Skip to main content

Help us improve the Digital Marketplace - send your feedback

HYPERSPHERIC SOLUTIONS LIMITED

GO 4 Schools MIS

GO 4 Schools MIS is a cloud-based Management Information System (and app) for schools with students from early years to post-16. It includes (but is not limited to) student and staff management, classroom management (attendance, behaviour, assessment, seating plans) census returns, exams management and access for students and parents.

Features

  • Student and staff records management and visibility based on permissions
  • Online markbooks, real-time tracking and analysis linked to accountability measures
  • Attendance recording, management, and analysis to improve safeguarding processes
  • Behaviour recording and analysis with detention and suspension management
  • Homework setting and monitoring, with parent and student mobile app
  • Data rich seating plans to enhance teaching and learning
  • Summative and full-text progress reports published online with read receipts
  • Parental/student access and mobile app with notifications and SMS
  • Exams management including base data and exam seating plans
  • School census, CTF production with statutory returns

Benefits

  • School improvement using real-time data for key decision makers
  • Transparency and accountability across roles in schools
  • Support staff in the classroom with access to key information
  • Support students in the classroom with shared information
  • Improve engagement with those with parental responsibility
  • Save money through time saving and reduction staff workload
  • Improve data security with SSO and GDPR compliance
  • Improve behaviour and attendance through clear policies and data capture
  • Save time – data entry and analysis in one system
  • Up-to-date view of school performance

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at businessadmin@go4schools.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 3 3 7 9 2 6 4 8 7 4 3 4 8 6

Contact

HYPERSPHERIC SOLUTIONS LIMITED Business Administration
Telephone: 01223967556
Email: businessadmin@go4schools.com

About your service

Service categories

Applications

Production and operations

  • Other operations
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Users should use modern, standards-compliant web browsers to access the service.
System requirements
  • Users should use modern, standards-compliant web browsers
  • Users should have a reliable Internet connection
  • Desktop computer users should have devices with 8GB+ RAM

User support

Email or online ticketing support
Yes
Support response times
Tickets are answered Mon-Fri 8am-5pm.
Our average response time for tickets is one hour.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
The support level included in the service costs includes:
* Unlimited use of our library or help articles and videos
* Unlimited use of our in-house support desk ticketing system (manned by our staff of ex school data managers, network managers and other technicians)
* A minimum of 3 months of free telephone support from the start of the service.
* Regular 'health checks' provided by our Education Services Team (who are all ex-senior-leaders or data managers) in the form of phone/video calls. Each customer has a specific member of our Education Services Team allocated to them to allow us to build a long-term relationship so we understand how (and why) the school works as it does and advise them appropriately in these calls.

Schools can purchase extended telephone support for our help desk and/or additional on-site or remote training and consultancy from our Education Services Team. Details of pricing for these can be found in our Pricing document.
Support available to third parties
No

Onboarding and offboarding

Getting started
The most powerful element of the onboarding process is our staff: our Education Services Team (made up of ex-senior-leaders and data managers) and our Technical Support team (made up of staff with ex-data manager, ex-network manager and other technical skills). We understand how schools works and challenges they face.

Each school has a specific Education Services consultant assigned to allow us to build a knowledge of the way the school works, and why. A pre-training call with their consultant is used to assess the optimal initial training plan for the school, e.g. as onsite training or multiple, shorter remote (e.g. Microsoft Teams) sessions.

They can ask follow-up questions through our support system. Where appropriate these may be referred to their consultant.

Initial training is followed with a series of health checks and calls, usually by video. These allow us to identify setup steps that the school may not have completed yet, either through omission or uncertainty, which we can then help them with.

We have a full set of online help pages which include "why" and "how" schools may choose to setup the system in the various ways. These are backed up with short videos from our team of consultants.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Data can be extracted using our API or as CSV downloads.
End-of-contract process
At the end of the contract, customers have the option of a 30-day data extraction period. All but a single main account is disabled, and this account can be used by customers (for 30 days) to extract the data they want.

At the end of this period, the final account is disabled, and their data is then purged from the LIVE service.
Within one month their data is also purged from data backups.

There are no exit costs for them.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
For the web interface, for all users, we use the responsive layout features in modern web standards to automatically adjust the layout of content on devices with smaller screens. There is no loss of functionality.
There is also a mobile app available for students and parents which provides a subset of the functionality available via the web application, but adds the ability for them to receive mobile app notifications.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service can be accessed via the web using modern, standards-compliant web browsers.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We follow accessibility guidelines during development and react to feedback from users. Our related product (GO 4 Schools) which is incorporated into this service has been used by around two million staff, students and parents over the years, and we are not aware of any significant, unresolved accessibility issues.
API
Yes
What users can and can't do using the API
The API allows the following to extract data from the service:
* Customers
* Third-party integrators (whose services integrate with GO 4 Schools directly)
* Integration proxies (whose services provide indirect access to data held in the service)

The service also provides "write-access" for specific data items such as attendance marks, email address, etc.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The service can be customised by schools to suit the way their school works.

This covers areas such as their curriculum and timetable, their behaviour and homework policies and their assessment and tracking policies.

They can also define fine-grained access levels for staff.

They can also customise their data sharing with students and parents, governors and trusts, including the consents they collect from parents, and the styling of the reports they produce for parents.

Scaling

Independence of resources
GO 4 Schools runs in Microsoft's Azure Kubernetes Services environment.

We monitor site performance and resource usage as a matter of course to ensure sufficient resources are available.

