Skip to main content

Help us improve the Digital Marketplace - send your feedback

Automation Anywhere, Inc.

Automation Anywhere Cloud - Agentic Process Automation System

Automation Anywhere provides a single, AI-powered agentic process automation system, accelerating transformation with flexible cloud-native Automation & AI products. Think of our APA System as AI's brainpower with automation's muscle, integrating agentic AI agents, machine learning, process orchestration, RPA, APIs, and natural language interfaces with public sector-ready governance and security.

Features

  • Agentic process automation platform unifying AI, RPA, orchestration, governance.
  • Cloud-native architecture supports resilient deployment across public-sector estates.
  • AI Agent studio builds AI agents using reusable skills, prompts.
  • Process reasoning engine applies GenAI Process Models for decisions.
  • Document automation extracts, classifies, validates content with Artificial Intelligence.
  • Process Discovery identifies opportunities, variants, bottlenecks, automation candidates quickly.
  • Automation co-pilot enables natural language assistance within business-friendly interfaces.
  • Co-pilot with AWS-Q connects enterprise LLMs via secure connectors.
  • APIs and RPA integrate with HR, Finance, Patient Admin systems.
  • Bot Store provides pre-built solutions, NHS blueprints, accelerators catalog.

Benefits

  • Accelerates ROI tracking through dashboards measuring automation value continuously.
  • Improves trust & security using Responsible AI and AI Guardrails.
  • Enables autonomous enterprise operations with seamless scalability and resilience.
  • Reduces manual effort via robotic process automation across end-to-end workflows.
  • Enhances clinical throughput by automating Clinical Services administration tasks.
  • Streamlines Patient Admin processes with integrated AI agents handling requests.
  • Strengthens governance using CoE Manager controls, auditability, policy enforcement.
  • Improves interoperability by connecting applications through APIs and integration.
  • Speeds adoption using flexible model, pre-built solutions, guided templates.
  • Captures Enterprise Knowledge, enabling AI agents to learn context.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at public.sector@automationanywhere.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 1 5 8 0 1 5 7 5 0 9 5 5 7 2

Contact

Automation Anywhere, Inc. Russ Boreham
Telephone: 00447928527102
Email: public.sector@automationanywhere.com

About your service

Service categories

Application Development and Deployment

Application platforms

  • Model driven application platforms
  • Robotic process automation
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
AAI will provide the Services in accordance with its then-current uptime availability standards established by the Service Level Agreement (“SLA”) which is available at https://www.automationanywhere.com/uptime-availability-SLA
System requirements
Device software and hardware requirements can be found at: https://docs.automationanywhere.com

User support

Email or online ticketing support
Yes
Support response times
Our award-winning team delivers deep technical expertise to serve you, wherever you operate in the world. Choose from flexible tiers designed so you get exactly the support you need.

https://www.automationanywhere.com/customer-support
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We firmly believe that the internet should be available and accessible to anyone and are committed to providing a website that is accessible to the broadest possible audience, regardless of ability.

To fulfill this, we aim to adhere as strictly as possible to the World Wide Web Consortium’s (W3C) Web Content Accessibility Guidelines 2.1 (WCAG 2.1) at the AA level. These guidelines explain how to make web content accessible to people with a wide array of disabilities. Complying with those guidelines helps us ensure that the website is accessible to blind people, people with motor impairments, visual impairment, cognitive disabilities, and more.

Our website utilizes various technologies that are meant to make it as accessible as possible at all times. We utilize an accessibility interface that allows persons with specific disabilities to adjust the website’s UI (user interface) and design it to their personal needs.

Additionally, the website utilizes an AI-based application that runs in the background and optimizes its accessibility level constantly. This application remediates the website’s HTML, adapts its functionality and behavior for screen-readers used by blind users, and for keyboard functions used by individuals with motor impairments.
Onsite support
Yes, at extra cost
Support levels
Our award-winning team delivers deep technical expertise to serve you, wherever you operate in the world. Choose from flexible tiers designed so you get exactly the support you need.

https://www.automationanywhere.com/customer-support

A Technical Account Manager (TAM) is provided for premium support customers at Gold tier and above.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Automation Anywhere provides a comprehensive training plan for new organizations adopting its software, ensuring that users are equipped with the necessary skills and knowledge to effectively utilize the platform. The training plan typically includes the following components:

* Role-Specific Training Paths: Tailored training paths are designed to address the unique needs of different roles within the organization, such as developers, administrators, business analysts, and end-users. This ensures that each participant receives relevant training aligned with their responsibilities.

