Skip to main content

Help us improve the Digital Marketplace - send your feedback

DATASUMI LTD

AI-Powered Agents Platform for Public Sector Digital Transformation

Transform public sector operations with AI-powered intelligent agents. These agents automate complex workflows enhance decision-making and improve citizen services. The fully compliant platform boasts natural language processing secure cloud deployment and real-time analytics. It’s designed specifically for UK government organisations needing GDPR compliance and sovereignty.

Features

  • Autonomous intelligent agents execute complex tasks without requiring manual intervention
  • Natural language processing enables intuitive conversational interactions across platform
  • Advanced workflow orchestration automates multistep business processes seamlessly
  • Realtime analytics dashboard delivers intelligent insights for informed decision making
  • Multicloud deployment supports public private and hybrid cloud infrastructure options
  • RESTful API integration enables seamless connectivity with existing enterprise systems
  • Enterprise grade security controls ensure GDPR compliance and data protection
  • Customisable agent behaviour adapts flexibly to specific organisational requirements workflows

Benefits

  • Increases productivity by automating routine tasks and reducing manual effort
  • Accelerates decisionmaking with artificial intelligence insights and actionable recommendations
  • Reduces operational costs significantly through intelligent automation and resource optimisation
  • Enhances service delivery with faster response times and improved accuracy
  • Improves user experience through natural language interaction and intuitive interfaces
  • Scales efficiently to handle growing workloads without additional staff resources
  • Maintains compliance with builtin governance controls and audit trail capabilities
  • Enables innovation by freeing staff to focus on strategic work

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at accounts@datasumi.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 4 9 4 2 2 1 0 9 4 5 6 4 5 3

Contact

DATASUMI LTD Datasumi Team
Telephone: +442045770319
Email: accounts@datasumi.com

About your service

Service categories

Application Development and Deployment

AI platforms

  • Search and knowledge discovery

AI software services

  • Conversational AI Software Services
  • Generative AI Software Services
  • Document AI Software Services
  • Anomaly Detection AI Software Services
  • Personalize AI Software Services
  • Forecast AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Our service integrates with existing enterprise systems via API, enabling autonomous workflow automation, intelligent task management, natural language query processing, and automated documentation for public sector digital transformation initiatives.
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
1. Data Quality: Agent performance depends on accurate, structured organisational data and clear process documentation for optimal automation effectiveness. 2. Integration Requirements: Legacy systems may require additional API development or configuration for full agent connectivity. 3. Planned Maintenance: Regular system updates and model improvements occur during scheduled maintenance windows, typically outside core business hours, with advance notification provided. 4. Processing Capacity: Agent response times depend on workload volumes and system specifications outlined in service level agreements.
System requirements
  • Modern web browser such as Chrome, Firefox, Edge or Safari
  • Stable internet connection with minimum bandwidth of five megabits second
  • REST API compatibility required for seamless enterprise system integration connectivity
  • Support for JSON or XML data exchange formats for integration

User support

Email or online ticketing support
Yes
Support response times
Standard response times: 4 hours during UK business hours (Monday-Friday, 9am-5pm GMT). Non-urgent queries responded to within 24 hours. Critical issues receive immediate attention with initial response within 1 hour. Weekend support available for urgent issues with 8-hour response time.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
No
Web chat support
No
Onsite support
No
Support levels
We offers three support tiers: Standard Support (included): Email and ticketing support with 4-hour response during UK business hours. Access to online knowledge base and documentation. Suitable for most public sector organisations. Premium Support: All Standard features plus 1-hour response time for critical issues, weekend support with 8-hour response, quarterly service reviews, priority bug fixes, and early access to new features. Enterprise Support: All Premium features plus dedicated technical account manager, custom SLA agreements, onsite implementation assistance, and bespoke training sessions. All tiers include: - Regular platform updates and patches - Security incident support - Policy analysis consultation - Integration technical assistance Enterprise tier includes a designated technical account manager and cloud support engineer for direct escalation and proactive system monitoring.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide comprehensive onboarding support to help users quickly start using Enhanced Policy Analysis with Generative AI:

• Dedicated onboarding specialist assigned to each new customer
• Interactive online training sessions covering core functionality
• Comprehensive user documentation and video tutorials accessible 24/7
• Live webinar training sessions for teams
• Customized setup assistance for integration with existing systems
• Email and phone support during initial deployment phase
• Sample datasets and templates to accelerate first use cases
• Best practices guides for policy analysis workflows

Our goal is to have users analyzing policies within 24 hours of account activation, with full proficiency typically achieved within one week through our structured onboarding program.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
Users can extract their data through multiple secure methods when the contract ends:

