AYOA
AYOA is a cloud-based Project, Productivity , Creativity and communication Tool combining AI-assisted Mind Mapping, Task Management, Project Boards, and real-time collaboration with interactive, colourful, customisable neurodivergent-friendly design. UK-hosted, ISO 27001:2022, CE+ certified, SBD, DEFCON 658 ready. 99.1% avail. (99.9% on PaaS). Gov-approved Assistive Technology for students and workers.
Features
- AI-Assisted Mind Mapping with ideation and content transformation
- Multi-view Project Management: Kanban, Gantt, Canvas, Document and Whiteboards
- Real-Time Collaboration: Co-edit, Chat, Comment, Team Pulse
- Cross-Platform Synchronisation: Web, iOS, Android, remote and offline
- Enterprise Integration: MS365; GWS, Dropbox, API
- Neurodivergent Accessible: Keyboard navigation, Adjustable themes and fonts, focus mode
- Advanced Task Management: Priority management, Automated workflow, Planner, Calendar
- Secure UK Hosting: Multi-cloud (GCP and AWS), data encryption
- Comprehensive audit trails: Task and Project level tracking
- AI Content Translation: Image and Audio to digital, Translation, Summarisation
Benefits
- Supports Neurodiversity goals: UK Gov approved, enable inclusive teams
- Reduce stress and burnout: Visual organisation reduces cognitive load
- Improve decision making: prevent groupthink, create space for all ideas
- Enhance information retention: 32% increase in memory vs. text-only
- Increase productivity: Eliminate tool switching with all-in-one solution
- Collaborate: bridge the gap between neurotypical and neurodiverse thinkers
- Data sovereignty and security: UK hosted, security certified
- Zero AI training on client data: protects sensitive information
- No vendor lock-in: standard exports, bulk exports, no termination fee
- Reliable: 99.1% uptime SaaS. 99.9% PaaS. Robust BCDR
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 1 3 0 3 5 0 1 3 9 8 9 7 1 6
Contact
OPENGENIUS LIMITED
Jacqueline Jeffreys
Telephone: 02038188242
Email: infosec@opengenius.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Project and portfolio management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
Scheduled maintenance: Monthly windows (as required) with maximum 6.5 hours downtime, minimum 48 hours notice, implemented outside core business hours.
Standard support hours: 9:00 AM - 5:00 PM UK time, Monday-Friday. Enhanced/Premium packages available for extended coverage. 24/7 self-service via knowledge base and AI chatbot.
File upload limits: Free tier 20MB, Ultimate/Enterprise tiers 60MB.
Minimum requirements: 2Mbps download speed, modern browsers (Chrome 90+, Firefox 88+, Safari 14+, Edge 90+), minimum 1024x768 resolution.
Data retention: Inactive accounts deleted after 6 months inactivity with advance notice. - System requirements
-
- Browser: Chrome 90+; Firefox 88+; Safari 14+, Edge 90+
- Network: 2Mbps download speed; Internet connection (offline available)
- Screen resolution: 1024x768
- Mobile device: iOS 13.0+; Android 8.0+ (API level 26)
- Authentication: MFA mandatory for admin; SSO for MS65, GWS
- Connection security: TLS 1.2+
- AYOA is accessed via standard web browsers, native mobile app
User support
- Email or online ticketing support
- Yes
- Support response times
-
Standard Support Hours: 9:00 AM - 5:00 PM UK time
Monday-Friday (weekend availability subject to Support package)
Response and Resolution:
Note: Response times are contractual commitments. Resolution times are targets and vary based on complexity.
Critical (service unavailable)
Target response time: 60 minutes
Target resolution time: 4 hours;
High (major feature unavailable)
Target response time: 2 hours
Target resolution time: 8 hours
Medium (minor feature issues)
Target response time: 1 working day
Target resolution time: 3 working days
Low (single user impact, feature request)
Target response time: 3 working days
Target resolution time: Best effort - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 A
- Web chat accessibility testing
- We've reviewed AYOA website accessibility with online Accessibility Checker solutions. We are an Accessibility Solution approved by UK-Government, and are continuing to adapt AYOA to maximise compatibility with WCAG 2.2AAA standards, including the improvement of keyboard navigation. The AYOA website has the 'ALLY' solution installed which allows user to select their chosen accessibility settings. The AYOA Help Centre is also aligned with this and has adjustment capabilities to suit neurodiverse users. We are continually developing and optimising accessibility solutions for our end users, using solutions like NVDA to help us improve compatibility with available solutions, as well as feedback from our neurodiverse community.
