Skip to main content

Help us improve the Digital Marketplace - send your feedback

CONSENT KIT LTD

Participant Kit (formerly Consent Kit) - Research CRM and Panel management

A CRM and participant management platform built specifically for user research, design research and Research Ops.

Focusing on inclusive and accessible participant experiences

Create powerful workflows to automate your research (research panels, communication, informed consent, data governance and scheduling)

The infrastructure you need to run your own research at scale.

Features

  • Research panels management - build your own panel
  • Real-time research project dashboards
  • Screener surveys
  • Consent forms & NDAs - Digital signatures
  • Scheduling automations
  • Participant CRM with bulk and 1-to-1 email
  • Participant audit trails, automated data governance
  • Online portal - Participants edit their own data
  • Powerful workflows to automate your research
  • Research Participant management system

Benefits

  • Easy to manage and grow your own research panel
  • Create powerful workflows to automate your research process
  • Track user research progress in real time
  • Standardise your research recruitment process across teams
  • Fully WCAG 2.2 AA compliant for participants and researchers
  • Significantly reduce operational risk from GDPR / data protection
  • Save 45 mins per participant in research admin time
  • Empower participants with agency over their own data
  • Precision screening and segmentation
  • True informed consent with granular permissions and dynamic consent

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ben@participantkit.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 9 9 8 6 0 8 3 7 5 8 1 4 9 6

Contact

CONSENT KIT LTD Ben Aldred
Telephone: 07563563579
Email: ben@participantkit.com

About your service

Service categories

Applications

Collaborative

  • Team collaboration
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
No contraints
System requirements
Modern web browser

User support

Email or online ticketing support
Yes
Support response times
We aim to respond to all issues within 24 hours.

Over the past 12 months, our average response time has been ~20 mins.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 A
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 A
Web chat accessibility testing
We have conducted some basic testing, though not recently. We are committed to accessibility across our platform and are open to reviewing our tools to maintain those high standards.
Onsite support
Yes, at extra cost
Support levels
Standard support (included with all plans)
Help centre documentation, in-app chat and email support with ticketing. All customers are assigned an account manager, as a founder-led company with deep expertise in research operations, in most cases, this will be our founder directly.

Priority support (additional cost)
Dedicated Slack channel in your workspace and phone support. Cost dependent on needs.

Guided onboarding (additional cost)
Our Research Ops Accelerator provides a 6-week pilot programme with dedicated setup, team onboarding, and hands-on support. From £1,995 (or £995 for a reduced-scope 3-week programme). Can be bundled with contracts, depending on contract value, this can be included at no additional cost.

Bespoke support (additional cost)
We can accommodate additional requirements including:

Technical setup and support
Integration
Development

Cost dependent on scope.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Our philosophy is that customers should get support however they want it. We offer flexible options to match different ways of working:

Self-serve resources:

Help centre documentation and quickstart guides
In-app guidance and onboarding emails for new team members

Direct support:
Responsive customer support via in-app chat and email
All customers are assigned an account manager. As a founder-led company, in most cases, this will be our founder directly
Unlike generic support teams, you're supported by people who understand research and research operations first-hand

Guided onboarding:
Our Research Ops Accelerator is a 6-week programme including a sandbox environment configured to your way of working, team walkthroughs, regular check-ins, and rollout planning. Can be bundled with contracts.

We created Participant Kit for teams who believe in responsible research. We understand the challenges of scaling research ops, managing compliance, and balancing efficiency with ethics. That knowledge informs everything, including how we support you.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
At the end of the contract, we send out email reminders with clear guidance about how to close the account down, including downloading research data and informing us it is ready to be closed.

On request, we can generate and send PDF copies of any live consent agreements to the participants with updated forwarding contact details set at the point of account closure.

Finally, we delete all of the account information and provide a certificate of deletion to the main administrator or Data Protection Officer (DPO).
End-of-contract process
All off-boarding is included in the cost. There is no additional costs
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is responsively designed. Some elements are hidden / repositioned, but there is no difference in functionality.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
A series of forms and dashboards accessed through a web browser.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have automated testing built into our development process, alongside manual, human testing as part of QA and for larger developments.

