Employee Engagement and Performance Management Software
Culture Amp is an employee experience platform that helps organisations measure and improve employee engagement, performance, and development through people‑science‑backed tools and guidance.
Features
- employee experience surveying
- performance management
- AI coach
- real time reporting
- people analytics
- development planning
- people science
- employee engagement and retention
- goal setting
- 1 on 1's
Benefits
- get real time employee feedback
- measure employee engagement
- Help employees realise their potential with development-focussed performance tools
- quickly share employee experience analyses
- foster a culture of continuous growth with personalised career paths
- Transform people data into actionable intelligence
- take action on employee feedback to drive engagement
- share feedback with peers, direct reports and managers
- measure performance in a manner which minimises bias
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 2 8 4 1 7 4 3 7 9 0 0 0 1 5
Contact
CULTURE AMP LIMITED
Oskar Karlsson
Telephone: 07717822092
Email: oskar.karlsson@cultureamp.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
Human capital management
- Core Human Resources Applications
- Talent Management Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- N/a
- System requirements
- Internet connectivity
User support
- Email or online ticketing support
- Yes
- Support response times
- Initial requests via Live Chat/Email support channels will be managed by our AI Agent. If it can assist, response is in moments. If it cannot respond to your question, you will be notified and connected with the team automatically. Once with the team, we pride ourselves in ensuring we are available for as long as required to give full attention to each inquiry. As such, we don't set explicit agreements on response times to allow specialists the time they need to provide a complete support experience to you. However, live chat typical response is within 20 mins, email 24-72 hours.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Our web chat aims to meet WCAG Level AA. We test and govern accessibility the same way we do across the platform (independent audits with Intopia, internal standards and automated checks, and AT/keyboard testing). However, we don’t currently have a published Intopia Statement of Conformance that is specifically scoped to “web chat,” so we can’t claim full conformance for that area yet.
- Onsite support
- Yes, at extra cost
- Support levels
- Onsite implementation support.
- Support available to third parties
- No
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Enterprise customers are onboarded through a guided implementation program led by a dedicated Implementation Manager for roughly the first 3 months, supported by your Customer Success Manager and People Scientist, with structured checklists, training, and a single upfront implementation fee.
What Enterprise onboarding includes:
An Implementation Manager who meets regularly for ~3 months to project-manage your first launch and provide technical guidance; plus a 1‑month account setup period.
Strategic services tailored to Enterprise, such as project planning, change management support, suggested comms and enablement for leaders, and a survey design planning session with People Science.
Coordinated team: you primarily work with an implementation expert; your Customer Success Manager (and People Scientist for Enterprise) stay engaged and transition you post‑launch into ongoing success planning.
In‑product Enterprise onboarding checklist and email nudges to drive timely setup and adoption, delivered when admins first log in
Access to private live virtual training from Culture Amp Training (CAT) for Enterprise implementations and launches, scheduled by IM/CSM when needed. Unlimited access to public training, and online/ anytime via Culture Amp Training and Culture Amp support guides. - Service documentation
- Yes
- Documentation formats
- Other
- Other documentation formats
-
- Online support guides
- Online culture amp training
- End-of-contract data extraction
-
How customers extract their data:
Use built‑in export options across products (admins can export reports, insights, and usage data).
Surveys:
Export Summary, Insights/Questions, Participation, Heatmaps, Comments, PPT, and CSV/XLS from each survey.
Raw Data Extract (RDE): Only available if enabled before launch; admins can export it themselves from the survey’s exports when enabled.
If RDE was not enabled, Support can provide a de‑identified data extract per survey upon request; this is a support‑assisted process.
Performance:
There are standard exports for performance reviews and related reports; some features (e.g., 1‑on‑1s, Continuous Feedback, Manager‑requested feedback history limits) have constraints noted in our offboarding guides. - End-of-contract process
- If a customer does not renew, we accept their notice and initiate offboarding processes, the Customer Sucess Manager and Support help by coordinating contacts and timelines, and reminding the customer to export data before the platform is turned off at expiry (once Culture Amp is shut off, we can’t save any data)
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Culture Amp is a responsive web app that works on modern mobile browsers—there’s no native mobile app. Surveys and many reports are optimized for small screens, with recent updates improving accessibility and mobile usability for key features like heatmaps and participation reports. Surveys can be completed on smartphones and tablets; the interface is designed for touch (e.g., swipeable response bars).
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
Culture Amp has an API for one-way, outbound data retrieval so you can securely access account data from the Culture Amp platform. It’s RESTful and currently does not support data ingestion.
What it’s for:
- Securely retrieve your Culture Amp account data for use in your systems.
-Common use cases include analytics/reporting, connecting Culture Amp data to other apps, and automating workflows. - API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Users can customise many parts of Culture Amp (surveys, comms, account branding).
