Skip to main content

Help us improve the Digital Marketplace - send your feedback

MAS NETWORKS LTD T/A CARELINELIVE

CareBrokerage

CareBrokerage, an easy to use, cloud-based software solution, streamlining care commissioning/brokerage processes, improving data collection allowing commissioners/brokers/care arrangers to take full control of the process from contracting->compliance->performance management. CareBrokerage stores multiple purchaser details (commissioning bodies/adult social care clients/self-funded service users). Purchasers and providers are allocated to geographical regions/subzones.

Features

  • Streamlines care commissioning/placement processes and improves the collection of data.
  • Stores details of multiple purchasers/funders, geographically.
  • Commissioners/brokers/care arrangers can add new care packages to the system.
  • No limit to the number of providers added.
  • Providers only notified about (and see) their own care packages.
  • New care package notifications sent by email/via provider dashboards.
  • Open care packages dashboard has configurable tier/priority “count down” capability.
  • New care packages can be requested by the providers.
  • Awarded and requested but declined care packages clearly shown.
  • Providers can see how long a package remains on offer.

Benefits

  • Supports rapid, efficient care package placement, replaces emailing/spreadsheets/chasing by phone.
  • Allows commissioners/brokers/care arrangers to take full control of the process.
  • Supports efficient contract compliance and performance management including via reporting.
  • Enables hybrid working.
  • Care packages can be offered efficiently based on service requirements/types/geography.
  • Enables contextual reference to supporting documents.
  • New providers can be added very quickly.
  • Efficient method for providers to request new care packages.
  • Efficient method for providers to see awarded/requested/declined care packages.
  • Reasons given by commissioner help reduce need for voice communication.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@carelinelive.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 7 8 7 0 3 6 2 2 5 1 6 0 9 0

Contact

MAS NETWORKS LTD T/A CARELINELIVE Peter Briggs
Telephone: 0330 088 5767
Email: sales@carelinelive.com

About the service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
  • Adult Social Care
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
CareBrokerage cloud software is web-based, so it can be accessed from any suitable, Chromium-based browser enabled device, e.g. Chrome, Edge, Chrome preferred, with an internet connection.
System requirements
  • CareBrokerage: via secure internet Chromium-based browser login.
  • Two latest versions of Chrome/Edge, latest version recommended.
  • Desktop/laptops required for UI access.

User support

Email or online ticketing support
Yes
Support response times
Issues raised by email: MAS Networks Ltd use best endeavours to determine (during Working Hours, i.e. Mon-Fri 9am - 5:30pm excluding public holidays in England, unless stated otherwise below) whether an issue affects protected functionality and into which priority category an issue raised falls. Priority categories:
Critical (reported 24x7)
High
Medium/Normal
Low
Target acknowledgement (email): 30 minutes.
Issue target response and fix times:
Critical: 2 hours response, 4 hours fix (24x7x365 clock)
High: 4 hours response, 2 working days fix
Normal: 8 hours response, 7 working days fix
Low: 3 working days response, future release fix
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
CareBrokerage Support Service operates 24x7x365 days p.a. for Critical (Cloud software service down, not due to customer specific localised issues affecting a customer such as failure of customer devices, mobile coverage, or local internet access etc.) issues, and during office hours (9:00 a.m. – 5:30 p.m., Monday to Friday excluding English public holidays) for all issues.

The Support Service is the first point of contact for all Customer enquiries and service-related issues, receives support requests via email to our support portal 24x7x365, or by phone during office hours. Support calls/emails/messages are logged, processed and followed up by our Support Service Staff for the cloud software SaaS prices quoted.

CareBrokerage Support Service also provides general advice and guidance on Service use, incident knowledge, workarounds and next release information.

Client management:

During implementation, MAS Networks’ Project Manager is responsible with escalation to the designated MAS Networks' Account Manager for the customer, and then MAS Networks' Operations Director or Managing Director if/when applicable.

Post implementation, MAS Networks' designated Account Manager and Contract Manager for the customer are responsible for BAU liaison and Contract and Performance reviews respectively, with escalation to MAS Networks' Operations Director or Managing Director if/when applicable.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide business process guidance to aid customers define the most appropriate changes to their business process to obtain maximum benefit from our cloud software. Upon implementation CareBrokerage cloud software will then reflect the new business process requirements and workflow as configured. We then provide contextual online training, and user documentation (collectively onboarding), plus support via a designated project manager, and our Support Service.

