EDT Solution
EDT delivers a secure cloud-native evidence and case management solution for UK regulators, law enforcement and prosecutors. One configurable platform unifies processing, workflows, review and disclosure. Incorporating defensible AI and continuous innovation, EDT supports evolving data types, compliance obligations and operational needs. Engagements include governance, SLAs, support and user enablement.
Features
- Unified evidence and case management platform for investigations and disclosure
- Processing and analysis of complex and emerging digital evidence types
- Integrated UK‑aligned disclosure and eDisclosure workflows
- AI‑augmented analytics for investigative insight
- Highly configurable workflows, fields, templates and user roles
- Secure cloud and private cloud deployment options
- Comprehensive audit trails and defensible evidence handling
- Advanced search, review, redaction, and annotation tools
- Controlled collaboration across teams/agencies with granular sharing
- Included service: governance, SLAs, change, release, user enablement, support
Benefits
- Eliminate silos across evidence, cases, review and disclosure
- Reduce data transfers, duplication, rework and compliance risks
- Increase efficiency across investigations, disclosures, and prosecutions
- Protect sensitive sources and operational integrity through strong access controls
- Meet disclosure obligations with configurable UK-aligned workflows
- Gain insight through defensible compliant AI‑assisted analytics
- Replace multiple point solutions with one integrated platform
- Reduce operational risk through SLAs, governance and incident management
- Scale securely from routine matters to complex investigations
- Accelerate adoption with embedded enablement, guidance and advisory support
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 7 0 8 0 8 7 5 9 3 6 1 3 8 2
Contact
EDISCOVERY UK LIMITED
EDT G-Cloud Team
Telephone: +61410687266
Email: info@edt.io
About your service
- Service categories
-
Applications
Content workflow and management
- EDiscovery and forensics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- Planned updates and enhancements are deployed under EDT’s service management framework and may require brief, scheduled maintenance windows. Where possible, EDT releases changes with no material impact to service availability. Clients are notified in advance of planned releases and provided with release notes. Urgent security patches and critical defect fixes may be applied outside the standard release cycle where required, with appropriate client communications.
- System requirements
-
- Internet connection required; faster connections improve user experience
- Latest versions of Chrome, Edge, Firefox, or Safari supported.
- OS‑agnostic; requires supported modern web browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is provided by our UK-based, security-cleared team during UK business hours, with global follow‑the‑sun support outside these hours. Support tickets can be logged 24x7. Major incident coverage is provided 24x7. Enhanced out‑of‑hours support coverage can be arranged in advance by agreement.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
EDT provides a structured, tiered support model, including.
Support levels provided
• Level 1 – Service Desk: First line support for incidents, service requests, and guidance
• Level 2 – Application Support: Functional, workflow, and configuration support
• Level 3 – Platform Engineering: Specialist engineering and development support for complex technical issues
Support is delivered through a single Service Desk using an online portal and email, with ticket logging available 24/7.
Cost of support levels
Standard support, including service desk, application support, platform engineering, is included within the subscription price.
Optional professional services (such as bespoke configuration, advanced advisory services, or additional training) are available at additional cost.
Account management
Each customer is assigned an Account Manager who acts as the primary point of contact for coordination, escalation, service reviews, and ongoing optimisation. Platform engineers and subject matter experts support them as required. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Getting started with EDT typically begins with a structured onboarding and initiation phase. This includes a project kick-off to agree governance, roles and responsibilities, delivery approach, security requirements, platform readiness, and success measures. EDT then works collaboratively with the client through scoping and design workshops to align platform configuration, workflows, permissions, and operational scenarios to the organisation’s needs and best-practice usage.
User enablement is delivered through a structured enablement program rather than one-off training. This approach is designed to support effective adoption and long-term self-sufficiency. It includes role-based user enablement, scenario-driven walkthroughs, and a formal Train-the-Trainer strategy that equips nominated client trainers with the knowledge and confidence to deliver ongoing enablement internally.
