Participant Kit (formerly Consent Kit) - Research CRM and Panel management
A CRM and participant management platform built specifically for user research, design research and Research Ops.
Focusing on inclusive and accessible participant experiences
Create powerful workflows to automate your research (research panels, communication, informed consent, data governance and scheduling)
The infrastructure you need to run your own research at scale.
Features
- Research panels management - build your own panel
- Real-time research project dashboards
- Screener surveys
- Consent forms & NDAs - Digital signatures
- Scheduling automations
- Participant CRM with bulk and 1-to-1 email
- Participant audit trails, automated data governance
- Online portal - Participants edit their own data
- Powerful workflows to automate your research
- Research Participant management system
Benefits
- Easy to manage and grow your own research panel
- Create powerful workflows to automate your research process
- Track user research progress in real time
- Standardise your research recruitment process across teams
- Fully WCAG 2.2 AA compliant for participants and researchers
- Significantly reduce operational risk from GDPR / data protection
- Save 45 mins per participant in research admin time
- Empower participants with agency over their own data
- Precision screening and segmentation
- True informed consent with granular permissions and dynamic consent
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 9 9 8 6 0 8 3 7 5 8 1 4 9 6
Contact
CONSENT KIT LTD
Ben Aldred
Telephone: 07563563579
Email: ben@participantkit.com
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No contraints
- System requirements
- Modern web browser
User support
- Email or online ticketing support
- Yes
- Support response times
-
We aim to respond to all issues within 24 hours.
Over the past 12 months, our average response time has been ~20 mins. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 A
- Web chat accessibility testing
- We have conducted some basic testing, though not recently. We are committed to accessibility across our platform and are open to reviewing our tools to maintain those high standards.
- Onsite support
- Yes, at extra cost
- Support levels
-
Standard support (included with all plans)
Help centre documentation, in-app chat and email support with ticketing. All customers are assigned an account manager, as a founder-led company with deep expertise in research operations, in most cases, this will be our founder directly.
Priority support (additional cost)
Dedicated Slack channel in your workspace and phone support. Cost dependent on needs.
Guided onboarding (additional cost)
Our Research Ops Accelerator provides a 6-week pilot programme with dedicated setup, team onboarding, and hands-on support. From £1,995 (or £995 for a reduced-scope 3-week programme). Can be bundled with contracts, depending on contract value, this can be included at no additional cost.
Bespoke support (additional cost)
We can accommodate additional requirements including:
Technical setup and support
Integration
Development
Cost dependent on scope. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
Our philosophy is that customers should get support however they want it. We offer flexible options to match different ways of working:
Self-serve resources:
Help centre documentation and quickstart guides
In-app guidance and onboarding emails for new team members
Direct support:
Responsive customer support via in-app chat and email
All customers are assigned an account manager. As a founder-led company, in most cases, this will be our founder directly
Unlike generic support teams, you're supported by people who understand research and research operations first-hand
Guided onboarding:
Our Research Ops Accelerator is a 6-week programme including a sandbox environment configured to your way of working, team walkthroughs, regular check-ins, and rollout planning. Can be bundled with contracts.
We created Participant Kit for teams who believe in responsible research. We understand the challenges of scaling research ops, managing compliance, and balancing efficiency with ethics. That knowledge informs everything, including how we support you. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
At the end of the contract, we send out email reminders with clear guidance about how to close the account down, including downloading research data and informing us it is ready to be closed.
On request, we can generate and send PDF copies of any live consent agreements to the participants with updated forwarding contact details set at the point of account closure.
Finally, we delete all of the account information and provide a certificate of deletion to the main administrator or Data Protection Officer (DPO). - End-of-contract process
- All off-boarding is included in the cost. There is no additional costs
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is responsively designed. Some elements are hidden / repositioned, but there is no difference in functionality.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- A series of forms and dashboards accessed through a web browser.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
We have automated testing built into our development process, alongside manual, human testing as part of QA and for larger developments.
We undertake third party testing at least yearly. The most recent was with the Royal National Institute of Blind People (RNIB) who completed a review of our participant facing interfaces. - API
- Yes
- What users can and can't do using the API
-
The Participant Kit API uses standard REST practices with resource-orientated URLs, JSON-encoded responses, and standard HTTP response codes, authentication and verbs.
