as PESC and the Digitary Learner Profile (DLP).

Users can push student records, credentials, and metadata, configure automated workflows based on system flags or criteria, and manage batch issuance processes through API-driven integrations. The API supports document rendering, secure signing workflows, and integration for receiving and sharing credentials within the Digitary network.

System configuration changes, major template logic changes, schema modifications, and new document type creation are typically managed through formal change requests rather than unrestricted API calls. API use is therefore primarily focused on data exchange, document creation, and automation, while platform governance, security controls, and structural changes remain managed through Digitary’s support and change management processes.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Parchment Digitary Services allows institutions to customise multiple aspects of the service. Universities can configure document types, document templates, branding (logos, fonts, layout), data fields, and presentation formats for different cohorts (e.g., undergraduate vs postgraduate). Institutions control what data is uploaded, how it is structured, and when documents are issued, including batch or individual issuance.

Customisation is also supported for email templates, user roles and permissions, sharing settings, authentication methods (SSO), and API data schemas (e.g., PESC or Digitary Learner Profile). Minor template updates (e.g., signature image changes) can be handled as support requests, while more complex changes (e.g., logic or schema updates, new document types) are managed through formal change requests.

The platform is fully customizable to meet the specific needs of individual institutions. Key features include support for diverse document types, options for both print and digital fulfillment, digital badges, and the ability to share documents in bulk with third parties.

Customisation is typically carried out by institutional administrators, supported by Parchment Support and the Customer Success Manager, ensuring governance, security, and consistency across the platform.

Scaling

Independence of resources
The platform operates on highly available, scalable AWS infrastructure, deployed across multiple availability zones to ensure resilience and consistent performance. The platform maintains a 99.95% availability target.

24/7/365 system monitoring and recovery proactively detects and mitigates performance issues.

Architecture supports load balancing, redundancy, and failover to reduce the risk of service degradation under peak demand. Institutions are provisioned with their own Organisation Portal Instance shielding it from other institutions' usage. The platform is performance tested with every release, 6 times yearly, at usage levels over and above peak usage, ensuring it's provisioned to perform well at very-high peak time usage.

Analytics

Service usage metrics
Yes
Metrics types
Parchment Digitary provides service usage metrics and operational reporting, including platform availability, performance monitoring, support ticket SLA metrics, and service desk performance reports. Institutions receive usage statistics such as credential issuance volumes, learner engagement, access and sharing activity, and adoption trends. Metrics are reviewed during Quarterly Business Reviews, alongside insights on platform usage, improvement recommendations, and roadmap updates. Security monitoring and system health metrics are also tracked through continuous infrastructure monitoring.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with CSA CCM v4.0
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
The platform supports data export through comprehensive, multi-format capabilities designed for effective interoperability. Users can execute bulk exports of document repositories, including high-fidelity PDFs, XML files, and detailed CSV metadata, alongside granular CSV extracts for badge attributes, metadata, and recipient records. Additionally, all system-level reports are exportable in standard spreadsheet formats (XLSX), ensuring that administrative data remains accessible, machine-readable, and ready for ingestion into downstream environments.
Data export formats
  • CSV
  • Other
Other data export formats
XLSX
Data import formats
  • CSV
  • Other
Other data import formats
  • XML
  • PDF
  • JSON

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Parchment Digitary Services guarantees 99.95% monthly application availability, measured using external monitoring tools that perform continuous HTTP/TLS health checks. Availability is calculated monthly and assessed against the 99.95% uptime target. The platform runs in a multi-availability-zone AWS environment, supporting high availability and fault tolerance.

The service includes 24/7/365 remote monitoring and recovery, enabling proactive detection and resolution of system issues. A daily maintenance window (00:00–03:00 GMT) is used for updates and platform maintenance, with advance notification provided when applicable.
Approach to resilience
The Digitary platform is deployed in a secure, highly scalable AWS environment across multiple availability zones, supporting resilience, redundancy, and high availability. The architecture includes load balancing, multi-node deployment, and failover capability to reduce service disruption risk.

A 24/7/365 monitoring and recovery capability proactively detects system issues and automatically restarts affected components where required. Performance is continuously monitored using remote monitoring tools, with a target that 80% of transactions complete in under 2.5 seconds.