Training and documentation
Comprehensive training is part of our onboarding process.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
MAS Networks will assist with the migration of data at the end of the contract, in a CSV Export format for CareBrokerage, with the following quite straightforward process which is our standard approach in this regard:
1. The Buyer provides written contract termination notice to: accounts@mas-group.co.uk
2. The Buyer will receive a written notification reply letting you know we have received the request. Our reply will include the end date.
3. MAS Networks will confirm at the same time what data we will be able to extract and deliver to you, please see the Service Definition for details.
4. The Buyer will be provided instruction on how to receive your data. The data comes in the form of CSV exports for CareBrokerage.
5. MAS Networks will delete the Buyer data in our hosting including any back-ups, within 3 months of the termination date, typically as stipulated in the Call-off Contract.
End-of-contract process
Our quoted cloud software SaaS charge normally includes sufficient time in each contract for our designated project manager (exit) to prepare and agree the exit plan with the customer, then manage the exit (supplier side) and for our technical services team to offboard the customer's data, preparing the CSV file exports, prior to deleting the customer's data in accordance with the following quite straightforward process which is our standard approach in this regard:

1. The Buyer provides written contract termination notice to: accounts@mas-group.co.uk
2. The Buyer will receive a written notification reply letting you know we have received the request. Our reply will include the end date.
3. MAS Networks will confirm at the same time what data we will be able to extract and deliver to you, please see the Service Definition for details.
4. The Buyer will be provided instruction on how to receive your data. The data comes in the form of CSV exports for CareBrokerage.
5. MAS Networks will delete the Buyer data in our hosting including any back-ups, within 3 months of the termination date, typically as stipulated in the Call-off Contract.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and offboarding documentation would be shared via email on project commencement, and cessation respectively.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
CareBrokerage cloud software:
Browser based: instant access to the main functional areas of the CareBrokerage service via a vertical tool bar, and interactive dashboards. Multiple browser tabs can be kept open. Data entry/review is via configurable, auto verifying fields for data type at the point of saving if not before. Extensive use made of colours, graphic charts, fly by/hover over tips.
Accessibility standards
WCAG 2.2 A
Accessibility testing
Accessibility is managed internally by our Product Designer, QA Engineer, and Director of Development.
We use automated tools and manual testing by QA Engineer to establish, maintain and drive improvement in regards to accessibility.
Accessibility requirements are understood by our Product Designer, through experience of working in the industry, understanding the standards, and the use of automated tooling and manual testing is used to ensure compliance.
API
Yes
What users can and can't do using the API
We have several API endpoints in place or currently in development for fetching information, so we request that Buyers please contact us for the latest information in this respect. That said, our CareBrokerage API is in line with Gov standards: REST, OpenAPI documentation, HTTPS, UTF-8, JSON, authorisation will be via OAuth2; JSON response format.
Only push processing supported.

We would expect to work with the customer's analysts to develop a complete configuration blueprint that describes how the solution needs to be configured to deliver the full functionality.

Our consultants would work with the customer's and/or 3rd party system analysts using configuration tools supplied as part of the Solution to build the desired configuration into the base Solution, and to test completeness and accuracy. Typically, this work is scoped and priced within the contract value.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Multiple elements of the CareBrokerage platform are configurable, including the following:
• Framework provider tier lists are configurable, providing a priority-based package distribution.
• Tier timing is configurable as well as pauses between tiers if applicable.
• Zone/region management allowing packages to be broadcast to only users configured for the zone/region.
• Working hours are configurable so that the tiered timing only runs during the working hours specified.
• Access control so user privileges can be set by role (Role Based Access Control).
• Email notifications can be configured.
• Care Options such as Domiciliary, Supported Living and Care Home can be adapted with subcategories by the support team.
• SysAdmin can configure broker access level and zone administration

Scaling

Independence of resources
CareBrokerage is built using a SQL database architecture, utilising PostgreSQL, and therefore is inherently fully scalable. In addition, CareBrokerage is hosted for UK customers by Amazon Web Services (AWS) in London (UK), a Tier 4 professional datacentre, using AWS High Availability, Multi-AZ and spot instances allowing the platform to grow automatically as required, on demand to suit any load. Hence, with this in-built spare capacity for large surges in activity, and by hosting on high availability servers, our AWS hosting scales and shrinks using spot instances.

