Skip to main content

Help us improve the Digital Marketplace - send your feedback

  1. Digital Marketplace
  2. Lot 2: Cloud software
  3. UserZoom


UserZoom is an all-in-one UX Insights Solution that includes platform, recruitment and professional services. It is used to provide in-depth quantitative and qualitative insights to understand, measure and improve digital experiences. We help product managers, researchers, marketers and UX designers scale their capabilities to rapidly improve digital experiences.


  • Cloud based solution - Remote access
  • Remote moderated requiring no browser extension
  • Remote unmoderated testing capabilites
  • Intercept survey on web/app
  • Video Session Replay
  • Think-out-loud feedback with transcriptions
  • Heatmaps, Clickstreams, Card sorting, Tree Testing, Surveys
  • Data Export Function into Microsoft Office Suite & SPSS
  • Real time reporting
  • Automated dashboards


  • Test UX & CX across desktop, mobile/tablet (iOS & Android)
  • Combine Qualitative & Quantitative Data
  • Statistically significant data
  • Test without geographical restrictions
  • Participant sourcing services
  • Professional Services / research projects delivered by UX experts
  • Obtain core Usability Metrics: Effectiveness, Efficiency, Satisfaction
  • Remote Moderated and Unmoderated testing
  • Research support, advice and training
  • All-in-one Research Solution with multiple methods


£31,500 a licence a year

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at Tell them what format you need. It will help if you say what assistive technology you use.


G-Cloud 13

Service ID

4 4 0 5 5 7 3 7 4 5 3 7 9 1 3


Telephone: 07795 110 232

Service scope

Software add-on or extension
Cloud deployment model
Public cloud
Service constraints
Video Session replay is limited to Chrome and Firefox,
Mobile tests are limited to iOS and Android
System requirements
  • Browser plug-in download required on desktop for Video Session Replay
  • Java Script code required to run live intercept surveys
  • Mobile app download required for Video Session Replay on Mobile

User support

Email or online ticketing support
Email or online ticketing
Support response times
Priority Critical /Emergency <15 minutes ; High <30 minutes; Medium< 1hour; Low<2 Hours

Responses (unless highly critical) will only be answered during weekdays
User can manage status and priority of support tickets
Online ticketing support accessibility
None or don’t know
Phone support
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Web chat
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
User must be logged-in to start a chat using the following URL:
Web chat accessibility testing
N/A. UserZoom only offers regular chat support.
Onsite support
Onsite support
Support levels
Service desk
Live chat

We provide an account manager, research partner and technical support.
Support available to third parties

Onboarding and offboarding

Getting started
Each user will have access to the UserZoom Academy. This includes over 30 on-demand videos designed to help our customers master the platform and develop research skills. It also includes live instructor-led classes as well as quick start videos to rapidly learn specific methods aimed at supporting designers, product owners, copywriters, researchers, marketers, UX and content specialists.

As well as the Academy there is a range of paid-for enablement options designed to support each level of maturity. These can include consultations with UserZoom experts through to change management programs to help teams manage research democratisation, build templates and processes, measurement and benchmarking and maturity mapping.
Service documentation
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
The Self-Service Solution includes a feature that allows users to download Customer Content and Study Content at any time during the Term. UserZoom will retain Customer Content and Study Content for 90 days after termination (the “Retention Period”) and, upon Customer’s written request during this Retention Period, will deliver Customer Content and Study Content to Customer.
End-of-contract process
Users will choose to terminate the contract or renew for another annual period.

Using the service

Web browser interface
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Designed for use on mobile devices
Differences between the mobile and desktop service
The mobile app lets study participants to perform studies/surveys with a greater user experience rather than the regular website.
Service interface
User support accessibility
None or don’t know
Customisation available
Description of customisation
UserZoom manager portal lets account administrators to fully customise their study settings. Also colours, logos, style designs can be changed. Professional services are also available for additional customisations.


Independence of resources
The Provider guarantees system availability for the components under its operational responsibility. The guaranteed system availability is 99.5% / year. The guaranteed availability refers to the production environment only.


Service usage metrics
Metrics types
> Number of studies launched in UserZoom
> Number of support tickets raised and resolved
> Number of participants tested with within a year
Reporting types
Reports on request


Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with SSAE-16 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Data sanitisation type
Explicit overwriting of storage before reallocation
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
The Analytics (results) page includes an option that allows users several exporting options, including excel or word
Data export formats
  • CSV
  • Other
Other data export formats
  • Word
  • Powerpoint
  • Spss
Data import formats
Other data import formats
Not applicable

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Guaranteed system availability is 99.95% / year.
Full refunds apply for breach of SLA.
Approach to resilience
This is available on request
Outage reporting
Email alerts, CSM phone calls

