Broadcast
Broadcast is a secure, UK-hosted file transfer system that enables local authorities and education establishments to safely collect, share and automate/streamline file collection, distribute and manage sensitive education files. A GDPR-compliant alternative to email file sharing, with targeted file requests, controlled access, encryption, search, filtering and audit logging.
Features
- Secure file distribution to schools and other education settings.
- Automated file requests with deadlines and role targeting.
- Centralised file management dashboard with filtering and search.
- Intelligent ZIP distribution auto-matching files to schools.
- Confidential file delivery to named users.
- Full audit trail for all files and interactions.
- Secure file returns from schools to local authorities.
- Built-in permissions and optional two-factor authentication.
- Integrated with Nexus platform for NCER local authorities.
- Free Perspective Lite access for all connected schools.
Benefits
- Saves significant administrative time for local authority teams.
- Reduces manual handling and email-based file transfers.
- Improves data security and GDPR compliance.
- Ensures correct information reaches the right people.
- Strengthens accountability through full audit trails.
- Speeds up communication between authorities and schools.
- Minimises errors caused by manual file distribution.
- Improves visibility across file requests and returns.
- Enhances collaboration between schools and local authorities.
- Delivers faster, safer and more efficient document workflows.
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 3 2 4 8 9 8 3 0 1 6 4 1 9 0
Contact
ANGEL SOLUTIONS LTD
Angel Procurement Team
Telephone: 08458330933
Email: procurement@angelsolutions.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
- Document
Content services
- Content Sharing and Collaboration Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Nexus is a powerful online system that enables local authorities to analyse and report on all primary and secondary assessment data, from EYFSP to Key Stage 5. Nexus also supports vulnerable children with comprehensive reporting on Looked after Children, Children in Need, Children with an EHCP, absence and exclusions.
- Cloud deployment model
- Private cloud
- Service constraints
- The service may be unavailable for short, planned maintenance periods to deploy new features, apply security updates, or carry out essential maintenance. Planned maintenance is scheduled in advance, and customers are notified ahead of time. Maintenance activities are designed to minimise disruption.
- System requirements
-
- Internet Access
- Modern, standards-compliant Web Browser
- Appropriate endpoint security controls, such as an up-to-date anti-virus
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is available Monday–Friday (UK business hours). Our standard first-response SLA is 48 hours. Our average first response time is approximately 5 hours.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support is provided as part of the standard Broadcast licence and is included in the overall licence cost.
Our support model is structured as follows:
• First-line support:
Customers have access to a dedicated first-line support desk during Monday–Friday UK business hours. This team handles the majority of queries, including usage questions, guidance, troubleshooting, and standard issue resolution.
• Technical support escalation:
Where required, issues are escalated from first-line support to specialist technical staff for further investigation and resolution.
• Developer escalation (as needed):
For complex, urgent, or product-level issues, support tickets may be escalated to our development teams. Developers are not customer-facing but work closely with support to diagnose and resolve underlying issues. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
We support users to start using Broadcast quickly and confidently through a structured, flexible onboarding approach.
Each customer is provided with a clear implementation plan and an assigned account manager who acts as a consistent point of contact throughout onboarding and beyond. We deliver scheduled online training sessions tailored to user roles, with optional chargeable onsite training available where appropriate. These sessions focus on real use cases to help users achieve value from day one. To build confidence before launch, we also provide test accounts that let users safely practice using the system and explore key functionality before going live.
Broadcast includes built-in help guides and clearly signposted support within the product, enabling users to access assistance at the point of need. Short “how-to” videos and comprehensive online user documentation are available for self-service learning and refresher training.
Following onboarding, we send follow-up emails outlining next steps, offering helpful tips, and providing additional resources to reinforce learning and encourage wider adoption. Ongoing support is available via our helpdesk and account management team, ensuring users continue to use the service effectively as their needs evolve. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- DOCX
- End-of-contract data extraction
-
Users can extract their data directly through the service while the contract is active, subject to their permissions, by downloading and exporting documents and files using the standard user interface.
