Skip to main content

Help us improve the Digital Marketplace - send your feedback

Iron Mountain UK Plc

Insight

View digital and physical content in a single pane of glass, through a secure data platform. Accelerate document-heavy processes with templated and customizable workflows. Combine AI speed and human-in-the-loop and rapidly deploy tailored agentic workflows that orchestrate users and data sources. Automate complex, multi-step, document-intensive processes with AI agents.

Features

  • Data extraction
  • Data discovery
  • Agentic AI framework
  • Content management
  • Information governance
  • Intelligent document processing
  • Data Transformation
  • Data Enrichment
  • Data Validation
  • Data Storage

Benefits

  • Improve the Customer Experience - make information accessible & useful
  • Drive Efficiency - Automate Manual processes, enrich information
  • Enable audit ready compliance with document enrichment at scale
  • Content Management - Search, view, edit and share documents.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidmanagementwe@ironmountain.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 6 7 9 2 9 8 6 2 3 8 5 3 9 4

Contact

Iron Mountain UK Plc Alice Blogg
Telephone: 08445 60 70 80
Email: bidmanagementwe@ironmountain.com

About your service

Service categories

Application Development and Deployment

AI platforms

AI software services

  • Conversational AI Software Services
  • Generative AI Software Services
  • Document AI Software Services
  • Personalize AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
No constraints.
System requirements
To purchase a license from Iron Mountain.

User support

Email or online ticketing support
Yes
Support response times
30 minutes for critical issues 24/7
General questions 5 days
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Iron Mountain's web chat functionality is accessible via the website, allowing users to browse FAQs, chat with an agent, or submit a request for assistance at any time. The chat is available 24/7 for support inquiries. Users can engage with agents for account questions, service feedback, and issue resolution. There are no restrictions noted for general use; users can initiate chats, seek answers, and submit requests.
Web chat accessibility testing
Not applicable.
Onsite support
Yes, at extra cost
Support levels
Level 1 Support - Included
Level 2 Support - Included
Level 3 Support - Included

Technical Account Manager available for new accounts / enterprise subscription
Support available to third parties
No
AI chatbot
No

Onboarding and offboarding

Getting started
Our Professional Services team provides training and documentation.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
APIs extract data into common formats - JSON, XML, CSV
End-of-contract process
At the end of the contract the customer provides a timeline for the engagement to end.
Professional Services and our Support team engage to export the data and provide to the customer.
Customer instance with data is decommissioned and deleted.
Fees vary by subscription and engagement statement of work.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Key accessibility features include text alternatives for non-text content, correct color contrast ratio (at least 4.5:1), keyboard operability, focus visibility, consistent screen structure, context-sensitive help, screen reader compatibility, and programmatically determined UI components. Platform customizations have resolved items such as contrast minimum, reflow, content on hover, headings, and labels identified in the VPAT report.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Web based user interface and REST APIs for ingesting, exporting and managing data / documents
Accessibility standards
None or don’t know
Description of accessibility
Key accessibility features include providing text alternatives for non-text content, correct color contrast ratio (at least 4.5:1), keyboard operability, focus visibility, consistent screen structure, context-sensitive help, screen reader compatibility, and programmatically determined UI components.
Accessibility testing
Iron Mountain conducts annual accessibility testing of Insight. Our accessibility vendor is an accessibility compliance third party assessor. Automated tools include Deque aXe browser extension & Deque aXe Auditor.
API
Yes
What users can and can't do using the API
Customers can integrate with REST Web Services using oAuth for Authentication and Authorization.
APIs include ability to upload, edt, search and delete documents and metadata as well as create, edit and delete users.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customize:
1) Dashboards
2) Single Sign On
3) Metadata Fields and Document Types
4) Business Workflows

Scaling

Independence of resources
Scaling by customer in a dedicated set of container images.

Analytics

Service usage metrics
Yes
Metrics types
Number of documents, documents by type, documents by status, number of users, number of documents by task.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
APIs extract data into common formats - JSON, XML, CSV
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
99.99% availability - refunds available per contract agreement if levels are not met.
Approach to resilience
Multiple (three) zones within region with redundant failover.
Outage reporting
We report them via email alerts.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
We do this via a web application firewall. Physical and logical controls are implemented in the Insight application UI and backend to restrict access to authorized persons.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Iron Mountain has numerous security policies available upon request. These include including Acceptable Use (Global), Asset Management Policy (Global), Change Management Policy (Global), Cloud Security Policy (Global), Configuration Management Policy (Global), Continuous Monitoring & Log Management Policy (Global), Cryptographic Protection Policy (Global), Cybersecurity Incident Response Policy (Global), Endpoint Security Policy (Global), Enterprise Risk Management Policy (Global), Identity and Access Management Policy (Global), Information Assurance Policy (Global), Information Classification and Handling (Global), Information Security Compliance Policy (Global), Information Security Governance Policy (Global), IT Information Security Risk Management Policy (Global), Maintenance Policy (Global), Network Security Management Policy (Global), Project & Resource Management Policy (Global), Secure Engineering & Architecture Principles Policy (Global), Security Awareness and Training Policy (Global), Security Operations Policy (Global), Systems and Information Backup Policy (Global), Third Party Risk Management Policy (Global), Vulnerability Management Policy (Global), and Web Security Policy (Global)

Our reporting structure is as follows:

Global Security and Compliance Team run by Chief Risk Officer and Chief Information Security Officer (CISO) reporting to the Chief Executive Officer (CEO)

Global Security and Compliance monitors the information security across the systems.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Changes are tracked in a central change management system with an approval process run by our change review board. Changes are reviewed for completeness and evaluated for risk as well as rollback, testing and user impact / communication.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Patching and Vulnerability management, anti-malware, endpoint disk encryption and intrusion prevention are managed via our Information Technology asset and endpoint management solutions. All workstations and servers are mitigated in an agreed, scheduled maintenance window following change management procedures with proper customer and end-user notification. For cloud based systems, automated agents continuously scan the environment looking for new security vulnerabilities. All alerts are sent to our 24x7 Virtual Security Operations (vSOC) team. Systems are patched following remediation times of: Critical (same week or sooner), High (within 2 weeks), Medium (within 90 days), Low (within 120 days).
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Insight systems are continuously monitored for security and use. All actions taken by personnel on production systems are logged and scanned for threats, including an Security Information Event Management (SIEM system) for threat analytics, which is regularly monitored by and alerted to Security personnel. Audit logs are maintained for a minimum of 90 days online plus 365 days in offline storage.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Our Cyber Incident Response Team (CIRT) monitors alerts 24x7 365 with an established incident response plan. Our CIRT team works to notify customers and to resolve any security incidents working together with their security teams.

Reports are sent per customer contract
Users report incidents to the cyber incident response team
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Bsi
ISO/IEC 27001 accreditation date
Tuesday 17 December 2024
What the ISO/IEC 27001 doesn’t cover
Not applicable.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Bsi
ISO 9001 accreditation date
Wednesday 31 January 2024
What the ISO 9001 doesn’t cover
Not applicable.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
9c3e47ae-3d10-47b2-81aa-5a8be4c7d4af
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
88f09d72-569f-4281-8de0-3a985e4280eb
Other security certifications
Yes
Any other security certifications
BS 10008:2014 Evidential weight and legal admissibility of electronic information

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidmanagementwe@ironmountain.com. Tell them what format you need. It will help if you say what assistive technology you use.