Training and enablement are primarily delivered remotely through instructor-led online sessions, supported by comprehensive user documentation, reference materials, and recorded content. Where required, onsite delivery can be provided by agreement.
During onboarding and early use, EDT provides live demonstrations, guided walkthroughs, and remote assistance to support configuration, early adoption, and knowledge transfer. Following go-live, EDT continues to support users through service management, guidance, optimisation, and ongoing enablement as part of business-as-usual operations. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
When the contract ends, EDT enables secure export, transfer, or deletion of customer data.
Authorised users can export case materials (documents and metadata) in industry‑standard formats suitable for downstream use. Exports may be self‑service or assisted by EDT.
Where needed, EDT prepares a transition‑out plan and works with the client to transfer data and provide essential technical documentation.
Upon written confirmation that the client has received their data, EDT can perform secure deletion, with audit evidence supplied to the client. - End-of-contract process
-
At contract expiry or termination, EDT works with the client to agree the appropriate exit approach in line with the contract.
EDT supports the secure export, transfer, or deletion of customer data, using agreed industry‑standard formats. Following confirmation that data has been successfully transferred or no longer required, EDT permanently deletes customer data from its systems in accordance with agreed security and compliance requirements.
Where required, EDT will agree an orderly transition‑out approach with the client.
Any end‑of‑contract activities, timelines, and arrangements are agreed with the client in advance to ensure a clear, secure, and compliant service closure. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- EDT is a secure, browser‑based interface designed for regulators, investigators, and prosecution teams managing complex digital evidence and case workflows. The interface is highly configurable, supporting role‑based views, custom fields, workflows, and permissions. Administrators can tailor the user experience to specific case types and operational requirements, including reusable case templates with pre‑configured settings and tools. The interface is intuitive for non‑technical users while providing advanced functionality for power users, enabling consistent, efficient, and adaptable case management.
- Accessibility standards
- None or don’t know
- Description of accessibility
- EDT is fully committed to accessibility and our engineering team adopts Accessibility-by-Design principles within our Software Development Life Cycle. We regularly audit our user interface experience against the standard and are committed to full compliance with WCAG 2.2 AA by Q4 2026.
- Accessibility testing
-
EDT has performed internal checks including keyboard-only navigation, focus visibility and order checks, and limited screen reader spot checks on key workflows. We have also run automated accessibility scanning on representative pages to identify common issues such as missing labels, insufficient colour contrast, and incorrect heading structure.
We are expanding this into a formal accessibility test approach targeting WCAG 2.2 AA, including documented test cases, regression checks per release, and planned external validation with assistive technology users. We also collaborate with our clients' accessibility experts and advisors to ensure external validation of our user design. - API
- Yes
- What users can and can't do using the API
-
EDT provides two primary APIs. The EDT Import API enables automated ingestion of processed, unprocessed, or hybrid datasets into EDT, supporting end-to-end data pipelines and integration with existing collection or processing tools.
The EDT Core API exposes over 330 endpoints, allowing authorised users to read, search, create, update, and delete core assets and their associated metadata. This enables technical users to automate workflows, build custom interfaces, implement bespoke integrations, and support reporting or analytics aligned to investigative and regulatory requirements.
All APIs are designed to support automation at scale while maintaining full audit trails and evidential integrity. Authentication is controlled through scoped API credentials, and all API activity is logged to support security and chain‑of‑custody requirements. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
EDT supports extensive configuration of business processes, workflows, and rules. Users can customise data fields, user roles and permissions, and interface elements. The user interface can be tailored to support specific workflows, such as investigations, document review, disclosure, and case management. Reusable case templates can also be configured with predefined settings, workflows, and layouts.
Customisation is performed via the EDT UI using configuration tools designed for non‑technical administrators. Changes can be applied at the organisation, case, or workflow level and adapted over time as requirements evolve, without custom development or vendor intervention.
