Skip to main content

Help us improve the Digital Marketplace - send your feedback

WULUF LTD

Objective Connect

Objective Connect is a highly secure file sharing platform for enterprise and government, enabling secure sharing/collaboration on documents, videos, and files with internal/external partners. Connect provides, sophisticated audit trails, collaboration workspaces, and compliance tools for efficient protected information exchange. Connect now has Legally compliant digital signatures for trusted/audited approvals.

Features

  • Secure file and document collaboration in controlled workspaces
  • Legally compliant digital signatures for trusted approvals
  • Tag-based access controls for granular permission policies
  • Comprehensive audit trails and compliance reporting
  • ISO 27001 certified security and governance framework
  • Native mobile access and responsive web interface
  • Task and process management per workspace
  • Integration with existing document systems via API
  • Two-factor authentication and federation support
  • Single Sign-On integration with SAML/OAuth/OpenID identity providers

Benefits

  • Enables secure multi-agency collaboration with external organisations
  • Improves compliance through full traceable audit trails
  • Provides export controls, aduit and governance
  • Controls access with tag-based permission policies
  • Supports rapid adoption with intuitive interface
  • Minimises IT overhead and infrastructure cost
  • Legally compliant signatures boost document trustworthiness
  • Highly scalable across government programmes and agencies
  • Enhances citizen outcomes via secure shared services
  • Improves compliance through full traceable audit trails

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ashleym@wuluf.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 2 0 2 8 5 6 3 4 0 8 1 2 0 2

Contact

WULUF LTD Ashley Morris
Telephone: 01242 357088
Email: ashleym@wuluf.com

About your service

Service categories

Applications

Collaborative

  • Enterprise community
  • Team collaboration
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Any document storage or publishing application.
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
As defined in Objective Cloud Service Terms and Objective Customer Support Plan.
System requirements
  • Supported web browsers, latest version of Google Chrome
  • Supported web browsers, latest version of Microsoft Edge
  • Supported web browsers, latest version of Mozilla Firefox
  • Supported device environment, latest and prior version of Android
  • Supported device environment, latest and prior version of iOS

User support

Email or online ticketing support
Yes
Support response times
Response and resolution time targets are defined in the Objective Customer Support Plan. For the Standard Service Level : - Support Hours are 10 x 5 ( 8am - 6pm on Business Days). - 24 hours on Business Days for Priority 1 incidents. - Support Portal Hours are 24 x 7. - Target Response Times by Priority Level are; Priority 1 (30 minutes, within Support Hours), Priority 2 (1 Support Hour), Priority 3 (4 Support Hours) and Priority 4 (8 Support Hours). - Refer to Customer Support Plan for corresponding Resolution Time Targets and definitions.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AAA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Objective provides the following technical support Service Levels: - Standard; and - Premium Standard service level is included as part of the Objective Connect subscription. The Premium technical support level subscription costs are determined by applying the specified Premium support uplift. Objective supplies the Support Services to the Customer's support contacts. Each customer can nominate up to four (4) Support Contacts who meet the conditions defined in the Customer Support Plan. Objective adopts the common four-level priority classification arrangement used in the IT industry. Contact for support incidents is with the Objective Support Team. For Objective Connect any third-party (external) participant is entitled to raise support incidents via the Support Portal.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Objective Connect is designed with zero training requirements in mind and most users start using it without any additional help. Extensive getting started guides, tutorial videos and FAQs are available from: https://www.objective.co.uk/resources/tutorials. Our Customer Success team provide skills transfer as part of the onboarding process. Additional training and workshops can be provided as a paid service, if required.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
All documents hosted in Objective Connect can be downloaded at any time. Audit trail can be exported by administrators to a CSV file at any time.
End-of-contract process
At the end of the contract users lose the option to create new secure workspaces and to add new documents to their workspaces. Administrators no longer have access to the administration features of Objective Connect. Prior to the end of the contract users and administrators can download all files and audit trails and close all workspaces, which will delete all contents from Objective Connect. 30 days after contact expiry, Objective will delete any remaining files in the account.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The web application is fully responsive and provides the same level of experience on mobile devices. Additionally there is a native mobile application for iOS and Android devices, which provides full access to the documents and folders hosted in Objective Connect.
Service interface
Yes
User support accessibility
WCAG 2.2 AAA
Description of service interface
Via supported browser or iOS / Android app
Accessibility standards
WCAG 2.2 AAA
Accessibility testing
Via testing with Government Customers and in Lab
API
Yes
What users can and can't do using the API
The API is public and integration with it is described in the API documentation. Enhanced functionality available for web applications is available through the API.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Administrators can brand Objective Connect by providing their organisation's logos and colour. This logo is displayed on the log in screen, email notifications and on Objective Connect workspaces. Brand colour is displayed on the log in screen and within the UI.

Scaling

Independence of resources
Objective Connect is a SaaS solution that scales up and down as required.

Analytics

Service usage metrics
Yes
Metrics types
The Objective Connect administration dashboard provides access to the following metrics: Connections are the currency of Connect and are calculated by multiplying the number of participants by the number of documents available in the same workspace. Administrators can view connection count at the account, workgroup, user or individual workspace level.
Reporting types
  • API access
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Objective

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Audit trails, containing records of all actions on the users' workspaces can be exported as CSV files through the customers' administration dashboard. Additionally, Workspace Record's in PDF format can also be generated for download. Presenting all audit events in a concise, human-readable document format.
Data export formats
  • CSV
  • Other
Data import formats
  • CSV
  • Other

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
Other
Other protection within supplier network
Robust network boundary controls provide the data protection within our network.

