Skip to main content

Help us improve the Digital Marketplace - send your feedback

SUPPECO LIMITED

Suppeco Core

Suppeco helps companies manage suppliers to get more value from their supplier relationships through better collaboration and performance tracking.

Features

  • Live Interactive Insights
  • Unlimited Stakeholder Mapping
  • Ecosystem-Wide Collaboration
  • Automated Workflows & Push Alerts
  • Supplier Account Plans
  • Shared Document Repository
  • Enterprise-Grade Security
  • Instant Deployment – No Customisation Required
  • Collaborative Comms Workspaces
  • KPI Creation Suite & Score Management

Benefits

  • Reduces Value Leakage Post-Contract
  • Makes Relationship Value Measurable
  • Enables Day-One Value Creation
  • Increases Operational Efficiency Through Automation
  • Surfaces Hidden Risks Before They Escalate
  • Supports ESG, Sustainability & Compliance Goals
  • Drives Cross-Functional Supplier Collaboration
  • Improves Supplier Performance & SLA Adherence
  • Integrates Seamlessly with Existing Systems
  • Enables Radical Transparency Across Tiers

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sheldon.mydat@suppeco.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 7 8 3 5 0 6 3 3 4 3 0 1 5 4

Contact

SUPPECO LIMITED Sheldon Mydat
Telephone: 07912651940
Email: sheldon.mydat@suppeco.com

About your service

Service categories

Applications

Collaborative

  • Enterprise community
  • Team collaboration
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
No constraints.
System requirements
  • TLS 1.2 or higher enabled in browser
  • Reliable and stable internet connection
  • Supported recent operating system
  • HTTPS (port 443) open, WebSocket support recommended for real-time features
  • Recommended: 10+ Mbps for smooth performance
  • Ability to make outbound HTTPS requests (if using API)
  • HTML5-compliant web browser
  • Local username/password supported or Optional: Federated identity (e.g. single sign-on)
  • Minimum 100MB free-space (for browser cache and local storage)
  • Processor: Dual-core, 1.5 GHz or higher

User support

Email or online ticketing support
Yes
Support response times
24/7 online support. The response process remains active on weekends, although like many SaaS platforms, response times may be slightly slower during non-core business hours, depending on severity and region.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Our Chat agent Branda is based on ChatGPT and operates yto equivalent standards but does equate to formal WCAG 2.1 AA conformance
Onsite support
No
Support levels
Suppeco provides a single, comprehensive support tier included in all licensing - there are no gated service levels or hidden fees. Support is available 24/7 via the in-platform Contact Support feature and email. All customers - including those in pilot or trial phases - have access to dedicated onboarding, structured discovery sessions, in-app guidance, and ongoing customer success engagement. Critical issues are triaged immediately, with prompt escalation where needed.

While there is no formal SLA published in standard materials, typical response times for general queries are within 4 business hours, often faster during core working hours. Complex issues may involve live screen-share sessions or scheduled support calls, coordinated through your Customer Success contact. Suppeco also provides regular touchpoints, supplier teach-ins, and relationship reviews as part of the service - not an optional add-on.

Real-time web chat and phone support are not standard offerings. The support model prioritises partnership, fast turnaround, and relationship-led engagement - not ticket queues or tiered service desks. All assistance is designed to help drive platform adoption, user confidence, and measurable supplier engagement.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Getting Started with Suppeco

Discovery & Onboarding Sessions

Collaborative setup workshops to align platform configuration with your goals

Guidance on supplier segmentation, workspace design, and governance structure

Platform Configuration Support

Help setting up supplier workspaces, KPIs, roles, and performance workflows

Assistance importing initial supplier and contract data if needed

Training & Teach-ins

Live virtual sessions for internal users and suppliers

Covers how to use dashboards, enter scores, manage documents, and engage in workspaces

Ongoing Customer Success Engagement

Regular check-ins, reviews, and optimisation support

Real-time assistance via in-app support or email

No-code, ready-to-use platform

No IT lift required - users can engage directly from day one with a browser and login
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data Extraction at Contract End

Full Data Portability

Customers retain ownership of their data, including supplier records, contracts, KPIs, performance history, commentary, documents, and governance logs.