Customisation is controlled through role‑based permissions. Authorised administrators can configure fields, workflows, templates, roles, permissions, and interface layouts. End users interact with the tailored interface appropriate to their role but cannot change core configurations unless explicitly authorised.
Scaling
- Independence of resources
- The solution is designed to scale at both the software and infrastructure levels to ensure users are not impacted by other users’ demand. It leverages application load balancers, auto‑scaling groups and serverless compute to automatically provision capacity as usage increases. Web services scale horizontally, and processing workloads are isolated to prevent contention. Case data and files are stored in cloud‑based services offering virtually unlimited scalability. If a private cloud deployment is selected, customers are provided with dedicated resources ensuring full isolation. Auto‑scaling is included within the SaaS subscription to maintain consistent performance during peak usage periods.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides operational and usage metrics through extensive reporting and monitoring features. Metrics include service availability, incident response and resolution times. Usage metrics include active users and hosted data volumes. An integrated Report Builder enables authorised users to generate out‑of‑the‑box or fully customised reports with charts, pivots and filtering. Users can create editable dashboards displaying live data and generate reports using automated templates.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Data export is controlled through role‑based permissions. Authorised users can export case data from the EDT platform using the application’s export capabilities.
Data can be exported in industry‑standard formats, including native documents, images, extracted text, and associated metadata, suitable for archiving or use in other review platforms. Export formats are agreed based on case requirements and organisational standards.
Exports can be completed on a self‑service basis or with EDT assistance for larger or more complex data sets. Secure transfer methods are used in line with agreed security and compliance requirements. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Concordance DAT standard legal export
- EDRM XML metadata and document export
- Microsoft Access export
- Excel‑compatible spreadsheet export
- IPRO LFP image load file export
- Nuix Discover or Ringtail MDB export
- Opticon OPT image load file export
- Relativity default load file export
- Summation compatible load file export
- Native files, images, PDF, text and media
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- CSV, Excel (XLS/XLSX), DAT and tab‑delimited files
- Microsoft Access MDB databases and Ringtail export MDBs
- Concordance, Relativity and Summation load file formats
- Cellebrite XML and UDFR mobile device exports
- Forensic image files used in digital investigations
- Native documents such as DOCX, XLSX and PDF
- Unstructured data including folders and mixed file types
- Compressed archives such as ZIP files
- Common audio and video media formats
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
As an AWS Advanced partner participating in the AWS Public Sector Solution Provider program, EDT leverages secure, scalable and highly available AWS services to deliver the EDT Solution. AWS infrastructure provides high reliability, with SLAs offering 99.99% uptime for many services.
EDT offers multiple private cloud hosting options to ensure client recovery point and recovery time objectives are met. - Approach to resilience
-
AWS infrastructure provides high levels of security, resilience, and reliability, with 99.99% uptime SLAs offered for many services.
The EDT Solution architecture and EDT's Business Continuity and Disaster Recovery plan include controls designed to mitigate availability risk, including: use of AWS services with high availability and automatic dispersion across AWS Availability Zones within the nominated AWS Region, automated backup schedules, and the application of standard secure configurations using infrastructure-as-code to minimise downtime if a tenancy rebuild is required.
Annual disaster recovery tests are conducted for each EDT Solution private cloud tenancy and EDT's corporate environment. - Outage reporting
- AWS provides availability dashboards, and EDT actively monitors the performance and status of EDT Solution tenancies. Alarms are configured to notify EDT's team, and EDT's incident management process ensures that nominated client contacts are notified of any service outages as soon as practicable. A post-incident report is also provided for full transparency into the root cause and assurance that actions have been taken to prevent recurrence.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Client EDT Solution administrators are responsible for managing Client User access via the EDT Solution user interface. EDT provides custom access group functionality that enables clients to implement role-based access control and segregation of duties using any combination of permissions.
The EDT Solution provides two authentication options; native EDT Accounts with multi-factor authentication (MFA) and SAML2-based SSO integration via an identity provider.