Analytics

Service usage metrics
Yes
Metrics types
Generally we would include the provision of the following service metrics and a review online with the customer on a quarterly basis:
1. Service availability levels.
2. Number of Customer-reported incidents at each priority level and fix times.
3. Number of supplier self-notified incidents at each priority level and fix times.
4. Any issues/support/breaches of the SLA.
5. Downtime periods.
6. Service availability figures and other relevant information to be provided to the Customer 5 days in advance of each meeting.
7. Product - issues and feature requests.
8. Product - new functionality exposure, anything in road map.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
CareBrokerage:
• Architecture adheres to NHS public cloud guidelines.
• Public cloud supplier, currently hosted+processed on AWS Tier-4 professional datacentre in the UK (London).
• Single-tenancy environment.
• Utilises PHP 8.2+PostgreSQL 14+Kubernetes 1.26
• BC/DR Plan available
• Auto-scaling architecture
• Backup: PITR+31-day snapshot retention, off-site replication, replication+failover enabled.
• No fixed-IP addresses.
• Strict firewall rules.
• Zero-trust methodology.
• Anti-malware protections.
• Web Application Firewall protects against DDOS attacks+potentially harmful connections.
• Automated testing of new software/dependency versions pre-deployment.
• Data stored at-rest encrypted using AES_256_GCM, data in-transit encrypted using AES_128_GCM, supported by TLS 1.3 minimum SSL connections.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
CareBrokerage cloud software includes the provision of 6 standard reports.

Plus the cost options of:
Custom reports, feasibility subject to scope and specification.
Data export formats
CSV
Data import formats
  • CSV
  • Other
Other data import formats
  • .doc
  • .docx
  • .xls
  • .xlsx
  • .pdf
  • .jpg
  • .jpeg
  • .png

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
CareBrokerage complies with current National Cyber Security Centre (NCSC) guidance as follows. CareBrokerage:
• All data stored at-rest is encrypted using AES_256_GCM, and data in-transit is encrypted using AES_128_GCM, supported by TLS 1.3 minimum for SSL connections, and;
• The platform has minimum password requirements in place.
• Is accessible via public internet; SSL enforced.
• Disables SSL 2.0, SSL 3.0, TLS 1.0 and TLS 1.1 protocols.
• Web services conform to local authority encryption standards.
• Utilises Service accounts with complex 32 character passwords.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
CareBrokerage:
• Architecture adheres to NHS public cloud guidelines.
• Public cloud supplier, currently hosted+processed on AWS Tier-4 professional datacentre in the UK (London).
• Single-tenancy environment.
• Utilises PHP 8.2+PostgreSQL 14+Kubernetes 1.26
• BC/DR Plan available
• Auto-scaling architecture
• Backup: PITR+31-day snapshot retention, off-site replication, replication+failover enabled.
• No fixed-IP addresses.
• Strict firewall rules.
• Zero-trust methodology.
• Anti-malware protections.
• Web Application Firewall protects against DDOS attacks+potentially harmful connections.
• Automated testing of new software/dependency versions pre-deployment.
• Data stored at-rest encrypted using AES_256_GCM, data in-transit encrypted using AES_128_GCM, supported by TLS 1.3 minimum SSL connections.

Availability and resilience

Guaranteed availability
We propose a Service Level Agreement, which includes the Target Service Availability of 99.85% for our hosted services in any given 12-calendar month period, 24 hours per day, 7 days a week, 365 days per annum, planned maintenance periods excepted.
Approach to resilience
CareBrokerage is an integrated solution, updating in real time, with all components developed by MAS Networks, hosted in the UK on AWS a Tier 4 professional datacentre, and we have 'automated' 24x7 monitoring.

As a consequence we have very high up-time records (to date showing 100% availability throughout 2024 & 2025, upto and including 28th Jan 2026 for MAS Networks Ltd CareLineLive care management suite cloud software solution!).

Indeed, we are classified as a Silver service by the NHS guidelines, reference this link: https://digital.nhs.uk/services/cloud-centre-of-excellence/cloud-security-good-practice-guide/9.-appendix-b-service-classifications

MAS Group also operate our own Business Continuity Plan, to maintain support to customers in the event of a threat to normal operations.

Consequently, we are pleased to confirm that we will provide our CareBrokerage solution with target availability of 99.85% (i.e. in the absence of P1 Critical system down, target availability is 99.85%, planned maintenance periods excepted).
Outage reporting
CareBrokerage is being enhanced. Please contact MAS Networks Ltd for details in this respect when procuring.

Identity and authentication

User authentication needed
Yes
User authentication
  • Username or password
  • Other
Other user authentication
In accordance with current National Cyber Security Centre (NCSC) guidance CareBrokerage:

a) All data is encrypted in-transit and at-rest, protecting against interception as well as unauthorised access to the underlying servers and supported by TLS 1.3 minimum for SSL connections, and;
b) the CareBrokerage platform has minimum password requirements in place. These are:

• Must be at least 8 characters long
• Must not be compromised, meaning:
• Cannot appear in known data breaches
• Checked against databases of leaked passwords
• If password has been exposed before, it will be rejected even if it meets length rules
Access restrictions in management interfaces and support channels
MAS Networks Ltd has access to all data, because we will be hosting the database and file storage. However, appropriate and strict access controls in place ensure that only the MD/Director of Development can authorise access to the data. Data is encrypted in-transit and at-rest at all stages.

