Objective Connect
Objective Connect is a highly secure file sharing platform for enterprise and government, enabling secure sharing/collaboration on documents, videos, and files with internal/external partners. Connect provides, sophisticated audit trails, collaboration workspaces, and compliance tools for efficient protected information exchange. Connect now has Legally compliant digital signatures for trusted/audited approvals.
Features
- Secure file and document collaboration in controlled workspaces
- Legally compliant digital signatures for trusted approvals
- Tag-based access controls for granular permission policies
- Comprehensive audit trails and compliance reporting
- ISO 27001 certified security and governance framework
- Native mobile access and responsive web interface
- Task and process management per workspace
- Integration with existing document systems via API
- Two-factor authentication and federation support
- Single Sign-On integration with SAML/OAuth/OpenID identity providers
Benefits
- Enables secure multi-agency collaboration with external organisations
- Improves compliance through full traceable audit trails
- Provides export controls, aduit and governance
- Controls access with tag-based permission policies
- Supports rapid adoption with intuitive interface
- Minimises IT overhead and infrastructure cost
- Legally compliant signatures boost document trustworthiness
- Highly scalable across government programmes and agencies
- Enhances citizen outcomes via secure shared services
- Improves compliance through full traceable audit trails
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 2 0 2 8 5 6 3 4 0 8 1 2 0 2
Contact
WULUF LTD
Ashley Morris
Telephone: 01242 357088
Email: ashleym@wuluf.com
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Any document storage or publishing application.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- As defined in Objective Cloud Service Terms and Objective Customer Support Plan.
- System requirements
-
- Supported web browsers, latest version of Google Chrome
- Supported web browsers, latest version of Microsoft Edge
- Supported web browsers, latest version of Mozilla Firefox
- Supported device environment, latest and prior version of Android
- Supported device environment, latest and prior version of iOS
User support
- Email or online ticketing support
- Yes
- Support response times
- Response and resolution time targets are defined in the Objective Customer Support Plan. For the Standard Service Level : - Support Hours are 10 x 5 ( 8am - 6pm on Business Days). - 24 hours on Business Days for Priority 1 incidents. - Support Portal Hours are 24 x 7. - Target Response Times by Priority Level are; Priority 1 (30 minutes, within Support Hours), Priority 2 (1 Support Hour), Priority 3 (4 Support Hours) and Priority 4 (8 Support Hours). - Refer to Customer Support Plan for corresponding Resolution Time Targets and definitions.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Objective provides the following technical support Service Levels: - Standard; and - Premium Standard service level is included as part of the Objective Connect subscription. The Premium technical support level subscription costs are determined by applying the specified Premium support uplift. Objective supplies the Support Services to the Customer's support contacts. Each customer can nominate up to four (4) Support Contacts who meet the conditions defined in the Customer Support Plan. Objective adopts the common four-level priority classification arrangement used in the IT industry. Contact for support incidents is with the Objective Support Team. For Objective Connect any third-party (external) participant is entitled to raise support incidents via the Support Portal.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Objective Connect is designed with zero training requirements in mind and most users start using it without any additional help. Extensive getting started guides, tutorial videos and FAQs are available from: https://www.objective.co.uk/resources/tutorials. Our Customer Success team provide skills transfer as part of the onboarding process. Additional training and workshops can be provided as a paid service, if required.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- All documents hosted in Objective Connect can be downloaded at any time. Audit trail can be exported by administrators to a CSV file at any time.
- End-of-contract process
- At the end of the contract users lose the option to create new secure workspaces and to add new documents to their workspaces. Administrators no longer have access to the administration features of Objective Connect. Prior to the end of the contract users and administrators can download all files and audit trails and close all workspaces, which will delete all contents from Objective Connect. 30 days after contact expiry, Objective will delete any remaining files in the account.
- Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The web application is fully responsive and provides the same level of experience on mobile devices. Additionally there is a native mobile application for iOS and Android devices, which provides full access to the documents and folders hosted in Objective Connect.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
- Via supported browser or iOS / Android app
- Accessibility standards
- WCAG 2.2 AAA
- Accessibility testing
- Via testing with Government Customers and in Lab
- API
- Yes
- What users can and can't do using the API
- The API is public and integration with it is described in the API documentation. Enhanced functionality available for web applications is available through the API.
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Administrators can brand Objective Connect by providing their organisation's logos and colour. This logo is displayed on the log in screen, email notifications and on Objective Connect workspaces. Brand colour is displayed on the log in screen and within the UI.
Scaling
- Independence of resources
- Objective Connect is a SaaS solution that scales up and down as required.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The Objective Connect administration dashboard provides access to the following metrics: Connections are the currency of Connect and are calculated by multiplying the number of participants by the number of documents available in the same workspace. Administrators can view connection count at the account, workgroup, user or individual workspace level.
- Reporting types
-
- API access
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Objective
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Audit trails, containing records of all actions on the users' workspaces can be exported as CSV files through the customers' administration dashboard. Additionally, Workspace Record's in PDF format can also be generated for download. Presenting all audit events in a concise, human-readable document format.
- Data export formats
-
- CSV
- Other
- Data import formats
-
- CSV
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- Other
- Other protection within supplier network
- Robust network boundary controls provide the data protection within our network.
