Cogniss: Nocode infrastructure for creating patient-facing healthcare apps
Cogniss is a no-code platform for the design, build and distribution of patient-facing digital health apps. Cogniss allows any individual, group or organisation to create their own digital health technologies without the need for any technical knowledge or developers. Through the platform you can create an expansive digital health ecosystem.
Features
- Build patient apps for information, support, prevention, treatment and research
- 100+ configurable features and functionality for digital health apps
- Publish apps to native iOS, Android and web
- Customisable app templates enabling rapid app development
- User personalisation based on profiles, behaviour and usage data
- Analytics dashboard with secure data export
- Open APIs for integration with external systems
- Super-app model enabling multiple apps from one platform
- Support with compliance with a dedicated DTAC self-certification tool
- Role-based admin access to manage apps and users
Benefits
- Create and manage apps without coding expertise
- Launch a minimum viable app in weeks
- Built to support NHS compliance and deployment readiness
- Retain full ownership of app intellectual property
- Predictable low-cost annual subscription pricing
- Protect data with robust role-based access controls
- Personalised user experiences driven by profiles and usage
- Comprehensive training and support via Cogniss Academy and Help Centre
- Update app content and functionality instantly
- Seamless automatic operating system compatibility updates
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 5 3 3 7 4 0 7 5 0 3 3 5 1 9
Contact
Cogniss
Lloyd Humphreys
Telephone: +44 7813 974609
Email: contact@cogniss.com
About your service
- Service categories
-
Application Development and Deployment
Application development
- Development languages, environments and tools
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
We fully manage the service. The installation and configuration have our standard configuration.
No more than once a year, there may be a planned maintenance on the server sytem the will require some downtime. This will be within our SLA agreements.
At least once a year the mobile apps for iOS and Android will need to be published to keep inline with Appstore and Google Play requirements to have app support the latest versions of their mobile OS. Customers need to manage their developer accounts as required by Apple and Google and will need to address any administrative requirements. - System requirements
-
- Windows Desktop/notebooks: Minimum 16GB RAM running Windows 11 and above
- Mac Desktops/notebooks: Minimum 8GB RAM running macOS 12 and above
- Cogniss Creator: Latest desktop version Chrome, Safari or Edge browser
- Mobile apps created on Cogniss: Latest OS minus 2 releases
User support
- Email or online ticketing support
- Yes
- Support response times
-
Response times:
1) Low priority - General question: 2 business days;
2) Normal priority - Non-critical functions of mobile/web app or Creator platform behaving abnormally: 1 business day;
3) High priority - Important functions of mobile/web app or Creator platform are degrading and impacting usability: Same business day or next business day, and;
4) Urgent - Mobile/web app or Creator platform is significantly degraded and is not usable: 1 hour (call contact) - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Accessibility has been considered throughout the design and development of the service. Automated accessibility testing has been carried out using browser-based tools (including Lighthouse and WAVE) on representative, authenticated user journeys to identify issues relating to keyboard navigation, focus management, labelling, colour contrast, and ARIA usage.
In addition, manual testing has been undertaken to validate key accessibility behaviours that automated tools cannot fully assess. This includes keyboard-only navigation through core workflows, verification of logical tab order, focus visibility, and interaction with common custom interface components such as menus, dialogs, and form controls.
Feedback from users with accessibility requirements has been incorporated during iterative product development, particularly around clarity of controls, consistency of navigation, and readability of interface elements. Any issues identified are reviewed and prioritised within the product roadmap and addressed as part of ongoing platform improvements.
The service is designed to support users in line with WCAG 2.2 AA. Formal third-party accessibility certification has not been undertaken at this stage, but accessibility testing and remediation form part of the standard development and quality assurance process. - Onsite support
- Yes, at extra cost
- Support levels
-
Cogniss users are assigned a dedicated Customer Success Manager upon commencing a contract with Cogniss. Customer Success Managers support and guide new users during the development of their application.
Support is also available through web chat, accessed through Intercom, a third-party tool, or by contacting support@cogniss.com.