Export Options

Data can be exported in structured formats such as CSV, JSON, or other agreed formats.

Suppeco’s team can assist with bulk exports of relational data, files, and insights.

APIs Available

Customers can use Suppeco’s APIs to extract data programmatically before contract closure if preferred.

Support Provided

The Customer Success team provides direct support during offboarding to ensure a smooth and complete data handover.

Security & Compliance

Data extraction follows GDPR and ISO 27001-aligned protocols, ensuring confidentiality, integrity, and traceability throughout the process.
End-of-contract process
At the end of a Suppeco contract, platform access is deactivated unless renewed. Users retain full ownership of their data and can extract all supplier records, documents, KPIs, commentary, and governance history. Suppeco supports this with structured data exports (e.g. CSV, JSON) and API access, and the Customer Success team provides offboarding guidance. All data is handled in accordance with GDPR and ISO 27001-aligned retention and deletion policies.

Included in the contract price is support for data extraction, access to APIs during the contract term, and secure handling of your data through the offboarding process. There are no hidden fees for exporting standard data.

Additional costs may apply if you request non-standard services, such as bespoke data formatting or transformation, extended platform access beyond contract expiry, or custom reporting outputs. Legal or audit support for specific certifications or forensic data may also be chargeable, if outside the scope of standard offboarding.

Suppeco is designed to avoid vendor lock-in, making sure you can transition cleanly with full access to your data.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
There is no degradation of features and data on responsive devices.
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
Suppeco provides a secure, API-first platform that allows customers to integrate supplier, contract, and performance data into and out of the system. Users can use the API to import supplier records, sync contract milestones, push performance scores or KPI data, extract reports into BI tools, and trigger workflow actions such as reviews or escalations. Communication metadata (e.g. from email or chat) can also be ingested for analysis by Suppeco’s AI engine, SuppEQ.

However, users cannot bypass role-based access controls or access other customer environments. The API does not allow modification of Suppeco’s core UI or platform behaviour. Users also cannot directly control SuppEQ’s AI outputs or disable platform-enforced security features like audit trails, encryption, or document versioning. All integrations respect Suppeco’s security architecture and permissions model.

The API is intended to extend Suppeco’s functionality within your enterprise environment - particularly for ERP, procurement, or BI tool integration - without compromising control, visibility, or compliance. For specific use cases, full API documentation can be shared by the Suppeco team.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Suppeco is fully configurable, allowing users to tailor the platform without custom development. Supplier workspaces can be customised by category, business unit, or region, with specific governance layers, stakeholder roles, and data visibility settings. Users can define their own KPIs, scoring rules, review cadences, and trigger automated alerts for missing or poor performance data.

Governance structures are flexible, supporting segmentation-based models with customised meeting types, escalation paths, and responsibilities. Users can upload and manage contracts, compliance documents, ESG evidence, and collaboration notes - with role-based access to control who sees what.

Role-Based Access Control (RBAC) allows precise permissions for internal teams, suppliers, and third parties, ensuring secure collaboration. Interface branding can be customised with company logos and adapted language. For integration needs, Suppeco offers APIs to connect with ERP systems, BI tools, and other enterprise platforms.

All configurations are made via the user interface - no coding or custom builds are required. Suppeco is designed to reflect the complexity of real-world supplier relationships while remaining easy to deploy and manage.

Scaling

Independence of resources
Suppeco runs on a scalable, multi-tenant cloud architecture within Microsoft Azure. It uses elastic resource allocation, autoscaling, and load balancing to ensure consistent performance, even under varying demand. Each customer environment is logically isolated, and real-time monitoring ensures that usage spikes from one user or organisation do not affect others.