For customer support, if trouble-shooting requires access to data within a particular customer's environment, explicit permission is requested for access from the customer, then access is approved for a MAS Networks staff member by either the MD, Director of Development/Director of Operations. All access requests are logged for future audit purposes.
Access restriction testing frequency
At least once a year
Management access authentication
  • Username or password
  • Other
Description of management access authentication
CareBrokerage secure user management:
o Authentication of (admin) users to management interfaces and support channels
▪ 2FA is enforced for all admin users, complex password requirements.
▪ Management/support requests accepted via telephone, email, and support portal.
▪ ISO 27001:2013 and Cyber Essentials Plus (+Cyber Essentials) certified
o Separation with access control within management interfaces
▪ Each organisation is hosted in a logically separate environment.
▪ Authentication credentials are separately managed for each environment.
▪ ISO 27001:2013 and Cyber Essentials Plus (+Cyber Essentials) certified

Audit information for users

Access to user activity audit information
No audit information available
Access to supplier activity audit information
No audit information available
How long system logs are stored for
Less than 1 month

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
MAS Networks Ltd, part of MAS Group, has the following Certifications:
• ISO 9001/2700
• Cyber Essentials Plus (+Cyber Essentials)
• NHS Digital Security Protection (DSP) Toolkit registered
• DCB0129 compliant
• Registered with the Information Commissioners Office (ICO)

CareLineLive: an NHS England Digital Social Care Record (DSCR) assured solution.
Information security policies and processes
MAS Group follow, maintain and uphold ISO 27001, and ISO 9001 information security policies and processes, are NHS Digital Security Protection (DSP) Toolkit registered, and are registered with the UK ICO.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Managing changes covers requirement gathering, specification, coding, testing and release management with respect to the live CareBrokerage environment.
We adhere to a strict change control process, documented in the MAS Group ISO Secure Systems & Development Aspects Policy. Any change requests will be carefully considered, documented in a requirements specification documentation that has to be agreed and signed off by all stakeholders prior to resources being assigned.
Major changes: applied during planned maintenance window in consultation and with agreement of the customer typically during low traffic periods. Minor changes: applied during normal hours of business at MAS Group discretion.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Appropriate patching controls ensure technical vulnerabilities are managed effectively: adherence to the Malware and Vulnerability Aspects Policy and Directive.
Controls (Anti-Virus software, hardware/software firewalls, Internet web traffic): scanned for malware, potential phishing threats are used to detect threats. Threats risk assessed, appropriate action determined by the ISMS committee, recorded in the risk register, risks mitigated depending on severity/impact.
Issues deemed critical: target resolution within two business days or as soon as possible.
Anti-Virus software, hardware/software firewalls, Internet web traffic scanned for malware, and potential phishing threats: Logs are checked regularly, any significant reports escalated to the ISMS Committee and investigated.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
MAS Group perform protective monitoring in accordance with our ISO policies and procedures, (clause A.12.4 refers) overview:
A12.4.1 Event logging: Event logs that record user activities, exceptions and information security events to be generated and retained for an agreed period to assist in monitoring access control and as evidence in potential information security investigations.
A.12.4.2 Protection of log information: Event logs and the systems and services used to generate them to be protected against unauthorised access or modification.
A.12.4.3 Administrator and operator logs: System administrator and operator activities to be recorded, with the logs protected and subject to review.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Incident reporting uses our ISO9001 logging process, identifies the problem, possible source, etc. Threat assessment is done determining what impact is likely and escalated as required. All incidents are reported on ISO27001 logs which will be shared with the Customer. We report routinely monthly but if there is a serious incident e.g. a GDPR breach then this is reported and acted upon immediately to minimise or mitigate any damage. Where needed we will also report to the ICO and other bodies as required.

Incident management processes are in place and tested yearly as part of disaster recovery testing.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
Citation ISO Certification Limited
ISO/IEC 27001 accreditation date
Tuesday 27 May 2025
What the ISO/IEC 27001 doesn’t cover
None to report.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
ISO 9001 certification accredited by
Citation ISO Certification Limited
ISO 9001 accreditation date
Tuesday 27 May 2025
What the ISO 9001 doesn’t cover
None to report.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
258881ab-07bf-46aa-ad96-9a7271326dc7
Cyber essentials plus
Yes
Cyber Essentials Plus Certificate Number
A3ea88c7-38c1-490f-8f0c-e701e546147c
Other security certifications
Yes
Any other security certifications
  • NHS DSP Toolkit, 2025-26 (version 8)
  • Clinical Safety (DCB0129)
  • Data Protection Act 2018

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

  • Plans for positive actions with community groups.
  • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@carelinelive.com. Tell them what format you need. It will help if you say what assistive technology you use.