- Onsite support
- Yes, at extra cost
- Support levels
-
Standard Support is included with all AYOA subscriptions at no additional cost, providing Monday-Friday 9am-5pm GMT email support, 24/7 self-service knowledge base, and AI chatbot assistance.
Three enhanced support packages are available (priced per organisation annually):
Extended Support (£2,000): Monday-Friday 7am-9pm GMT with priority ticket routing and quarterly service reviews.
Priority Support (£7,000): Extended hours plus weekends (7am-9pm daily), telephony support, named account support representative, monthly service reviews, beta feature access, and quarterly custom training.
Premium 24/7 Support (£16,000): Round-the-clock emergency hotline, dedicated account manager, fortnightly service reviews, proactive system health monitoring, unlimited training, priority product roadmap input, and annual UK onsite visit.
Response times are contractual commitments: Critical (1 hour), High (2 hours), Standard (24 hours), Low (72 hours). Resolution times are targets varying by complexity.
Support packages can be upgraded anytime with pro-rata charges; downgrades take effect at renewal.
Technical expertise available: Senior Technical Support specialists (SFIA Level 5) provide advanced troubleshooting, system optimisation, and enterprise deployment support at £1,200/day for complex requirements. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Account creation: users sign up via web interface with email and password or via SSO (Microsoft 365/Google Workspace)
Free tier is available immediately with view/comment access and limited project boards. Ultimate (standard for Enterprise users) have unlimited access
Onboarding: standard onboarding includes embedded step-by-step tips, guided workflows, 24/7 self-service help centre, video tutorials, AI chatbot assistance and 9-5pm email and portal assistance via AYOA Helpdesk.
Enterprise onboarding: As with standard onboarding. Professional Services available:
Product specialist/ Assistive Technology training delivery: (£500 per 4-hour remote session, SFIA Level 3)
Enterprise deployment and user migration assistance (£1,200/day, SFIA Level 5)
Advanced custom training programmes and train-the-trainer sessions (£1,200/day, SFIA Level 5)
Initial setup: users create their first workspace, familiarise themselves with available project views, choose their preference and customise interface settings (themes, fonts, layouts). Pre-built templates available to reduce setup time. - Service documentation
- No
- End-of-contract data extraction
-
AYOA ensures no vendor lock-in with comprehensive data export options at contract termination.
Standard export is available at no cost: users retain full data ownership and can export their project and workspace data at any time through built-in interface features in multiple formats including OPMF (Open Mind Map Format) and Microsoft Office formats. No data extraction charges apply for standard exports.
Bulk export service (optional): for large-scale enterprise data migration upon contract termination, a comprehensive bulk export service is available at £1,200 (SFIA Level 4-5), delivered within 30 days of request.
API access: where configured, enterprise customers may extract data programmatically via API throughout the contract term and at termination. Subject to API configuration availability, to be defined at contract award.
Data retention: customer data is retained for 30 days to allow extraction, then permanently deleted.
As standard, users receive advance notification before deletion in the event of account deactivation.
Zero exit fees apply in the event of early termination. Pro-rata refunds for unused subscription terms are available subject to consumer rights legislation review.
Standard support assists with export processes during business hours; enhanced support packages provide dedicated assistance for complex data migrations. - End-of-contract process
-
Upon contract termination, customers retain full data ownership with no exit fees. Standard data export features are included at no cost, accessible through the AYOA interface in multiple formats (OPMF, PDF, Microsoft Office etc.). Data remains accessible for 30 days post-termination to allow extraction. Pro-rata refunds for unused subscription terms available subject to consumer rights legislation review.
Additional costs:
Bulk export service for large-scale enterprise data migration: £1,200 (delivered within 30 days). This comprehensive extraction service is optional; most customers successfully export data using standard built-in features.
