Embers the Dragon Programme
Embers the Dragon is a digital programme for early emotional health and literacy for children in nursery and primary school and for family use at home. It includes specialised teaching resources and parents' website, and a clinically proven App with a parenting course, activity library, animated series and educational games.
Features
- Digital parenting course with interactive modular construction
- Purpose-built animated series based on recommended social learning theory
- Psychoeducation films for parents and family activities support learning
- Dedicated child space in-app, filled with educational games/activities
- Parents track goal-based outcomes and successful parenting techniques in-app
- Positive Behavioural Support Plan can be compiled, exported and shared
- Comprehensive aggregate outcomes and usage data reported for all customers
- Option to track usage and outcomes for individual users
- Comprehensive digital schools programme includes lesson plans, slide decks, activities
- Dedicated parents' website accompanying school programme embeds and extends learning
Benefits
- Scalable NICE-compliant app, clinically proven mental health intervention
- App prescribable by primary care if below CAMHS referral threshold
- App prescribable by CAMHS as monitorable support for waitlisted families
- App prescribable by CAMHS as adjunct to targeted therapy
- Easily implemented through all app platforms via license-based access codes
- User-friendly reporting interface for outcome tracking by clinicians
- Specialised primary school mental health resources implementable off the shelf
- School Parents Platform integrates home activities and extends parenting skills
- Whole school approach: assembly, class or 1:1 teaching resources
- School programme supports GLDs, school readiness, PHSE requirements and more
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 0 4 4 1 8 8 5 4 6 3 5 5 0 4
Contact
EMBERS THE DRAGON LTD
Yvonne Silove
Telephone: 07957545893
Email: hello@embersthedragon.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Education
- Children's Social Care
- Other
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Requires an internet connection. The mobile application requires a device running a supported version of iOS or Android.
- System requirements
- No system requirements
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 24 hours during weekdays. Next working day at weekends.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Onsite support is provided to commissioning clients (clinicians, educators) and not the eventual end user (patient). This is to support with onboarding and interoperability.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We are able to provide onsite and/or online training to commisioning organisations who will be prescribing the app to their patients. User documentation is also included.
The app has a built in onboarding and training section, inclusive of tooltips and a support inbox for our end user (patients). - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Video
- End-of-contract data extraction
- Users can request a full data export via the support desk in CSV format prior to contract termination
- End-of-contract process
-
On expiration or termination of the contract:
Access Revocation: All access is suspended immediately following the contract end date.
Trial Periods: For customers concluding a free trial or paid pilot, service access is revoked immediately, but data is retained for 60 days to facilitate seamless conversion to a full annual license.
Data Extraction: Customers can export relevant user progress data (via CSV/Excel format) directly from the dashboard at any time prior to the contract end date.
Data Deletion: In accordance with our GDPR and data retention policies, all customer data is securely deleted from our servers (AWS/MySQL) 30 days after contract termination (or 60 days for trials), unless a specific data retention agreement is in place.
No Exit Fees: There are no standard termination or exit charges.
Included in the standard subscription:
Full Platform Access
Infrastructure: All cloud hosting costs (AWS) and video streaming bandwidth.
Maintenance: Standard software updates, security patches, and bug fixes.
Support and onboarding documentation
Evaluation: Standard impact and usage analytics on user engagement and efficacy
Additional Costs (if required):
On-site or bespoke remote training sessions.
Custom content creation or bespoke feature development.
Data recovery requests made after the standard deletion period (where technically feasible). - Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Our web platform has been desgiend the give an identical user experience for both mobile and desktop users.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The wesbite is fully responsive and designed to work across all browsers. The app is a modern mobile application designed to be easily accessible and understandable by our patient users.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
Service Status: Partially Compliant
1. Web Interface: Fully compliant with WCAG 2.1 AA, supporting all standard assistive technologies including screen readers, keyboard navigation, and zooming.
2. Mobile App: Partially compliant. Meets AA standards for visual and cognitive accessibility (contrast, subtitles). However, native screen reader support is currently unavailable due to Unity 3D engine limitations (WCAG 4.1.2). We claim a disproportionate burden regarding retrofitting the current engine.
