Studybugs Cohorts (G-Cloud Edition)
Studybugs Cohorts empowers local authority children’s teams to work together with schools, academy trusts, police, the NHS and parents to safeguard children and raise school attendance.
Features
- Secure online portal for all LA teams working with children.
- Part of nationwide platform for children’s welfare and school attendance.
- Coordinate with schools, academy trusts, police, NHS, parents, …
- The best school attendance information, live and complete.
- Instant alerts to facilitate early intervention.
- Real-time reports – just ask in English.
- Tools to plan, record and coordinate actions.
- Works for all cohorts (CIN, CP, LAC, EHCP, SEND, …).
Benefits
- Unite teams. Ensure every child’s welfare by working together effectively.
- Strengthen safeguarding.
- Improve school attendance.
- Meet statutory responsibilities.
- Save money.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 5 8 7 6 4 4 3 0 3 2 4 5 3 5
Contact
STUDYBUGS LIMITED
James Catt
Telephone: 07856 868999
Email: info@studybugs.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Education
- Children's Social Care
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Cohorts is a standalone service but works alongside our other services, Cohorts for Virtual Schools and AP Manager, to secure safeguarding across all children the LA is responsible for.
- Cloud deployment model
- Public cloud
- Service constraints
- No constraints.
- System requirements
- A modern web browser, eg Google Chrome or Microsoft Edge
User support
- Email or online ticketing support
- Yes
- Support response times
- Our excellent support team usually reply to queries within an hour from 7am to 5pm, Monday-Friday.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
We provide a consistent, prompt online support service for all customers and users via the Studybugs web app and by email, at no additional charge.
We are happy to refer you to customers who will vouch for the quality and timeliness of this service.
You will be assigned an account manager who will work closely with you throughout the contract to ensure you’re receiving the service you need. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- When you first log in you’ll see our simple getting started guide along with an introductory video. From there you can start using Studybugs immediately. You can access further documentation and training videos at any time. Online training sessions with our dedicated training team are also included at no extra charge.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- Throughout the contract you’re able to extract all your data whenever you need it, on demand. You can also do this when the contract ends. You can extract in various formats including: Excel, ODF, CSV, Common Transfer File (CTF) (XML).
- End-of-contract process
- At the end of the contract we’ll delete or return all data to you at no charge. We’ll then close your account.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- We provide the same consistent service across mobile and desktop.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Users will access Studybugs via their web browser using a simple, secure and easy-to-use interface.
Using Studybugs Assistant, tailored reports and visualisations can be called up instantly – no training required – simply by asking in plain English. For example, “Show me a breakdown of absences today for CIN pupils across all our primary schools”. Drill down to discover the underlying issues with just a couple of clicks. Live dashboards enable you to keep a bird’s eye view of everything. Simply pin your favourite answers for ready access. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Studybugs Cohorts has been designed with accessibility in mind. Our users include those with a range of special needs and disabilities and we gather their feedback as they use Studybugs and make appropriate changes if necessary.
During development we use a suite of automated accessibility testing tools and non-compliances are addressed before updates are released. - API
- Yes
- What users can and can't do using the API
- Studybugs provides a secure API for you to access pupil and school data on demand. Typically we see this used for automating data transfers to other LA systems.
- API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Users can refine and customise reports and visualisations by asking in plain English via Studybugs Assistant. They can then build a live dashboard by pinning their favourite answers, and move and place these as they please.
Users can also customise a wide range of live alerts, specifying who should be alerted and when. For example, a social worker could arrange to be alerted when a child in their caseload is marked absent from school; the CME team could be notified when a pupil’s enrolment status changes; or when a school’s attendance starts trending downwards, this could be automatically flagged to the Head of Attendance.
Alerts, information and visualisations can all be customised to work for any cohort you like. Studybugs’s unique cohort analysis engine performs the necessary calculations taking into account not just how the cohort is now, but how it’s changed over time.
Scaling
- Independence of resources
-
We have over 10 years experience operating our cloud-native service and employ several strategies to ensure our service remains reliable for all users at all times:
Scalability, Load Balancing and Fault Tolerance: Our infrastructure is highly scalable handling fluctuations in demand without compromising performance. Incoming traffic is distributed across multiple servers to ensure a failure or overload of a single server doesn’t affect others.
Performance Monitoring and Capacity Planning: We continuously monitor the service to ensure performance targets are being met. We also plan ahead to anticipate future demand and scale-up as needed.
