Echo360 - Learning Transformation Platform
Echo360 delivers an interoperable Learning Transformation Platform that unifies video creation, interactive content authoring, engagement tools, and multi‑modal assessment to transform education and training. Its modular Echosystem enables scalable, inclusive, data‑driven learning experiences across hybrid, remote, and in‑person environments for educators, businesses, and frontline workers.
Features
- Video management: Create, capture, store, search, and manage videos.
- Interactive authoring: Build and personalise learning content easily.
- Live polling: Real‑time polls and gamified interactions.
- Video analytics: Track engagement and performance using advanced analytics.
- Captioning/transcription: Automatic captions and transcripts for accessibility.
- Remote access: Access and personalise content anytime, any device.
- System integrations: Connect with LMS, HRIS, and BI platforms.
- Cloud editing: Edit video content securely in the cloud.
- Video Feedback – Deliver feedback enhanced by adaptive AI tools.
Benefits
- Capture, edit, and share video lectures effortlessly across platforms securely.
- Engage learners with live polling, quizzes, and gamified interactions everywhere.
- Quickly manage content on the move using intuitive mobile tools.
- Publish content from multiple devices anywhere, with secure synchronisation support.
- Improve accessibility with automated captions and searchable transcripts for compliance.
- Monitor performance via real-time analytics to optimise learning outcomes continuously.
- Integrate seamlessly with LMS, HRIS, and business intelligence systems workflows.
- Support hybrid, remote, and in-person delivery without disrupting operations workflows.
- Reduce administrative overhead with streamlined content lifecycle management and governance.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 1 8 0 9 1 6 1 7 5 2 3 3 7 0
Contact
Echo360
Ian Nickson
Telephone: 07714402853
Email: inickson@echo360.com
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
- Media Services
- Creative
Content services
- Enterprise Content Management Applications
- Content Sharing and Collaboration Applications
Persuasive content management
- Digital Asset Management Applications
- Video Platforms
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Our service is designed to be hardware agnostic, working seamlessly across all modern devices and setups without requiring specific configurations. We do not impose hardware limitations, and users can access features from any standard computer or mobile device. While routine planned maintenance may occur, we schedule it to minimise disruption and maintain platform reliability. Support remains fully available across all environments, ensuring consistent performance regardless of organisational infrastructure.
- System requirements
-
- Cho360 requires no specialized hardware or software
- Echo360 is supported on all modern browsers
- Echo360 is supported on all operating systems
User support
- Email or online ticketing support
- Yes
- Support response times
- Echo360’s Customer Care operates 24/7/365, with first-tier specialists triaging, prioritizing, and assigning each ticket to the appropriate support engineer for a rapid initial response.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Echo360 evaluates the accessibility of its web-based support and chat experiences through internal testing and vendor accessibility assurance aligned with WCAG 2.1 guidelines. Testing includes keyboard-only navigation and compatibility with common assistive technologies such as screen readers. User feedback is monitored and incorporated into ongoing accessibility improvements.
- Onsite support
- Yes
- Support levels
-
Echo360 assigns a severity level to every Customer Care case to reflect the technical impact of the issue. Customers may recommend a severity when submitting a case, which is reviewed and confirmed by our support team to ensure accurate triage and faster resolution.
In addition to technical severity, Echo360 considers business priority to ensure support aligns with customers’ operational needs. Priority reflects factors such as timelines, deadlines, instructional impact, and critical workflows.
Customers can influence prioritization by providing relevant business context when submitting a case, including affected users, key academic or project deadlines, and workflow impact. When no additional context is provided, priority defaults to the assigned severity, ensuring every issue receives appropriate and timely attention. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Echo360 helps users get started quickly through a combination of guided onboarding, training resources, and ongoing support. New customers receive structured onboarding tailored to their institution’s goals, including platform configuration, LMS integration support, and best-practice guidance.
Echo360 provides a comprehensive online knowledge base with step-by-step user documentation, videos, and FAQs for instructors, administrators, and students. Live and recorded webinars, training sessions, and release updates are regularly available to support adoption and feature awareness.
Instructor-focused training emphasizes efficient course setup, content creation, and student engagement, while administrator training covers system configuration, analytics, and governance. When required, Echo360 can also provide instructor and administrator training sessions led by product specialists, delivered remotely or onsite.
Ongoing assistance is available through Echo360’s Customer Care team, ensuring users have access to expert help as they adopt and expand their use of the platform. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of a contract, Echo360 enables customers to extract their data in a structured and secure manner. Institutions can export their media content, including video and associated metadata, using Echo360’s administrative tools and APIs. Analytics and reporting data can also be retrieved through available reporting interfaces or APIs.
Echo360 works with customers during the offboarding process to define scope, timelines, and preferred delivery methods, ensuring data is provided in standard, usable formats. Data extraction is completed in accordance with contractual terms, data protection requirements, and institutional policies, after which customer data is securely removed from Echo360 systems per agreed retention schedules. - End-of-contract process
-
At the end of the contract, Echo360 works with the customer to support an orderly offboarding process. Customers are provided with the ability to extract their data, including media content and relevant metadata, in accordance with contractual terms and agreed timelines. Once data extraction is complete, Echo360 securely deletes customer data from its systems based on defined retention and data protection policies.