* Online Training: Training sessions are offered online via Automation Anywhere University. Online courses allow for self-paced learning.
Certification Tracks: Automation Anywhere offers certification tracks to validate participants' proficiency in using the platform. Certifications are available for different skill levels, including Beginner, Advanced, and Master certifications, providing a structured learning path.

* Continuous Learning and Updates: As RPA technology evolves, the training program is regularly updated to reflect the latest advancements and features. This ensures that participants stay current with industry trends and best practices.

* Access to Resources: Participants have access to a wealth of resources, including training videos, documentation (docs.automationanywhere.com), and community forums, to support their learning journey and provide ongoing assistance.

Please refer to https://pathfinder.automationanywhere.com/university for more information.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Automation 360 Cloud includes mechanisms to ensure that all relevant data can be extracted in a suitable format when the contract ends. Key capabilities include:

Data Export Tools: Administrators can export bot definitions, audit logs, execution history, credential configurations, and user roles in standard formats such as JSON and CSV.

Bot Migration Utility: Automation Anywhere provides tools to package and export bots, reusable components, and associated metadata.

Open APIs: The platform offers RESTful APIs that allow programmatic access to bot data, execution logs, and system configurations - enabling seamless integration with external systems or migration utilities.

Version Control and Backup: Bots and assets are versioned and can be backed up regularly, ensuring that historical data and configurations are preserved and portable.

Documentation and Support: Detailed documentation is available to guide administrators through the data extraction and migration process, including best practices for extraction.

Compliance and Governance: All exported data maintains encryption and audit integrity, supporting GDPR and NHS data governance requirements during transition.

Automation 360 emphasizes that the primary storage of business data remains within the customer's environment. The cloud is utilized primarily for processing purposes, and data is retained in the cloud only for the duration of the process.
End-of-contract process
Upon termination or expiration of this IAA (located at https://www.automationanywhere.com/legal/intelligent-automation-agreement), Customer will cease all use of Software provided hereunder and return, or destroy upon AAI’s request, all copies of any part of the Software then in Customer’s possession or under Customer’s control. The terms in Sections/Articles 2.2, 2.4, 3.3, 4, 5, 9-11, 13, 14, and 17 will survive any termination or expiration of this IAA.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Orchestration and administration capabilities are available via mobile service - full features and functionality are available via desktop service.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The Automation 360 Cloud Service Status site displays real-time operational status, historical operational status, maintenance information, and incident history for all Automation 360 Cloud services worldwide, across all hosting regions: https://www.automationanywhere.com/legal/uptime-availability-sla
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We firmly believe that the internet should be available and accessible to anyone and are committed to providing a website that is accessible to the broadest possible audience, regardless of ability.

To fulfill this, we aim to adhere as strictly as possible to the World Wide Web Consortium’s (W3C) Web Content Accessibility Guidelines 2.1 (WCAG 2.1) at the AA level. These guidelines explain how to make web content accessible to people with a wide array of disabilities. Complying with those guidelines helps us ensure that the website is accessible to blind people, people with motor impairments, visual impairment, cognitive disabilities, and more.

Our website utilizes various technologies that are meant to make it as accessible as possible at all times. We utilize an accessibility interface that allows persons with specific disabilities to adjust the website’s UI (user interface) and design it to their personal needs.

Additionally, the website utilizes an AI-based application that runs in the background and optimizes its accessibility level constantly. This application remediates the website’s HTML, adapts its functionality and behavior for screen-readers used by blind users, and for keyboard functions used by individuals with motor impairments.
API
Yes
What users can and can't do using the API
Automation Anywhere Cloud Control Room APIs enable users and external systems to authenticate, manage users and devices, trigger automations, retrieve audit data, and orchestrate bot execution.

Setup begins with the Authentication API, which generates a token required for all subsequent API calls. Once authenticated, users can interact with modules such as Audit, Device, Trigger, API Task Execution, Policy Management, and AI Agent Studio APIs to configure or operate Control Room services.