We undertake third party testing at least yearly. The most recent was with the Royal National Institute of Blind People (RNIB) who completed a review of our participant facing interfaces.
API
Yes
What users can and can't do using the API
The Participant Kit API uses standard REST practices with resource-orientated URLs, JSON-encoded responses, and standard HTTP response codes, authentication and verbs.
What users can do:

View projects
Create, view and delete studies
Create and view participants
View and filter consents by status
Create, view and delete data links (associating external data with participants)

Limitations:

Service configuration (user management, templates, panels, settings) is managed through the web application rather than the API
API access is request-only — users contact us to be set up

We work closely with customers who have API access to accommodate their integration needs and can extend functionality where required.

For full documentation see https://participantkit.com/docs/api
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Panel recruitment, screeners, consent forms can be customised in lots of ways and can be included in custom workflows to create powerful research automations.

The forms and workflows can also be templated to make them re-usable and conform to your governance process.

Administrators can define their own data retention policy.

Administrators can create and manage teams across their organisation.

Researchers can invite collaborators to their projects.

We have various out of the box integrations with services like Calendly. We also have a Zapier integration that enables a wide range of integrations with tools you already use.

Custom integrations can also be written to connect to any external, bespoke, systems through our API.

Scaling

Independence of resources
Our architecture is designed to scale elastically to meet demand. Performance monitoring is in place to ensure our internal performance metrics are being met.

As part of new customer onboarding, we review capacity and increase the capacity to anticipate the new expected load if needed.

Each account runs on its own instance of our mail server, so deliverability is not affected by bad actors beyond your control and your reputation is preserved.

Full separation from other users is available on request - subject to costs

Analytics

Service usage metrics
Yes
Metrics types
We provide metrics across several areas of the platform:

Project metrics:

Consent status and agreement tracking per study
Participant activity and history

Panel metrics:

Panellist numbers over time
Panel utilisation
Panel demographics and diversity tracking

Admin and compliance metrics:

How many participants have given consent
How many recordings have been linked to consent
Data deletion reminders for recordings that need action
Audit trails and activity tracking

Custom reports can be requested via our support channels for additional analytics requirements.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
More sensitive data like passwords and signatures are stored within our database encrypted.

We have expirable links for uploaded assets so it would not be possible to take copies of these assets or share them.

Physical access is controlled by our cloud hosting provider AWS (via Heroku)
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Our philosophy is simple: it's your data, so you should be able to get it out whenever you need it.

Most areas of the platform where data is inputted, including panels, studies and participant records, are exportable via CSV. Users with administrator access can self-serve exports at any time.

Exports can also be requested via our support channels if needed.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We aim for 95% uptime. We carry out maintenance transparently and provide advance notice of planned downtime where possible.
Response times are based on priority: urgent issues within 2 hours, high priority within 4 hours. Resolution targets range from 24 hours for urgent issues to 2-5 working days for high priority.
Support is provided Monday to Friday, 9:00-17:00 GMT/BST. Custom SLAs can be arranged for enterprise customers.
https://participantkit.com/legal/service-level-agreement
Approach to resilience
Our infrastructure runs on Heroku, built on AWS. AWS data centres are certified to ISO 27001, SOC 1/2, and PCI Level 1, with physical security and redundancy managed at that level.
We architect our systems to eliminate single points of failure. Data is encrypted at rest using AES256. Backups are taken daily and retained for 7 days, then weekly up to 30 days. Heroku's Continuous Protection allows point-in-time restore within the past 4 days.
We maintain Business Continuity and Disaster Recovery plans which are tested annually. Service status is available at https://consentkit.statuspage.io/
More information is available on request.
Outage reporting
We maintain a public service status page at https://consentkit.statuspage.io/ which reports current status, planned maintenance, and any outages.
Users can subscribe to updates via email alerts to receive notifications of any service disruptions.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
We also offer SSO / SAML with services like Okta, Google and Microsoft
Access restrictions in management interfaces and support channels
Access to management interfaces follows least privilege principles. Our admin console is restricted via IP address and multi-factor authentication. Direct infrastructure access (Heroku) requires MFA. Privileged accounts are individually assigned, logged, and monitored.
For support channels, requests via in-app chat come from authenticated users. We verify identity before actioning sensitive requests such as password resets or billing changes. We never share PII in support communications, referring to participants by anonymous ID only.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials certification
Information security policies and processes
We have an ISO 27001 Information Security Management System (ISMS) in place, though we are not yet certified.

