Insight
View digital and physical content in a single pane of glass, through a secure data platform. Accelerate document-heavy processes with templated and customizable workflows. Combine AI speed and human-in-the-loop and rapidly deploy tailored agentic workflows that orchestrate users and data sources. Automate complex, multi-step, document-intensive processes with AI agents.
Features
- Data extraction
- Data discovery
- Agentic AI framework
- Content management
- Information governance
- Intelligent document processing
- Data Transformation
- Data Enrichment
- Data Validation
- Data Storage
Benefits
- Improve the Customer Experience - make information accessible & useful
- Drive Efficiency - Automate Manual processes, enrich information
- Enable audit ready compliance with document enrichment at scale
- Content Management - Search, view, edit and share documents.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 6 7 9 2 9 8 6 2 3 8 5 3 9 4
Contact
Iron Mountain UK Plc
Alice Blogg
Telephone: 08445 60 70 80
Email: bidmanagementwe@ironmountain.com
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI software services
- Conversational AI Software Services
- Generative AI Software Services
- Document AI Software Services
- Personalize AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No constraints.
- System requirements
- To purchase a license from Iron Mountain.
User support
- Email or online ticketing support
- Yes
- Support response times
-
30 minutes for critical issues 24/7
General questions 5 days - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Iron Mountain's web chat functionality is accessible via the website, allowing users to browse FAQs, chat with an agent, or submit a request for assistance at any time. The chat is available 24/7 for support inquiries. Users can engage with agents for account questions, service feedback, and issue resolution. There are no restrictions noted for general use; users can initiate chats, seek answers, and submit requests.
- Web chat accessibility testing
- Not applicable.
- Onsite support
- Yes, at extra cost
- Support levels
-
Level 1 Support - Included
Level 2 Support - Included
Level 3 Support - Included
Technical Account Manager available for new accounts / enterprise subscription - Support available to third parties
- No
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- Our Professional Services team provides training and documentation.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- APIs extract data into common formats - JSON, XML, CSV
- End-of-contract process
-
At the end of the contract the customer provides a timeline for the engagement to end.
Professional Services and our Support team engage to export the data and provide to the customer.
Customer instance with data is decommissioned and deleted.
Fees vary by subscription and engagement statement of work. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Key accessibility features include text alternatives for non-text content, correct color contrast ratio (at least 4.5:1), keyboard operability, focus visibility, consistent screen structure, context-sensitive help, screen reader compatibility, and programmatically determined UI components. Platform customizations have resolved items such as contrast minimum, reflow, content on hover, headings, and labels identified in the VPAT report.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Web based user interface and REST APIs for ingesting, exporting and managing data / documents
- Accessibility standards
- None or don’t know
- Description of accessibility
- Key accessibility features include providing text alternatives for non-text content, correct color contrast ratio (at least 4.5:1), keyboard operability, focus visibility, consistent screen structure, context-sensitive help, screen reader compatibility, and programmatically determined UI components.
- Accessibility testing
- Iron Mountain conducts annual accessibility testing of Insight. Our accessibility vendor is an accessibility compliance third party assessor. Automated tools include Deque aXe browser extension & Deque aXe Auditor.
- API
- Yes
- What users can and can't do using the API
-
Customers can integrate with REST Web Services using oAuth for Authentication and Authorization.
APIs include ability to upload, edt, search and delete documents and metadata as well as create, edit and delete users. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customize:
1) Dashboards
2) Single Sign On
3) Metadata Fields and Document Types
4) Business Workflows
Scaling
- Independence of resources
- Scaling by customer in a dedicated set of container images.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Number of documents, documents by type, documents by status, number of users, number of documents by task.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- APIs extract data into common formats - JSON, XML, CSV
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- 99.99% availability - refunds available per contract agreement if levels are not met.
- Approach to resilience
- Multiple (three) zones within region with redundant failover.
- Outage reporting
- We report them via email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- We do this via a web application firewall. Physical and logical controls are implemented in the Insight application UI and backend to restrict access to authorized persons.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Iron Mountain has numerous security policies available upon request. These include including Acceptable Use (Global), Asset Management Policy (Global), Change Management Policy (Global), Cloud Security Policy (Global), Configuration Management Policy (Global), Continuous Monitoring & Log Management Policy (Global), Cryptographic Protection Policy (Global), Cybersecurity Incident Response Policy (Global), Endpoint Security Policy (Global), Enterprise Risk Management Policy (Global), Identity and Access Management Policy (Global), Information Assurance Policy (Global), Information Classification and Handling (Global), Information Security Compliance Policy (Global), Information Security Governance Policy (Global), IT Information Security Risk Management Policy (Global), Maintenance Policy (Global), Network Security Management Policy (Global), Project & Resource Management Policy (Global), Secure Engineering & Architecture Principles Policy (Global), Security Awareness and Training Policy (Global), Security Operations Policy (Global), Systems and Information Backup Policy (Global), Third Party Risk Management Policy (Global), Vulnerability Management Policy (Global), and Web Security Policy (Global)
Our reporting structure is as follows:
Global Security and Compliance Team run by Chief Risk Officer and Chief Information Security Officer (CISO) reporting to the Chief Executive Officer (CEO)
Global Security and Compliance monitors the information security across the systems. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Changes are tracked in a central change management system with an approval process run by our change review board. Changes are reviewed for completeness and evaluated for risk as well as rollback, testing and user impact / communication.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Patching and Vulnerability management, anti-malware, endpoint disk encryption and intrusion prevention are managed via our Information Technology asset and endpoint management solutions. All workstations and servers are mitigated in an agreed, scheduled maintenance window following change management procedures with proper customer and end-user notification. For cloud based systems, automated agents continuously scan the environment looking for new security vulnerabilities. All alerts are sent to our 24x7 Virtual Security Operations (vSOC) team. Systems are patched following remediation times of: Critical (same week or sooner), High (within 2 weeks), Medium (within 90 days), Low (within 120 days).
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Insight systems are continuously monitored for security and use. All actions taken by personnel on production systems are logged and scanned for threats, including an Security Information Event Management (SIEM system) for threat analytics, which is regularly monitored by and alerted to Security personnel. Audit logs are maintained for a minimum of 90 days online plus 365 days in offline storage.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Our Cyber Incident Response Team (CIRT) monitors alerts 24x7 365 with an established incident response plan. Our CIRT team works to notify customers and to resolve any security incidents working together with their security teams.
Reports are sent per customer contract
Users report incidents to the cyber incident response team - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Bsi
- ISO/IEC 27001 accreditation date
- Tuesday 17 December 2024
- What the ISO/IEC 27001 doesn’t cover
- Not applicable.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Bsi
- ISO 9001 accreditation date
- Wednesday 31 January 2024
- What the ISO 9001 doesn’t cover
- Not applicable.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 9c3e47ae-3d10-47b2-81aa-5a8be4c7d4af
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 88f09d72-569f-4281-8de0-3a985e4280eb
- Other security certifications
- Yes
- Any other security certifications
- BS 10008:2014 Evidential weight and legal admissibility of electronic information
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-