What users can customise:
Survey content: You can run templates as-is, tweak wording to your company lingo, or fully customise by adding/removing/modifying questions. There are also blank “Custom” templates for building from scratch.
Creating custom surveys: Survey creators/admins can duplicate existing surveys, use templates, or build a custom survey with zero questions and add their own items. An unattributed custom option is available via the specific template.
Survey communications: You can edit invites and reminders for email, Slack, and Microsoft Teams (not report notifications/Reporting Rules). Variables can be used to personalise messages.
Sender name on emails: Account Admins can set a custom sender name for Engagement/Experience/Effectiveness emails to improve recognition. This does not apply to Performance emails.
Branding: Account-level settings like company name, timezone, and logo are editable. You can also set a survey-specific logo that differs from the account logo.
Languages: Default performance templates are translated; you can customise questions and use auto-translate or add manual translations. Some custom content remains in the original language and may create mixed-language experiences.
Scaling
- Independence of resources
-
We mitigate “noisy neighbour” effects in our multi‑tenant communications/Flow services by isolating work per account, interleaving tasks across workers, and throttling or sidelining excess traffic so one tenant can’t degrade others.
examples:
Per‑account workflow isolation using Temporal: We trigger a dedicated workflow per account integration. Temporal’s task queues interleave execution across workers so one tenant can’t monopolize worker resources, which directly addresses noisy‑neighbour risk.
Horizontally scalable workers: Workers poll Temporal task queues and scale horizontally; when a workflow has no more messages, it sleeps and frees resources for other tenants’ workflows.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Yes, but with scope. The platform does provide usage metrics, though what’s available varies by feature and is typically aggregate rather than user-level detail. We maintain individual confidentiality as per protections set at commencement of projects i.e. not usually to less than groups of users, depending on the metric requested and protections set.
e.g.
For surveys - participation is visible.
AI Coach: Account Administrators can access a built-in Coach Usage Report showing aggregate usage volume and interaction depth across the account.
1-on-1s: There is an in-product 1-on-1 Conversations Usage Report for Account Admins to track engagement across departments - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
Culture Amp ensures data at rest is protected through a combination of rigorous physical security and industry-standard encryption. Our underlying AWS infrastructure maintains compliance with CSA CCM v4.0 and SSAE-18 / ISAE 3402 standards, ensuring world-class physical access control.
At the software level, full disk encryption AES 256 is employed for all data at rest. Data is encrypted at rest with keys that are automatically rotated. Culture Amp uses AWS KMS to store and manage keys. - Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Admins export data per feature (Surveys, Performance, Develop, Users); there’s no single “export everything” button. For areas without built‑in exports, individual users can manually export their own content or use print-to-PDF workarounds. Transfers to third parties must follow confidentiality rules, and CA can facilitate secure transfer when needed
- Data export formats
-
- CSV
- Other
- Other data export formats
- XLS/XLSX
- Data import formats
-
- CSV
- Other
- Other data import formats
- XLSX
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Culture Amp segregates its production environment from other systems, with remote access restricted to an encrypted VPN service requiring strong multi-factor authentication. All access is logged and audited for accountability. A combination of AWS Security Groups, along with host and network-based Access Control Lists (ACLs), is used to restrict traffic to only essential systems and services. Furthermore, we leverage Web Application Firewall (WAF) and Intrusion Detection System (IDS) technologies to monitor traffic for malicious behaviour and ensure early detection of potential security threats.
Availability and resilience
- Guaranteed availability
- There is no contractual uptime guarantee by default though observed uptime (>99.5%) and the public status page provides latest updates (status.cultureamp.com). A modular SLA/Uptime policy is potentially possible to ararnge as part of commercial agreements/ discussions
- Approach to resilience
-
Framework & Governance: Culture Amp’s BCM framework includes Business Impact Analysis (BIA), Crisis Management plans, and recovery procedures validated through annual testing. We employ tiered activation, from executive notification for significant incidents to automatic BCP invocation for major disasters. Policies are reviewed and updated annually to ensure effectiveness.
Technology Continuity & DR: Our Technology Continuity Management Standard defines recovery roles and scenario-based testing. Production systems are load-balanced across multiple AWS Availability Zones to ensure high availability. DR simulations are conducted at least annually, with results reported to executive leadership. SRE teams standardise backup/restore processes to guarantee cross-regional recoverability.
Operational Execution: Technology Operations manages ITSM and annual DR simulations, while our Security Operations team provides 24/7 monitoring and incident response. Critical third-party partners are contractually mandated to meet recovery timeframes, perform independent testing, and provide regular resilience attestations. - Outage reporting
-
All Customer impacting incidents are publicly reported on our Product Status page within 5-7 minutes of confirmation of an incident. Updates are posted as they are received until incident resolution. Customers can subscribe to incident updates delivered via email there.