• Self-service data export portal allowing users to download all data in standard formats (JSON, CSV, XML)
• Automated data package creation containing all user content, configurations, and metadata
• API access for programmatic data extraction using standard REST endpoints
• Assisted extraction service where our technical team helps with bulk data transfer
• Direct secure transfer to user-specified cloud storage or on-premises systems
• Data verification tools to ensure completeness and integrity of extracted data
• 90-day retention period post-contract to allow for data recovery if issues arise
• Secure deletion certification provided once data extraction is complete

All extraction processes maintain full audit trails and comply with data protection regulations.
End-of-contract process
At contract end, we provide a comprehensive transition process:

**Included at no additional cost:**
• 90-day data retention period for recovery purposes
• Standard data export in common formats (JSON, CSV, XML)
• Final usage reports and analytics summaries
• Account deactivation and secure data deletion certification
• Knowledge transfer documentation

**Process timeline:**
• 60 days notice: Transition planning begins
• 30 days notice: Data export preparation and user notification
• Contract end: Service access terminated, data export available
• 90 days post-contract: Final data deletion

**Additional costs may apply for:**
• Expedited data extraction (less than 30 days notice)
• Custom data format conversion
• On-site transition assistance
• Extended data retention beyond 90 days
• Assisted migration to new provider

All processes comply with GDPR and government data handling requirements.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile experience is optimized for smaller screens with responsive design, ensuring all core functionalities are accessible. However, some advanced analytics features may have a simplified interface on mobile devices.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Our service provides a web-based graphical user interface accessible through standard web browsers. The interface features intuitive dashboards, interactive data visualization tools, and streamlined navigation designed for ease of use.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We conduct regular testing with screen readers including JAWS and NVDA, as well as keyboard-only navigation tests. User testing includes individuals with visual impairments and mobility restrictions to ensure comprehensive accessibility compliance.
API
Yes
What users can and can't do using the API
Users can integrate our service with existing systems through RESTful API endpoints. The API allows users to configure service parameters, submit data for analysis, retrieve results, and manage user access. Users can set up automated workflows and schedule recurring tasks. Limitations include rate limiting for API calls and some advanced customization options that require direct web interface access.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customize dashboard layouts, report templates, data visualization preferences, and analytical parameters. Customization is performed through the web interface settings panel, with some advanced options available via API. Account administrators and users with appropriate permissions can make customizations to their organization's instance, with some features requiring admin-level access.

Scaling

Independence of resources
We guarantee user isolation through multiple technical approaches:

• Multi-tenant architecture with strict resource partitioning per customer
• Dynamic resource allocation and auto-scaling based on individual tenant demand
• Dedicated compute resources for processing-intensive operations
• Rate limiting and queuing systems to prevent resource monopolization
• Real-time monitoring with automatic load balancing across infrastructure
• Separate database instances and storage containers per customer
• Quality of Service (QoS) guarantees with SLA-backed performance commitments

Our infrastructure automatically scales resources independently for each user, ensuring consistent performance regardless of system-wide demand.

Analytics

Service usage metrics
Yes
Metrics types
We provide comprehensive service usage metrics including:

• Query volume and processing times
• User activity and session analytics
• API usage statistics and response times
• Data processing volumes and accuracy metrics
• System performance and uptime statistics
• Storage utilization and bandwidth consumption
• Security event monitoring and compliance reporting
• Cost breakdown by department/user group

All metrics include historical trends, real-time monitoring, and customizable alerting for proactive management.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
NCSC approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data through multiple convenient methods:

• Self-service web portal with one-click export functionality
• RESTful API endpoints for programmatic data extraction
• Scheduled automated exports to user-specified cloud storage
• Bulk download options for large datasets
• Real-time data streaming for continuous synchronization
• Email delivery of smaller export packages
• Secure FTP/SFTP transfer for enterprise customers

All exports maintain data integrity, include metadata, and support incremental/full backup options with comprehensive audit logging.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • JSON
  • XML
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • JSON
  • XML

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
We guarantee 99.9% uptime availability for Enhanced Policy Analysis with Generative AI, measured monthly.

**Service Level Agreement:**
• 99.9% uptime guarantee (8.76 hours maximum downtime per month)
• Planned maintenance excluded from calculations (scheduled during off-peak hours)
• 24/7 monitoring and automated failover systems
• Load balancing across multiple availability zones
• Real-time service status dashboard available to customers

**SLA Refunds:**
• 99.0-99.89% uptime: 10% monthly service credit
• 98.0-98.99% uptime: 25% monthly service credit
• Below 98.0% uptime: 50% monthly service credit

**Resilience Features:**
• Automatic failover to backup systems within 60 seconds
• Redundant data centers in geographically separate locations
• Regular disaster recovery testing
• Incident response team available 24/7
• Root cause analysis provided within 48 hours of any outage