Availability and resilience
- Guaranteed availability
- Availability Service Level (ASL) targets, as defined in the Objective Customer Support Plan: - Standard level: 99.50% - Premium level: 99.90% Availability is calculated monthly, using formula in Objective Customer Support Plan. The ASL applies to the production instance of the Cloud Services only. Service Credits regime applies to Customers who have purchase 'Premium' support for their Cloud Service. The Service Credit regime is defined in the Objective Customer Support Plan.
- Approach to resilience
- Objective addresses each of the core tenants of information security; confidentiality, integrity and availability (CIA) within the design and execution of Objective Connect. Objective considers the entire 'System' when describing the security posture of any single element. We consider the various processes and procedures throughout the product's delivery and the individual functions involved in delivering and managing the solution. The delivery of any SaaS platform has multiple dimensions that must be considered when defining the overall security posture of the service. The service is comprised of: 1. The application: the people, process, and procedures involved in creating the software to be delivered as a service. 2. The platform: the third-party hyper-scale cloud provider responsible for the supply and base operation of the platform the application is running upon. 3. The delivery: the people, process and procedures undertaken within Objective to continuously refine and optimise the delivery side of the application. Objective takes security seriously, addressing the core tenants of information security across the entire 'System'. Objective Connect partners with Amazon Web Services (AWS). Integration extends natively to dedicated national networks. Together, this partnership balances the productivity benefits of moving to the cloud with keeping your data safe, secure and sovereign
- Outage reporting
- The Objective support portal contains a news section that is used to notify customers of unplanned outages. Customers are notified of planned outages via email notifications, product login page updates and the support portal.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Username or password
- Access restrictions in management interfaces and support channels
- Customer access to management interfaces is controlled by assigning users administrator roles. All actions completed by administrators in the system will be recorded in activity logs. Within Objective, access to the system is controlled by the Information Security Management System (ISMS), which is certified to ISO 27001:2013, and associated access policies. Access is provided to authorised persons only and on a need-to-know basis. All user account activity is monitored via centralised logging. Where possible, users are given seperate accounts for administrative purposes.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Objective maintains a single set of global policy documents for ISO 27001: Objective has a comprehensive set of Information Security policies and processes to manage both Quality and Information Security. The ISMS defines Objective Corporation’s general approach to information security, the organisation and structure of the information security management system and generic procedures which apply to interested parties including Objective staff - so that they are clear about their responsibilities and can apply the procedures effectively. The Executive Management Team of Objective Corporation is committed to providing the resources needed to implement the information security management system to ensure data and information is managed appropriately. Objective management team ensures that the Information Security Management System (ISMS) is established, implemented and maintained in a planned and systematic manner. This is accomplished with the appointment of the Chief Information Security Officer (CISO), responsible for the adequate and effective implementation, management and maintenance of the system. In addition to the ISMS policy, a number of additional policies are established, maintained and promoted within the organisation & externally where applicable to our company clients and stakeholders, as part of our commitment to comply with the relevant regulations, acts and statutory requirements as applicable.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- The Objective software development lifecycle and security software development lifecycle ensure a complete record from ideation to deployment is created and maintained. The development lifecycle is validated against the OWASP Application Security Verification Standard. During the early ideation phases, software concepts, application requirements, security requirements and decisions are all captured. Throughout the development and maintenance lifecycle of the product, all decisions are captured and linked directly to source code assets. During the run phase of the service, all support tickets are captured and linked to related decisions, source code assets and deployments.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- As part of measures to ensure the security of our source code Objective undertakes a range of security vulnerability detection and remediation measures. Vulnerabilities can be created or inherited, our software development lifecycle addresses both. Vulnerability assessments leveraging Dynamic Application Security Testing (DAST) and Static Application Security Testing (SAST) are undertaken. In addition, automated and manual penetration testing provides further vulnerability assessment. The third-party risk introduced through open-source libraries is addressed with automated open-source risk scanning for vulnerabilities and licence compliance. Where vulnerabilities are identified, Objective will review and prioritise remediation accordingly.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Objective Corporation maintains and monitors the platform for security incidents 24x7. In addition to comprehensive vulnerability detection, protective monitoring extends to the security of source code which is addressed via: - Code storage and integrity: Objective source code is contained within resilient source code repositories providing code integrity, malware scanning, and integrity protection. - Defect discovery and remediation: Objective leverages automated and manual testing of all applications. Testing occurs at multiple levels within source code as well as functional and operational testing. Incidents are responded to as per the Security Incident Response Plan.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Objective maintains a Security Incident Response Plan as part of our ISO 27001 certification, aligned with the NIST Computer Security Incident Handling Guide (SP 800-61 R2) phases: •Preparation – covers the period prior to an incident and includes the creation of incident response plan, ensures key staff are aware of the plan. •Detection and Analysis – The Security Manager determines the category and required communications. •Containment, eradication and recovery – Contain to prevent further damage, progress to eradicate the incident and recover the impacted systems. •Post-incident activities - Post Incident Reviews are conducted for each Incident, includes root cause analysis.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Scottish Wide Area Network (SWAN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0.1%
- Between £250,000 and £500,000
- 0.1%
- Between £500,001 and £1,000,000
- 0.1%
- Between £1,000,001 and £2,500,000
- 0.1%
- Between £2,500,001 and £5,000,000
- 0.1%
- Over £5,000,001
- 0.1%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- F27c0ed2-6453-45df-9b13-bbbdb6619a8f
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 7900a468-5a3b-4eb5-9b4c-e37f22d7b797
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-