Analytics
- Service usage metrics
- Yes
- Metrics types
- You can pull up usage information on demand within Studybugs Cohorts. You can also request specific metrics from our support team and we’ll be happy to provide where we’re able.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- You’re able to extract all data whenever you need it, on demand. You can extract your data in various formats including: Excel, ODF, CSV, CTF (XML). If a you need data in a particular format then you can contact our support team.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- CTF (XML)
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- Excel (XLSX)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We aim to provide a reliable service for all users. While we do not offer an uptime guarantee, over the past 12 months there has been no interruption to service whatsoever (100% uptime) during working hours (8am to 5pm).
We are able to carry out maintenance and service updates with no downtime and where downtime is required, we schedule this outside working hours where possible. - Approach to resilience
-
Studybugs’s physical infrastructure is hosted and managed by Amazon in the Republic of Ireland. Amazon continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. Amazon’s data centre operations have been accredited under: ISO 27000, ISO 22301, ISO 27001, ISO 27017, ISO 27701, SOC1/2/3, CSA and many more standards. For additional information see https://aws.amazon.com/security.
Data is backed up continually and automatically, on secure, access-controlled, high-durability storage across multiple data centres. Every change is written to write-ahead logs and in the unlikely event of unrecoverable hardware failure, these logs can be automatically 'replayed' to recover the database to within seconds of its last known state. In addition to these backup procedures, our infrastructure is designed to scale and be fault tolerant by automatic replacement of failed instances, reducing the likelihood of needing to restore from backup.
In the event of a major outage, for example affecting an entire data centre zone, we are able to restore servers and data automatically, dynamically re-deploying them if necessary in a different zone (still within the EU or UK) within minutes. - Outage reporting
-
In the rare case there’s a service outage we will post this on our public status page. This is independently hosted to ensure its availability in the case of major issues with our website. Users can subscribe to this page for live updates.
We’ll also proactively report major outages to you by email.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Private data is access-controlled and Studybugs staff members only have access as needed for support purposes or where required by law. Access is restricted using multi-factor authentication or IP-whitelisting.
We also conduct regular audits, penetration testing and continuous monitoring and alerting to detect and prevent unauthorised access attempts. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Our security governance involves the establishment and enforcement of policies, procedures, and controls to protect our service. We start with a thorough risk assessment to identify potential threats and vulnerabilities and use that to develop our policy. Once our policies are established our Technical Director (who is responsible for the security of our service) ensures their implementation across the organisation. This includes a combination of technical controls and employee training. We utilise continuous improvement and monitoring to adapt to evolving threats and security trends.
- Information security policies and processes
-
We adhere to strict information security policies and processes to ensure the confidentiality, integrity, and availability of data. These include encryption protocols, access controls, and regular security audits. We regularly risk assess our security posture with reporting to our board.
We continually adjust our approach based on feedback, industry regulations, best practices (such as the NCSC’s Cloud Security Principles), which includes penetration testing and external validation against known security standards such as Cyber Essentials.
To ensure compliance with our polices we use a combination of technical controls (such as access control and multi-factor authentication) and employee training. We also conduct periodic security assessments and audits to identify and address any potential vulnerabilities or non-compliance issues.
Our Technical Director is responsible for the security of our service and our security policy is available at https://studybugs.com/security. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We follow a strict change management process which has been designed taking into account best industry practice including relevant standards such as ISO27001.
All changes are tracked in our source code repository. Changes are reviewed by appropriate senior engineers, including for potential security impact. We then run a comprehensive suite of automated tests, which include tests that verify our security policies are met, on every change before it’s released.
Our servers are “immutable” – once deployed with a known good configuration, that configuration can’t be changed.
We also maintain an inventory of all system components, including hardware, software and configuration. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We monitor various threat intelligence sources such as government alerts, industry forums, and security vendors to stay updated on potential threats. We also regularly conduct vulnerability scanning. When an applicable threat is identified, our process is to triage the threat and respond appropriately by, for example, deploying a patch or adjusting configuration. Security patches are deployed as quickly as required after validation and testing, and within 14 days.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use a combination of automated tools and manual cross-checks to monitor network activity including monitoring for any signs of security compromise or data loss. Logging data is shipped off server instances instantly to immutable log stores leaving no opportunity for modification. From there we configure automated monitoring and alarms for a variety of system and security events. Security events are categorised and critical events are raised to our Technical Director who then follows our Security Incident Response process to resolve the incident within 48 hours.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We have processes in place to respond to security and operational incidents (eg our Security Incident Response process). This includes automated monitoring and alerting systems, defining incident categories and severity levels, establishing an incident response team, maintaining documentation and evidence, communicating with stakeholders, and conducting post-incident reviews and process improvements.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 49f2722d-26c1-490c-b7ef-db2841abcf55
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- F6a8ce1a-8f3d-4b22-a1d8-68eb4eda6e0a
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-