Digital MODULAR Workplace Adjustment System
Empowers employers to attain inclusion excellence and interaction via specific, focused, solutions for those with disabilities and other barriers to performance in workplace environments.
The platform, accessed via a discrete Referral Form in Azure, facilitates monitoring progress, impact on absence, performance and other metrics. Generates tailored outputs of Management Information.
Features
- Wellbeing and disability management in the workplace
- Configurable workflow, documentation and reporting
- User-Centric workflow system, step by step task guidance
- Volumetric data-based insights on agreed metrics
- Tracking of all communications, related to cases
- Notifications via email and SMS to managers and others
- Goods Supply: Provides input to related procurement/supply/HR systems
Benefits
- Offers specific parts of our service, filling buyer provision gaps
- Improves engagement for those with disabilities and line-managers
- Facilitates the improvement of employee health and wellbeing
- Provides specific support for specific problems
- Assists improvement and engagement
- Supports disability-related suppliers/supply chains
- Facilitates ratings & QA for providers of workplace adjustment services
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 2 7 8 0 0 4 9 2 0 1 9 1 0 3
Contact
MICROLINK PC (UK) LIMITED
Hazel Knights
Telephone: 02380240300
Email: sam@microlinkpc.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No service constraints - the platform configures extensively and has multiple integration options.
- System requirements
- Late-release internet browser
User support
- Email or online ticketing support
- Yes
- Support response times
-
Response within 2 hours, Monday- Friday 09:00 - 17:00 (UK time)
There is no support available outside normal working hours - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support Levels:
The nature of support supplied depends directly on which part or parts of our whole service the Buyer wishes to acquire, but generally:
1. Online or telephone support for each case
2. Account Manager support for client stakeholders
3. End User technical support – installation of adjustments (where supply of goods is selected)
4. End User technical support – post installation of hardware or software
5. Organisational technical support
Cost of Support:
1. Included
2. Included
3. Included
4. £55/hour
5. £125/hour
We do not supply a separate or dedicated technical account manager or cloud support engineer. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Implementation is project-driven, starting with requirements gathering via web session or in-person, and then managed via project team between Microlink and the Buyer involving all relevant stakeholders. Onsite and online training is packaged as part of the project and tailored to specific requirements. Onboarding is delivered through a dedicated Onboarding Team. Training is delivered via webinars to build knowledge of how the system works and expand the Buyer's Disability Confidence in making use of the system.
- Service documentation
- No
- End-of-contract data extraction
- Under this system personal data is obtained directly from data subjects by direct informed and transparent consent at the very outset of each case. Microlink acts as a Data Controller in relation to that personal data. There is no Buyer Data on the system save for incidental Business Card contact data of stakeholders within the Buyer with whom Microlink deals in the course of delivering the services and implementing recommended adjustments. Data Subject rights to access or delete data operate under and in full compliance with Data Protection Legislation. Any residual Buyer Data can be returned to the Buyer at the end of the contract in such format as may be agreed (usually as a .csv file).
- End-of-contract process
- Upon end/termination of contracts, user accounts, are automatically de-activated and the user is notified via email or other means as selected by the user. Any user-specific application data within the platform (note this excludes personal/sensitive data held by Microlink as a Data Controller) will only be retained in accordance with our data retention policy to facilitate any specific requirements for extraction of data.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The layout of the user interface adapts depending on the screen size utilised by the end user. Accordingly, it does not matter whether an end user is using a desktop or any other mobile device, be it tablet or smartphone.
The Portal uses bootstrap responsive design function remains the same across device types. Differences would include layout only to ensure good user experience and follow best practices. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
The interface is a Customer Portal accessed by an individual customer employee seeking assistance. Access is via username and password and can be configured for SSO. The customer employee inputs basic data into the Portal which creates a Case. Case creation enables a Case Advisor to contact the customer employee.
All communication takes place, and documents are managed through the Portal. The Portal is pre-configured to meet accessibility requirements.
Managers can also be afforded access to view the status of cases for employees for whom they are responsible. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- By reason of the nature of its business in providing workplace adjustments Microlink has access to all assistive software and its own Digital Accessibility department. We use a full range of these applications to conduct accessibility testing on our systems and documentation.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Microlink utilises and configures our environments within Microsoft Azure and has designed the service automatically to allocate additional resources depending on demand. Microlink also makes use of Azure’s Web Application Firewalls and monitoring tools to detect Distributed Denial of Service and respond appropriately.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- The Customer Portal is expressly configured to allow for the end-user to store their workplace adjustment documentation there. This can be downloaded by that end-user to their own system at any time.
- Data export formats
-
- CSV
- Other
- Other data export formats
- As agreed with the Buyer in any Exit Plan
- Data import formats
- Other
- Other data import formats
- Direct input
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Service uptime >99% if there is planned maintenance that can affect this it is arranged in advance and usually done outside of operating hours. We scope for RPO 1 hour as we backup hourly and RTO 2 hours in disaster event.