Service credits automatically applied to next month's billing when SLA thresholds aren't met.
Approach to resilience
Enhanced Policy Analysis with Generative AI is designed with multiple layers of resilience:

**Infrastructure Resilience:**
• Multi-zone deployment across geographically separated UK data centers
• Automated failover systems with sub-60-second recovery times
• Load balancing across multiple server clusters
• Redundant network connections and power supplies
• Real-time health monitoring with predictive failure detection

**Application Resilience:**
• Microservices architecture enabling component-level failover
• Database replication with automatic synchronization
• Stateless application design supporting horizontal scaling
• Circuit breakers preventing cascade failures
• Graceful degradation maintaining core functionality during partial outages

**Data Resilience:**
• Continuous backup to multiple locations with point-in-time recovery
• Cross-regional data replication with consistency checks
• Immutable audit logs ensuring data integrity

**Operational Resilience:**
• 24/7 NOC monitoring with escalation procedures
• Automated incident response and remediation
• Regular disaster recovery testing and business continuity planning
• Detailed runbooks for all failure scenarios

Full datacenter resilience specifications available upon request for qualified government procurement.
Outage reporting
Enhanced Policy Analysis with Generative AI provides comprehensive outage reporting through multiple channels:

**Public Status Dashboard:**
• Real-time service status available at status.policyanalysis.gov.uk
• Historical uptime data and incident reports
• Scheduled maintenance notifications
• Component-level status monitoring (authentication, processing, data access)

**Email Alerts:**
• Automatic incident notifications to registered administrators
• Customizable alert thresholds and escalation rules
• Maintenance window advance notifications (48-hour minimum)
• Resolution confirmations and post-incident summaries

**API Access:**
• RESTful status API for automated monitoring integration
• Real-time incident data feeds
• Programmatic access to maintenance schedules
• Webhook notifications for third-party monitoring systems

**Additional Reporting:**
• SMS alerts for critical incidents (optional)
• Dedicated account manager notifications for enterprise customers
• Monthly uptime reports with detailed analysis
• Root cause analysis documents for significant incidents
• Service level agreement compliance reporting

All outage communications follow government digital service standards for transparency and accessibility.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Management interfaces and support channels are protected by role-based access controls and require authentication (username/password, IAM, or SSO). Sensitive functions are restricted to authorised staff only. Access is logged and regularly reviewed.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users receive audit information on a regular basis
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users receive audit information on a regular basis
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
Enhanced Policy Analysis with Generative AI follows comprehensive information security policies aligned with ISO/IEC 27001 and government standards:

**Security Policy Framework:**
• Information Security Management System (ISMS) with documented procedures
• Data classification and handling policies covering OFFICIAL, SECRET classifications
• Access control and privilege management procedures
• Incident response and business continuity plans
• Vendor and third-party risk management policies

**Reporting Structure:**
• Chief Information Security Officer (CISO) reporting to board level
• Security steering committee with quarterly reviews
• Monthly security posture reports to executive leadership
• Weekly operational security status updates

**Policy Enforcement:**
• Annual mandatory security awareness training for all staff
• Quarterly policy review and updates
• Automated policy compliance monitoring and alerts
• Regular internal and external security audits
• Disciplinary procedures for policy violations
• Continuous monitoring with SIEM integration
• Risk assessment and remediation tracking

All policies undergo legal review and are updated to reflect changing threat landscape and regulatory requirements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Enhanced Policy Analysis with Generative AI employs comprehensive configuration and change management:

**Component Tracking:**
• CMDB maintains complete asset inventory
• Version control tracks all software components and dependencies
• Automated discovery tools monitor infrastructure changes

**Change Management:**
• Formal change approval process with security impact assessments
• Risk-based categorization (emergency, standard, minor changes)
• Security team review for high-risk modifications
• Rollback procedures for failed deployments
• Automated testing in staging environments

**Compliance:**
• CSA CCM v4.0 and SSAE-18 compliant processes
• Audit logs for all changes
• Compliance reporting
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Our process includes continuous vulnerability assessment and risk analysis using external sources (such as MITRE, NVD). All identified threats are evaluated, and critical patches are deployed within 24 hours. Information is sourced from threat intelligence feeds, security bulletins, and partner notices. Non-critical issues follow a scheduled patch cycle.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Continuous system log monitoring and automated anomaly detection enable early identification of threats. Incident response processes are in place for prompt mitigation.
Incident management type
Supplier-defined controls
Incident management approach
Incidents are promptly triaged and escalated based on severity, with forensic investigation undertaken and full incident reports provided post-resolution. Preventative actions are taken to reduce future risk.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E68c70aa-02cf-45a9-ab6f-2218c02dfe62
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at accounts@datasumi.com. Tell them what format you need. It will help if you say what assistive technology you use.