The contract price includes access to the Echo360 platform, standard platform features, hosting, security, regular updates, documentation, and access to Customer Care support. Routine onboarding assistance and standard support services are included as part of the subscription.
Additional costs may apply for optional services beyond the standard contract, including advanced professional services, custom development, specialized training, and non-standard data exports. Scoping, planning, and execution of activities to support migration to another solution, such as detailed data mapping, transformation, or consultation, are not included in the contract price and are provided as chargeable professional services. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Echo360 provides a consistent experience across desktop and mobile. Desktop offers the full feature set optimized for larger screens, while mobile is optimized for touch, smaller displays, and streamlined viewing and interaction.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Echo360 provides a modern, web-based interface with intuitive navigation, responsive design, and accessibility-aligned user controls across desktop and mobile devices.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Echo360 conducts accessibility-focused interface testing aligned with WCAG 2.2, including keyboard navigation and screen reader compatibility. Feedback from users of assistive technologies is monitored and used to guide ongoing usability and accessibility improvements.
- API
- Yes
- What users can and can't do using the API
-
Echo360’s API enables authorized users to securely integrate Echo360 with external systems and automate key workflows.
Through the API, users can create, retrieve, update, and manage core resources such as users, courses, sections, enrollments, media, and analytics data, supporting integrations with LMS platforms, identity systems, and institutional reporting tools.
For security and data integrity, the API enforces role-based access controls and permission scopes.
Users cannot bypass Echo360’s authorization model, access data outside their assigned permissions, modify system-level configurations, or perform actions reserved for the Echo360 application interface. All API access is authenticated, audited, and subject to rate limiting to ensure platform stability and compliance. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Echo360 offers flexible configuration and customization options that allow institutions to align the platform with their branding, workflows, and integration needs, without requiring extensive technical effort.
Customers can apply institutional branding across the Echo360 interface, including logos, color schemes, and naming conventions, delivering a consistent experience for instructors and learners within Echo360 and embedded LMS environments. The user interface is configurable to support different instructional use cases, such as lecture capture, interactive media, analytics, and student engagement.
Echo360 provides configurable player behavior, media presentation options, and feature availability based on role and context, allowing institutions to tailor experiences for instructors, students, and administrators. LMS integrations are configurable to align with institutional workflows, authentication models, and course structures.
For deeper customization, Echo360 offers robust, well-documented APIs that enable institutions to build custom integrations, automate workflows, and extend platform capabilities to meet specific business or academic requirements. Professional services are available to support advanced configurations and custom development when needed.
Scaling
- Independence of resources
-
Echo360 is built on a scalable, multi-tenant cloud architecture designed to ensure consistent performance for all customers. Resources are logically isolated by tenant, and the platform uses elastic scaling, load balancing, and capacity management to handle fluctuations in demand without impacting other users.
Echo360 continuously monitors system performance and usage patterns, applying throttling, rate limiting, and automated scaling where appropriate to protect platform stability. This approach ensures that heavy usage by one customer or cohort does not adversely affect the performance, availability, or reliability experienced by others.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Echo360 provides service metrics that support operational insight, adoption measurement, and performance monitoring. Metrics include system availability and uptime, media usage and storage, content views and engagement, learner interaction data, and reporting on courses, users, and activity. Administrators can access dashboards and reports through the platform or export data via APIs for institutional analysis, compliance, and continuous improvement.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export their data from Echo360 using built-in administrative tools and APIs. Administrators can download media files and associated metadata directly from the platform, while analytics and reporting data can be exported through reporting interfaces or retrieved programmatically via the API. For large-scale or structured exports, Echo360 works with customers to define the scope and delivery method to ensure data is provided securely and in usable formats.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- MP4 (standard video format)
- JSON (Via API)
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- MP4
- MOV
- AVI
- MP3
- WAV
- JPEG/JPG/PNG
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Echo360 provides a high-availability, cloud-hosted service designed for continuous operation and resilience. Service availability targets and commitments are defined in the Echo360 Service Level Agreement (SLA).
Echo360 typically guarantees 99.9% service availability, measured on a monthly basis, excluding scheduled maintenance and force majeure events. Platform availability is continuously monitored, with redundancy and automated recovery mechanisms in place to minimize service disruption.
If Echo360 fails to meet the committed availability levels, affected customers are eligible for service credits, calculated as a percentage of the monthly subscription fee in accordance with the SLA. Credits are applied to future invoices rather than provided as cash refunds. Detailed definitions of uptime, exclusions, measurement methodology, and credit thresholds are documented in the SLA provided as part of the contract. - Approach to resilience
-
Echo360 is designed for resilience using a cloud-native architecture aligned with the government’s Asset Protection and Resilience principle.