Through the APIs, users can make changes including creating or deleting scheduled automations (for supported versions), mapping triggers, managing work queues (for supported WLM API versions), generating API task execution URLs, updating policies, and managing device or model connections.

Further information is available at: docs.automationanywhere.com
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
No

Scaling

Independence of resources
Each customer's Automation 360 environment is deployed using application load balancing across highly available public Cloud infrastructure services. The infrastructure services support both microservices running on Docker containers in Kubernetes clusters and datastores (database, cache, logging, file system, storage) supporting HA across multiple zones within a region. Both Amazon Web Services (AWS) and Google Cloud Platform (GCP) public clouds are used.

Analytics

Service usage metrics
Yes
Metrics types
The Automation 360 Cloud Service Status site displays real-time operational status, historical operational status, maintenance information, and incident history for all Automation 360 Cloud services worldwide, across all hosting regions: https://www.automationanywhere.com/legal/uptime-availability-sla
Reporting types
Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with CSA CCM v4.0
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Automation 360 Cloud includes mechanisms to ensure that all relevant data can be extracted in a suitable format. Administrators can export bot definitions, audit logs, execution history, credential configurations, and user roles in standard formats such as JSON and CSV. Automation Anywhere also provides tools to package and export bots, reusable components, and associated metadata. The platform offers RESTful APIs that allow programmatic access to bot data, execution logs, and system configurations - enabling seamless integration with external systems or migration utilities.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Automation 360 is deployed across 16 global data centers with >99.9% SLA and 4-hour RTO/RPO disaster recovery guarantees.

Service status and history can be found at: https://status.automationanywhere.digital/
Approach to resilience
Automation 360 Cloud uses a multi-layered security architecture designed for enterprise-grade protection, regulatory compliance, and operational resilience.

It applies Zero Trust and least‑privilege principles across all components, supported by fine‑grained role‑based access control (RBAC) to limit access to bots, data, and system functions. A centralized Credential Vault secures all credentials with encryption in transit and at rest, while all communication—including bot execution and API traffic—is protected using TLS 1.2+ over HTTPS and WSS. Comprehensive audit logging provides immutable, read‑only trails that bind user identities to every action. Control Room–enforced versioning and change management ensure consistent governance of bots and Bot Runners.

Automation Anywhere maintains an extensive set of compliance certifications, including SOC 1 Type 2, SOC 2 Type 2, ISO 27001, ISO 22301, GDPR‑aligned privacy controls, HITRUST for healthcare compliance, and UK Cyber Essentials. These certifications can be downloaded securely from the Automation Anywhere Compliance Portal.

The platform’s global architecture spans 16 data centers, offering a >99.9% SLA and 4‑hour RTO/RPO disaster‑recovery guarantees. Integration with enterprise security tools—firewalls, IDS/IPS, anti‑malware, and external log servers—further strengthens protection. A DevSecOps approach embeds secure coding, vulnerability scanning, and static analysis throughout development.
Outage reporting
Users can access public dashboards for service reports, found at: https://status.automationanywhere.digital/

The primary channel for communicating the timing of Cloud status and maintenance windows, or outages, is the Automation 360 Cloud Service Status site. You can subscribe to this website and receive updates.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Username and Password: Standard authentication using a username and password combination.

Two-Factor Authentication: As an administrator, you can set up 2FA so that the users can validate their identity when logging in to the Control Room using both their user credentials and a second authentication factor.

Single Sign-On (SSO): Allows users to access multiple services and systems with one set of credentials, managed through Identity Providers (IdPs) like Okta.

Active Directory Integration: Seamless integration with Microsoft Azure Active-Directory using LDAP and Kerberos for authentication.

SAML (Security Assertion Markup Language): A standard protocol used for SSO processes with public identity providers
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
Certifications: Automation Anywhere holds certifications such as SOC 2, ISO 27001, and HITRUST, demonstrating adherence to rigorous security and compliance standards. Customers can now access the various summary reports and certifications on the Compliance Portal (https://www.automationanywhere.com/compliance-portal) under NDA.

Security Breach Response: In the event of a security breach, a dedicated disaster response team communicates with the customer, gathering information and responding Without undue delay, within 72 hours or as required by the applicable law . The platform's security measures and incident response protocols are designed to quickly address and mitigate any breach including escalation protocols as required.