EDT controls access to the hosting AWS environment, which is strictly controlled in accordance with the principle of least privilege, and requires frequent authentication via EDT's identity provider. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
• ISO/IEC 27017:2015
• SOC 2 Type II
• Cyber Essentials
• IRAP (EDT AusGov SaaS Solution) - Information security policies and processes
-
EDT operates a mature multi-framework Information Security Management System (ISMS) designed to safeguard EDT and Client Data against confidentiality, integrity, and availability risks. This includes a comprehensive information security strategy and policy framework to guide EDT's security culture and operational security procedures.
EDT's ISMS is certified against ISO/IEC 27001:2022 and ISO/IEC 27017:2015, and undergoes annual audits, including ISO surveillance and SOC 2 Type II audits. EDT’s ISMS also ensures compliance with applicable jurisdictional legislation and standards.
EDT's Information Security and Privacy Governance Committee (ISPGC) oversees EDT's ISMS and Information Security Program (ISP), meeting monthly to monitor control effectiveness and program performance. EDT's ISP includes a structured calendar of internal and external assurance activities and continuous improvement initiatives to ensure EDT's ISMS remains effective and aligned with evolving risks, threats, and best practices.
Client data stored in EDT Solution tenancies is classed as Restricted - the highest classification level defined in EDT's Information Asset Management Policy, and clients may request evidence of EDT's security controls, audit reports, and certificates to support their own governance requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- EDT's ISMS framework includes a comprehensive change management policy and procedures. Changes are classified as standard, minor, major, or emergency, with a clear definition and approval processes for each. Major (high-impact) changes to the EDT Solution architecture must be reviewed and approved by EDT's Architecture Review Board (ARB). This cross-functional committee includes full executive membership and senior technical leaders who must assess security risks before approving or rejecting proposed changes. Minor (low-to-medium impact) changes to the EDT solution must also be approved through defined operational workflows, including vulnerability scanning, peer review, and approval. Standard changes are low-impact and pre-approved.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- EDT operates a vulnerability detection and management program. Static Application Security Testing (SAST) is performed on the EDT software production codebase, all code changes, and third-party libraries. Dynamic Application Security Testing (DAST) conducts external application vulnerability scans for each EDT Solution tenancy. EDT Solution tenancy hosts are continuously scanned for third-party vulnerabilities. Penetration Tests are completed annually for each EDT Solution tenancy with 'continuous penetration testing' tools running daily to assure the perimeter in between. Operating system patches are installed automatically where possible, as quickly as possible, and the maximum target timeframe for treating all vulnerability levels is 30 days.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
EDT leverages AWS logs and tools, including Amazon GuardDuty, to monitor EDT Solution tenancies for signs of compromise. EDT responds to alarms promptly and within client-agreed SLAs.
EDT has also recently partnered with a globally trusted managed detection and response service to enhance security monitoring and incident response capability, with implementation planned for all EDT Solution tenancies by the end of 2026. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- EDT's ISMS framework includes a comprehensive Incident Management Plan that is aligned with the phases recommended by NIST, including preparation, detection, analysis, containment, eradication, and recovery. Incidents must be reported via designated communication channels, and EDT's designated Major Incident Response Team completes annual tabletop exercises to ensure the plan remains effective. EDT's incident management process ensures that nominated client contacts are notified of any service outages as soon as practicable and in accordance with the contract. A post-incident report is also provided to for transparency regarding the root cause and assurance that actions have been taken to prevent recurrence.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 11.5%
- Between £250,000 and £500,000
- 8.5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 10.5%
- Over £5,000,001
- 12.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Certified by A-LIGN (accredited by ANSI National Accreditation Board)
- ISO/IEC 27001 accreditation date
- Tuesday 9 December 2025
- What the ISO/IEC 27001 doesn’t cover
- Not applicable
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ea8f8ba0-dcfe-4c50-9046-848f90977d62
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- ISO/IEC 27017:2015
- SOC 2 Type II
- IRAP (EDT AusGov SaaS Solution)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-