3. Mitigation: All content is available in alternative accessible formats via the Web Portal. We are monitoring Unity's roadmap to implement screen reader support in future updates - Accessibility testing
-
Current Status: We have not yet conducted external user research specifically with participants using assistive technology (e.g., screen readers). This decision is based on the current technical architecture of the mobile application (built on the 3D Unity engine), which requires a planned engine update to fully support native accessibility layers. Conducting research prior to this update would not yield valid data.
Prioritised Research: Our user research strategy has currently prioritised the primary clinical needs of our specific user base (children with emotional and behavioural challenges). We have conducted internal testing to ensure the app meets WCAG 2.1 AA standards for visual and cognitive accessibility (e.g., colour contrast, simplified navigation, and subtitles), which addresses the needs of the majority of our users.
Future Roadmap: Formal user testing with assistive technology users is planned as a subsequent phase of our development roadmap, contingent upon the deployment of the updated Unity accessibility framework. - API
- No
- Customisation available
- No
Scaling
- Independence of resources
-
Web Platform (Wix Enterprise): Hosted on a serverless, multi-tenant infrastructure utilising elastic auto-scaling to instantly provision resources during traffic spikes. A global Content Delivery Network (CDN) offloads 90% of static traffic to edge servers, while automated load balancing across multiple data centres ensures high availability and prevents "noisy neighbour" performance degradation.
Mobile Application (AWS): Built on AWS Fargate (serverless compute) for automatic container scaling in real-time. An Application Load Balancer distributes traffic across healthy tasks, while AWS RDS ensures dedicated database I/O performance. CloudWatch provides proactive monitoring to trigger immediate scaling events and maintain service stability.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The back end of the website and app provides data on usage, whilst in addition, the back end of the app provides outcome measures data. This allows commissioners and clinicians to track individual progress, review wider population trends and engagement.
- Reporting types
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can request a copy of their data through the support desk (support@embersthedragon.co.uk), or individual users can delete their account and data directly within the app settings.
- Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
- N/a data is generated via App interaction not file uploads
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
-
In addition to TLS 1.2+ encryption for all data in transit:
DDoS Protection: The infrastructure benefits from AWS Shield Standard, which provides always-on network flow monitoring and automated mitigation against Distributed Denial of Service (DDoS) attacks.
Forced HTTPS: The Application Load Balancer is configured to reject non-secure connections, enforcing HTTPS (port 443) for all web and API traffic.
Strong Ciphers: We utilize industry-standard strong cipher suites (AES-256) managed via AWS Certificate Manager (ACM) to ensure the integrity of the data tunnel - Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
In addition to encryption, we protect internal data using the standard AWS 'Defense in Depth' architecture:
Private Network (VPC): Our database and application servers run inside a Virtual Private Cloud, meaning they have no direct connection to the public internet.
Firewalls (Security Groups): We use AWS Security Groups to strictly block all traffic to the database unless it comes specifically from our own application servers.
Component Isolation: The application runs on AWS Fargate, which isolates each process in its own secure container, preventing different parts of the system from accessing each other's data memory.
Availability and resilience
- Guaranteed availability
-
We guarantee 99.9% service availability during business hours (excluding planned maintenance). Our infrastructure is built on AWS, which offers a monthly uptime percentage of at least 99.99% for the underlying compute and database services.
Compensation: In the unlikely event that availability drops below 99.9% in a given month, customers may be eligible for service credits calculated as a percentage of their monthly subscription fee, awarded upon request and investigation of the outage. - Approach to resilience
-
1. Embers Website (Wix Enterprise): Our public-facing platform utilises a resilient "Multi-Cloud" infrastructure operating across Google Cloud Platform (GCP), AWS, and private data centres. This architecture eliminates single points of failure through active-active clustering and automated failover mechanisms; if a primary node becomes unresponsive, traffic is instantly redirected to a healthy secondary location. Performance isolation is guaranteed via elastic auto-scaling, while a global Content Delivery Network (CDN) with over 200 nodes offloads 90% of static traffic to edge servers, ensuring the service remains accessible even during high-traffic events or localised internet disruptions.
