Skip to main content

Help us improve the Digital Marketplace - send your feedback

SureCert

SureScore Corporate Due Diligence

Corporate due diligence service that assesses organisations using automated data checks, risk scoring and adverse intelligence to identify fraud, financial crime and compliance risks. Supports supplier onboarding, grant assurance, procurement checks and ongoing monitoring for public sector and regulated organisations.

Features

  • Automated corporate identity and structure checks
  • Risk scoring across fraud and financial crime indicators
  • Analysis of directors, ownership and control
  • Adverse media and sanctions screening
  • Configurable risk rules and thresholds
  • Continuous or periodic monitoring options
  • Secure API integration with buyer systems
  • Audit logs and decision traceability
  • Cloud-hosted SaaS platform
  • Scalable processing for high-volume checks

Benefits

  • Identify high-risk organisations quickly
  • Reduce manual due diligence effort
  • Improve fraud and financial crime detection
  • Support procurement and grant assurance
  • Enable consistent, repeatable risk decisions
  • Integrate easily with existing workflows
  • Strengthen regulatory compliance
  • Improve auditability and transparency
  • Reduce onboarding and approval delays
  • Support ongoing supplier monitoring

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ian@surecert.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 9 6 8 8 7 5 3 3 7 1 6 9 6 6

Contact

SureCert Ian Savage
Telephone: 07515 816158
Email: ian@surecert.com

About your service

Service categories

Applications

Enterprise resource management

  • Procurement
  • Project and portfolio management

Financial

  • Treasury and Risk Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
The service integrates with buyer systems including procurement platforms, grant management systems, CRM systems, case management tools and internal risk platforms via secure APIs. It is commonly used alongside identity or document verification services but does not require any other SureCert services to operate.
Cloud deployment model
Public cloud
Service constraints
The service requires an internet connection and access via a supported web browser or API. Certain verification checks depend on the availability of third-party data sources, which may occasionally impact response times. Planned maintenance is scheduled outside core business hours where possible and communicated in advance. The service does not operate offline and requires users to provide suitable data, documents and images for verification.
System requirements
  • Modern web browser with JavaScript enabled
  • Reliable internet connection
  • HTTPS connectivity for secure access
  • Device capable of capturing identity documents and images
  • Secure email access for notifications
  • API access requires HTTPS and authentication credentials
  • Ability to upload images and documents
  • TLS-supported network environment
  • Role-based user access configured by buyer
  • No local software installation required

User support

Email or online ticketing support
Yes, at extra cost
Support response times
Support requests are acknowledged within one business day. Response times vary based on issue severity, with higher-priority issues responded to more quickly. Support is provided during standard business hours, Monday to Friday. Weekend and public holiday support is not standard but may be available by prior agreement.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support levels

SureCert provides structured support levels designed to meet the needs of public sector and regulated organisations.

Standard Support is included as part of the service and provides access to email/ticketing and phone support during UK business hours (9am–5pm, Monday to Friday). Support requests are prioritised by severity, with higher-impact issues responded to first.

Enhanced Support may be provided by agreement and at additional cost. This can include extended support hours, faster response times, increased support capacity during critical periods, and additional implementation or configuration support.

Onsite Support is available at extra cost where required, for example for onboarding, integration workshops, assurance activities or stakeholder sessions.

A dedicated technical contact or account manager may be assigned for larger contracts or complex integrations. Where appropriate, access to a cloud support engineer is provided to support technical onboarding, API integration and operational queries.

Support arrangements and costs are agreed contractually at call-off stage to ensure they are proportionate to the scope and risk of the service.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Buyers are supported through a structured onboarding process tailored to their delivery model. This includes remote onboarding sessions, configuration of verification workflows, user access setup, and API credential provisioning where required.

Users are supported with online documentation, integration guides, and step-by-step configuration materials. Where the service is accessed via API, technical support is provided to assist with integration and testing, including access to a sandbox environment.

Training is delivered remotely via online sessions and walkthroughs, with follow-up support available through email and ticketing. Onsite onboarding or training can be provided at additional cost where required.

This approach ensures buyers can begin using the service quickly, securely and in line with their operational and compliance requirements.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, buyers can request extraction of their data through a managed offboarding process. Data is exported securely in structured, commonly used formats suitable for reuse or transfer to another system.

For API-integrated customers, data can be extracted via secure API endpoints where appropriate. For hosted services, exports are provided through secure file transfer.

Data extraction is carried out in accordance with UK GDPR requirements, ensuring confidentiality, integrity and secure handling of personal data. Buyers are supported throughout the process to ensure data is complete and usable prior to service termination.
End-of-contract process
At the end of the contract, a controlled offboarding process is followed. Buyer access to the service is disabled following confirmation of contract end. Where requested, buyer data is securely extracted and provided as part of the contract price.