Customers receive advance automated account expiration notifications. During the 30-day grace period, all export features remain accessible.
AYOA support (standard 9am-5pm UK) assist with basic export processes at no additional charge.
After 30 days, inactive account data is permanently deleted per GDPR compliance.
Contracts can be terminated anytime without penalty. Support package downgrades take effect at renewal; subscription cancellations processed immediately with appropriate pro-rata refunds where applicable.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- While an application installation is not required for accessing AYOA on desktop or laptops (or indeed mobile devices) we do have an AYOA app for iOS and Android.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
-
AYOA provides a cloud-based web interface accessible via Chrome 90+, Firefox 88+, Safari 14+, and Edge 90+ (minimum 1024x768 resolution). The highly customisable visual interface supports neurodivergent users with multiple workspace views: Mind Maps, Kanban boards, Gantt charts, Canvas view, and Infinite Whiteboards.
Accessibility features include dyslexia-compatible fonts, high-contrast themes, adjustable font sizes, keyboard navigation, and focus mode. Progressive WCAG 2.2 AAA compliance ensures inclusive access.
Mobile applications (iOS 13.0+, Android 8.0+) provide synchronised access with offline mode.
Customisation options include extensive photo/GIF libraries, AI image generation, configurable colour schemes, and pre-built templates designed to reduce cognitive load. - Accessibility standards
- WCAG 2.2 A
- Accessibility testing
-
As an Assistive Technology solution approved and provided by the Department of Education in the UK (as well as the Department of Work and Pensions for those eligible for the Access to Work scheme) AYOA is tested by neurodivergent users daily, and is showcased at assistive technology exhibitions and events internationally where it is scrutinised by assistive technology audiences (as well as through keynote sessions delivered by our CEO).
We actively monitor our feedback from our user community which informs improvements delivered by our development pipeline. We are continually improving alignment with WCAG 2.2AAA because at the moment we are partially compliant across numerous elements of the standard. Our improvement pipeline includes website accessibility (notably the user interface providing access to help and support) and further enhancing accessibility solutions within the product itself. - API
- Yes
- What users can and can't do using the API
-
AYOA's RESTful API enables enterprise customers to integrate with existing systems and automate workflows this is currently on a partial basis: custom API integrations can be made available upon request for Enterprise tier customers.
Setup capabilities: Organisations can provision user accounts, create workspaces, configure permissions, and establish SSO authentication through Microsoft 365 or Google Workspace integration.
Modification capabilities: Users can create and update Mind Maps, Tasks, and Projects; manage team memberships; synchronise calendar data; convert emails to tasks (through Gmail integration); and access file storage through Dropbox, Google Drive, or OneDrive connections.
Limitations: API access requires Enterprise subscription tier. Standard export features are available to all users at no cost, but custom API development requires Professional Services engagement (Integration Specialist at £1,500/day, SFIA Level 6). Bulk data operations and advanced automation features require prior scoping and may incur additional implementation costs as per SFIA rates. API documentation provided upon contract award and implementation planning. - API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Customisation capabilities:
Visual customisation (all users):
Multiple Layouts:
Mind Maps can be shown in radial, organic, capture views
Cross-application configurable colour schemes and themes
High-contrast themes and dyslexia-compatible fonts
Adjustable font sizes and line spacing
Speed Keys
Keyboard functionality and shortcuts
Custom images from extensive photo/GIF library or AI-generated images (or upload your own)
Sketch capability and freeform
Auto-focus, auto-layout, auto-cleanup
Workspace Customisation:
Switch between view types: Canvas view, workflows/Kanban boards, Gantt timelines
Document view for executive summaries
Whiteboards with infinite personalisation
Presentation, flowchart diagrams, sticky notes
Show/hide collaborators, notes and comments within project views
Adjustable detail levels from granular to high-level summaries
Workflow Customization (Enterprise):
Create reusable project templates with preset workflows
Custom tagging systems
Progress sliders for task status
Priority and urgency settings
Custom integrations via API (requires Professional Services)
Administrative Customisation:
Role-based permissions and access levels
SSO configuration (Microsoft 365, Google Workspace)
Workspace-level settings and policies
Who can customise:
Individual users control personal preferences; workspace administrators manage team settings; enterprise administrators configure organisation-wide policies and integrations.
