Headzone Emotional Literacy Digital Safety and Ai Education Platform
Headzone is a Saas platform to facilitate the teaching of emotional literacy in RSHE topics in schools, providing early intervention with creative tools like sandplay, lifeline, Ai sessions, self referral, unburdening overwhelmed teachers and helpless parents whilst empowering children to understand themselves and others with empathy, perspective taking and compassion.
Features
- Browser based
- Interactive guided learning for children
- Role based access for relevant user groups
- child led safeguarding referrals to designated safeguarding leads
- Age appropriate UX/UI
- Simple and intuitive onboarding
- Minimal personally identifiable data collection
- Digital sandplay, lifelines, breathing exercises,
- Child tree contribution inner and outer change
- Emoji check in and check out scales
Benefits
- Deliver mandatory RSHE grief education without specialist training
- Reduce unnecessary referrals through upstream interventions
- Early intervention unconscious creative play processing
- Save teacher time with ready-to-use scripted lesson plans
- Build child resilience before crisis through skills-based education
- Allow schools to meet September 2026 statutory grief education requirements
- Protect child privacy with minimal data collection design
- neurodiverse adaptive with multicultural sandplay symbols
- LA and MAT bulk activation, easy schools onboarding
- Built for 26,000 Schools so no child left behind
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 4 3 5 6 4 4 1 1 6 5 3 2 2 1
Contact
HEADZONE
Rukhiya Budden
Telephone: 07720889469
Email: info@headzone.app
About your service
- Service categories
-
Applications
Content workflow and management
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Headzone cannot guarantee full functionality in outdated or non-mainstream browsers. Support will be ensured for the 4 most recent major releases from each major browser vendor. Eg. Apple Safari, Microsoft Edge, Google Chrome, and Mozilla Firefox. Browsers with low market share (such as Opera) will not be supported, however in most cases, it's expected the application would still continue to function without issue.
- System requirements
- Any popular web browser on a desktop or mobile device
User support
- Email or online ticketing support
- Yes
- Support response times
- Same day response during business hours subject to agreed service level agreements.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- None to date, Existing off the shelf solutions to be explored eg intercom.
- Onsite support
- No
- Support levels
-
Support will be limited to users accessing the functionality of the application which will be provided initially by email. As the application develops support will include a ticketing system. Support will initially be provided by a first line technical account manager with an escalation process for issues that need deeper technical investigation.
Support is included with each contract with different service level agreements available where specific response times are required. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
New users will be provided with full onboarding guidance initially with video based introductions presented in a specific flow for new users. This information can be accessed anytime on subsequent visits. Online documentation will be provided to support users with commonly asked questions. This will be updated as feedback is obtained from new users.
As the application develops we intend to use guides provided using walkthrough software which will be subject to user feedback. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Specific classes of data can be exported on request when a contract ends and would be provided in a CSV document format. There is currently no self-extraction capability in the system, however this will be kept under review as the platform develops and user base grows.
- End-of-contract process
- Contract terms will usually be agreed in advance (eg. 12/24 months). In the event of a contract not being renewed the contract owner will be provided with options to close their account. This will include the optional export of data related to their use of the service. This is not expected to provided at additional cost. We don't expect there to be additional off-boarding processes that need to be followed.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The application will use responsive design features to ensure it's accessible on mobile, tablet and desktop devices. The application isn't designed or intended for mobile phone use so there may be limitations based on screen size, but the overall functionality will be the same.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Yes, different user groups will have access to a dashboard to manage their profile and activities. This will include functional menus and visible metrics relevant to the user.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- No testing has been undertaken during the prototyping of this application. Beta testers will be invited to use the application during development and accessibility audits will be undertaken to ensure the relevant minimum AA standards are met.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
-
The application is built on a multi-tenant architecture with each tenant (typically a school) having their own logical isolation of data.
Demand from individual users can be controlled through rate limiting, workload prioritisation, and background job queues to reduce competition for server resource. Our production environment will use elastic, auto-scaling infrastructure to adjust capacity during periods of increased demand, supported by continuous monitoring and alerting. Usage patterns will be regularly reviewed to ensure sufficient capacity is maintained, ensuring consistent performance and availability for all users regardless of overall system load.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Users will be able to request an export of their data which will be available to download in a CSV format.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
99.5% monthly uptime target.