In Intercom, the Fin AI chatbot aims to provide resolutions to tier 0 and 1 enquiries with triaging workflows configured to escalate enquiries unable to be resolved by the chatbot to members of the Cogniss Support team, or where required, a member of the Cogniss Technical team. - Support available to third parties
- No
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Upon commencing a contract with Cogniss, a user is assigned a dedicated Customer Success Manager and a Kickoff call is arranged with key stakeholders from the user's organisation to align on project goals and timelines.
New users are provided with access to Cogniss Academy, an online learning environment, that enables them to learn the fundamentals of building a Mobile or Web app on the Cogniss Creator platform, as well as guides and resources.
Users are also invited to attend online training sessions and workshops that support them in designing and developing their app, and regular calls are scheduled with their Customer Success Manager to ensure continued support throughout the project.
New users also receive full access, at no additional cost, to the Cogniss Help Centre and can access our Support Chat. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- When a user's contract ends, they can extract / export their app data in a CSV file via Cogniss Insights, which is the data and analytics dashboard in the Cogniss platform. The type of data that can be extracted includes user engagement data. The user will also be able to extract their data via API if they have set this up.
- End-of-contract process
-
When a Cogniss user informs us of their decision to not renew their contract they are briefed on the offboarding process by their dedicated Customer Success Manager. There are no additional costs associated with the offboarding process.
Users are provided with guidance and support on how best to export their app content and data. If their app is hosted on a dedicated environment, we aim to decommission their environment within 14 days after the end of their contract. This process deletes the environment and all apps and data associated with it. If their app is hosted on a shared environment their app, and all associated data, will be deleted the day after their contract ends. Users are also provided with an offboarding survey to provide feedback on their Cogniss experience and to confirm if they would like to be contacted by us in the future. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- N/A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The Cogniss Creator platform can be accessed on both mobile and desktop browsers but we recommend using the desktop version when creating and editing apps to ensure the best possible user experience. Mobile apps developed on Cogniss Creator can be run natively on iOS and Android devices.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
The Cogniss Creator platform enables users to create Mobile applications, which can be published on the Apple App Store and Google Play Store, and Web applications, which can be accessed through all web browsers.
Cogniss' no-code platform is intuitive and user-friendly, making use of a component-based structure to allow users to rapidly build and deploy fully functioning applications. Users can configure their app homescreen using a widget library, add content using various content types such as text, images, and video, use Cogniss' powerful behavior engine to create customisable and personalised experiences for their app users. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Accessibility has been considered throughout the design and development of the service. Automated accessibility testing has been carried out using browser-based tools (including Lighthouse and WAVE) on representative, authenticated user journeys to identify issues relating to keyboard navigation, focus management, labelling, colour contrast, and ARIA usage.
In addition, manual testing has been undertaken to validate key accessibility behaviours that automated tools cannot fully assess. This includes keyboard-only navigation through core workflows, verification of logical tab order, focus visibility, and interaction with common custom interface components such as menus, dialogs, and form controls.
Feedback from users with accessibility requirements has been incorporated during iterative product development, particularly around clarity of controls, consistency of navigation, and readability of interface elements. Any issues identified are reviewed and prioritised within the product roadmap and addressed as part of ongoing platform improvements.
The service is designed to support users in line with WCAG 2.2 AA. Formal third-party accessibility certification has not been undertaken at this stage, but accessibility testing and remediation form part of the standard development and quality assurance process. - API
- Yes
- What users can and can't do using the API
-
The Cogniss API is available to all users with valid authentication. Access to functionality is controlled by role-based access permissions, so users can only perform actions allowed by their access level.
Users can:
- Perform authentication operations
- Set up and configure service resources permitted by their role.
- Update, manage, and retrieve and filter data they are authorised to access.
- Trigger supported operations, such as sending notifications or retrieving results.
Users cannot:
- Access data or perform actions outside of their assigned permissions.
- Modify system-managed infrastructure, internal services, or read-only fields.
- Bypass system rules, validations, or rate limits.
Current limitations:
- Almost all requests require authentication.
- Some operations are asynchronous and may return status updates instead of immediate results. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Buyers who have a dedicated Cogniss environment are able to apply their own branding to the platform as well as configure existing platform settings as per their needs. Mobile or Web apps created within a dedicated environment are fully customisable per app.