Once the contract has ended, access to the service is removed. If the customer requires a copy of their data after termination, they must submit a written request within 10 days of the termination. Provided all outstanding charges have been settled, Angel Solutions will supply a copy of their data within a reasonable timeframe. - End-of-contract process
-
At the end of the contract, access to the service ends and the customer’s right to use the software and associated services ceases. Any undisputed fees owed up to the termination date must be paid. Termination does not affect any rights or obligations that have already accrued, and any clauses intended to continue after termination, such as confidentiality, remain in force.
The subscription price includes use of the software for the contract term, hosting, standard support, routine maintenance, and planned updates. It also includes retention of customer data during the contract and standard backup processes as part of the live service.
Following termination, Angel Solutions may securely delete customer data unless the customer makes a written request for a copy of the most recent backup within ten days of contract end. Where such a request is made and all outstanding charges have been settled, Angel Solutions will use reasonable commercial efforts to provide the data within 30 days.
Any work beyond the standard service is chargeable. This includes data extraction or return, bespoke support related to offboarding, or handling and disposal of customer data beyond normal processes. All reasonable costs associated with these activities are payable by the customer. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Documentation is available online compliant with WCAG 2.1 AA.
For further details please visit https://www.zendesk.co.uk/company/agreements-and-terms/accessibility/
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Broadcast supports modern mobile browsers and is built to adapt to smaller screens. Core functionality remains available on phones and tablets, including viewing content, searching, and basic interactions.
For more data-driven and complex screens, the mobile view is refined and simplified, using graceful degradation where needed to ensure it remains clear and usable. More advanced configuration and management views are better suited to desktop, where there is more screen space and context. - Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is accessed through a secure, browser-based web interface. Users authenticate using their assigned accounts and access features based on role-based permissions. The interface allows authorised users to distribute, receive, and manage documents and related communications. No client-side software installation is required, and the service is accessed over standard internet connections using HTTPS.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
While the service is not currently certified against a formal accessibility standard, it is designed to be usable and practical for a wide range of users.
The interface uses clear layouts, consistent navigation, readable text, and straightforward interactions. It is built using semantically correct markup where possible, helping ensure content is structured logically and behaves predictably across browsers and devices.
The service supports keyboard navigation for most core actions and avoids unnecessary complexity. Where limitations exist, users can still complete key tasks through alternative views or on desktop devices, ensuring they are not blocked from using the service. - Accessibility testing
- No formal interface testing has been carried out with users of assistive technology, as this has not previously been a requirement for the service. Accessibility considerations are reviewed as part of general interface design and ongoing development, and user feedback is welcome.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- The service is designed as a multi-tenant SaaS with logical separation between customers. Usage is monitored and managed to ensure fair and reliable access for all users. While no shared service can offer a guarantee, the platform is operated to minimise contention and maintain consistent performance across tenants. We provide support and incident response for any performance issues.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
User Logins
File Access Logs
File Collection Statistics
Dashboards with Analytics - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Data is stored on enterprise storage systems with built-in encryption at rest using AES-256. Encryption is enabled by default at the hardware level, cannot be disabled, and is FIPS 140-2 compliant. Physical access to storage infrastructure is restricted and controlled within the hosting environment.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Data can be accessed and exported by authorised users through the standard user interface while the contract is active, subject to permissions. There is no separate bulk export or automated export mechanism. Following contract termination, customers may request a copy of their data in line with the contract terms, which is provided as a one-off export by the supplier.
- Data export formats
- Other
- Other data export formats
- XLSX
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- ZIP
- All commonly supported file types
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Traffic between users and the service is encrypted using TLS version 1.2 or above. TLS termination is performed at the network boundary, with internal network traffic protected by private network controls.
Availability and resilience
- Guaranteed availability
- Within reasonable commercial endeavours, the software is available 24 hours a day, seven days a week, except during planned maintenance of the Software.
- Approach to resilience
-
The service is hosted in UK-based data centres and is designed for high availability and operational resilience. The hosting environment includes redundant power, cooling, and network connectivity, with no single point of failure. Network connectivity is provided through multiple redundant internet connections with automatic failover.
