Skip to main content

Help us improve the Digital Marketplace - send your feedback

CULTURE AMP LIMITED

Employee Engagement and Performance Management Software

Culture Amp is an employee experience platform that helps organisations measure and improve employee engagement, performance, and development through people‑science‑backed tools and guidance.

Features

  • employee experience surveying
  • performance management
  • AI coach
  • real time reporting
  • people analytics
  • development planning
  • people science
  • employee engagement and retention
  • goal setting
  • 1 on 1's

Benefits

  • get real time employee feedback
  • measure employee engagement
  • Help employees realise their potential with development-focussed performance tools
  • quickly share employee experience analyses
  • foster a culture of continuous growth with personalised career paths
  • Transform people data into actionable intelligence
  • take action on employee feedback to drive engagement
  • share feedback with peers, direct reports and managers
  • measure performance in a manner which minimises bias

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at oskar.karlsson@cultureamp.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 2 8 4 1 7 4 3 7 9 0 0 0 1 5

Contact

CULTURE AMP LIMITED Oskar Karlsson
Telephone: 07717822092
Email: oskar.karlsson@cultureamp.com

About your service

Service categories

Applications

Enterprise resource management

  • Enterprise performance management

Human capital management

  • Core Human Resources Applications
  • Talent Management Applications
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
N/a
System requirements
Internet connectivity

User support

Email or online ticketing support
Yes
Support response times
Initial requests via Live Chat/Email support channels will be managed by our AI Agent. If it can assist, response is in moments. If it cannot respond to your question, you will be notified and connected with the team automatically. Once with the team, we pride ourselves in ensuring we are available for as long as required to give full attention to each inquiry. As such, we don't set explicit agreements on response times to allow specialists the time they need to provide a complete support experience to you. However, live chat typical response is within 20 mins, email 24-72 hours.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Our web chat aims to meet WCAG Level AA. We test and govern accessibility the same way we do across the platform (independent audits with Intopia, internal standards and automated checks, and AT/keyboard testing). However, we don’t currently have a published Intopia Statement of Conformance that is specifically scoped to “web chat,” so we can’t claim full conformance for that area yet.
Onsite support
Yes, at extra cost
Support levels
Onsite implementation support.
Support available to third parties
No
AI chatbot
Yes

Onboarding and offboarding

Getting started
Enterprise customers are onboarded through a guided implementation program led by a dedicated Implementation Manager for roughly the first 3 months, supported by your Customer Success Manager and People Scientist, with structured checklists, training, and a single upfront implementation fee.

What Enterprise onboarding includes:
An Implementation Manager who meets regularly for ~3 months to project-manage your first launch and provide technical guidance; plus a 1‑month account setup period.

Strategic services tailored to Enterprise, such as project planning, change management support, suggested comms and enablement for leaders, and a survey design planning session with People Science.

Coordinated team: you primarily work with an implementation expert; your Customer Success Manager (and People Scientist for Enterprise) stay engaged and transition you post‑launch into ongoing success planning.

In‑product Enterprise onboarding checklist and email nudges to drive timely setup and adoption, delivered when admins first log in

Access to private live virtual training from Culture Amp Training (CAT) for Enterprise implementations and launches, scheduled by IM/CSM when needed. Unlimited access to public training, and online/ anytime via Culture Amp Training and Culture Amp support guides.
Service documentation
Yes
Documentation formats
Other
Other documentation formats
  • Online support guides
  • Online culture amp training
End-of-contract data extraction
How customers extract their data:
Use built‑in export options across products (admins can export reports, insights, and usage data).

Surveys:

Export Summary, Insights/Questions, Participation, Heatmaps, Comments, PPT, and CSV/XLS from each survey.

Raw Data Extract (RDE): Only available if enabled before launch; admins can export it themselves from the survey’s exports when enabled.

If RDE was not enabled, Support can provide a de‑identified data extract per survey upon request; this is a support‑assisted process.

Performance:

There are standard exports for performance reviews and related reports; some features (e.g., 1‑on‑1s, Continuous Feedback, Manager‑requested feedback history limits) have constraints noted in our offboarding guides.
End-of-contract process
If a customer does not renew, we accept their notice and initiate offboarding processes, the Customer Sucess Manager and Support help by coordinating contacts and timelines, and reminding the customer to export data before the platform is turned off at expiry (once Culture Amp is shut off, we can’t save any data)
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Culture Amp is a responsive web app that works on modern mobile browsers—there’s no native mobile app. Surveys and many reports are optimized for small screens, with recent updates improving accessibility and mobile usability for key features like heatmaps and participation reports. Surveys can be completed on smartphones and tablets; the interface is designed for touch (e.g., swipeable response bars).
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
Culture Amp has an API for one-way, outbound data retrieval so you can securely access account data from the Culture Amp platform. It’s RESTful and currently does not support data ingestion.

What it’s for:
- Securely retrieve your Culture Amp account data for use in your systems.