Identity and authentication

User authentication needed
User authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to the Userzoom Platform is performed using username/password credentials. Multi-Factor Authentication (MFA) is available for its configuration (and enforcement by administrators) for any user in the Platform. In addition, Single Sign-On access is also available through SAML 2.0 and other major standards.
Access to Userzoom accounts can be restricted to be only possible from certain IP addresses.
Access restriction testing frequency
At least once a year
Management access authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Standards and certifications

ISO/IEC 27001 certification
Who accredited the ISO/IEC 27001
ISO/IEC 27001 accreditation date
21/10/2018 and 11/11/2016
What the ISO/IEC 27001 doesn’t cover
ISO27001 certificate is only issued for our data centre (Rackspace and Amazon Web Services)
ISO 28000:2007 certification
CSA STAR certification
CSA STAR accreditation date
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
PCI certification
Cyber essentials
Cyber essentials plus
Other security certifications
Any other security certifications
  • SOC2 Type II
  • TrustArc Privacy certification
  • COPPA certification by Privo

Security governance

Named board-level person responsible for service security
Security governance certified
Security governance standards
Other security governance standards
SSAE 16 (SOC2 Type II)
Information security policies and processes
This is the table of contents of the UserZoom Information Security Policy:

Information Obsolescence
UserZoom information security
Information Classification
Password Policies and Requirements
Employee Policies, Access Control and Data Management
Change Management
Data Segregation
Security Incident Response and Risk Management
Risk Assessment methodology
Incident Handling
Data Leak/Loss
Notification / Response
Data Protection Officer (DPO)
Q&A (Quality Assurance)
Background / Configuration Control
Code Reviews
Automated Testing
Deployment Scheduling / Preproduction UsageTicketing
Baseline Configuration (Hardening)
Change Request Procedures
Configuration Scheduling
Configuration changes first steps
Application Changes
Change Notification / Follow up

Operational security

Configuration and change management standard
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach
All changes that are to be performed in the Production Environment can only be executed by Senior Management. All code changes are reviewed by at least 2 engineers and one of the VPs of Engineering before being pushed to Production. The Security Team is directly involved in the development lifecycle and collaborates daily with the R&D Team to ensure that all new developments are in line with industry best practices and Userzoom's internal policies.
Vulnerability management type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach
Vulnerability information is obtained from third-party services and systems are examined for known
vulnerabilities and recommend actions.
The scheduling plan deals with critical security and functionality patches. This plan helps Userzoom deal with the prioritisation and scheduling of updates, by their nature, must be deployed in a more immediate fashion. They are applied almost immediately depending on severity following the full change management. Once a patch has been determined valid, it is typically placed in a test environment. The test environment mirrors production as closely as possible.
All critical security patches are installed within 30 days of vendor release
Protective monitoring type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach
As a key part of the configuration and change management, UserZoom performs internal audits and vulnerability assessments every 30 days. If any kind of vulnerability that may affect UserZoom systems is detected, it gets patched following the internal procedure. Once the patch has been applied and the issue has been remediated, additional scans are performed immediately. UserZoom maintains a log of all patches applied to systems
Incident management type
Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach
Userzoom has a complete incident management policy available upon request. It contains details around incident reporting categorisation and handling. It also addresses the procedure to deal with a potential data breach and defines the steps to take both from a technical and compliance perspective.

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Public sector networks

Connection to public sector networks

Social Value

Covid-19 recovery

Covid-19 recovery

UserZoom has a COVID committee which regularly reviews ongoing changes and ensures the business has the right measures in place to best support our employees.
Tackling economic inequality

Tackling economic inequality

Currently under review
Equal opportunity

Equal opportunity

UserZoom is an equal opportunity employer. We do not unlawfully discriminate in employment opportunities or practices on the basis of gender, race, colour, religion, age, citizenship, sexual orientation, gender identity, gender expression, marital status, pregnancy, national origin, ancestry, physical or mental disability or condition, or any other protected class under applicable federal, state, or local laws. We also prohibit unlawful discrimination based on the perception that anyone has any of those characteristics or is associated with a person who has or
is perceived as having any of those characteristics.


We are People First and it is our goal to be a world-class place to work. We know that to feel great, perform at our best and achieve success, we must first take care of ourselves. We are committed to improving the health and wellbeing of our people and we aim to make this accessible to everyone globally through the UZ Be program.

Wellbeing is a journey where we make choices towards a healthy and happy state of being. It doesn’t matter where we start on our wellbeing journey, it’s more important that we are headed in the right direction. The UZ Be Cycle is our holistic approach and focuses on four pillars that represent positive actions to support us on this journey. The four pillars are move, connect, nourish and thrive.

We gain insights from the UserZoom by proactively seeking feedback on wellbeing events and initiatives.


£31,500 a licence a year
Discount for educational organisations
Free trial available
Description of free trial
We offer a time-limited period focused on orientating the platform with UserZooms support. This is focused on establishing the value of UserZoom and the partnership potential of working together,

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at Tell them what format you need. It will help if you say what assistive technology you use.