Buyers who make use of a shared Cogniss environment are unable to configure platform settings but can fully customise the Mobile or Web apps they develop on the Cogniss Creator platform.
Scaling
- Independence of resources
- The Cogniss Platform runs on AWS and has load balancing across multiple EC2 instances in separate availability zones, ensuring reliability and scalability. The Cogniss API is stateless so open sessions are not kept open, ensuring resources are managed efficiently. The Cogniss Platform by default is installed as a single tenancy platform so is not affected by external users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Cogniss Insights shows general metrics of app usage
- Reporting types
-
- API access
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can extract all app data from the provided APIs.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The Cogniss platform by default have three instances installed with redundancy built-in to ensure availability.
We have set SLAs for buyers tracked over a monthly period. Service Credits are calculated as a percentage of the total charges paid by you (excluding one-time payments such as upfront payments made for Reserved Instances or payments made that cover the costs of development of new features or solutions) for Cogniss subscription during the monthly billing cycle in which the Unavailability occurred in accordance with the schedule below:
1) Less than 99.9% but equal to or greater than 99.0% over a month, service credit of 10% of a monthly subscription;
2) Less than 99.0% but equal to or greater than 95.0% over a month, service credit of 30% of a monthly subscription; and,
3) Less than 95.0% over a month, service credit of 100% of a monthly subscription.
We will apply any Service Credits only against future payments for the applicable subscription otherwise due from the buyer. Service Credits will not entitle you to any refund or other payment from Cogniss or related entities. Service Credits may not be transferred or applied to any other account. - Approach to resilience
- We have agreements with our suppliers to ensure services meet agreed SLAs. Our suppliers for the platform are ISO27001 certified ensuring correct processes are in place.
- Outage reporting
- Alarms are setup on AWS service dashboard. These are delivered via email and SMS.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is resricted based on roles. Only Platform Admins and App admins have access to management interfaces.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
Security and Privacy are our highest priority. We follow the methodology of minimum access. Only required personnel have access to specific data. For the Cogniss platform, it has been designed, from its inception, to put privacy and data security at the fore-front. From the web and mobile apps, access to any data are controlled via defined roles (Role-Based Access Control) within the platform.
We are currently working for ISO27001:2022 certification. - Information security policies and processes
- We use an Information Security Mangement System (ISMS) that have all our policies and controls conforming to ISO27001:2022. Our system schedules and tracks all required training for all personnel. The ISMS enforces the setup of correct governance to ensure incidents are reported and communicated as required. Our consistent tracking and training ensure policies are being followed. Internal audits are also performed to ensure compliance.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Change requests are prioritised and assessed for security impacts. If there are security impacts these must be resolved before proceeding. If no resolution is found then the change is not approved. If there are no security issues or a resolution is found, the change will be implemented. As part of the implementation and testing, further security and code reviews are completed before final deployment.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- From the latest information bulletins from our suppliers we assess the threats to server systems and will schedule related patches where necessary; Server systems patches are deployed with every platform upgrade, which is about 6 weeks, and; We scan our code base for vulnerabilities and address issues with dependencies and our base code.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Base code is scanned with every feature introduction and update deployment; Critical issues are resolved before any deployment; Dependencies are scanned upon introduction and every update, and; Developer code are reviewed for vulnerabilities by senior engineers.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We have an Incident Response Plan which describes potential threat vectors. All personnel are required to review the Incident Response Plan and are mandated to report any potential breaches or incidents. Our ISMS ensures personnel are aware of potential incidents and are trained to report accordingly. Our Incident Response Plan ensures that the correct governance is in place and the required communication to stakeholders is accurate and distributed to the correct channels and within the correct timeframes.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
A two week free trial is available to ensure that the Cogniss platform is the right option for the buyer.
Prior to the trial a Trial Success Plan will be agreed with the customer and reviewed during and at the end of the trial.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 2.5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 7.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 71edd97f-6cf9-4a91-b9cc-aaaea29c4ac5
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- A3738de2-18da-4dc6-b9ed-40d4740f3699
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-