Skip to main content

Help us improve the Digital Marketplace - send your feedback

STUDYBUGS LIMITED

Studybugs Cohorts (G-Cloud Edition)

Studybugs Cohorts empowers local authority children’s teams to work together with schools, academy trusts, police, the NHS and parents to safeguard children and raise school attendance.

Features

  • Secure online portal for all LA teams working with children.
  • Part of nationwide platform for children’s welfare and school attendance.
  • Coordinate with schools, academy trusts, police, NHS, parents, …
  • The best school attendance information, live and complete.
  • Instant alerts to facilitate early intervention.
  • Real-time reports – just ask in English.
  • Tools to plan, record and coordinate actions.
  • Works for all cohorts (CIN, CP, LAC, EHCP, SEND, …).

Benefits

  • Unite teams. Ensure every child’s welfare by working together effectively.
  • Strengthen safeguarding.
  • Improve school attendance.
  • Meet statutory responsibilities.
  • Save money.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@studybugs.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 5 8 7 6 4 4 3 0 3 2 4 5 3 5

Contact

STUDYBUGS LIMITED James Catt
Telephone: 07856 868999
Email: info@studybugs.com

About your service

Service categories

Applications

Production and operations

  • Other operations

Service industry and public sector operations

  • Education
  • Children's Social Care
  • Other
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Cohorts is a standalone service but works alongside our other services, Cohorts for Virtual Schools and AP Manager, to secure safeguarding across all children the LA is responsible for.
Cloud deployment model
Public cloud
Service constraints
No constraints.
System requirements
A modern web browser, eg Google Chrome or Microsoft Edge

User support

Email or online ticketing support
Yes
Support response times
Our excellent support team usually reply to queries within an hour from 7am to 5pm, Monday-Friday.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
We provide a consistent, prompt online support service for all customers and users via the Studybugs web app and by email, at no additional charge.

We are happy to refer you to customers who will vouch for the quality and timeliness of this service.

You will be assigned an account manager who will work closely with you throughout the contract to ensure you’re receiving the service you need.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
When you first log in you’ll see our simple getting started guide along with an introductory video. From there you can start using Studybugs immediately. You can access further documentation and training videos at any time. Online training sessions with our dedicated training team are also included at no extra charge.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
Throughout the contract you’re able to extract all your data whenever you need it, on demand. You can also do this when the contract ends. You can extract in various formats including: Excel, ODF, CSV, Common Transfer File (CTF) (XML).
End-of-contract process
At the end of the contract we’ll delete or return all data to you at no charge. We’ll then close your account.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
We provide the same consistent service across mobile and desktop.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Users will access Studybugs via their web browser using a simple, secure and easy-to-use interface.

Using Studybugs Assistant, tailored reports and visualisations can be called up instantly – no training required – simply by asking in plain English. For example, “Show me a breakdown of absences today for CIN pupils across all our primary schools”. Drill down to discover the underlying issues with just a couple of clicks. Live dashboards enable you to keep a bird’s eye view of everything. Simply pin your favourite answers for ready access.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Studybugs Cohorts has been designed with accessibility in mind. Our users include those with a range of special needs and disabilities and we gather their feedback as they use Studybugs and make appropriate changes if necessary.

During development we use a suite of automated accessibility testing tools and non-compliances are addressed before updates are released.
API
Yes
What users can and can't do using the API
Studybugs provides a secure API for you to access pupil and school data on demand. Typically we see this used for automating data transfers to other LA systems.
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Users can refine and customise reports and visualisations by asking in plain English via Studybugs Assistant. They can then build a live dashboard by pinning their favourite answers, and move and place these as they please.

Users can also customise a wide range of live alerts, specifying who should be alerted and when. For example, a social worker could arrange to be alerted when a child in their caseload is marked absent from school; the CME team could be notified when a pupil’s enrolment status changes; or when a school’s attendance starts trending downwards, this could be automatically flagged to the Head of Attendance.

Alerts, information and visualisations can all be customised to work for any cohort you like.  Studybugs’s unique cohort analysis engine performs the necessary calculations taking into account not just how the cohort is now, but how it’s changed over time.

Scaling

Independence of resources
We have over 10 years experience operating our cloud-native service and employ several strategies to ensure our service remains reliable for all users at all times:

Scalability, Load Balancing and Fault Tolerance: Our infrastructure is highly scalable handling fluctuations in demand without compromising performance. Incoming traffic is distributed across multiple servers to ensure a failure or overload of a single server doesn’t affect others.

Performance Monitoring and Capacity Planning: We continuously monitor the service to ensure performance targets are being met. We also plan ahead to anticipate future demand and scale-up as needed.

