Aspyre
Aspyre is a cloud-based platform designed to govern and deliver change in regulated environments. It replaces fragmented tools with a single, real-time view across portfolios, programmes and projects, improves reporting consistency, strengthens assurance and oversight, supports collaboration, and enables tighter financial control and earlier identification of risk and savings.
Features
- Portfolio, programme and project management within a single integrated system
- Planning management with milestones, tasks, deliverables and dependencies
- Risk, issue and dependency management aligned to public sector standards
- Financial, savings and benefits tracking at project and portfolio level
- Strategic objectives, KPIs and efficiency targets linked to delivery
- Ideas, initiatives and service request capture with configurable workflows
- Real-time dashboards and reporting with reusable, centrally managed data
- Meeting agendas, minutes, actions and decisions linked to delivery
- Resource planning and capacity tracking across programmes and projects
- Configurable workflows, templates and fields without code or supplier dependency
Benefits
- Provides organisation-wide visibility and control across all delivery activity
- Improves planning accuracy and delivery confidence across programmes and projects
- Strengthens governance, assurance and proactive risk management
- Ensures costs, savings and benefits are actively monitored and realised
- Improves alignment between strategy, priorities and delivery outcomes
- Supports consistent assessment, prioritisation and approval of new work
- Reduces reporting effort while improving data accuracy and consistency
- Reduces administrative effort and improves accountability and traceability
- Supports better resource allocation and informed prioritisation decisions
- Allows rapid alignment to organisational processes without costly custom development
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 6 2 7 1 7 8 4 7 7 4 8 2 5 0
Contact
MOSAIQUE LIMITED
Neil Cassidy
Telephone: 01564 711201
Email: neil.cassidy@mosaiquegroup.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Project and portfolio management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service may be unavailable for a short time after 21:00hrs to allow for periodic updating of the application.
- System requirements
-
- Connection to the internet
- Web browser - all common browsers and versions are supported
User support
- Email or online ticketing support
- Yes
- Support response times
- Our cloud-based ticketing system will instantly log all calls and reply back to the sender with an email acknowledging receipt. Support is available during standard office hours of 09:00 to 17:30, Monday to Friday.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
- All clients can access support using the Help facility in Aspyre or by submitting an email to our dedicated support team. We also provide a dedicated technical account manager that can be contacted via phone or email.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We support users through a structured onboarding process designed to help them start using the service quickly and effectively.
This includes initial configuration of the service to reflect the buyer’s requirements, followed by live training sessions delivered remotely. Training is tailored to different user roles, such as administrators, project managers and standard users, to ensure each group understands how to use the service in practice.
We provide user documentation and guidance materials to support ongoing use, alongside recorded training resources where appropriate. A small number of users are typically trained as in-house administrators, enabling the organisation to manage configuration, user access and day-to-day administration independently.
Ongoing support is provided via our online support desk, with access to guidance and assistance as users continue to adopt the service. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Users can extract their data at any time using the system’s built-in XML export functionality. This enables organisations to self-serve structured data exports without reliance on the supplier. At the end of the contract, we will provide a structured flat-file export of the client’s data at no additional cost. Any documents uploaded by users to the application are not included in the standard data export. These documents can be downloaded directly by the client at any time during the contract. If required, we can retrieve and provide these documents on the client’s behalf as an additional, chargeable service.
- End-of-contract process
- At the end of the contract, users retain full access to the service for the duration of the contract term and can extract their data at any time prior to contract expiry. Users can export structured data directly from the system using the built-in XML export functionality. In addition, at contract end we will provide a structured flat-file export of the client’s data at no additional cost. External documents uploaded to the application are not included in the standard data export and can be downloaded directly by the client at any time during the contract. If required, we can retrieve and provide these documents on the client’s behalf as an additional, chargeable service. Once data extraction has been completed and the contract has ended, the service instance is securely decommissioned in line with our data retention and disposal policies.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- No difference other than screen size. The application automatically resizes to fit the available screensize. If data is amended using a mobile device then this will automatically be reflected in the desktop service, and vice versa.
- Service interface
- No
- User support accessibility
- EN 301 549
- API
- Yes
- What users can and can't do using the API
-
Authorised API users can use the public API to retrieve read-only project, programme and portfolio data from system areas. Data can be extracted from a specified folder or portfolio level, including associated sub-levels, and filtered to return only records created or updated since a specified date. API access is provided via dedicated API user accounts and is separate from standard Aspyre user access.
The API exposes a subset of fields for selected modules. Field availability is intentionally controlled to support performance, security and governance requirements. The API is intended for reporting and integration purposes only and is subject to defined request limits and fair usage controls.
API access includes defined endpoints, authentication, a baseline request allowance per endpoint, and an API contract with supporting documentation and field-mapping to align standard API fields with client-configured fields. Higher usage volumes, high-frequency polling, large historical data extracts, additional environments, guaranteed throughput, priority handling, and bespoke endpoints or payloads are not included as standard and are available via paid usage packages.
Aspyre has supported bespoke 3rd party integrations, including a purpose-built API developed to support data exchange with NHSE. These integrations are delivered on a case-by-case basis and are not included as standard. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise Aspyre extensively through configuration, without the need for bespoke development.
As part of an Aspyre package, we work directly with the buyer to complete the initial system configuration, drawing on our experience of supporting similar organisations. We also train nominated users to act as in-house administrators, enabling them to manage and adapt the configuration independently over time.
Aspyre can be configured in a range of ways, including enabling or disabling functionality and screens, adding or removing data fields, renaming fields to reflect local terminology, managing dropdown values, setting mandatory fields, and adding on-screen guidance to support users. Organisational branding can also be applied by uploading logos, which are then automatically included on reports generated by the system.