Analytics

Service usage metrics
Yes
Metrics types
Yes, Suppeco provides detailed service usage metrics. Users can track platform activity, including logins, engagement levels, workspace utilisation, document sharing, KPI updates, and participation in reviews. Metrics cover both internal users and suppliers, helping organisations monitor adoption, collaboration, and governance performance. Data can be viewed within the platform or exported for reporting.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
ISAE 3402 certification at the data centre and infrastructure layer.

Application-layer controls are aligned with ISO 27001
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Suppeco allows users to export supplier data, KPIs, documents, and performance records using built-in tools or APIs. Exports are available in standard formats like CSV or JSON, with role-based access controls in place. At contract end, the Customer Success team assists with data extraction. Standard exports are included in the contract. Additional costs may apply for non-standard formats, data transformation, or extended access. All exports follow strict security and compliance standards.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • PDF
  • Standard document Formats
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • PDF
  • DOCX, XLSX

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Suppeco protects data within its network using encryption at rest, secure access controls, and ISO 27001-aligned security practices. Data is stored in Microsoft Azure with built-in redundancy and continuous monitoring. Role-Based Access Control (RBAC) ensures users can only access authorised data. All access is logged and auditable, with regular vulnerability scanning and security patching. Sensitive information is encrypted using industry-standard algorithms, and backup processes follow strict retention and recovery policies.

Availability and resilience

Guaranteed availability
Suppeco is architected for high availability and resilient performance, operating within Microsoft Azure’s enterprise-grade infrastructure. Platform availability typically exceeds 99.9%, supported by autoscaling, redundancy, and 24/7 monitoring.

Service Level Agreements (SLAs) for availability can be defined in customer contracts, particularly for enterprise deployments. These SLAs may include agreed uptime targets and associated remedies, such as service credits, if availability falls below the contracted threshold.

The availability framework is underpinned by Azure’s infrastructure SLAs and enhanced by Suppeco’s operational controls, which include proactive monitoring, incident response procedures, and scheduled maintenance planning. Specific SLA terms, including uptime percentages and any refund mechanisms, are scoped during commercial agreement.
Approach to resilience
Suppeco is built for resilience using a cloud-native architecture hosted on Microsoft Azure. The platform supports autoscaling, load balancing, and application redundancy to maintain performance and uptime during variable demand or component failure. Continuous monitoring, regular backups, and defined recovery procedures help ensure service continuity and data protection.

At the infrastructure level, Suppeco benefits from Azure’s globally distributed data centres, which provide physical and operational resilience. These include redundant power, networking, and cooling systems, along with data replication across availability zones. Azure’s infrastructure meets standards such as ISO 27001, SOC 1/2, and ISAE 3402, supporting high availability and fault tolerance.
Outage reporting
Suppeco reports service outages through multiple direct communication channels. Customers are informed via:

Direct email to designated contacts

Customer Success outreach for real-time coordination and updates

Platform notifications if accessible during partial outages

Periodic newsletters for broader updates and post-incident summaries, where appropriate

For major incidents, Suppeco provides impact updates and can deliver a root cause analysis (RCA) after resolution. All events are logged and managed under formal operational procedures. Suppeco does not currently use a public status page; all communication is handled directly with affected customers.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Other user authentication
Suppeco authenticates users through secure, role-based login methods. Standard authentication uses email and password with enforced complexity and expiration policies. The platform also supports Single Sign-On (SSO) via identity providers such as Microsoft Entra ID, allowing integration with enterprise authentication systems. Access is further controlled through role-based access control (RBAC), ensuring users can only access authorised features and data. All authentication events are logged for audit and monitoring purposes.
Access restrictions in management interfaces and support channels
Suppeco restricts access to management interfaces using Role-Based Access Control (RBAC), with admin rights granted only to authorised staff. Privileged accounts require multi-factor authentication, and all actions are logged and reviewed. Support access is limited to authorised personnel on a session basis, with customer approval where needed. User identity is verified before sharing sensitive information, and all support activity is auditable.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Suppeco is certified under both ISO/IEC 27001 and the Cyber Essentials scheme, demonstrating a strong and verifiable commitment to information security.