-Common use cases include analytics/reporting, connecting Culture Amp data to other apps, and automating workflows.
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Users can customise many parts of Culture Amp (surveys, comms, account branding).

What users can customise:
Survey content: You can run templates as-is, tweak wording to your company lingo, or fully customise by adding/removing/modifying questions. There are also blank “Custom” templates for building from scratch.

Creating custom surveys: Survey creators/admins can duplicate existing surveys, use templates, or build a custom survey with zero questions and add their own items. An unattributed custom option is available via the specific template.

Survey communications: You can edit invites and reminders for email, Slack, and Microsoft Teams (not report notifications/Reporting Rules). Variables can be used to personalise messages.

Sender name on emails: Account Admins can set a custom sender name for Engagement/Experience/Effectiveness emails to improve recognition. This does not apply to Performance emails.

Branding: Account-level settings like company name, timezone, and logo are editable. You can also set a survey-specific logo that differs from the account logo.

Languages: Default performance templates are translated; you can customise questions and use auto-translate or add manual translations. Some custom content remains in the original language and may create mixed-language experiences.

Scaling

Independence of resources
We mitigate “noisy neighbour” effects in our multi‑tenant communications/Flow services by isolating work per account, interleaving tasks across workers, and throttling or sidelining excess traffic so one tenant can’t degrade others.

examples:
Per‑account workflow isolation using Temporal: We trigger a dedicated workflow per account integration. Temporal’s task queues interleave execution across workers so one tenant can’t monopolize worker resources, which directly addresses noisy‑neighbour risk.

Horizontally scalable workers: Workers poll Temporal task queues and scale horizontally; when a workflow has no more messages, it sleeps and frees resources for other tenants’ workflows.

Analytics

Service usage metrics
Yes
Metrics types
Yes, but with scope. The platform does provide usage metrics, though what’s available varies by feature and is typically aggregate rather than user-level detail. We maintain individual confidentiality as per protections set at commencement of projects i.e. not usually to less than groups of users, depending on the metric requested and protections set.

e.g.
For surveys - participation is visible.

AI Coach: Account Administrators can access a built-in Coach Usage Report showing aggregate usage volume and interaction depth across the account.

1-on-1s: There is an in-product 1-on-1 Conversations Usage Report for Account Admins to track engagement across departments
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Culture Amp ensures data at rest is protected through a combination of rigorous physical security and industry-standard encryption. Our underlying AWS infrastructure maintains compliance with CSA CCM v4.0 and SSAE-18 / ISAE 3402 standards, ensuring world-class physical access control.

At the software level, full disk encryption AES 256 is employed for all data at rest. Data is encrypted at rest with keys that are automatically rotated. Culture Amp uses AWS KMS to store and manage keys.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Admins export data per feature (Surveys, Performance, Develop, Users); there’s no single “export everything” button. For areas without built‑in exports, individual users can manually export their own content or use print-to-PDF workarounds. Transfers to third parties must follow confidentiality rules, and CA can facilitate secure transfer when needed
Data export formats
  • CSV
  • Other
Other data export formats
XLS/XLSX
Data import formats
  • CSV
  • Other
Other data import formats
XLSX

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Culture Amp segregates its production environment from other systems, with remote access restricted to an encrypted VPN service requiring strong multi-factor authentication. All access is logged and audited for accountability. A combination of AWS Security Groups, along with host and network-based Access Control Lists (ACLs), is used to restrict traffic to only essential systems and services. Furthermore, we leverage Web Application Firewall (WAF) and Intrusion Detection System (IDS) technologies to monitor traffic for malicious behaviour and ensure early detection of potential security threats.

Availability and resilience

Guaranteed availability
There is no contractual uptime guarantee by default though observed uptime (>99.5%) and the public status page provides latest updates (status.cultureamp.com). A modular SLA/Uptime policy is potentially possible to ararnge as part of commercial agreements/ discussions
Approach to resilience
Framework & Governance: Culture Amp’s BCM framework includes Business Impact Analysis (BIA), Crisis Management plans, and recovery procedures validated through annual testing. We employ tiered activation, from executive notification for significant incidents to automatic BCP invocation for major disasters. Policies are reviewed and updated annually to ensure effectiveness.

Technology Continuity & DR: Our Technology Continuity Management Standard defines recovery roles and scenario-based testing. Production systems are load-balanced across multiple AWS Availability Zones to ensure high availability. DR simulations are conducted at least annually, with results reported to executive leadership. SRE teams standardise backup/restore processes to guarantee cross-regional recoverability.

Operational Execution: Technology Operations manages ITSM and annual DR simulations, while our Security Operations team provides 24/7 monitoring and incident response. Critical third-party partners are contractually mandated to meet recovery timeframes, perform independent testing, and provide regular resilience attestations.
Outage reporting
All Customer impacting incidents are publicly reported on our Product Status page within 5-7 minutes of confirmation of an incident. Updates are posted as they are received until incident resolution. Customers can subscribe to incident updates delivered via email there.