Analytics

Service usage metrics
Yes
Metrics types
You can pull up usage information on demand within Studybugs Cohorts. You can also request specific metrics from our support team and we’ll be happy to provide where we’re able.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
You’re able to extract all data whenever you need it, on demand. You can extract your data in various formats including: Excel, ODF, CSV, CTF (XML). If a you need data in a particular format then you can contact our support team.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • CTF (XML)
  • PDF
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
Excel (XLSX)

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We aim to provide a reliable service for all users. While we do not offer an uptime guarantee, over the past 12 months there has been no interruption to service whatsoever (100% uptime) during working hours (8am to 5pm).

We are able to carry out maintenance and service updates with no downtime and where downtime is required, we schedule this outside working hours where possible.
Approach to resilience
Studybugs’s physical infrastructure is hosted and managed by Amazon in the Republic of Ireland. Amazon continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. Amazon’s data centre operations have been accredited under: ISO 27000, ISO 22301, ISO 27001, ISO 27017, ISO 27701, SOC1/2/3, CSA and many more standards. For additional information see https://aws.amazon.com/security.

Data is backed up continually and automatically, on secure, access-controlled, high-durability storage across multiple data centres. Every change is written to write-ahead logs and in the unlikely event of unrecoverable hardware failure, these logs can be automatically 'replayed' to recover the database to within seconds of its last known state. In addition to these backup procedures, our infrastructure is designed to scale and be fault tolerant by automatic replacement of failed instances, reducing the likelihood of needing to restore from backup.

In the event of a major outage, for example affecting an entire data centre zone, we are able to restore servers and data automatically, dynamically re-deploying them if necessary in a different zone (still within the EU or UK) within minutes.
Outage reporting
In the rare case there’s a service outage we will post this on our public status page. This is independently hosted to ensure its availability in the case of major issues with our website. Users can subscribe to this page for live updates.

We’ll also proactively report major outages to you by email.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Private data is access-controlled and Studybugs staff members only have access as needed for support purposes or where required by law. Access is restricted using multi-factor authentication or IP-whitelisting.

We also conduct regular audits, penetration testing and continuous monitoring and alerting to detect and prevent unauthorised access attempts.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Our security governance involves the establishment and enforcement of policies, procedures, and controls to protect our service. We start with a thorough risk assessment to identify potential threats and vulnerabilities and use that to develop our policy. Once our policies are established our Technical Director (who is responsible for the security of our service) ensures their implementation across the organisation. This includes a combination of technical controls and employee training. We utilise continuous improvement and monitoring to adapt to evolving threats and security trends.
Information security policies and processes
We adhere to strict information security policies and processes to ensure the confidentiality, integrity, and availability of data. These include encryption protocols, access controls, and regular security audits. We regularly risk assess our security posture with reporting to our board.

We continually adjust our approach based on feedback, industry regulations, best practices (such as the NCSC’s Cloud Security Principles), which includes penetration testing and external validation against known security standards such as Cyber Essentials.

To ensure compliance with our polices we use a combination of technical controls (such as access control and multi-factor authentication) and employee training. We also conduct periodic security assessments and audits to identify and address any potential vulnerabilities or non-compliance issues.

Our Technical Director is responsible for the security of our service and our security policy is available at https://studybugs.com/security.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We follow a strict change management process which has been designed taking into account best industry practice including relevant standards such as ISO27001.

All changes are tracked in our source code repository. Changes are reviewed by appropriate senior engineers, including for potential security impact. We then run a comprehensive suite of automated tests, which include tests that verify our security policies are met, on every change before it’s released.

Our servers are “immutable” – once deployed with a known good configuration, that configuration can’t be changed.

We also maintain an inventory of all system components, including hardware, software and configuration.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We monitor various threat intelligence sources such as government alerts, industry forums, and security vendors to stay updated on potential threats. We also regularly conduct vulnerability scanning. When an applicable threat is identified, our process is to triage the threat and respond appropriately by, for example, deploying a patch or adjusting configuration. Security patches are deployed as quickly as required after validation and testing, and within 14 days.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use a combination of automated tools and manual cross-checks to monitor network activity including monitoring for any signs of security compromise or data loss. Logging data is shipped off server instances instantly to immutable log stores leaving no opportunity for modification. From there we configure automated monitoring and alarms for a variety of system and security events. Security events are categorised and critical events are raised to our Technical Director who then follows our Security Incident Response process to resolve the incident within 48 hours.
Incident management type
Supplier-defined controls
Incident management approach
We have processes in place to respond to security and operational incidents (eg our Security Incident Response process). This includes automated monitoring and alerting systems, defining incident categories and severity levels, establishing an incident response team, maintaining documentation and evidence, communicating with stakeholders, and conducting post-incident reviews and process improvements.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
49f2722d-26c1-490c-b7ef-db2841abcf55
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
F6a8ce1a-8f3d-4b22-a1d8-68eb4eda6e0a
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@studybugs.com. Tell them what format you need. It will help if you say what assistive technology you use.