Skip to main content

Help us improve the Digital Marketplace - send your feedback

EMBERS THE DRAGON LTD

Embers the Dragon Programme

Embers the Dragon is a digital programme for early emotional health and literacy for children in nursery and primary school and for family use at home. It includes specialised teaching resources and parents' website, and a clinically proven App with a parenting course, activity library, animated series and educational games.

Features

  • Digital parenting course with interactive modular construction
  • Purpose-built animated series based on recommended social learning theory
  • Psychoeducation films for parents and family activities support learning
  • Dedicated child space in-app, filled with educational games/activities
  • Parents track goal-based outcomes and successful parenting techniques in-app
  • Positive Behavioural Support Plan can be compiled, exported and shared
  • Comprehensive aggregate outcomes and usage data reported for all customers
  • Option to track usage and outcomes for individual users
  • Comprehensive digital schools programme includes lesson plans, slide decks, activities
  • Dedicated parents' website accompanying school programme embeds and extends learning

Benefits

  • Scalable NICE-compliant app, clinically proven mental health intervention
  • App prescribable by primary care if below CAMHS referral threshold
  • App prescribable by CAMHS as monitorable support for waitlisted families
  • App prescribable by CAMHS as adjunct to targeted therapy
  • Easily implemented through all app platforms via license-based access codes
  • User-friendly reporting interface for outcome tracking by clinicians
  • Specialised primary school mental health resources implementable off the shelf
  • School Parents Platform integrates home activities and extends parenting skills
  • Whole school approach: assembly, class or 1:1 teaching resources
  • School programme supports GLDs, school readiness, PHSE requirements and more

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@embersthedragon.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 0 4 4 1 8 8 5 4 6 3 5 5 0 4

Contact

EMBERS THE DRAGON LTD Yvonne Silove
Telephone: 07957545893
Email: hello@embersthedragon.co.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
  • Education
  • Children's Social Care
  • Other
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Requires an internet connection. The mobile application requires a device running a supported version of iOS or Android.
System requirements
No system requirements

User support

Email or online ticketing support
Yes
Support response times
Within 24 hours during weekdays. Next working day at weekends.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Onsite support is provided to commissioning clients (clinicians, educators) and not the eventual end user (patient). This is to support with onboarding and interoperability.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We are able to provide onsite and/or online training to commisioning organisations who will be prescribing the app to their patients. User documentation is also included.

The app has a built in onboarding and training section, inclusive of tooltips and a support inbox for our end user (patients).
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
Video
End-of-contract data extraction
Users can request a full data export via the support desk in CSV format prior to contract termination
End-of-contract process
On expiration or termination of the contract:

Access Revocation: All access is suspended immediately following the contract end date.
Trial Periods: For customers concluding a free trial or paid pilot, service access is revoked immediately, but data is retained for 60 days to facilitate seamless conversion to a full annual license.
Data Extraction: Customers can export relevant user progress data (via CSV/Excel format) directly from the dashboard at any time prior to the contract end date.
Data Deletion: In accordance with our GDPR and data retention policies, all customer data is securely deleted from our servers (AWS/MySQL) 30 days after contract termination (or 60 days for trials), unless a specific data retention agreement is in place.
No Exit Fees: There are no standard termination or exit charges.

Included in the standard subscription:

Full Platform Access
Infrastructure: All cloud hosting costs (AWS) and video streaming bandwidth.
Maintenance: Standard software updates, security patches, and bug fixes.
Support and onboarding documentation
Evaluation: Standard impact and usage analytics on user engagement and efficacy

Additional Costs (if required):

On-site or bespoke remote training sessions.
Custom content creation or bespoke feature development.
Data recovery requests made after the standard deletion period (where technically feasible).
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Our web platform has been desgiend the give an identical user experience for both mobile and desktop users.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The wesbite is fully responsive and designed to work across all browsers. The app is a modern mobile application designed to be easily accessible and understandable by our patient users.
Accessibility standards
None or don’t know
Description of accessibility
Service Status: Partially Compliant

1. Web Interface: Fully compliant with WCAG 2.1 AA, supporting all standard assistive technologies including screen readers, keyboard navigation, and zooming.

2. Mobile App: Partially compliant. Meets AA standards for visual and cognitive accessibility (contrast, subtitles). However, native screen reader support is currently unavailable due to Unity 3D engine limitations (WCAG 4.1.2). We claim a disproportionate burden regarding retrofitting the current engine.