Refunds will be provided on a tiered scale if uptime falls short of this target. 5% credit for 99.0-99.5% availability
10% for 95-99%
25% for 90-95%
50% below 90%
Credits must be claimed within 30 days of the incident.
Planned maintenance will be scheduled outside school hours with a minimum of 5 business days notice. - Approach to resilience
-
The application will be hosted in an AWS data centre who we consider to have taken all reasonable steps to ensure the physical resilience of the infrastructure and operating environment.
A scalable architecture will be used to allow additional resources to be easily added to the hosting environment as usage demands increase. Should the application reach a user threshold (to be determined) we expect to introduce additional redundancy to the infrastructure to avoid potential performance bottlenecks and improve resilience as resource demand fluctuates. - Outage reporting
- A public status page will be provided using a service such as Atlassian Status Page. This will provide alerts and notifications to a DevOps representative who can take appropriate action. As well as investigating the root cause of the issue, this could involve status updates being published on the application website, social media or direct email notifications to customers.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
All users with access to the application will be created with role-based permissions limiting access. Passwords will be encrypted and never sent by email, but through an invitation to create a new password of the users choosing.
Email support will relate to the individual making the support request only and be handled through email initially, with options for live chat to be considered at a later stage. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- Other
- Other security governance standards
- CyberEssentials Plus certificate ID 0014417e-5293-4df8-9ea6-11f3d74ce344
- Information security policies and processes
-
UK GDPR and KCSIE 2024 compliant. TLS 1.3, AES-256 encryption, MFA, RBAC, immutable audit logging, annual penetration testing. UK-only data hosting (AWS London).
Information security policies are enforced through documented procedures, technical controls, and ongoing oversight. Access to systems and data is governed by role based access control (RBAC) and at least privilege principles, with al access and security relevant actions recorded in immutable audit logs. security events, authentication activity and administrative actions are monitored continuously reviewed regularly. Any suspected security incident is assesed promptly, escalated internally, and managed in line with our incident response process, including notification where required under UK GDPR. Vulnerabilities management includes automated dependency monitoring, regular patching and annual penetration testings with findings tracked and remediated accdoding to severity.
Safeguarding and data access roles-reviewed periodically to ensure alignment with KCSIE guidance. Compliance is reviewed at least annually, with policies updated in response to regulatory changes, security findings and or service updates. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- All configuration items will be identified and tracked through version control. Changes will be raised through a formal change/feature request process that will be assessed for risk and potential impact on users and other areas of the application. Changes will be tested and reviewed by a nominated person and deployed using version control. Emergency changes will follow a defined procedure with retrospective review where appropriate.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Headzone undergoes independent security testing through Cyber Essentials plus certification, providing externally validated assurance of our security controls. Additional testing to assess risk based vulnerabilities is planned and monitoring management of threats, code reviews, infrastructure, scanning severity is planned as the platform scales.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- The production version of the application will have continual monitoring for behaviour, errors and security-relevant events using tools such as Sentry.io. This will provide alerts to unusual activity, potential compromises or service degradation. Issues will be triaged and escalated to a DevOps engineer and given a priority determined by risk and impact. Security related incidents will be investigated and resolved in line with change management controls. High risk incidents will be responded to immediately, with all incidents reviewed within 24 hours. A post incident debrief will identify lessons learned and control improvements.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We will have defined incident management processes for events such as service degradation, security alerts and availability issues. Users will also be able to report incidents using designated support channels which will be logged and assessed based on impact and risk severity. Incidents will be triaged by first line support and escalated where appropriate. Updates will be provided to affected users either through the channel issues were reported through, or using a status page. Post incident reports will be reviewed for actions to support continual improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Headzone offers a limited free pre-launch trial ahead of the September 2026 statutory implementation. Trials are provided to a capped number of early-adopter organisations to ensure quality, onboarding support and evaluation and to support implementation readiness prior to full licensing.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 7.5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- C553750b-06f4-491d-ba65-5d4f562b6f0d
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 0014417e-5293-4df8-9ea6-11f3d74ce344
- Other security certifications
- Yes
- Any other security certifications
- Insurance Certificates
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-