We have completed CSA STAR Level 1 self-assessment (https://cloudsecurityalliance.org/star/registry/consent-kit/) and are updating this to the current standard well before any award date. Note: the product has recently been renamed from Consent Kit to Participant Kit, which will be reflected in the updated submission.

Our founder has overall responsibility for information security strategy and day-to-day operational implementation. Policies are reviewed at least annually and communicated to all staff as part of onboarding.
We maintain the following policies:

Information Security Policy
Mobile Devices and BYOD Policy
Access Control and Password Policy
Data Management and Classification Policy
Change Management (including Code Reviews and Automated Testing)
Acceptable Use of Assets Policy
Security Incident Response and Risk Management
Risk Assessment Methodology
Use of Cryptographic Controls Policy
Clear Desk and Screen Policy
Backup Policy
Supplier Relationships Policy
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We use modern development practices. All changes to production systems, code, or configuration require peer review through GitHub Pull Requests.
Changes are assessed for security impact through:
Static Application Security Testing and dependency scanning in CI pipeline
Peer review of all Pull Requests before merging
Automated integration, unit, and security tests
Ongoing vulnerability scanning
A "Green Build" (all tests passing) is required before code can be merged or deployed. Failure blocks deployment. Changes are tested in staging before production.
Components are tracked through Git with full change history. High-risk areas handling sensitive data receive dedicated security reviews.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
All vulnerabilities are managed and tracked through a defined set of stages.

Once a vulnerability is detected, it is assigned a score, using the CVSS scoring system.

We have an internal SLA that stipulates deadlines for fixing vulnerabilities. If necessary, a post-mortem is arranged as a learning exercise for our whole company to improve security.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We have protective monitoring controls at multiple levels. Automated dependency scanning, static code analysis, and secrets detection run continuously. Runtime protection monitors our application, blocking threats including zero-day vulnerabilities, SQL injection, and other attacks in real-time.
When a potential compromise is identified, we follow our documented incident response plan. Incidents are triaged, categorised by severity, and assigned to appropriate personnel.
Response times depend on severity: critical incidents receive first response within 2 hours with 24-hour resolution target; high priority within 4 hours.
Incident management type
Supplier-defined controls
Incident management approach
We have documented incident response procedures with pre-defined processes for common events including data breaches, malicious code, denial of service, phishing, and unauthorised access. Incidents are categorised by severity with defined response times.
Users report incidents via in-app chat, email (support@consentkit.com), or phone. We assign a ticket number immediately and rate severity. Response times range from 2 hours for critical incidents to same business day for lower priority.
Incident reports are provided via email on request. We have a vulnerability disclosure policy for reporting security vulnerabilities.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
We offer a 14-day free trial with full access to all features - nothing is limited or restricted. For larger contracts, we can arrange an extended trial period to support proper evaluation.
The trial includes all platform functionality, support, and the ability to work with real data.
Link to free trial
https://app.participantkit.com/sign-up

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
Yes
CSA STAR accreditation date
Monday 7 June 2021
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
Our current self-assessment was completed against CAIQ v3.1. We are actively updating to CAIQ v4, which will be completed prior to contract award. This updated assessment provides improved alignment with current cloud security frameworks and clearer articulation of shared responsibility boundaries.
Physical and environmental controls — including datacenter security, equipment maintenance, power resilience, and physical media sanitisation — fall under our infrastructure provider's responsibility. Our SaaS is hosted on Heroku (AWS), whose datacentres maintain ISO 27001, SOC 1, and SOC 2 certifications. These inherited controls are documented within our assessment.
Network infrastructure controls relating to firewalls and physical network architecture are managed by our cloud provider under the shared responsibility model.
Virtual machine and hypervisor controls are not applicable as we deliver SaaS only; customers do not provision or manage virtual infrastructure.
As a fully remote micro organisation, we do not operate company-managed offices or networks. Employee device security is governed by documented policies rather than centralised Mobile Device Management.
Our assessment directly covers application security, access controls, encryption, data protection, incident management, business continuity, and supply chain security — the controls within our operational responsibility as a SaaS provider.
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Bbde008c-5428-4240-b107-9a87f2827ea6
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ben@participantkit.com. Tell them what format you need. It will help if you say what assistive technology you use.