Planned outages (maintenance) are communicated via the Product Status page and in platform/email messaging is sent for impacted Users with a timeline in all major timezones.

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
For platform admin access (e.g., dashboards, reports, admin tasks), users must authenticate via email/password, SSO, or Google, depending on what your org has enabled.

For taking surveys however, sign-in is typically not required; participants can use their unique survey link without logging in. However, if your admins enable Authenticated Capture, respondents must log in before accessing the survey.
Access restrictions in management interfaces and support channels
Culture Amp limits access in admin interfaces and support channels using least privilege, RBAC, and MFA, with time‑bound, approved access for support and thorough logging. Access is only granted to authorised users with a validated business need and is removed when no longer required.
Access restriction testing frequency
At least once a year
Management access authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
Culture Amp authenticates admin/manager access primarily via Single Sign-On (SSO), using SAML 2.0 or Google OAuth, with your organization’s IdP enforcing MFA and password policies.

Culture Amp does not provide native MFA; MFA is applied through your IdP when SSO is enabled.

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
SOC2 Type II
ISO 42001
Information security policies and processes
Culture Amp operates a formal Information Security Management System (ISMS) independently certified against ISO/IEC 27001 and SOC 2 Type II standards. Our comprehensive policy suite governs critical domains, including risk management, secure software development (SDLC), incident response, cryptography, business continuity, and third-party risk.

Reporting Structure: Security is integrated at the executive level. Our Chief Information Security Officer (CISO) leads the dedicated security function, reporting directly to the Chief Technology Officer (CTO) to ensure technical alignment and resource prioritisation.

Policy Compliance & Enforcement: To ensure strict adherence to these policies, we employ a multi-layered assurance model:

- External Audits: Annual independent audits for ISO 27001 and SOC 2 Type II verify the operational effectiveness of our controls.

- Continuous Monitoring: We utilise automated compliance tools to monitor our cloud infrastructure against security benchmarks in real-time.

- Internal Governance: Mandatory security awareness training for all staff ensure a culture of compliance.

- Technical Guardrails: Policy is enforced through automated technical controls, such as mandatory multi-factor authentication (MFA) and CI/CD security gating.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Tracking & Lifecycle: Culture Amp utilises a Configuration Management Database (CMDB) to track service components throughout their lifecycle.

Change Management: Software and infrastructure updates are documented, tested, and reviewed prior to production. As part of this process, changes undergo security impact assessments to identify risks.

Deployment & Compliance: Changes are managed via a controlled CI/CD pipeline with automated security scanning and testing integrated into the release process maintaining a secure and stable production environment, supported by CIS-based hardening baselines and regular scanning to ensure ongoing compliance and integrity.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Culture Amp performs continuous vulnerability monitoring across all supported assets. Code and third-party libraries are scanned prior to merging to identify and prevent critical risks from entering production. We conduct regular scans of all other production systems at least weekly using industry-standard tools.

Vulnerability data from scans, vendor feeds, CERT advisories, and reports are reviewed for applicability and criticality. The security team triages these results according to our Vulnerability Management Policy. This systematic approach ensures timely identification and remediation of security gaps across our entire infrastructure.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Culture Amp identifies compromises through centralised logging in our Splunk SIEM, employing breach and anomaly detection to flag activity outside typical patterns. We monitor systems, applications, and network traffic for threats in real-time.

Our response is governed by NIST 800-61 standards and supported by specific playbooks. When a potential compromise is detected, integrated alerting immediately notifies accountable stakeholders. We follow defined incident handling processes to contain and remediate threats. For security incidents, Culture Amp ensures high-priority responsiveness, committing to notify impacted customers within 48 hours, ensuring transparency and rapid mitigation throughout the incident lifecycle.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Culture Amp’s incident management follows NIST 800-61 standards, utilising a formal Security Incident Response Plan and playbooks for common events. This ensures a consistent lifecycle from detection to remediation.

Reporting: Users and customers report incidents via security@cultureamp.com, while internal staff raise security incident tickets for security investigation.

Response & Notification: We utilise centralised logging and automated alerting for rapid detection. Post-incident, we provide formal reports; all high-priority (P1) incidents require a Root Cause Analysis (RCA) within five business days to ensure transparency.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
2-week trial period with sample data to test and experience the service.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
2%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
7%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
12%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Standards Institution (BSI)
ISO/IEC 27001 accreditation date
Tuesday 5 March 2019
What the ISO/IEC 27001 doesn’t cover
Clause 7: Physical Security Controls:
7.1
7.3 - 7.6
7.8 - 7.9
7.11 - 7.13

Clause 8 - Technological Controls:
8.30
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
Yes
CSA STAR accreditation date
Friday 22 November 2024
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
Scope covers entire service offering
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
Yes
Any other security certifications
SOC 2 Type II

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at oskar.karlsson@cultureamp.com. Tell them what format you need. It will help if you say what assistive technology you use.