Talk2DB - Conversational Data Query
SoftServe’s Talk2DB is a cloud-hosted generative AI software service that enables users to query structured databases using natural language. The service translates plain English questions into database queries and returns clear, interpreted results, allowing non-technical users to access data insights without requiring SQL or specialist analytical skills.
Features
- Natural language interface for querying relational databases
- Automatic translation of user questions into database queries
- Secure, role-based access to underlying data sources
- Support for structured and complex database schemas
- Retrieval-augmented generation (RAG) for contextual accuracy
- Integration with existing data visualisation and reporting tools
- Configurable business rules and data access controls
- Cloud-hosted delivery with scalable performance
- Continuous model updates and accuracy improvements
Benefits
- Enables wider access to data across an organisation
- Reduces dependency on specialist data and SQL skills
- Accelerates decision-making through faster data access
- Improves confidence in data-driven decisions
- Reduces operational costs associated with manual reporting
- Supports governance through controlled data access
- Scales easily as data volumes and users grow
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 4 3 7 9 1 5 4 5 0 0 9 3 0 5
Contact
SOFTSERVE SYSTEMS LTD
Adam Heaton
Telephone: +447833366949
Email: aheat@softserveinc.com
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI software services
- Conversational AI Software Services
- Generative AI Software Services
- Personalize AI Software Services
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- N/a
- System requirements
- N/a
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 24 hours
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Testing with individuals experiencing visual impairments, motor disabilities, and cognitive impairments. We utilise a range of assistive technologies, including screen readers, voice recognition software, and alternative input devices. This thorough process allows us to evaluate the usability and functionality of our service effectively.
- Onsite support
- Yes
- Support levels
-
1) Core: 09:00 to 17:00 Mon-Fri excluding English Public holidays; suitable for most business-critical applications.
2) Extended: 08:00 to 18:00 Mon-Fri excluding English Public holidays.
3) 24x7: full 24x7x365 support.
4) Bespoke: customised set of service hours that meets unique business requirements.
Different business needs require flexibility in response and resolution times:
1) Core: resolution times are P1: 1 day, P2: 2 days, P3: 8 days and P4: 20 days.
2) Enhanced: resolution times are P1: 4 hours, P2: 8 hours, P3: 4 days and P4: 10 days.
3) Bespoke: a customised set of response and resolution times that meets your unique business requirements.
Severity Levels for Incidents are defined as follows:
a) Priority Level 1 (Critical) - reported problem causes a halt to the client’s core business processes and no work-around is available.
b) Priority Level 2 (Major) - reported problem causes degradation of the client’s core business processes and no reasonable work-around exists.
c) Priority Level 3 (Intermediate) - reported problem impacts the client’s operational environment; it does not affect core business processes; a work-around is available.
d) Priority Level 4 (Minor) - a non-critical problem causing some disruption with little or no impact on client operation. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- To ensure users start effectively using our service, all new customers receive dedicated support from a Account Manager. This includes expert assistance from DevOps and cloud architects to optimize solutions for specific workloads, complemented by comprehensive online documentation and tutorials available on our portal. Additionally, customers have access to free online training courses to enhance their understanding and usage of our services.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- Customers have multiple options to extract their data, ensuring flexibility and ease of access. Users can download their data using the same methods they used for upload, whether it’s over their network via the internet or express routes, or through Import/Export services. Additionally, customers maintain full autonomy over how their data is stored and managed within their environments and have the capability to seamlessly port their environments and associated data whenever needed, providing complete control over their digital assets.
- End-of-contract process
-
Our standard procedure for end-of-contract entails timely notification to customers, prompting them to prepare accordingly. Customers assess their data needs and back up critical information as necessary, coordinating with us to facilitate the termination process and any required data retrieval or service terminations. Once executed, we welcome feedback on their experience, ensuring a smooth transition for both parties.
Additional costs will only be incurred for work outside of the agreed contract scope. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Same
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
We offer a control panel for provisioning, management, and decommissioning of service components. It integrates seamlessly with our service management system, allowing users to submit tickets and requests. Additionally, it provides users with resources such as a library of documentation and instructional videos.
Our web interface is compatible with all major web browsers and can be accessed over various networks including the Internet, PSN, N3/HSCN, and Janet. It features security with standards-based encryption, two-factor authentication, and optional IP address restrictions. The interface does not require plugins and supports any modern desktop or mobile browser that can handle secure HTTPS connections. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We conduct task-based interface testing with users of assistive technology, including screen reader users, keyboard-only users, and users of magnification and high-contrast modes, to validate real-world usability across core user journeys. Findings are documented, mapped to WCAG 2.2 AA criteria, prioritised by user impact, and re-tested after remediation to provide clear audit evidence.