Scaling
- Independence of resources
-
AYOA guarantees resource independence through enterprise-grade multi-cloud architecture with automatic scaling and isolation.
Multi-cloud deployment (GCP UK, AWS S3 UK) with geographic redundancy
Enterprise cloud providers employ resource isolation and auto-scaling
99.9% availability SLA maintained at PaaS level regardless of user load
AYOA operates an automated failover within 4-hour RTO for redundancy
Fair usage monitoring prevents excessive resource consumption
Proactive system health monitoring including vulnerability scanning
Workspace-level data segregation with role-based access controls
Independent workspace operations with dedicated resource allocation
Each customer operates in an isolation at application layer ensuring consistent performance and data security regardless of concurrent platform activity.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Standard metrics (all customers):
Uptime and availability reporting (99.1% SLA monitoring)
Service performance tracking
Security incident response and resolution metrics
Enhanced metrics (on request, subject to Support Package):
Detailed usage reporting
User activity and engagement statistics
Custom compliance reporting
Support Packages
Standard: Basic metrics via help centre
Extended/Priority: Quarterly/monthly service reviews with analytics
Premium 24/7: Fortnightly reviews with proactive monitoring and comprehensive reporting
Senior Business Consultant services (£1,500/day, SFIA Level 6) available for advanced analytics and custom reporting requirements. - Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Multi-cloud redundancy
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Mind Maps export as PDF, DOC, HTML, TXT, PPT, PNG, or OPML; Document View offers the same formats. Word exports include Classic, Clean, Typewriter, Dyslexia-friendly, APA, Harvard, and MHRA styles, with options for formatting, images, bibliographies, and branch links. Task Boards export as JPG, PNG, PDF, or CSV (including archived tasks, notes, checklists). Gantt/Timeline exports as CSV or PDF with selectable ranges. Whiteboards export as PNG or JPG. No export limits, though Fair Use monitoring applies.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- DOC
- JPG
- PNG
- HTML
- PPT
- OPML
- TEXT
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- DOCX
- TEXT, HTML
- PPTX
- XLSX
- OPML
- IMX
- MD
- MP3, OGG
- JPG, PNG
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
AYOA guarantees 99.1% monthly uptime, measured excluding planned maintenance. Our multi-cloud infrastructure spans Google Cloud Platform and Amazon Web Services across UK data centres, providing enterprise-grade reliability with geographic redundancy and automated failover.
Service Level Agreement:
Target availability: 99.1% per calendar month
Planned maintenance: Maximum 6.5 hours monthly, scheduled outside core business hours with 48-hours minimum notice. Typically 4 hours maximum.
Real-time system monitoring with automated incident detection
Service Credits for Availability Breaches:
If monthly availability falls below 99.1%, service credits (percentage of monthly subscription fee) automatically apply:
98.0%-99.09%: 10% credit
95.0%-97.99%: 25% credit
90.0%-94.99%: 50% credit
Below 90.0%: 100% credit (full month refund)
Customers must claim within 30 days. Credits applied to next invoice or as service extension.
Business Continuity:
Recovery Time Objective (RTO): 4 hours
Recovery Point Objective (RPO): 1 hour
Automated backups: hourly snapshots (2-day retention), daily (7 days), weekly (4 weeks), monthly (12 months)
UK-to-UK data replication
Quarterly BCDR testing
Incident Response:
Critical incidents: 60-minute response, 4-hour target resolution
24-hour BCDR incident notification
Root cause analysis within 30 days - Approach to resilience
-
AYOA is architected with multi-cloud infrastructure, automated redundancy, and comprehensive business continuity measures.
Multi-cloud deployment across Google Cloud Platform and Amazon Web Services provides vendor diversification and eliminates single points of failure.
Primary hosting utilises GCP UK for databases and AWS S3 for file storage, both with geographic redundancy across UK data centres.
Automated failover mechanisms ensure service continuity during infrastructure disruptions.
Our cloud providers maintain certified facilities with redundant power systems, network connectivity, and environmental controls.