3. Mitigation: All content is available in alternative accessible formats via the Web Portal. We are monitoring Unity's roadmap to implement screen reader support in future updates
Accessibility testing
Current Status: We have not yet conducted external user research specifically with participants using assistive technology (e.g., screen readers). This decision is based on the current technical architecture of the mobile application (built on the 3D Unity engine), which requires a planned engine update to fully support native accessibility layers. Conducting research prior to this update would not yield valid data.

Prioritised Research: Our user research strategy has currently prioritised the primary clinical needs of our specific user base (children with emotional and behavioural challenges). We have conducted internal testing to ensure the app meets WCAG 2.1 AA standards for visual and cognitive accessibility (e.g., colour contrast, simplified navigation, and subtitles), which addresses the needs of the majority of our users.

Future Roadmap: Formal user testing with assistive technology users is planned as a subsequent phase of our development roadmap, contingent upon the deployment of the updated Unity accessibility framework.
API
No
Customisation available
No

Scaling

Independence of resources
Web Platform (Wix Enterprise): Hosted on a serverless, multi-tenant infrastructure utilising elastic auto-scaling to instantly provision resources during traffic spikes. A global Content Delivery Network (CDN) offloads 90% of static traffic to edge servers, while automated load balancing across multiple data centres ensures high availability and prevents "noisy neighbour" performance degradation.

Mobile Application (AWS): Built on AWS Fargate (serverless compute) for automatic container scaling in real-time. An Application Load Balancer distributes traffic across healthy tasks, while AWS RDS ensures dedicated database I/O performance. CloudWatch provides proactive monitoring to trigger immediate scaling events and maintain service stability.

Analytics

Service usage metrics
Yes
Metrics types
The back end of the website and app provides data on usage, whilst in addition, the back end of the app provides outcome measures data. This allows commissioners and clinicians to track individual progress, review wider population trends and engagement.
Reporting types
Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can request a copy of their data through the support desk (support@embersthedragon.co.uk), or individual users can delete their account and data directly within the app settings.
Data export formats
CSV
Data import formats
Other
Other data import formats
N/a data is generated via App interaction not file uploads

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
In addition to TLS 1.2+ encryption for all data in transit:

DDoS Protection: The infrastructure benefits from AWS Shield Standard, which provides always-on network flow monitoring and automated mitigation against Distributed Denial of Service (DDoS) attacks.

Forced HTTPS: The Application Load Balancer is configured to reject non-secure connections, enforcing HTTPS (port 443) for all web and API traffic.

Strong Ciphers: We utilize industry-standard strong cipher suites (AES-256) managed via AWS Certificate Manager (ACM) to ensure the integrity of the data tunnel
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
In addition to encryption, we protect internal data using the standard AWS 'Defense in Depth' architecture:

Private Network (VPC): Our database and application servers run inside a Virtual Private Cloud, meaning they have no direct connection to the public internet.

Firewalls (Security Groups): We use AWS Security Groups to strictly block all traffic to the database unless it comes specifically from our own application servers.

Component Isolation: The application runs on AWS Fargate, which isolates each process in its own secure container, preventing different parts of the system from accessing each other's data memory.

Availability and resilience

Guaranteed availability
We guarantee 99.9% service availability during business hours (excluding planned maintenance). Our infrastructure is built on AWS, which offers a monthly uptime percentage of at least 99.99% for the underlying compute and database services.

Compensation: In the unlikely event that availability drops below 99.9% in a given month, customers may be eligible for service credits calculated as a percentage of their monthly subscription fee, awarded upon request and investigation of the outage.
Approach to resilience
1. Embers Website (Wix Enterprise): Our public-facing platform utilises a resilient "Multi-Cloud" infrastructure operating across Google Cloud Platform (GCP), AWS, and private data centres. This architecture eliminates single points of failure through active-active clustering and automated failover mechanisms; if a primary node becomes unresponsive, traffic is instantly redirected to a healthy secondary location. Performance isolation is guaranteed via elastic auto-scaling, while a global Content Delivery Network (CDN) with over 200 nodes offloads 90% of static traffic to edge servers, ensuring the service remains accessible even during high-traffic events or localised internet disruptions.