What users can do:
View projects
Create, view and delete studies
Create and view participants
View and filter consents by status
Create, view and delete data links (associating external data with participants)
Limitations:
Service configuration (user management, templates, panels, settings) is managed through the web application rather than the API
API access is request-only — users contact us to be set up
We work closely with customers who have API access to accommodate their integration needs and can extend functionality where required.
For full documentation see https://participantkit.com/docs/api - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Panel recruitment, screeners, consent forms can be customised in lots of ways and can be included in custom workflows to create powerful research automations.
The forms and workflows can also be templated to make them re-usable and conform to your governance process.
Administrators can define their own data retention policy.
Administrators can create and manage teams across their organisation.
Researchers can invite collaborators to their projects.
We have various out of the box integrations with services like Calendly. We also have a Zapier integration that enables a wide range of integrations with tools you already use.
Custom integrations can also be written to connect to any external, bespoke, systems through our API.
Scaling
- Independence of resources
-
Our architecture is designed to scale elastically to meet demand. Performance monitoring is in place to ensure our internal performance metrics are being met.
As part of new customer onboarding, we review capacity and increase the capacity to anticipate the new expected load if needed.
Each account runs on its own instance of our mail server, so deliverability is not affected by bad actors beyond your control and your reputation is preserved.
Full separation from other users is available on request - subject to costs
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide metrics across several areas of the platform:
Project metrics:
Consent status and agreement tracking per study
Participant activity and history
Panel metrics:
Panellist numbers over time
Panel utilisation
Panel demographics and diversity tracking
Admin and compliance metrics:
How many participants have given consent
How many recordings have been linked to consent
Data deletion reminders for recordings that need action
Audit trails and activity tracking
Custom reports can be requested via our support channels for additional analytics requirements. - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
-
More sensitive data like passwords and signatures are stored within our database encrypted.
We have expirable links for uploaded assets so it would not be possible to take copies of these assets or share them.
Physical access is controlled by our cloud hosting provider AWS (via Heroku) - Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Our philosophy is simple: it's your data, so you should be able to get it out whenever you need it.
Most areas of the platform where data is inputted, including panels, studies and participant records, are exportable via CSV. Users with administrator access can self-serve exports at any time.
Exports can also be requested via our support channels if needed. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We aim for 95% uptime. We carry out maintenance transparently and provide advance notice of planned downtime where possible.
Response times are based on priority: urgent issues within 2 hours, high priority within 4 hours. Resolution targets range from 24 hours for urgent issues to 2-5 working days for high priority.
Support is provided Monday to Friday, 9:00-17:00 GMT/BST. Custom SLAs can be arranged for enterprise customers.
https://participantkit.com/legal/service-level-agreement - Approach to resilience
-
Our infrastructure runs on Heroku, built on AWS. AWS data centres are certified to ISO 27001, SOC 1/2, and PCI Level 1, with physical security and redundancy managed at that level.
We architect our systems to eliminate single points of failure. Data is encrypted at rest using AES256. Backups are taken daily and retained for 7 days, then weekly up to 30 days. Heroku's Continuous Protection allows point-in-time restore within the past 4 days.
We maintain Business Continuity and Disaster Recovery plans which are tested annually. Service status is available at https://consentkit.statuspage.io/
More information is available on request. - Outage reporting
-
We maintain a public service status page at https://consentkit.statuspage.io/ which reports current status, planned maintenance, and any outages.
Users can subscribe to updates via email alerts to receive notifications of any service disruptions.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- We also offer SSO / SAML with services like Okta, Google and Microsoft
- Access restrictions in management interfaces and support channels
-
Access to management interfaces follows least privilege principles. Our admin console is restricted via IP address and multi-factor authentication. Direct infrastructure access (Heroku) requires MFA. Privileged accounts are individually assigned, logged, and monitored.
For support channels, requests via in-app chat come from authenticated users. We verify identity before actioning sensitive requests such as password resets or billing changes. We never share PII in support communications, referring to participants by anonymous ID only. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials certification
- Information security policies and processes
-
We have an ISO 27001 Information Security Management System (ISMS) in place, though we are not yet certified.