The platform is hosted on enterprise-grade cloud infrastructure with built-in redundancy across multiple availability zones. Critical services are load-balanced and designed to fail over automatically, minimizing the impact of component or infrastructure failures. Data is stored using replicated, highly durable storage services to protect against loss and support rapid recovery.
Echo360 continuously monitors system health and performance, with automated alerting and incident response processes to address issues quickly. Regular backup and recovery procedures are in place to support service continuity.
Physical datacentre resilience, including power, cooling, environmental controls, and physical security, is managed by accredited third-party cloud providers operating to recognised international standards (such as ISO/IEC 27001 and SSAE-18). Additional technical and architectural details can be provided on request. - Outage reporting
-
Echo360 reports service outages through multiple communication channels to ensure customers are informed in a timely and transparent manner.
Service status and incidents are communicated via Echo360’s public status page, which provides real-time availability updates, incident descriptions, and resolution progress. For significant incidents, Echo360 also notifies customers through direct communications such as email alerts to designated contacts.
Following resolution, Echo360 provides incident summaries or post-incident communications outlining impact, root cause, and corrective actions, where appropriate. This approach ensures customers have clear visibility into service health and outage management.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
- Echo360 supports user authentication through integration with an institution’s existing single sign-on (SSO) solution, enabling users to access the platform using their standard institutional credentials. The service supports industry-standard authentication protocols and integrates with common identity providers and learning platforms. This approach simplifies access, reduces password management overhead, and allows institutions to retain control over user identity, authentication policies, and access lifecycle management.
- Access restrictions in management interfaces and support channels
- Echo360 restricts access to management interfaces and support channels using role-based access controls and least-privilege principles. Administrative access is limited to authorised users based on defined roles, with authentication enforced through secure login and, where configured, federated identity and MFA. Support channel access is restricted to approved customer contacts and Echo360 personnel. All access is logged and monitored, with regular reviews to ensure permissions remain appropriate and compliant with security policies.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- Echo360 supports management and administrative access through integration with an institution’s existing single sign-on (SSO) solution. Administrative users authenticate using their standard institutional credentials, with access controlled through role-based permissions. This approach ensures secure management access, simplifies user administration, and allows institutions to retain control over authentication policies and access management.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Echo360’s security governance aligns with recognised standards, including ISO/IEC 27001–aligned practices and SSAE-18 / SOC 2 controls through cloud providers. Echo360 maintains formal security policies covering risk management, access control, vulnerability management, and incident response.
- Information security policies and processes
-
Echo360 maintains a formal information security program aligned with recognised industry standards and best practices. Security policies cover areas including access control, data protection, encryption, vulnerability management, incident response, change management, and business continuity.
Security governance is overseen by senior leadership, with defined roles and responsibilities for security, engineering, and operations teams. Policies are approved, reviewed, and updated regularly to reflect changes in risk, technology, and regulatory requirements.
Compliance with security policies is enforced through technical controls, documented procedures, and ongoing monitoring. Echo360 conducts regular security reviews, vulnerability assessments, and third-party audits where applicable. Employees receive security awareness training and are required to follow established policies as part of their roles. Incidents and exceptions are tracked, escalated, and remediated through formal reporting and review processes, ensuring continuous improvement and accountability across the organization. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Echo360 follows a structured, standards-aligned approach to configuration and change management in line with the government’s Operational Security principle. All changes undergo documented risk assessment, approval, testing, and controlled deployment, with changes tracked and auditable. The platform runs on enterprise cloud infrastructure compliant with SSAE-18 / ISAE 3402, providing additional assurance at the infrastructure layer. Continuous monitoring and post-change review help maintain platform stability and security.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Echo360 follows a risk-based vulnerability management process aligned with the government’s Operational Security principle. Potential threats are assessed through regular vulnerability scanning, external penetration testing, and continuous monitoring of platform components. Threat intelligence is sourced from cloud providers, security advisories, vendor disclosures, and industry best practices. Security patches are prioritised by severity and impact, with critical issues remediated promptly and deployed through controlled change management processes to minimise risk and service disruption.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Echo360 uses continuous protective monitoring to identify potential security compromises across its platform. Monitoring includes log analysis, alerting, and anomaly detection across infrastructure and application services. When a potential compromise is identified, incidents are triaged immediately, investigated by security and operations teams, and contained using defined incident response procedures. Response actions are prioritised by severity, with critical security incidents addressed promptly to minimise impact and restore service in line with established response objectives.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Echo360 maintains a formal incident management process with predefined procedures for common security and service events. Incidents can be reported by users through the Customer Care portal or designated support channels. Incidents are logged, triaged, and managed according to severity, with escalation to technical and security teams as required. Echo360 provides incident communications during significant events and delivers post-incident reports summarising impact, root cause, and corrective actions when appropriate.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Echo360 offers a limited free or trial experience that provides access to core platform features for evaluation purposes. Advanced functionality, full administrative controls, integrations, analytics, and production support are not included. The free offering is typically time-limited and intended for evaluation only.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2%
- Between £250,000 and £500,000
- 4%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 8%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Volunteering opportunities for staff
-