DOCMAIL
As the UK’s leading hybrid mail solution, Docmail streamlines business communications to save you time and money. From desktop letters to automated bulk mailings, we provide a secure, cost-effective platform for sending personalized, consistent, and time-critical documents while ensuring you remain in total control of every delivery.
Features
- real time reporting and 24/7 MI availability
- on-demand service available 24/7
- range of postal options available
- Choose paper size
- bespoke messages and logo printing on envelope front
Benefits
- on demand availability - 24/7
- UK based, inhouse support availability FREE
- FAQs and online guidance FREE
- templates can be changed by customer on demand
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 4 6 0 3 7 8 5 0 9 6 3 9 0 7
Contact
CFH DOCMAIL LTD
Jon Marsh
Telephone: 01761416311
Email: tenders@cfh.com
About your service
- Service categories
-
Applications
Content workflow and management
- Document
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- No contraints
- System requirements
- Solution is provided licence free to all users
User support
- Email or online ticketing support
- Yes
- Support response times
- With 4 hours during working hours
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
- We provide a technical account manager, solution trainer, phone and e-mail support during office working hours.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide the option of online or face to face training for new users. After initial training there is always back up support available from our in house Customer Support Team.
- Service documentation
- No
- End-of-contract data extraction
- We only hold user data for 30 days before it is purged from our system. Where templates are uploaded to the user's personal library these can be deleted on demand. We can provide a certificate of destruction for any remaining data or physical data if required.
- End-of-contract process
- We will provide an exit plan that sets out our procedures for end of contract. At the end of any contract we will work with the buyer to ensure a smooth transition to a new supplier. We will provide day to day support, working with key staff to end the contract efficiently, remove any data and close any portals etc.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- No difference
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
We have a web based interface that works equally well on laptop, computer, tablet or smart phone.
The portal is CFH branded and is user friendly, with tips and hints provided as well as online support if needed. - Accessibility standards
- None or don’t know
- Description of accessibility
- The website is fully responsive and can be accessed on mobile phones, tablets, laptops, and desktop computers. This enables users to access the service using the devices and accessibility tools they are most comfortable with, including built-in screen readers, text-to-speech software, magnification tools, and other assistive applications already configured on their own devices.
- Accessibility testing
- We have done extensive user acceptance testing and continue to do so as we develop our services further.
- API
- Yes
- What users can and can't do using the API
-
The API is a SOAP-based webservice allowing the creation, proofing and confirmation of orders for mailings, single letters, postcards and greeting cards.
Documents (PDF, RTF or Word files) are submitted as files or selected by name from your account. Address lists may be selected by name, submitted as a file (CSV, XLS, XLSX, Tab delimited, fixed length fields etc.) or added as individual addresses using the AddAddress call.
A PDF proof approval is available, but is no longer a required step in the process.
Payment is made via Top-Up credit on the customer Account, or for large volume users, payment on invoice may be available (subject to status, volume and regularity of orders).
The API documentation includes an example for creating a mailing with a Visual Studio console application using C# .NET 6.
Examples in the API documentation are based around Microsoft Visual Basic .NET code. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- Because the software is our own and it runs on our own servers we can ensure that we always have capacity to scale with demand. We can add bandwidth and resource as needed.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Provision of service including volumes, pricing, number of users, number of mail packs, types of service ie first class, economy access mail. Use of colour/mono also duplex/simplex printing.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Through SFTP or HTTPS
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- .txt
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We do our best endeavours to ensure availability. Our rolling availability is over 99.8%. We would discuss this with any buyer and agree a suitable SLA for this.
- Approach to resilience
- This is available on request.
- Outage reporting
- Our public dashboard shows a banner in the event of a service outage and key buyers receive emails if requested to alert of outages.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- These are restricted inhouse via access control and administration rights. For our external customers this is through hierarchy tiers, administration rights etc as required by each client.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Our InfoSec policies are written in line with our ISO 27001 certification. We provide initial training to all staff during induction relating to our InfoSec policies and this is renewed at least annually. All our Standard Operating Procedures are aligned with our certification and these are reviewed at least annually. Charge Hands and Managers are responsible for ensuring all staff adhere to our SOPs on an ongoing basis.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
CFH manages changes via our inhouse Accord tool. Service components are tracked through their lifetime using an Accord Ticket (parent) and linked Change Requests (CRs). These follow a lifecycle of authorisation, development in a separate environment, peer-to-peer inspection, and final sign-off by a senior authority.
Security impacts are assessed during the approval stage within Accord, where request implications are examined. Additionally, the DPO is consulted to conduct a Data Protection Impact Assessment (DPIA) if a change presents high risks to personal data. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
CFH assesses threats through a formal risk management process that identifies asset-specific vulnerabilities based on their likelihood and impact on confidentiality, integrity, and availability. Potential threat information is gathered from industry trends, customer requirements, and consultations with external engineers or consultants.
Patches are deployed via a controlled Change Management process using the inhouse Accord tool. They are developed in isolated environments and undergo peer-to-peer inspections before a senior technical lead supervises their promotion to the live environment to ensure stability and minimise business disruption. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
CFH identifies compromises by monitoring system non-conformities and security events through our inhouse Accord management tool and SIEM software, tracking deviations such as failed logins or unusual traffic.
When a compromise is found, CFH triggers its Incident Management procedures to triage and contain the threat. Implementation of responses is verified via peer-to-peer inspections.
CFH responds without undue delay, prioritising immediate action to minimise disruption. For personal data breaches, the organization is contractually committed to notifying customers within 12 hours of becoming aware of the incident. - Incident management type
- Supplier-defined controls
- Incident management approach
-
CFH manages incidents through a formal framework categorized into Cyber Security, Non-Cyber Security, or Non-Information Security events. Pre-defined procedures guide responses for common events like malware or hardware failure.
Users must report actual or suspected incidents promptly to the Group IT Service Desk via telephone, email, or instant messaging. Reports must include the date, location, and a detailed description. While technical evidence is retained internally, formal notifications are prepared by the DPO for external reporting when regulatory guidelines are met.
We will provide appropriate incident reports, providing all information and details of actions taken and outcomes - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We can provide a limited period or value trial for free if required. This will include availability of all aspects of the service and is not a restricted version.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Saturday 16 December 2023
- What the ISO/IEC 27001 doesn’t cover
- All parts of this service are covered by this certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Friday 30 May 2025
- What the ISO 9001 doesn’t cover
- All parts of this service are covered by this certification.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Viking Cloud
- PCI DSS accreditation date
- Monday 24 February 2025
- What the PCI DSS doesn’t cover
- All parts of this service are covered by this certification.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5c51a1f4-1794-4f2e-b4a3-69f319616f33
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- E768349e-720d-4c3f-afc4-b7db63051909
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-