Following confirmation that data extraction has been completed, remaining customer data is securely deleted in line with documented retention schedules, UK GDPR obligations and security policies.

Standard offboarding activities, including account closure and secure data deletion, are included within the contract price. Additional support, such as bespoke data extracts, extended retention periods, or onsite assistance, can be provided at an additional cost where required and agreed in advance.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Our documentation has been developed with recognised accessibility and usability best practices in mind and reflects a good-faith effort to align with commonly accepted industry standards. Content structure, formatting, and language have been designed to promote clarity, consistency, and ease of use across a broad audience. While these practices are informed by widely adopted guidelines, the documentation has not been formally evaluated or certified against any specific external standard, such as WCAG. As a result, conformity should be understood as indicative rather than verified, and ongoing review and improvement may be required as formal testing or validation is undertaken.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
It is an API and it will function the same on mobile and desktop.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service also exposes RESTful APIs to integrate corporate due diligence directly into existing buyer systems, portals and digital services.
Accessibility standards
None or don’t know
Description of accessibility
The service is not a user interface, it is an API that can be configured by the client to ensure it meets accessibility standards.
Accessibility testing
While not directly relevant to the API but when it has been delivered as part of previous solutions it meets the following:

Accessibility has been considered throughout the design and development of the service interface.

The platform is designed in line with WCAG 2.2 AA principles, including keyboard navigation support, screen reader compatibility, sufficient colour contrast, clear labelling, and logical focus order.

Testing includes internal accessibility reviews, browser-based accessibility tooling, and validation using screen readers and keyboard-only navigation.

User feedback from public sector and regulated-sector deployments has informed iterative improvements to usability and accessibility, including simplifying user journeys and reducing cognitive load.

Where required, accessibility considerations are incorporated into buyer-specific configurations and integrations to ensure end-user journeys remain inclusive and accessible.
API
Yes
What users can and can't do using the API
Users can integrate SureCert’s services into their own systems using secure RESTful APIs. Through the API, users can:
• Configure verification workflows (for example identity verification, document checks, proof of address and corporate due diligence)
• Submit identity, document and organisation data for verification
• Trigger and monitor verification processes in real time
• Retrieve verification results, risk indicators and audit data
• Manage API keys and access permissions
• Integrate verification outcomes into downstream systems and decision workflows

Changes to workflows, thresholds and integrations can be managed via the API or in conjunction with SureCert’s configuration support.

The API does not allow users to modify core verification algorithms, third-party data sources or security controls. Certain configuration changes (for example onboarding new data sources or bespoke risk rules) may require SureCert support and governance approval to ensure compliance and data protection.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Buyers can customise the service through configuration and integration options.

Customisable elements include:
• Verification workflows (e.g. identity checks, document types, proof of address, corporate due diligence)
• Rules and thresholds applied to verification outcomes and risk indicators
• User journeys (hosted verification journeys or embedded journeys via API)
• Integration with existing systems using APIs (e.g. case management, CRM or grant platforms)
• Branding elements within user-facing verification flows where required

Customisation is carried out via:
• Administrative configuration within the service interface
• Secure APIs and configuration settings documented for technical teams

Customisation can be performed by:
• Authorised buyer administrators through the service interface
• Buyer technical teams or approved partners using the API

All customisation is configuration-based and supported within the standard SaaS offering, ensuring maintainability, security and compliance with public sector requirements.

Scaling

Independence of resources
The service is built on a scalable, multi-tenant cloud architecture with logical separation between customers. Resources are monitored and managed dynamically to ensure that increases in demand from one user do not adversely affect the performance or availability experienced by others. Capacity management, performance monitoring and automated scaling controls are used to maintain consistent service levels across all users.

Analytics

Service usage metrics
Yes
Metrics types
The service provides usage and operational metrics including verification volumes, success and failure rates, processing times, and status outcomes. Audit and activity logs are available to support compliance, assurance and reporting requirements. Metrics can be accessed for operational monitoring and service performance review, subject to user permissions and data protection controls.

Reporting can be provided on a buyer-defined basis, for example monthly, quarterly or on request, depending on operational and governance requirements. Metrics may be accessed via reports or provided to support service reviews, assurance activities and contract management.
Reporting types
Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Experian

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
NCSC approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data through a managed and secure process. Data exports are requested via support channels or accessed through secure API endpoints where applicable. Exports are delivered using secure file transfer methods and provided in agreed, commonly used formats to ensure usability and portability. All data exports are handled in accordance with UK GDPR and information security requirements.
Data export formats
  • CSV
  • Other
Other data export formats
JSON (via API exports)
Data import formats
  • CSV
  • Other
Other data import formats
JSON (via API integration)

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is designed to operate with high availability using resilient cloud infrastructure and proactive monitoring. Availability targets and any applicable service levels are defined contractually at Call-Off stage, based on the buyer’s requirements and the agreed service configuration.

