Skip to main content

Help us improve the Digital Marketplace - send your feedback

CFH DOCMAIL LTD

DOCMAIL

As the UK’s leading hybrid mail solution, Docmail streamlines business communications to save you time and money. From desktop letters to automated bulk mailings, we provide a secure, cost-effective platform for sending personalized, consistent, and time-critical documents while ensuring you remain in total control of every delivery.

Features

  • real time reporting and 24/7 MI availability
  • on-demand service available 24/7
  • range of postal options available
  • Choose paper size
  • bespoke messages and logo printing on envelope front

Benefits

  • on demand availability - 24/7
  • UK based, inhouse support availability FREE
  • FAQs and online guidance FREE
  • templates can be changed by customer on demand

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@cfh.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 4 6 0 3 7 8 5 0 9 6 3 9 0 7

Contact

CFH DOCMAIL LTD Jon Marsh
Telephone: 01761416311
Email: tenders@cfh.com

About your service

Service categories

Applications

Content workflow and management

  • Document

Enterprise portals and digital workspaces

  • Multi-Audience Portals
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
No contraints
System requirements
Solution is provided licence free to all users

User support

Email or online ticketing support
Yes
Support response times
With 4 hours during working hours
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
We provide a technical account manager, solution trainer, phone and e-mail support during office working hours.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide the option of online or face to face training for new users. After initial training there is always back up support available from our in house Customer Support Team.
Service documentation
No
End-of-contract data extraction
We only hold user data for 30 days before it is purged from our system. Where templates are uploaded to the user's personal library these can be deleted on demand. We can provide a certificate of destruction for any remaining data or physical data if required.
End-of-contract process
We will provide an exit plan that sets out our procedures for end of contract. At the end of any contract we will work with the buyer to ensure a smooth transition to a new supplier. We will provide day to day support, working with key staff to end the contract efficiently, remove any data and close any portals etc.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
No difference
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
We have a web based interface that works equally well on laptop, computer, tablet or smart phone.
The portal is CFH branded and is user friendly, with tips and hints provided as well as online support if needed.
Accessibility standards
None or don’t know
Description of accessibility
The website is fully responsive and can be accessed on mobile phones, tablets, laptops, and desktop computers. This enables users to access the service using the devices and accessibility tools they are most comfortable with, including built-in screen readers, text-to-speech software, magnification tools, and other assistive applications already configured on their own devices.
Accessibility testing
We have done extensive user acceptance testing and continue to do so as we develop our services further.
API
Yes
What users can and can't do using the API
The API is a SOAP-based webservice allowing the creation, proofing and confirmation of orders for mailings, single letters, postcards and greeting cards.

Documents (PDF, RTF or Word files) are submitted as files or selected by name from your account. Address lists may be selected by name, submitted as a file (CSV, XLS, XLSX, Tab delimited, fixed length fields etc.) or added as individual addresses using the AddAddress call.

A PDF proof approval is available, but is no longer a required step in the process.

Payment is made via Top-Up credit on the customer Account, or for large volume users, payment on invoice may be available (subject to status, volume and regularity of orders).

The API documentation includes an example for creating a mailing with a Visual Studio console application using C# .NET 6.

Examples in the API documentation are based around Microsoft Visual Basic .NET code.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
No

Scaling

Independence of resources
Because the software is our own and it runs on our own servers we can ensure that we always have capacity to scale with demand. We can add bandwidth and resource as needed.

Analytics

Service usage metrics
Yes
Metrics types
Provision of service including volumes, pricing, number of users, number of mail packs, types of service ie first class, economy access mail. Use of colour/mono also duplex/simplex printing.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Through SFTP or HTTPS
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • .txt
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We do our best endeavours to ensure availability. Our rolling availability is over 99.8%. We would discuss this with any buyer and agree a suitable SLA for this.
Approach to resilience
This is available on request.
Outage reporting
Our public dashboard shows a banner in the event of a service outage and key buyers receive emails if requested to alert of outages.

Identity and authentication

User authentication needed
Yes
User authentication
Username or password
Access restrictions in management interfaces and support channels
These are restricted inhouse via access control and administration rights. For our external customers this is through hierarchy tiers, administration rights etc as required by each client.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users receive audit information on a regular basis
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Our InfoSec policies are written in line with our ISO 27001 certification. We provide initial training to all staff during induction relating to our InfoSec policies and this is renewed at least annually. All our Standard Operating Procedures are aligned with our certification and these are reviewed at least annually. Charge Hands and Managers are responsible for ensuring all staff adhere to our SOPs on an ongoing basis.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
CFH manages changes via our inhouse Accord tool. Service components are tracked through their lifetime using an Accord Ticket (parent) and linked Change Requests (CRs). These follow a lifecycle of authorisation, development in a separate environment, peer-to-peer inspection, and final sign-off by a senior authority.

Security impacts are assessed during the approval stage within Accord, where request implications are examined. Additionally, the DPO is consulted to conduct a Data Protection Impact Assessment (DPIA) if a change presents high risks to personal data.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
CFH assesses threats through a formal risk management process that identifies asset-specific vulnerabilities based on their likelihood and impact on confidentiality, integrity, and availability. Potential threat information is gathered from industry trends, customer requirements, and consultations with external engineers or consultants.

Patches are deployed via a controlled Change Management process using the inhouse Accord tool. They are developed in isolated environments and undergo peer-to-peer inspections before a senior technical lead supervises their promotion to the live environment to ensure stability and minimise business disruption.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
CFH identifies compromises by monitoring system non-conformities and security events through our inhouse Accord management tool and SIEM software, tracking deviations such as failed logins or unusual traffic.

When a compromise is found, CFH triggers its Incident Management procedures to triage and contain the threat. Implementation of responses is verified via peer-to-peer inspections.

CFH responds without undue delay, prioritising immediate action to minimise disruption. For personal data breaches, the organization is contractually committed to notifying customers within 12 hours of becoming aware of the incident.
Incident management type
Supplier-defined controls
Incident management approach
CFH manages incidents through a formal framework categorized into Cyber Security, Non-Cyber Security, or Non-Information Security events. Pre-defined procedures guide responses for common events like malware or hardware failure.

Users must report actual or suspected incidents promptly to the Group IT Service Desk via telephone, email, or instant messaging. Reports must include the date, location, and a detailed description. While technical evidence is retained internally, formal notifications are prepared by the DPO for external reporting when regulatory guidelines are met.

We will provide appropriate incident reports, providing all information and details of actions taken and outcomes
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We can provide a limited period or value trial for free if required. This will include availability of all aspects of the service and is not a restricted version.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Saturday 16 December 2023
What the ISO/IEC 27001 doesn’t cover
All parts of this service are covered by this certification.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI
ISO 9001 accreditation date
Friday 30 May 2025
What the ISO 9001 doesn’t cover
All parts of this service are covered by this certification.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Viking Cloud
PCI DSS accreditation date
Monday 24 February 2025
What the PCI DSS doesn’t cover
All parts of this service are covered by this certification.
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
5c51a1f4-1794-4f2e-b4a3-69f319616f33
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
E768349e-720d-4c3f-afc4-b7db63051909
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@cfh.com. Tell them what format you need. It will help if you say what assistive technology you use.