- Approach to resilience
-
Resilience is underwritten by our service provider, Microsoft Azure.
Azure provides independent availability zones (AZ) so if one fails the others remain operational currently our setup spans 2 or 3 different AZ depending on the resource and the fault tolerance requirements, geo-redundancy is planned but not yet available. - Outage reporting
-
Any outage is reported by dynamic email alerting. Outage alerts are sent to pre-registered user(s) at the client by the Microlink IT support desk.
The service itself is monitored via external services every minute and alerts are sent to IT staff immediately if an issue is detected.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Other user authentication
- External users can access the service via one of two methods – either username and password authentication but we cannot enforce MFA in this case we prefer they use SSO instead which delegates identity management and means they can enforce their own requirements on password complexity and MFA – SSO supports common protocols and IdP’s.
- Access restrictions in management interfaces and support channels
- We implement comprehensive access control policies, defining and restricting who can access data based on their role and the necessity of access. These policies are enforced through robust authentication and authorisation mechanisms, including multi-factor authentication and the principle of least privilege. Regular audits and compliance checks are conducted to ensure that logical segregation controls are effectively implemented and maintained. These audits also help identify potential vulnerabilities and enforce continuous improvement in our security posture. Continuous monitoring and logging of access and activities related to client data help in detecting and responding to potential security incidents promptly.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Description of management access authentication
-
Internal users are authenticated via EntraID (the IdP) and Auth0 (the SSO provider) in this case our IdP manages the identities and enforces our policies of password complexity and MFA.
For External users a one-size-fits-all solution it is not possible as some will not have SSO available or use different IdP’s. If they choose not to use SSO, we offer the option of password and username with recommendation they use an MFA as well such as an OTP authenticator, the responsibility is delegated to them as it is their account.
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Microlink is ISO 27001:2022 certified and maintains information security policies accordingly. This includes the Business Management System Manual, which details the scope, the objectives, the responsibilities and the risk rating and management, as well as the mobile device policy, clear desk, access, teleworking and encryption management policy. Several other policies are also in force, including Change and Release procedure, document retention policy, incident management procedure, information classification and handling policy and the physical security policy. Finally, Microlink maintains a detailed Risk Register for logging of events and triggering any preventative/remedial measures. There is a documented escalation path from operator level right through to our board with dynamic stakeholder alerting at each level.
All of these policies and procedures are subject to independent external review at least once a year, and also the subject of annual audit by many of our corporate clients. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Microlink utilises an internal proprietary change management system and tracks all changes within our case management system. This system ensures that the change and justification for the change and impacted areas including potential security impacts are recorded. Once a change has been defined the system facilitates getting approval signed by all the owners of the impacted areas. Once a review is approved by a member of the Executive Board it is implemented on a staging environment for review and once it meets acceptance criteria, it is deployed to production.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Through Microsoft Azure we have a number of systems in place including automated container vulnerability scanning, monthly patching of servers, and penetration testing of the service. We apply security patches as soon as they are available. Our approach focuses on maintaining system integrity through timely updates and monitoring rather than structured threat modelling.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Microlink utilises testing tools - static application security, dynamic application security, and human led testing comprising manual security tests and penetration testing to identify potential compromises. When discovered, the compromise is recorded, and impact measured so it can be categorised appropriately: Info / None, Low, Medium, High, Critical.
We aim to respond to incidents quickly based on severity/impact. Our process includes immediate acknowledgment upon detection and prioritisation according to our internal incident management workflow. While we do not commit to fixed SLAs, our goal is to begin investigation promptly and apply fixes as soon as practical to minimise disruption. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Microlink utilises an incident management system, that allows any staff to report and record incidents as and when they occur. This process ensures appropriate recording and remediation of incidents is performed. Incidents are actively monitored and allow Microlink to record new controls and risks within our risk register.
Incidents that affect our buyers are communicated directly to the buyer from the buyer’s Account Manager.
Escalation Based on Severity
Low: Logged for reference, monitored for patterns, closed after documentation.
Medium: Assigned to the security team for investigation and remediation.
High: Immediate escalation to the IT Teams, management, and possibly legal/compliance teams. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 7.5%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Wednesday 9 July 2025
- What the ISO/IEC 27001 doesn’t cover
- Due to the nature of the services we provided, data masking or anonymisation is not possible, so it is not covered by our certification. We can provide a redacted version of our SOA for ISO27001 showing all the sections covered.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- NQA
- ISO 9001 accreditation date
- Monday 18 December 2023
- What the ISO 9001 doesn’t cover
- Nothing. Everything is covered.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 3646e13c-d7dc-42b3-a7ed-07a5814cc080
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 80f895cd-7070-464a-98f1-307a7c616c2f
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-