Planned outages (maintenance) are communicated via the Product Status page and in platform/email messaging is sent for impacted Users with a timeline in all major timezones.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
-
For platform admin access (e.g., dashboards, reports, admin tasks), users must authenticate via email/password, SSO, or Google, depending on what your org has enabled.
For taking surveys however, sign-in is typically not required; participants can use their unique survey link without logging in. However, if your admins enable Authenticated Capture, respondents must log in before accessing the survey. - Access restrictions in management interfaces and support channels
- Culture Amp limits access in admin interfaces and support channels using least privilege, RBAC, and MFA, with time‑bound, approved access for support and thorough logging. Access is only granted to authorised users with a validated business need and is removed when no longer required.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
-
Culture Amp authenticates admin/manager access primarily via Single Sign-On (SSO), using SAML 2.0 or Google OAuth, with your organization’s IdP enforcing MFA and password policies.
Culture Amp does not provide native MFA; MFA is applied through your IdP when SSO is enabled.
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
SOC2 Type II
ISO 42001 - Information security policies and processes
-
Culture Amp operates a formal Information Security Management System (ISMS) independently certified against ISO/IEC 27001 and SOC 2 Type II standards. Our comprehensive policy suite governs critical domains, including risk management, secure software development (SDLC), incident response, cryptography, business continuity, and third-party risk.
Reporting Structure: Security is integrated at the executive level. Our Chief Information Security Officer (CISO) leads the dedicated security function, reporting directly to the Chief Technology Officer (CTO) to ensure technical alignment and resource prioritisation.
Policy Compliance & Enforcement: To ensure strict adherence to these policies, we employ a multi-layered assurance model:
- External Audits: Annual independent audits for ISO 27001 and SOC 2 Type II verify the operational effectiveness of our controls.
- Continuous Monitoring: We utilise automated compliance tools to monitor our cloud infrastructure against security benchmarks in real-time.
- Internal Governance: Mandatory security awareness training for all staff ensure a culture of compliance.
- Technical Guardrails: Policy is enforced through automated technical controls, such as mandatory multi-factor authentication (MFA) and CI/CD security gating. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Tracking & Lifecycle: Culture Amp utilises a Configuration Management Database (CMDB) to track service components throughout their lifecycle.
Change Management: Software and infrastructure updates are documented, tested, and reviewed prior to production. As part of this process, changes undergo security impact assessments to identify risks.
Deployment & Compliance: Changes are managed via a controlled CI/CD pipeline with automated security scanning and testing integrated into the release process maintaining a secure and stable production environment, supported by CIS-based hardening baselines and regular scanning to ensure ongoing compliance and integrity. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Culture Amp performs continuous vulnerability monitoring across all supported assets. Code and third-party libraries are scanned prior to merging to identify and prevent critical risks from entering production. We conduct regular scans of all other production systems at least weekly using industry-standard tools.
Vulnerability data from scans, vendor feeds, CERT advisories, and reports are reviewed for applicability and criticality. The security team triages these results according to our Vulnerability Management Policy. This systematic approach ensures timely identification and remediation of security gaps across our entire infrastructure. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Culture Amp identifies compromises through centralised logging in our Splunk SIEM, employing breach and anomaly detection to flag activity outside typical patterns. We monitor systems, applications, and network traffic for threats in real-time.
Our response is governed by NIST 800-61 standards and supported by specific playbooks. When a potential compromise is detected, integrated alerting immediately notifies accountable stakeholders. We follow defined incident handling processes to contain and remediate threats. For security incidents, Culture Amp ensures high-priority responsiveness, committing to notify impacted customers within 48 hours, ensuring transparency and rapid mitigation throughout the incident lifecycle. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Culture Amp’s incident management follows NIST 800-61 standards, utilising a formal Security Incident Response Plan and playbooks for common events. This ensures a consistent lifecycle from detection to remediation.
Reporting: Users and customers report incidents via security@cultureamp.com, while internal staff raise security incident tickets for security investigation.
Response & Notification: We utilise centralised logging and automated alerting for rapid detection. Post-incident, we provide formal reports; all high-priority (P1) incidents require a Root Cause Analysis (RCA) within five business days to ensure transparency. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- 2-week trial period with sample data to test and experience the service.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Standards Institution (BSI)
- ISO/IEC 27001 accreditation date
- Tuesday 5 March 2019
- What the ISO/IEC 27001 doesn’t cover
-
Clause 7: Physical Security Controls:
7.1
7.3 - 7.6
7.8 - 7.9
7.11 - 7.13
Clause 8 - Technological Controls:
8.30 - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Friday 22 November 2024
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
- Scope covers entire service offering
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
- SOC 2 Type II
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
-