A key differentiator is that Aspyre supports multiple configurations across different parts of the system structure. This allows separate organisations, directorates, or departments to work in ways that suit their own processes, while still operating within a single shared platform and producing reports tailored to different audiences.
Scaling
- Independence of resources
-
Each customer’s data is hosted in a logically separate database, ensuring complete data isolation between organisations. This means activity from one customer cannot impact the performance, security, or integrity of another customer’s data.
The application is delivered via a scalable cloud infrastructure. The web and application tiers automatically scale to meet user demand, allowing the service to handle peak usage without degrading performance for other users. Resource utilisation is monitored to ensure consistent availability and responsiveness across all customers.
This approach ensures that users are not affected by the demand other organisations place on the service.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Users with Administrator level access can use a suite of administrative tools including an 'Audit Trail' facility.
Reporting types
• Real-time dashboards
• Regular reports
• Reports on request - Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export structured data using Aspyre’s XML export functionality. In addition, reports generated within Aspyre can be exported into commonly used formats, including PDF, Excel, Word and PowerPoint, enabling users to retain and reuse information outside the system.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Xml
- Xlsx
- Docx
- Pptx
- Csv
- Image
- Text
- Mht
- Data import formats
-
- CSV
- Other
- Other data import formats
- .mpp
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Please refer to 'Addendum 1 - Service Level Agreement' which can be found in the document - Aspyre Terms and Conditions for G-Cloud 15.
- Approach to resilience
- Please refer to 'Section 3. Data Backup, Restore & Disaster Recovery' of the uploaded document - Aspyre Service Definition for G-Cloud 15.
- Outage reporting
- Please refer to 'Section 3. Data Backup, Restore & Disaster Recovery' of the uploaded document - Aspyre Service Definition for G-Cloud 15.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is controlled through role-based access control. Administrative permissions are assigned only to authorised users and can be limited by organisation, division, or department to ensure users only access what is necessary for their role. Client administrators can manage user accounts, permissions, and configuration settings within their permitted scope.
Access for Mosaique support staff is restricted to authorised personnel only and is provided solely for the purpose of delivering support and resolving incidents. All access is managed and reviewed in line with our information security policies. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Mosaique Limited follows a formal Information Security Policy supported by documented processes to protect information confidentiality, integrity and availability, and to ensure compliance with applicable legal and regulatory requirements, including UK GDPR.
The policy is supported by procedures covering areas such as access control, password management, data backup, incident management, malware protection, encryption, and secure system use. Business continuity and backup arrangements are documented, maintained and reviewed to support service resilience.
An Information Security Manager is responsible for overseeing information security, providing guidance on policy implementation, and coordinating the investigation of any actual or suspected security incidents. All staff are required to report information security incidents or concerns promptly in line with the incident management process.
Information security responsibilities form part of staff induction, and ongoing awareness is maintained through policy access and guidance. Policies are reviewed regularly to ensure they remain appropriate and effective, with updates approved by the designated policy owner.
Compliance with information security policies is reinforced through role-based access controls, documented procedures, supplier agreements, and management oversight. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Aspyre follows a controlled configuration and change management process throughout the service lifecycle. System components and configurations are version-controlled and tracked from development through testing and deployment. Changes are logged, reviewed, and approved before release.
All proposed changes are assessed for potential security, performance, and availability impacts. Where relevant, changes are tested in a non-production environment prior to deployment. Security considerations form part of change assessment, including access controls, data protection, and system integrity. Changes are implemented using defined release procedures to minimise risk and disruption to users. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We operate a proactive vulnerability management process to identify, assess and remediate security risks to our services.
Potential threats are identified through regular platform monitoring, supplier security notifications, cloud service alerts, and trusted external sources such as vendor advisories and recognised security bodies. Vulnerabilities are assessed based on severity, exploitability and potential impact.
Security patches and updates are prioritised according to risk and applied promptly, following testing where appropriate. Critical security patches are deployed as soon as practicable.
This approach ensures vulnerabilities are identified early and mitigated in a timely and controlled manner. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Aspyre is hosted on Amazon Web Services (AWS), which provides continuous monitoring of the underlying infrastructure, including network activity, servers, storage and operating systems. Monitoring includes availability, performance metrics and security-related events to help identify potential compromises.
Alerts generated by AWS monitoring services are reviewed promptly, and any suspected security incidents are investigated in line with our incident management process. Where a potential compromise is identified, access can be restricted, affected components isolated and remedial action taken without undue delay.
Incidents are responded to as soon as they are detected, with priority given to security-related events. - Incident management type
- Supplier-defined controls
- Incident management approach
- We operate a defined incident management process to ensure incidents are handled consistently and resolved promptly in line with agreed SLAs. Common incident types are covered by pre-defined procedures, including prioritisation based on impact and urgency. Users report incidents via email to the Aspyre Support team, where incidents are logged, assigned and tracked through our support ticketing system. Investigation and remediation actions are carried out until service is restored. Where required, incident updates and summary reports are provided to users. Full details of our incident management approach are set out in the Aspyre Service Definition for G-Cloud.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We offer a free 30-day trial of Aspyre. The trial includes core functionality such as project setup, plans and Gantt charts, risks and issues, milestones, meetings, document storage and reporting. Advanced modules including finances, benefits, KPIs, resources and stakeholders are not included.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12.5%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- EY CertifyPoint
- ISO/IEC 27001 accreditation date
- Tuesday 5 November 2019
- What the ISO/IEC 27001 doesn’t cover
- The ISO/IEC 27001 accreditation mentioned above applies to the data hosting provided by our third-party partners, AWS. Further documentation around this and any other data-hosting related information is available on request.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 40ea7bb1-cdf1-4331-ad2d-9af28d5d677e
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-