UK-to-UK data replication ensures data availability and supports our 4-hour Recovery Time Objective and 1-hour Recovery Point Objective for critical systems.
Microservices architecture with containerised deployment enables isolated failure handling without system-wide impact.
Load balancing distributes traffic across multiple availability zones. Real-time health monitoring triggers automatic remediation for degraded services.
Multi-tier backup strategy: hourly snapshots (2-day retention), daily backups (7 days), weekly (4 weeks), monthly (12 months). Backups stored in geographically separate locations from primary data. Quarterly restore testing validates recovery procedures.
ISO 27001:2022 certified Business Continuity and Disaster Recovery plans tested quarterly. Incident Management Policy ensures coordinated response. Personnel trained through quarterly tabletop exercises and annual security refreshers.
Detailed data centre security specifications available upon request - Outage reporting
-
AYOA provides comprehensive reporting through multiple channels to ensure customers remain informed during service disruptions.
During incidents, we provide immediate notifications through:
In-app notifications visible to all active users
Social media updates via official AYOA channels
Direct telephony contact where pre-agreed escalation channels exist
Customers can access incident status and updates through our support portal (support.ayoa.com)
Outages are categorised by severity and our contractual response times are:
Critical (service completely unavailable): 60-minute response time
High (major feature unavailable): 2-hour response time
Medium (minor feature issues): 1 working day response
Low (single user impact): 3 working days response
Resolution times may vary due to a dependency on incident severity but our targets are:
Critical: 4 hours
High: 8 hours
Medium: 72 hours
Low: Best effort / next viable release
Following service restoration we will provide root cause analysis within 30 days
Detailed post-incident resolution reports available for Premium Support customers
Service credit calculations automatically generated where applicable
Lessons learned incorporated into annual continuous improvement initiatives
Planned Maintenance:
Scheduled maintenance communicated minimum 48 hours in advance where client impact is anticipated (target 7 days) via email, in-app notifications and support portal announcements.
All maintenance scheduled outside core UK business hours
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
-
Management interfaces require MFA for all administrative accounts. Privileged access follows principle of least privilege via RBAC —no shared credentials. Admin accessible only from company-managed devices with endpoint protection. GCP /AWS console access restricted by IP allowlists/MFA. Infrastructure management requires 12-32 character complex passwords with automatic session timeouts. All privileged account activity logged with 20-day retention.
Support channels operate on authenticated ticket systems. Customer support staff access customer accounts only through secure admin portals with audit logging. Access requests processed through approval workflow. Quarterly access reviews verify appropriate permissions. Remote administrative access prohibited without business justification and enhanced monitoring. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Less than 1 month
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Comprehensive information security governance aligned with ISO 27001:2022, Cyber Essentials Plus, and SOC 2 Type II certifications and adherence to Secure By Design and NCSC Cloud Principles. Actively aligning with Defense Digital standards currently.
ISO 27001:2022 certified ISMS
Documented InfoSec procedures covering access control, data protection, incident response, and vendor management
Internal legal and risk registers maintained for compliance with UK and international data protection, human rights, and emerging AI laws
Multi-factor authentication (MFA) mandatory for admin accounts
Role-based access control (RBAC) across all systems
AES-256 encryption at rest, TLS 1.2+ in transit with regular key rotation
Annual external penetration testing
Internal security audits (monthly and quarterly intervals spanning application, access, network, vendor, devices, database)
Security awareness training at onboarding with quarterly NCSC tabletop exercises and annual refreshers
Monthly InfoSec team security incident reviews
Comprehensive employee offboarding procedures with signed confidentiality statements
Dedicated InfoSec team conducting regular security reviews and documenting findings and actions
Vendor assessments at onboarding with quarterly compliance reviews
Incident response procedures with 24-hour communication protocols for ICO compliance
Compliance monitoring through annual BCDR testing and quarterly tabletop exercises
Annual ISMS reporting and quarterly Board updates.
All documentation subject to minimum annual review to maintain certification standards. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
OpenGenius tracks all service components through our comprehensive asset inventory recording ownership, type, CIA scores, and lifecycle status from acquisition to secure disposal.
Changes follow our formal change management process
Every change evaluated for security impact on confidentiality, integrity, and availability, except Standard Change.