The platform follows a controlled release and maintenance process, with scheduled upgrades, UAT environments, and change validation prior to production deployment. Backup, recovery testing, and security monitoring are in place to support operational continuity.
Outage reporting
Parchment Digitary provides a public platform status page that displays real-time availability and service health information: https://status.digitary.net/
.
Outages, incidents, and maintenance events are communicated through status updates and institutional notifications. Planned maintenance and significant changes are announced in advance, including release notes and scheduled maintenance alerts.

Availability and incident performance are also reviewed through service reporting, SLA tracking, and Quarterly Business Reviews, providing transparency on uptime, performance, and operational issues.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to Digitary’s management interfaces and Support Portal is restricted through authenticated user accounts, role-based permissions, and controlled support escalation pathways. Institutional administrators manage access to organisational portals, while Digitary support staff operate under defined support roles and escalation tiers. Support requests are submitted via a secure ticketing portal, and sensitive actions are limited to authorised personnel. Platform access is monitored using 24/7/365 operational monitoring, and incidents are handled through formal escalation procedures.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Parchment Digitary operates formal security, access control, incident management, change management, and data protection processes, supported by AWS cloud security controls. The platform uses 24/7/365 monitoring, vulnerability scanning, patch management, and controlled release procedures.

Data protection includes TLS encryption in transit, AES-256 encryption at rest on AWS S3, and secure storage media sanitisation aligned with NIST SP 800-88 and DoD 5220.22-M. Incident response follows defined escalation paths, including SOC monitoring and Customer Support leadership.

Compliance and performance are reviewed through service reporting, SLA monitoring, and Quarterly Business Reviews, ensuring accountability and continuous improvement.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Digitary follows a controlled configuration and change management process supported by defined release, testing, and approval workflows. System changes are planned, tested in User Acceptance Testing (UAT) environments, and validated prior to production deployment. Scheduled releases occur approximately every two months, with advance communication to customers where applicable.

Service components are monitored throughout their lifecycle using 24/7/365 remote monitoring, uptime tools, and performance tracking. Changes are reviewed for operational stability and potential security impact, and incidents or issues are managed through formal support escalation processes.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Digitary manages vulnerabilities through continuous security monitoring, AWS security controls, and regular patching and platform updates. Potential threats are identified via remote monitoring tools, infrastructure alerts, and AWS security advisories. Software updates and fixes are deployed through a controlled release process, with testing in UAT environments prior to production rollout. Scheduled releases occur approximately every two months, with critical fixes applied as required. Threat intelligence is sourced from AWS security services, internal monitoring, and platform performance tools.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Digitary uses 24/7/365 remote monitoring and recovery, supported by AWS infrastructure monitoring and external uptime and performance tools (e.g., Site24x7). Monitoring tracks availability, performance, errors, and potential security incidents. Alerts trigger incident response and escalation procedures, enabling rapid investigation and remediation. Support SLAs define priority-based response targets, including 30-minute response for critical incidents. Monitoring insights are reviewed through service reporting and quarterly business reviews, supporting continuous improvement and proactive risk management.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Digitary manages incidents through a formal support and escalation process via its Support Portal and ticketing system. Users report incidents by submitting support tickets, which are prioritised according to defined P1–P4 severity levels with SLA response targets (e.g., 30-minute response for critical incidents). Incidents are monitored through 24/7/365 remote monitoring, and escalated to the Customer Support Manager and senior leadership when required. Incident progress and outcomes are tracked within the support system, and service performance is reviewed through regular reporting and Quarterly Business Reviews.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
3%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
8%
Between £1,000,001 and £2,500,000
12%
Between £2,500,001 and £5,000,000
17%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Moss Adams Certifications LLC, Ansi National Accreditations Board, IAF
ISO/IEC 27001 accreditation date
Wednesday 16 October 2024
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Wednesday 9 February 2022
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
N/A
PCI certification
Yes
Who accredited the PCI DSS certification
PCI Security Standards Council
PCI DSS accreditation date
Tuesday 10 June 2025
What the PCI DSS doesn’t cover
We have PCI certification for Catalog and Parchment, since these are the only areas PCI is applicable to.
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
4a4bc4ae-3c41-470d-97a4-ebc10f592d2a
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
2d0362aa-3ec2-4529-b07e-cc167d357a7b
Other security certifications
Yes
Any other security certifications
  • SOC2 Type II
  • SOC3

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gclouduk@instructure.com. Tell them what format you need. It will help if you say what assistive technology you use.