For any spikes that occur, we can enlist additional resources as required within minutes using kubernetes' scaling facilities.

Additional resources can be enrolled independently in the following areas
* Network gateway, load balancing and firewall services
* Authentication services
* API services
* Web-front-end services
* Database services

Analytics

Service usage metrics
Yes
Metrics types
System engagement: Date of last usage of the system by each each member of staff, student and parent.

Setup progress: Simple yes/no metrics to indicate whether required simple setup steps have been completed, percentage metrics to indicate progress against multi-step set up steps.

Usage metrics: Numeric metrics to indicate levels of usage of specific features.
Reporting types
  • API access
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
There is a "School Data Service" built in to the service which allows broad, general data sets to be loaded and extracted as CSV, Excel or JSON data.

Most web pages in the service where tabular data is displayed provide the option to download the data as a CSV file.

Customers can also use the API to extract data in JSON format.
Data export formats
  • CSV
  • Other
Other data export formats
JSON
Data import formats
  • CSV
  • Other
Other data import formats
XML

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
Other
Other protection within supplier network
We use MFA to protect our network from intrusion by users, role-based access control to restrict access to subnets containing sensitive data and network security groups in Azure to control network flow between subnets.

Availability and resilience

Guaranteed availability
99.95% over a year, excluding scheduled maintenance.

Service credits are available for service failures exceeding 2 hours. The credits allow the service term to be extended by a duration equivalent to the failure. For example, a failure of 2 hours in a day would lead to an additional 2 hours being added to the licence term. Full details are available in the Terms and Conditions document.
Approach to resilience
We use Azure Kubernetes Services in Microsoft Azure datacentres to provide a solid basis for a resilient infrastructure and platform.

Within this environment, each 'compute resource' has a built-in level of redundancy (i.e. there are multiple 'live' instances of each resource where possible and 'hot spares' where not). The resources for each component are distributed over independent availability zones.

Similarly, storage resources are replicated across availability zones where needed.
Outage reporting
There is a public support service dashboard that users can check for notifications about service status. The dashboard is independent of the service, so is not affected by any service issues.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Most customers opt to use identity federation, but they can use choose to use simple username/password authentication.

After authentication, access is controlled via specific permissions which can be organised into roles. Permissions can be set as "Grant" or "Deny", with "deny" taking priority.

We provide a range of pre-defined built-in roles, but customers can also define their own.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
We take an active approach to security governance.

We have a weekly Security Governance meeting overseen by a board member to assess our security posture and to identify any steps that need to be taken by teams and timescales for delivering them.

We use information drawn from a wide variety of sources, including reports from privileged account usage, penetration tests, firewall logs and automated audits of software installed on devices connected to our network (and any updates they might need to mitigate vulnerabilities).

This is backed up with application of minimum permissions assigned to staff and ongoing staff training.
Information security policies and processes
The information security policies we follow require that:
* There are regular reviews of information security arrangements (which are carried out in our Security Governance meetings), and that prioritised actions are delivered in a timely manner.
* All staff receive appropriate training to understand information security requirement and that they report any concerns they might have.

The information security processes we follow impose strict technical controls on the way we work as a company, including:
* Staff are provided with the minimum level of access required to perform their duties
* All use of privileged accounts is logged for accountability.
* The company network can be accessed only by company staff using company devices who have been authenticated with multi-factor authentication. All communication with the company network is encrypted. Devices in need of critical security updates are blocked until the updates have been applied.
* All data is stored centrally to ensure access can be easily revoked if necessary
* All computer disks are encrypted
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We use git to manage change tracking and version control for our software components and their configuration. We use a 2-peer review process within our software development for all changes. Once changes have passed peer review, they are tested by our independent QA team on a staging environment before being released to the production environment. This testing includes security checks.

All changes to our infrastructure and platform components (I.e. Microsoft Azure) are logged through Azure.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We use a variety of methods to identify potential vulnerabilities:
* Our baseline is that operating system and application security updates are applied to company devices within 14 days.
* This is backed up with automated audits of software on company devices. This is checked against the industry-standard CVE (security vulnerability) database to identify known issues. We take remedial actions within 14 days, or faster if there is a known exploit for a vulnerability; we are notified immediately if this situation arises.
* We run automated penetration tests

We review these reports produced by these processes weekly
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Logs are collated in real time into a central location. The logs include page access logs, authentication logs, application logs and system logs. As logs are ingested, automated rules check for known suspicious patterns.

Metrics are also collated in real time into a central location. The metrics include network traffic volumes, user session volumes, error rates, etc. As metrics are ingested, automated rules check for known unusual patterns.

Where patterns need investigating, an alert is sent to the appropriate team who can query and filter the underlying logs and metrics. This usually happens within minutes
Incident management type
Supplier-defined controls
Incident management approach
We have work-instructions prepared to enable our staff to respond quickly to events that are 'anticipatable', including compromised user accounts for staff member of customers and unusual network traffic from specific IP addresses.

Known users can report incidents or potential incidents via our Support Desk, via email or by phone.

We are transparent about incidents. Non-reportable incidents would be communicated to affected customers with as much useful detail as possible, and reportable incidents would be reported to the Information Commissioner's Office.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
10%
Between £250,000 and £500,000
15%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
17.5%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
C2af8298-1e55-4ccf-8b09-f0a2969ded67
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at businessadmin@go4schools.com. Tell them what format you need. It will help if you say what assistive technology you use.