Data Segregation: Automation Anywhere applications use a unique tenant ID to ensure that data access is logically segregated by tenant. No data processing or storage operations can expose the data of one customer to another customer. Each customer's environment is isolated, ensuring data privacy and security.

Protection from Cyber-Attacks: The platform employs industry-standard security measures to protect against external cyber-attacks. This includes encryption (AES 256 at rest, TLS in transit), web application firewalls, and role-based access control (RBAC). Systems are monitored 24/7, and compliance with standards such as SOC 2, ISO 27001, and HITRUST is maintained.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Automation Anywhere maintains an asset and configuration management framework aligned with ISO 27001 standards. Our Asset Management Policy governs the identification, tracking, and lifecycle management of organizational assets including physical infrastructure, software, data, and intellectual property, with defined roles, responsibilities, and safeguards to ensure accountability and protection.

Configuration and system settings for core platform components are documented and centrally managed through the Control Room. This includes bot files, component locations, connections, and credential management. Documentation is updated in line with product lifecycle policies, software releases, and security patches to ensure accuracy and compliance. Periodic audits and reporting are also performed.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Automation Anywhere conducts regular security assessments and penetration testing to ensure the security and integrity of its platform and internal network. Our recent penetration assessment test is performed by SISA, a CREST Accredited provider.

These activities help identify vulnerabilities and ensure that security controls are effective. The platform's security practices include vulnerability scanning, penetration testing, and risk analysis, which are performed periodically to detect and remediate any potential security threats.

Security Testing is part of Software Development Lifecycle right from secure design to secure testing. Penetration Tests are also conducted internally on quarterly basis and annually by third party.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Automation Anywhere operates a formal vulnerability and patch management process that covers servers, endpoints, and supporting code. This process includes regular vulnerability scanning, assessment, and prioritization of patches based on severity.

The vulnerability management process includes the use of specialized tools to detect vulnerabilities in open source and third-party libraries, with regular penetration tests conducted to monitor and address security issues.

Further information on our Security/Technical and Organizational Measures (TOMs) can be found at: https://www.automationanywhere.com/legal/intelligent-automation-agreement
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Certifications: Automation Anywhere holds certifications such as SOC 2, ISO 27001, and HITRUST, demonstrating adherence to rigorous security and compliance standards for common events. Customers can now access the various summary reports and certifications on the Compliance Portal (https://www.automationanywhere.com/compliance-portal) under NDA.

Security Breach Response: In the event of a security breach, a dedicated disaster response team communicates with the customer, gathering information and responding without undue delay, within 72 hours or as required by the applicable law .

Users can quickly report incidents through the dedicated customer support portal, which will be escalated to the dedicated disaster response team.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
With Community Edition, students and developers can explore the benefits of our Automation 360 cloud platform at no charge.

- Access state-of-the art enterprise-class technology
- Instant-on ease of use with drag-and-drop simplicity
- Build bots at any skill level
- Step-by-step in-product learning

For restrictions/limitations please see: https://www.automationanywhere.com/products/enterprise/community-edition
Link to free trial
https://www.automationanywhere.com/products/enterprise/community-edition

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
25%
Over £5,000,001
30%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
A-Lign Security and Compliance Incorporated
ISO/IEC 27001 accreditation date
Monday 23 September 2024
What the ISO/IEC 27001 doesn’t cover
.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Alcumus ISOQAR
ISO 9001 accreditation date
Tuesday 2 September 2025
What the ISO 9001 doesn’t cover
.
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Thursday 3 June 2021
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
.
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
6775ebca-8b7b-4839-9dfd-4c8d196785c9
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
Yes
Any other security certifications
  • HITRUST CSF Certificate
  • ISO 42001:2023 Certificate
  • ISO 22301 Certificate
  • ISO 27001:2022, 27017:2015, 27018:2019 - Product and Cloud
  • SOC 1 Type 2 and SOC 2 Type 2 Report
  • SOC 3 Report
  • Veracode Reports
  • Black Duck Reports
  • HIPAA Report
  • OSS Reports

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at public.sector@automationanywhere.com. Tell them what format you need. It will help if you say what assistive technology you use.