Availability and resilience

Guaranteed availability
Availability Service Level (ASL) targets, as defined in the Objective Customer Support Plan: - Standard level: 99.50% - Premium level: 99.90% Availability is calculated monthly, using formula in Objective Customer Support Plan. The ASL applies to the production instance of the Cloud Services only. Service Credits regime applies to Customers who have purchase 'Premium' support for their Cloud Service. The Service Credit regime is defined in the Objective Customer Support Plan.
Approach to resilience
Objective addresses each of the core tenants of information security; confidentiality, integrity and availability (CIA) within the design and execution of Objective Connect. Objective considers the entire 'System' when describing the security posture of any single element. We consider the various processes and procedures throughout the product's delivery and the individual functions involved in delivering and managing the solution. The delivery of any SaaS platform has multiple dimensions that must be considered when defining the overall security posture of the service. The service is comprised of: 1. The application: the people, process, and procedures involved in creating the software to be delivered as a service. 2. The platform: the third-party hyper-scale cloud provider responsible for the supply and base operation of the platform the application is running upon. 3. The delivery: the people, process and procedures undertaken within Objective to continuously refine and optimise the delivery side of the application. Objective takes security seriously, addressing the core tenants of information security across the entire 'System'. Objective Connect partners with Amazon Web Services (AWS). Integration extends natively to dedicated national networks. Together, this partnership balances the productivity benefits of moving to the cloud with keeping your data safe, secure and sovereign
Outage reporting
The Objective support portal contains a news section that is used to notify customers of unplanned outages. Customers are notified of planned outages via email notifications, product login page updates and the support portal.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Username or password
Access restrictions in management interfaces and support channels
Customer access to management interfaces is controlled by assigning users administrator roles. All actions completed by administrators in the system will be recorded in activity logs. Within Objective, access to the system is controlled by the Information Security Management System (ISMS), which is certified to ISO 27001:2013, and associated access policies. Access is provided to authorised persons only and on a need-to-know basis. All user account activity is monitored via centralised logging. Where possible, users are given seperate accounts for administrative purposes.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Objective maintains a single set of global policy documents for ISO 27001: Objective has a comprehensive set of Information Security policies and processes to manage both Quality and Information Security. The ISMS defines Objective Corporation’s general approach to information security, the organisation and structure of the information security management system and generic procedures which apply to interested parties including Objective staff - so that they are clear about their responsibilities and can apply the procedures effectively. The Executive Management Team of Objective Corporation is committed to providing the resources needed to implement the information security management system to ensure data and information is managed appropriately. Objective management team ensures that the Information Security Management System (ISMS) is established, implemented and maintained in a planned and systematic manner. This is accomplished with the appointment of the Chief Information Security Officer (CISO), responsible for the adequate and effective implementation, management and maintenance of the system. In addition to the ISMS policy, a number of additional policies are established, maintained and promoted within the organisation & externally where applicable to our company clients and stakeholders, as part of our commitment to comply with the relevant regulations, acts and statutory requirements as applicable.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
The Objective software development lifecycle and security software development lifecycle ensure a complete record from ideation to deployment is created and maintained. The development lifecycle is validated against the OWASP Application Security Verification Standard. During the early ideation phases, software concepts, application requirements, security requirements and decisions are all captured. Throughout the development and maintenance lifecycle of the product, all decisions are captured and linked directly to source code assets. During the run phase of the service, all support tickets are captured and linked to related decisions, source code assets and deployments.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
As part of measures to ensure the security of our source code Objective undertakes a range of security vulnerability detection and remediation measures. Vulnerabilities can be created or inherited, our software development lifecycle addresses both. Vulnerability assessments leveraging Dynamic Application Security Testing (DAST) and Static Application Security Testing (SAST) are undertaken. In addition, automated and manual penetration testing provides further vulnerability assessment. The third-party risk introduced through open-source libraries is addressed with automated open-source risk scanning for vulnerabilities and licence compliance. Where vulnerabilities are identified, Objective will review and prioritise remediation accordingly.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Objective Corporation maintains and monitors the platform for security incidents 24x7. In addition to comprehensive vulnerability detection, protective monitoring extends to the security of source code which is addressed via: - Code storage and integrity: Objective source code is contained within resilient source code repositories providing code integrity, malware scanning, and integrity protection. - Defect discovery and remediation: Objective leverages automated and manual testing of all applications. Testing occurs at multiple levels within source code as well as functional and operational testing. Incidents are responded to as per the Security Incident Response Plan.
Incident management type
Supplier-defined controls
Incident management approach
Objective maintains a Security Incident Response Plan as part of our ISO 27001 certification, aligned with the NIST Computer Security Incident Handling Guide (SP 800-61 R2) phases: •Preparation – covers the period prior to an incident and includes the creation of incident response plan, ensures key staff are aware of the plan. •Detection and Analysis – The Security Manager determines the category and required communications. •Containment, eradication and recovery – Contain to prevent further damage, progress to eradicate the incident and recover the impacted systems. •Post-incident activities - Post Incident Reviews are conducted for each Incident, includes root cause analysis.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
  • Public Services Network (PSN)
  • Scottish Wide Area Network (SWAN)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0.1%
Between £250,000 and £500,000
0.1%
Between £500,001 and £1,000,000
0.1%
Between £1,000,001 and £2,500,000
0.1%
Between £2,500,001 and £5,000,000
0.1%
Over £5,000,001
0.1%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
F27c0ed2-6453-45df-9b13-bbbdb6619a8f
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
7900a468-5a3b-4eb5-9b4c-e37f22d7b797
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ashleym@wuluf.com. Tell them what format you need. It will help if you say what assistive technology you use.