Risk likelihood and impact scored using our 1-5 framework
Graded authorisation based on risk level (department head to CEO/CISO)
Changes progress through segregated dev/test/production environments
Continuous logging and monitoring post-implementation
Documentation maintained per ISO 27001:2022 requirements, with regular reviews through internal audits and management reviews. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
We maintain threat intelligence processes collecting information on security threats, evaluating exposure through technical vulnerability assessments and conducting regular security testing
Critical patches are prioritised and deployed rapidly following our Patch Management Policy . Changes undergo security impact assessment via our Change Management Procedure with Critical patches fast-tracked (automated where possible industry standard 24-72 hours) Testing is segregated before production deployment.
Threat Intelligence Procedure includes InfoSec notification / attendance:
Vendor security advisories
Security forums and specialist interest groups
CVE databases and vulnerability feeds
BitDefender threat intelligence
Industry security bulletins
All activities documented and reviewed through the auditing process. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
GCP/AWS infrastructure has comprehensive protective monitoring (GCP Cloud Logging, AWS CloudWatch). We track authentication and access patterns and data volumes with automated alerting for multiple failed logins, unusual geographic access, abnormal data volumes, and known attack signatures.
Under ISO 27001:2022 Incident Management Policy, detected compromises trigger immediate automated protections: credential resets, session terminations, and account suspensions within minutes. CEO escalation occurs within one hour, ICO/NCSC/affected client in 24. Critical incidents: 4-hour response time, same-day resolution target. RTO: 4 hours; RPO: 1 hour. All incidents logged in AYOA Security Incident workflow supporting quarterly BCDR testing and 99.1% SaaS uptime (99.9% PaaS) - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- ISO 27001:2022-certified Incident Management Policy covers security breaches, service outages, data loss, and performance issues. Users report incidents via email, in-app support, or account representatives. All incidents are logged in the CRM and, for security events, within the AYOA workflow, categorised by severity. Critical incidents receive a 4-hour response; high priority 8 hours; standard 24-72 hours. Security incidents escalate to CEO, ICO, and insurers within 24 hours (1 hour for CEO), with affected customers notified within 24 hours. Root cause analysis is completed within 30 days, and remediation/prevention plans implemented. Annual BCDR testing and quarterly tabletop exercises ensure readiness.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- AYOA Free offers 10 project spaces consisting of Mind Maps, Task Boards, and Whiteboards. No time limit, but commercial use, exports, Gantt/Timeline, AI tools, collaboration and integrations are locked. Inactivity over six months leads to account deactivation. Ultimate Trial: 7 days full-feature access.
- Link to free trial
- https://auth.ayoa.com/signup
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 8%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 12%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 18%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- DNV/UKAS
- ISO/IEC 27001 accreditation date
- Thursday 3 October 2024
- What the ISO/IEC 27001 doesn’t cover
-
OpenGenius has excluded 5 controls from the ISO 27001:2022 Statement of Applicability, all within the Physical Controls domai. These exclusions relate to physical security responsibilities managed by the building provider, Tec Marina.
Excluded Controls:
A.7.1 - Physical security perimeters
A.7.2 - Physical entry controls and access points
A.7.4 - Physical security monitoring of premises
A.7.5 - Protection against physical and environmental threats
A.7.11 - Supporting utilities (power, environmental systems)
Justification: All exclusions are consistently documented as "Not in scope for OpenGenius, managed by Tec Marina" and referenced in detail in our Physical Security Policy.
Please note: We have however marked the following controls as Implemented and have built security management systems around these accordingly:
A.7.3 - Securing offices/rooms/facilities and
A.7.12 - Cabling security
A.7.2 - Physical entry controls and access points
A.7.4 - Physical security monitoring of premises
This reflects OpenGenius's retained responsibility for certain physical security aspects within leased office space.
These exclusions are aligned with our SaaS operations from leased premises, where building-level physical security infrastructure is contractually managed by the property provider, with clear delineation of security responsibilities through our lease and premise security management agreements with Tec Marina. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 6f0fdafa-57a1-45d1-a88c-ec4527dca5fb
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 5d0877cb-be5c-4bb4-984d-594a807394e6
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-