We have completed CSA STAR Level 1 self-assessment (https://cloudsecurityalliance.org/star/registry/consent-kit/) and are updating this to the current standard well before any award date. Note: the product has recently been renamed from Consent Kit to Participant Kit, which will be reflected in the updated submission.
Our founder has overall responsibility for information security strategy and day-to-day operational implementation. Policies are reviewed at least annually and communicated to all staff as part of onboarding.
We maintain the following policies:
Information Security Policy
Mobile Devices and BYOD Policy
Access Control and Password Policy
Data Management and Classification Policy
Change Management (including Code Reviews and Automated Testing)
Acceptable Use of Assets Policy
Security Incident Response and Risk Management
Risk Assessment Methodology
Use of Cryptographic Controls Policy
Clear Desk and Screen Policy
Backup Policy
Supplier Relationships Policy - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We use modern development practices. All changes to production systems, code, or configuration require peer review through GitHub Pull Requests.
Changes are assessed for security impact through:
Static Application Security Testing and dependency scanning in CI pipeline
Peer review of all Pull Requests before merging
Automated integration, unit, and security tests
Ongoing vulnerability scanning
A "Green Build" (all tests passing) is required before code can be merged or deployed. Failure blocks deployment. Changes are tested in staging before production.
Components are tracked through Git with full change history. High-risk areas handling sensitive data receive dedicated security reviews. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
All vulnerabilities are managed and tracked through a defined set of stages.
Once a vulnerability is detected, it is assigned a score, using the CVSS scoring system.
We have an internal SLA that stipulates deadlines for fixing vulnerabilities. If necessary, a post-mortem is arranged as a learning exercise for our whole company to improve security. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We have protective monitoring controls at multiple levels. Automated dependency scanning, static code analysis, and secrets detection run continuously. Runtime protection monitors our application, blocking threats including zero-day vulnerabilities, SQL injection, and other attacks in real-time.
When a potential compromise is identified, we follow our documented incident response plan. Incidents are triaged, categorised by severity, and assigned to appropriate personnel.
Response times depend on severity: critical incidents receive first response within 2 hours with 24-hour resolution target; high priority within 4 hours. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We have documented incident response procedures with pre-defined processes for common events including data breaches, malicious code, denial of service, phishing, and unauthorised access. Incidents are categorised by severity with defined response times.
Users report incidents via in-app chat, email (support@consentkit.com), or phone. We assign a ticket number immediately and rate severity. Response times range from 2 hours for critical incidents to same business day for lower priority.
Incident reports are provided via email on request. We have a vulnerability disclosure policy for reporting security vulnerabilities. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
We offer a 14-day free trial with full access to all features - nothing is limited or restricted. For larger contracts, we can arrange an extended trial period to support proper evaluation.
The trial includes all platform functionality, support, and the ability to work with real data. - Link to free trial
- https://app.participantkit.com/sign-up
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Monday 7 June 2021
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
-
Our current self-assessment was completed against CAIQ v3.1. We are actively updating to CAIQ v4, which will be completed prior to contract award. This updated assessment provides improved alignment with current cloud security frameworks and clearer articulation of shared responsibility boundaries.
Physical and environmental controls — including datacenter security, equipment maintenance, power resilience, and physical media sanitisation — fall under our infrastructure provider's responsibility. Our SaaS is hosted on Heroku (AWS), whose datacentres maintain ISO 27001, SOC 1, and SOC 2 certifications. These inherited controls are documented within our assessment.
Network infrastructure controls relating to firewalls and physical network architecture are managed by our cloud provider under the shared responsibility model.
Virtual machine and hypervisor controls are not applicable as we deliver SaaS only; customers do not provision or manage virtual infrastructure.
As a fully remote micro organisation, we do not operate company-managed offices or networks. Employee device security is governed by documented policies rather than centralised Mobile Device Management.
Our assessment directly covers application security, access controls, encryption, data protection, incident management, business continuity, and supply chain security — the controls within our operational responsibility as a SaaS provider. - PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Bbde008c-5428-4240-b107-9a87f2827ea6
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-