The service uses redundant infrastructure components, including load balancers, firewalls, application servers, and storage systems with automated failover. Databases are deployed using SQL Server Always On Availability Groups to maintain availability in the event of component failure. Data is backed up regularly, with copies stored separately to support recovery. Resilience arrangements and detailed architecture information are available on request. - Outage reporting
- Customers are notified by email of planned maintenance in advance. In the event of an unplanned outage, customers are informed by email as soon as reasonably practicable, with further updates provided where appropriate until the service is restored.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces within the service is restricted through role-based permissions and granted on a least-privilege basis. Customer administrators can manage users and permissions within their own organisation only and cannot access data or settings belonging to other customers. Customers do not have access to internal management or support systems. Internal management and support interfaces are restricted to authorised staff using role-based access controls. Support channels are limited to authenticated users and named customer contacts, and access is controlled to prevent unauthorised use.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
Angel Solutions operates under a mature, formally governed Information Security Management System aligned with ISO 27001:2022, for which we are fully certified. This framework underpins all our security policies, risk‑management practices, and operational controls, ensuring that information security is embedded into every aspect of our service delivery.
In addition, we maintain Cyber Essentials Plus certification, which independently validates the effectiveness of our technical controls across areas such as secure configuration, access management, malware protection, patching, and boundary defences. The combination of ISO 27001:2022 and Cyber Essentials Plus ensures that we follow robust, audited processes covering governance, risk assessment, incident management, supplier oversight, asset protection, and continuous improvement.
Together, these certifications demonstrate our commitment to maintaining a secure environment, protecting client data, and adhering to industry‑recognised best practices. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Configuration and change management for the service is handled through internal processes. Service components, including application code, configuration, and infrastructure, are tracked throughout their lifecycle from development through deployment, maintenance, and retirement. Changes are logged and versioned so the service's current state can be identified at any time.
All changes are assessed before deployment to understand scope, risk, and potential impact. This includes security considerations such as access control, data handling, availability, and potential vulnerabilities. Changes are reviewed, approved, and tested before release. Expedited changes follow an accelerated approval and testing process, but are still reviewed before deployment. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management is handled through defined internal processes. Potential threats are assessed by reviewing security advisories, monitoring the service, and evaluating the impact on confidentiality, integrity, and availability. Information on vulnerabilities is obtained from software and infrastructure vendors, security advisories, and publicly available vulnerability databases. Security patches are prioritised based on risk and severity. High- or critical-vulnerability fixes are addressed as a priority following assessment and testing, while lower-risk updates are applied through planned maintenance. All security changes are reviewed and tested before deployment to reduce the risk of introducing further issues.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is carried out through routine monitoring of systems, logs, and service behaviour to identify unusual activity or indicators of compromise. Potential issues are identified through alerts, log review, and investigation of abnormal performance or access patterns. When a potential compromise is identified, it is investigated promptly to confirm impact and scope, and appropriate containment and remediation actions are taken. Incidents are responded to as soon as practicable based on severity, with priority given to issues that may affect service availability, data security, or customer access.
- Incident management type
- Supplier-defined controls
- Incident management approach
- If an incident is reported by a customer or identified internally, it is triaged through defined internal processes. Incidents are assessed for impact and severity and escalated to technical specialists as required. Customers are kept informed via their support ticket, and where incidents affect multiple customers or represent a wider outage, proactive communications are issued. Incident details, actions taken, and resolutions are recorded in the support system, and incident reports are provided to customers where appropriate. Data protection incidents are managed in line with legal and regulatory obligations, including notification where required.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 2%
- Between £2,500,001 and £5,000,000
- 2%
- Over £5,000,001
- 2%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Thursday 31 May 2018
- What the ISO/IEC 27001 doesn’t cover
-
The ISO/IEC 27001 certification scope covers the entire organisation and all services provided.
The ISO/IEC 27001 certification does not cover customer-controlled environments, including customer infrastructure, networks, and end-user devices. Security controls within these environments are the responsibility of the customer and fall outside our ISMS scope. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 3de4cc80-efb9-4379-9073-2c51cf54bce3
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 087fae39-3e13-481e-85fe-cd15c189dfbb
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-