- API
- Yes
- What users can and can't do using the API
- You can use API calls to create, manage, and monitor Service Requests and view details about the components of your environment. We provide native access to the underlying APIs and CLI, enabling full programmatic control over your application environments and the users who access them.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users can customise the service through configuration of environments, workflows, integrations, and access controls. Customisation is carried out by authorised administrators via the user interface and API, without requiring changes to the underlying service code
Scaling
- Independence of resources
- The service ensures tenant isolation through dedicated or logically segregated resources, preventing one user’s demand from affecting others. Autoscaling, capacity controls, and usage monitoring are used to maintain consistent performance under varying load.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide service usage and operational metrics including availability, performance, capacity utilisation, request volumes, incident and request trends, response and resolution times, and user activity. Where applicable, metrics also cover security events and service health indicators.
Metrics are provided through real-time dashboards, regular scheduled reports, and reports on request. An API is available for customers who wish to integrate metrics into their own monitoring or reporting tools.
The solution supports resource tagging, including FOCUS-aligned resource tagging, to enable cost allocation, reporting, and governance. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Customers have multiple options to extract their data, ensuring flexibility and ease of access. Users can download their data using the same methods they used for upload, whether it’s over their network via the internet or express routes, or through Import/Export services. Additionally, customers maintain full autonomy over how their data is stored and managed within their environments and have the capability to seamlessly port their environments and associated data whenever needed, providing complete control over their digital assets.
- Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.99%
- Approach to resilience
- Our service is deployed across a number of sites, regions and zones. Each zone is designed to eliminate single points of failure (such as power, network and hardware). Customers are encouraged to ensure their solution spans multiple sites, regions or zones to ensure service continuity should a failure occur.
- Outage reporting
- All outages will be reported via the Service Status page and notifications. Outages are identified as Planned maintenance, Emergency maintenance, and platform issues. In addition, the designated Account Manager will proactively contact customers as appropriate.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- We maintain individual role-based authorisation of privileged accounts that is subject to regular validation. A privileged account is a duly authorised user identity with administrative access to a Cloud Service, including associated infrastructure, networks, systems, applications, databases and file systems.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- We have policies for infrastructure security, physical security, availability, components & boundaries, network architecture, production network, SQL DB, operations, monitoring, integrity and data protection.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Change management system documents all changes, responsible parties, time of change and senior-level sign off. All changes pass through a Change Advisory Board (CAB).
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Our vulnerability management process involves continuous assessment of threats using automated scanning tools and timely patch deployment, with critical vulnerabilities addressed urgently. We gather threat information from trusted sources and prioritise remediation using risk-rating processes. We deploy automated patch management solutions for both operating systems and third-party software to ensure swift and consistent patch deployment, minimising the window of opportunity for attackers. Regular back-to-back vulnerability scans track progress, allowing us to stay ahead of emerging threats and maintain the security of our services.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Our protective monitoring processes utilise threat monitoring systems across all infrastructure, continuously analysing activity for anomalies. When potential compromises are detected, we respond promptly with predefined incident response plans, including isolating affected systems, collecting forensic evidence, and notifying stakeholders. Our response is swift, prioritising incidents based on severity to minimise impact and prevent further escalation. We aim to resolve incidents quickly while ensuring thorough investigation and mitigation measures to prevent future occurrences.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Our incident management processes are comprehensive, encompassing pre-defined procedures for common events to ensure a quick and coordinated response. Users report incidents through designated channels, including helpdesk tickets, email, or dedicated incident reporting platforms. Once reported, our team assesses the situation, containing and mitigating the incident's impact. Following resolution, incident reports detailing the nature of the incident, actions taken, and recommendations for preventing future occurrences are provided to stakeholders. ISO27001-complaint processes and systems for incident response are operational.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 2%
- Between £2,500,001 and £5,000,000
- 3%
- Over £5,000,001
- 4%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- EY Point
- ISO/IEC 27001 accreditation date
- Thursday 3 October 2024
- What the ISO/IEC 27001 doesn’t cover
- N/a
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- DNV - Business Assurance
- ISO 9001 accreditation date
- Wednesday 26 November 2025
- What the ISO 9001 doesn’t cover
- N/a
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 2a47d344-1ff4-4747-85ab-8138036d754a
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-