2. Embers App (AWS Infrastructure): The mobile service is built on a "self-healing" cloud architecture using AWS Fargate (serverless compute), which automatically detects unhealthy application tasks and replaces them with fresh instances without human intervention. An Application Load Balancer (ALB) dynamically distributes incoming traffic across healthy containers to isolate users from single-component failures. Data integrity is secured by Amazon RDS, which ensures consistent I/O performance and performs automated daily backups with transaction log retention, enabling Point-in-Time Recovery (PITR) to restore data precisely in the event of corruption. - Outage reporting
-
1. Embers App (AWS Infrastructure) We communicate service status and outages through the following channels:
Email Alerts: Priority email notifications are sent to registered administrators during major service incidents.
Direct Support: Users can query system status via the standard support helpdesk.
2. Embers Website (Wix Enterprise Infrastructure)
Public Dashboard: Real-time service availability is viewable at status.wix.com. This dashboard provides a granular breakdown of all platform components (e.g., Editor, Live Sites, Payments).
Email & SMS Alerts: Users and administrators can subscribe to automatic incident updates via email, SMS, or Atom/RSS feed directly from the status page.
Admin Dashboard: The "Uptime & Security" dashboard within the Embers site admin panel provides site-specific uptime statistics and alerts for any localized issues affecting the service.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Users cannot access any management interfaces; these are separate to the app
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials, DTAC, DSPT
- Information security policies and processes
-
Security governance is led by the Chief Operating Officer (COO), who holds accountability for information security and compliance. We operate a 'Cloud First' governance model underpinned by our Cyber Essentials certification. Our framework includes:
Annual Audit: We undergo independent technical audits annually to maintain Cyber Essentials accreditation.
NHS Compliance: We align with the National Data Guardian’s ten data security standards (DSPT) and DTAC clinical safety standards.
Risk Management: The COO reviews asset inventories, access logs, and critical vendor performance (AWS) quarterly.
We maintain policies strictly aligned with Cyber Essentials controls:
Access Control: Multi-Factor Authentication (MFA) is enforced on all administrative accounts; admin rights are restricted to the Director and Lead Developer.
Patch Management: Critical vulnerabilities are patched within 14 days in line with CE+ requirements.
Device Security: All endpoints are managed, encrypted, and run active anti-malware protection.
Reporting: Incidents are reported to the COO and, where required, to the ICO (GDPR) and NHS Digital (DSPT) within 72 hours. - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We utilize an immutable infrastructure approach managed by our technical partner:
Code Review: All code changes require peer review by senior engineers within the partner's team before merging.
Release Approval: Major feature releases require final sign-off from the Embers Product Director before deployment to the live environment.
Tracking: All changes are version-controlled and traceable back to specific Jira tickets. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Our development partner manages vulnerability scanning as part of their ISO 27001 certified lifecycle:
Automated Scanning: Code repositories are automatically scanned for CVEs in third-party dependencies during the build process.
Patching SLA: We enforce a contractual SLA requiring them to apply 'Critical' or 'High' severity security patches within 14 days of identification.
Oversight: Embers reviews security reports quarterly to ensure SLA compliance. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Metric Alarms: AWS CloudWatch Alarms trigger alerts on abnormal spikes in CPU, memory, or error rates (HTTP 5xx).
Traffic Analysis: Application Load Balancer (ALB) logs are analyzed to detect anomalous traffic patterns.
Response: Critical alerts are routed immediately to the engineering team via automated notification channels for triage - Incident management type
- Supplier-defined controls
- Incident management approach
-
We follow a structured Incident Response Plan (IRP) aligned with NHS DSPT requirements:
Triage: Incidents are categorised by severity (Critical/Data Loss to Minor).
Containment: The engineering team isolates affected components (e.g., revoking keys).
Reporting: Users can report incidents via our support email. Major incidents are communicated to customers via direct email updates within defined SLAs - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- All features are included; the free trial is time-based
- Link to free trial
- Www.embersthedragon.co.uk/get-the-embers-app
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 25%
- Between £500,001 and £1,000,000
- 35%
- Between £1,000,001 and £2,500,000
- 50%
- Between £2,500,001 and £5,000,000
- 70%
- Over £5,000,001
- 80%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- C30e30f7-34d3-434e-b70b-ccc2027c1302
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- NHS Data Security and Protection Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-