Where availability service levels are agreed, service credits may be applied if availability falls below the agreed threshold within a defined measurement period. Service credits are calculated as a proportion of the affected service charges and are applied in accordance with the terms set out in the Call-Off Contract or service schedule.

Planned maintenance is managed to minimise disruption and, where possible, carried out outside of core service hours with advance notice provided. Availability performance is monitored continuously and incidents are managed through defined incident and escalation processes.
Approach to resilience
The service is designed using resilient cloud architecture to support continuous operation and rapid recovery from failure. Critical components are deployed with redundancy and monitored continuously to detect and respond to issues quickly. Automated scaling and capacity management help ensure performance during periods of increased demand.

The underlying datacentre infrastructure is provided by third-party cloud providers operating resilient facilities with redundant power, networking and environmental controls. Data is protected through regular backups and recovery processes to support business continuity.

Resilience arrangements, including detailed architecture and disaster recovery processes, are documented and can be provided to buyers on request where required. The service is regularly reviewed and tested to ensure resilience controls remain effective and aligned with operational and security requirements.
Outage reporting
Service outages and incidents are managed through defined incident management processes. Where a service disruption occurs, affected buyers are notified via email and support ticket updates. Incident status and progress are tracked internally and communicated to buyers as appropriate.

Where required, outage information and status updates can be shared directly with buyers on request. Post-incident reports are produced for significant incidents, outlining impact, root cause and corrective actions taken.

The service does not rely on a public status dashboard by default, but incident information can be provided through agreed communication channels to ensure buyers are informed in a timely and transparent manner.

Identity and authentication

User authentication needed
Yes
User authentication
  • Username or password
  • Other
Other user authentication
OAuth 2.0 compliant mechanism for accessing the API.
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using role-based access controls (RBAC). Only authorised staff with appropriate job roles are granted access to administrative functions or support tools. Access is provisioned on a least-privilege basis and reviewed regularly. Management and support access is logged and monitored, and credentials are revoked promptly when staff change roles or leave the organisation. Support systems are accessible only to authenticated users via secure internal networks and approved devices.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Username or password
  • Other
Description of management access authentication
OAuth 2.0

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials
Information security policies and processes
The organisation maintains documented information security policies and procedures covering areas including access control, data protection, incident management, vulnerability management, secure development, business continuity and data retention. These policies are aligned with recognised best practice and support compliance with UK GDPR and Cyber Essentials requirements.

Overall responsibility for information security sits at board level, with day-to-day implementation and oversight delegated to senior technical leadership. Clear reporting and escalation routes are in place for security risks and incidents, ensuring issues are reviewed, managed and addressed promptly.

Policies are communicated to relevant staff and contractors, supported by role-based access controls and security awareness activities. Compliance with policies is monitored through regular reviews, audits, vulnerability assessments and incident reporting processes. Policies and procedures are reviewed periodically and updated as required to reflect changes in risk, technology and regulatory requirements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration items and service components are tracked throughout their lifecycle using controlled versioning and configuration management tools. Changes are logged, reviewed and approved prior to implementation. Each change is assessed for potential security, performance and operational impact, with higher-risk changes subject to additional review and testing. Changes are tested in non-production environments before deployment, and rollback procedures are in place to minimise risk. Access to make configuration changes is restricted to authorised personnel and monitored to ensure accountability.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Potential threats are identified through regular vulnerability scanning, penetration testing and security monitoring. Vulnerabilities are assessed based on risk, severity and potential impact to the service. Patches and mitigations are prioritised and deployed promptly, with critical issues addressed as a priority. Threat intelligence is informed by vendor advisories, security bulletins, cloud provider notifications and independent penetration testing findings. Remediation actions are tracked to completion and reviewed to reduce the likelihood of recurrence.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
System activity and security events are logged and monitored to identify potential compromises, including unauthorised access attempts or anomalous behaviour. Alerts are reviewed by authorised personnel and investigated promptly. Where a potential compromise is identified, incident response procedures are initiated to contain, assess and remediate the issue. Response times are prioritised based on severity, with critical incidents escalated immediately. Monitoring outputs are retained to support investigation, audit and continuous improvement.
Incident management type
Supplier-defined controls
Incident management approach
The organisation operates documented incident management processes covering common security and operational events. Incidents can be reported by users through email or the online support ticketing system. Incidents are logged, categorised by severity, and escalated according to defined procedures. Buyers are kept informed of relevant incidents through agreed communication channels, including ticket updates and email notifications. Incident reports are provided for significant incidents, outlining impact, actions taken and any remedial or preventative measures implemented.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Ea4ba1b0-9a88-47bc-833d-38ab1bcfb620
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ian@surecert.com. Tell them what format you need. It will help if you say what assistive technology you use.