2. Embers App (AWS Infrastructure): The mobile service is built on a "self-healing" cloud architecture using AWS Fargate (serverless compute), which automatically detects unhealthy application tasks and replaces them with fresh instances without human intervention. An Application Load Balancer (ALB) dynamically distributes incoming traffic across healthy containers to isolate users from single-component failures. Data integrity is secured by Amazon RDS, which ensures consistent I/O performance and performs automated daily backups with transaction log retention, enabling Point-in-Time Recovery (PITR) to restore data precisely in the event of corruption.
Outage reporting
1. Embers App (AWS Infrastructure) We communicate service status and outages through the following channels:

Email Alerts: Priority email notifications are sent to registered administrators during major service incidents.

Direct Support: Users can query system status via the standard support helpdesk.

2. Embers Website (Wix Enterprise Infrastructure)

Public Dashboard: Real-time service availability is viewable at status.wix.com. This dashboard provides a granular breakdown of all platform components (e.g., Editor, Live Sites, Payments).

Email & SMS Alerts: Users and administrators can subscribe to automatic incident updates via email, SMS, or Atom/RSS feed directly from the status page.

Admin Dashboard: The "Uptime & Security" dashboard within the Embers site admin panel provides site-specific uptime statistics and alerts for any localized issues affecting the service.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Users cannot access any management interfaces; these are separate to the app
Access restriction testing frequency
At least every 6 months
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials, DTAC, DSPT
Information security policies and processes
Security governance is led by the Chief Operating Officer (COO), who holds accountability for information security and compliance. We operate a 'Cloud First' governance model underpinned by our Cyber Essentials certification. Our framework includes:

Annual Audit: We undergo independent technical audits annually to maintain Cyber Essentials accreditation.
NHS Compliance: We align with the National Data Guardian’s ten data security standards (DSPT) and DTAC clinical safety standards.
Risk Management: The COO reviews asset inventories, access logs, and critical vendor performance (AWS) quarterly.

We maintain policies strictly aligned with Cyber Essentials controls:

Access Control: Multi-Factor Authentication (MFA) is enforced on all administrative accounts; admin rights are restricted to the Director and Lead Developer.

Patch Management: Critical vulnerabilities are patched within 14 days in line with CE+ requirements.

Device Security: All endpoints are managed, encrypted, and run active anti-malware protection.

Reporting: Incidents are reported to the COO and, where required, to the ICO (GDPR) and NHS Digital (DSPT) within 72 hours.
Software Security Code of Practice
No

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We utilize an immutable infrastructure approach managed by our technical partner:

Code Review: All code changes require peer review by senior engineers within the partner's team before merging.

Release Approval: Major feature releases require final sign-off from the Embers Product Director before deployment to the live environment.

Tracking: All changes are version-controlled and traceable back to specific Jira tickets.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Our development partner manages vulnerability scanning as part of their ISO 27001 certified lifecycle:

Automated Scanning: Code repositories are automatically scanned for CVEs in third-party dependencies during the build process.

Patching SLA: We enforce a contractual SLA requiring them to apply 'Critical' or 'High' severity security patches within 14 days of identification.

Oversight: Embers reviews security reports quarterly to ensure SLA compliance.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Metric Alarms: AWS CloudWatch Alarms trigger alerts on abnormal spikes in CPU, memory, or error rates (HTTP 5xx).

Traffic Analysis: Application Load Balancer (ALB) logs are analyzed to detect anomalous traffic patterns.

Response: Critical alerts are routed immediately to the engineering team via automated notification channels for triage
Incident management type
Supplier-defined controls
Incident management approach
We follow a structured Incident Response Plan (IRP) aligned with NHS DSPT requirements:

Triage: Incidents are categorised by severity (Critical/Data Loss to Minor).

Containment: The engineering team isolates affected components (e.g., revoking keys).

Reporting: Users can report incidents via our support email. Major incidents are communicated to customers via direct email updates within defined SLAs
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
All features are included; the free trial is time-based
Link to free trial
Www.embersthedragon.co.uk/get-the-embers-app

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
25%
Between £500,001 and £1,000,000
35%
Between £1,000,001 and £2,500,000
50%
Between £2,500,001 and £5,000,000
70%
Over £5,000,001
80%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
C30e30f7-34d3-434e-b70b-ccc2027c1302
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
NHS Data Security and Protection Toolkit

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@embersthedragon.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.