Its ISO 27001-certified Information Security Management System (ISMS) governs data protection, access control, risk management, incident response, and operational security. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), with all services hosted on Microsoft Azure’s secure infrastructure, which holds additional certifications including ISO 27001, SOC 1/2, and ISAE 3402.

Cyber Essentials certification confirms Suppeco meets UK government-backed standards for protection against common cyber threats, covering firewalls, access controls, patching, malware protection, and secure configuration.

Suppeco enforces role-based access control (RBAC), audit logging, and continuous monitoring. Security practices include annual external penetration testing, regular vulnerability scanning, and secure backup and sanitisation procedures. Staff receive ongoing security training, and policies cover user lifecycle management, change control, asset handling, and acceptable use.

Documentation to support assurance reviews is available under NDA where required.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Suppeco follows ISO/IEC 27001-aligned change management. Components are tracked via asset registers and version control. Changes are assessed for operational and security impact, reviewed by relevant teams, and categorised by risk. Deployment runs through non-production, UAT, smoke test, and production environments with peer review, automated testing, and rollback plans. Only authorised staff can make changes. All actions are logged and monitored post-deployment.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Suppeco operates a structured vulnerability management process aligned with ISO/IEC 27001. Vulnerabilities are identified through automated scanning, penetration testing, and monitored threat intelligence feeds (e.g. vendor alerts, CVE bulletins, Microsoft Azure advisories). Threats are assessed based on criticality, exposure, and business impact. Patches for critical vulnerabilities are typically deployed within 48 hours, with lower-risk issues managed through scheduled releases. The process includes risk scoring, logging, remediation tracking, and periodic review. Suppeco’s approach ensures timely, risk-based mitigation of vulnerabilities across all services, infrastructure, and dependencies.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Protective Monitoring Practices

Continuous system and infrastructure monitoring using Microsoft Azure’s built-in security tooling

Audit logging of all access, configuration changes, and user activity

Anomaly detection and alerting based on pre-defined rules and threat patterns

Log retention and review in line with data protection and compliance requirements

Role-based access monitoring to detect unauthorised access or privilege misuse

Regular vulnerability scanning and security event reviews

Incident response procedures linked to monitoring outputs to enable rapid investigation and containment.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Suppeco follows ISO/IEC 27001-aligned incident management with pre-defined processes for common events like outages or unauthorised access. Users can report incidents via in-app support, email, or their Customer Success contact. Incidents are triaged, investigated, and resolved with updates provided directly. Formal incident reports (including root cause and actions taken) are available on request. All incidents are logged and reviewed for continuous improvement.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
The VFP (Value First Pilot) is a time-boxed, live deployment of Suppeco’s core capabilities, designed to deliver measurable value quickly. It focuses on specific supplier relationships, enabling collaboration, insight generation, and performance improvement within a defined scope, without full platform rollout.
Link to free trial
https://docsend.com/view/mb7siwspi4ip9m8p

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
8%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
12%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Citation Cyber
ISO/IEC 27001 accreditation date
Saturday 6 May 2023
What the ISO/IEC 27001 doesn’t cover
Current certification renewing 05/05/2026
Our ISO/IEC 27001 certification covers Suppeco’s core platform, people, processes, and controls used to deliver and support the live service. The following are not within scope:

Customer-managed environments and controls, including user devices, local networks, identity governance, and customer configuration choices.

Third-party services outside our ISMS scope. Key suppliers (e.g. cloud infrastructure) are risk-assessed and contractually managed, but their internal ISMS certifications are separate.

Customer data governance decisions, such as data classification, retention policies, and lawful basis determinations, beyond the controls provided by Suppeco.

Professional or advisory services delivered outside the platform, unless explicitly stated as in scope.

Non-production or experimental tools that do not process live customer data, such as internal R&D or proof-of-concept environments.

All production environments processing customer data and the operational controls supporting them are included within the certified ISMS.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
7c18c5db-e52e-48db-a009-e297028396ed
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sheldon.mydat@suppeco.com. Tell them what format you need. It will help if you say what assistive technology you use.