DocFusion - a dynamic, template-driven document composition and automation engine
DocFusion is a dynamic, template-driven document composition and automation engine.
DocFusion enables you to turn regularly used documents and forms into intelligent templates which allow workflow, document generation and automation, digital signatures and document storage. All of these are fundamental to effective customer and stakeholder communication management
Features
- Intelligent document template authoring
- Enterprise document template management
- Connect document templates to hundreds of data sources
- Enterprise template approval and access control
- Generate documents from your systems
- Store generated documents in your document repository
- Digitally sign generated documents
- Generate customised documents based on data
Benefits
- Promote standardised cross-company documentation and messaging
- Generate Compliant Documents Intelligently using connected Data
- Reduce operational risks associated with inaccurate data in Documents
- Democratise document template creation to the knowledge holders
- Quicken turn around on customer enquiries
Pricing
£600 a licence
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
5 7 0 2 5 3 3 9 8 1 4 7 9 1 4
Contact
JAAM AUTOMATION LTD
Justin Smith
Telephone: +447711772589
Email: info@jaamautomation.com
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- DocFusion allows you to connect your documents the data sources that produce them.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- Template creation an designer is Windows based only.
- System requirements
- DocFusion licensing
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- Within 4 hours, Monday to Friday, 8AM to 5PM
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.1 AA or EN 301 549
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- First, Second, and Third line support provided - included in subscription. A technical account manager and customer success manager are included.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We include online training alongside quick start training.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- All data can be exported from the system on request. Template documents can be removed or exported.
- End-of-contract process
- The service will discontinue in terms of access to features and functionality. Data can then be extracted from the system if required to be ported. All cloud instances of the application will then be removed within a defined period.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.1 AA or EN 301 549
- Description of service interface
- There is both a user interface and an API layer available for the product.
- Accessibility standards
- WCAG 2.1 AA or EN 301 549
- Accessibility testing
- The technology has been designed and tested using a veriety of screen readers and assistive technologies.
- API
- Yes
- What users can and can't do using the API
- All system functions are available via the API. These are restricted via authentication and authorisation frameworks.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- Each instance is split accross 5 nodes for scaling. If one node is at capacity, load is spread across other nodes. Nodes are spun up and down depending on demand on the service.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Document generation metrics e.g. Number of document created, created by, what application called the service.
- Reporting types
-
- API access
- Reports on request
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- DocFusion
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a Tigerscheme qualified provider or a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Users can export the date via the user interface or via the API.
- Data export formats
- Other
- Other data export formats
-
- Word Documents
- PDF Documents
- JSON
- Data import formats
- Other
- Other data import formats
-
- XML
- JSON
- Word
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We have uptime of 99.98 on the DocFusion service.
- Approach to resilience
- The cloud infrasturcture is run accross multiple nodes. Nodes are spun up and down depending on load and for fail over purposes. Backup nodes will come online if primary nodes are unavailable.
- Outage reporting
- Service outages can be viewed via the API and also via the service dashboards provided by the underlying data center provided e.g. Azure.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- All access to application aspects are role based security using username and password to gain access.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- TO DO
- Information security policies and processes
- We have internal processes that are based on ISO standards. Security training is undertaken for all new starts and is revised on an annual basis.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
The components of our services are tracked through their lifetime via Azure DevOps (GIT)
Changes are assessed for potential security impact via the following methods
• Code Scanning (SonarQube)
• Code Reviews - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We do an impact assessment (assessing Threat, Vulnerability, Impact and Likelihood)
We attempt to replicate vulnerability
If vulnerability is identified as a threat, we follow a mitigation process depending on the type of vulnerability (eg. patch, isolate environments)
We attempt to deploy urgent patches within 24 hours
We get information about potential threats from:
• Pentest results
• OWASP
• SonarQube / SonarCloud
• SCH
• CSA (Cloud Security Alliance)
• Microsoft, Google
• Zero Day
• Veracode
• CVE Mitre
• NIST - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We identify potential compromises by:
• Azure Security Centre
• Azure threat monitoring
• Azure Front Door
• Defender
We respond to potential compromises by:
• We treat this as a “Major Incident” and follow our “Major Incident Management Process Document'
Response to incidents are as follows:
• Incident response times depend on the severity of an incident for public cloud environments.
• For private cloud or on-premise customers incident response times are negotiated and defined as part of the Service Level Agreement between the parties. - Incident management type
- Supplier-defined controls
- Incident management approach
-
• We follow our “Incident Management Process policy" - documents available on request
• By default, incidents are reported via e-mail and will enter our support ticketing system. The incident report process can also be customised, negotiated, and defined as part of a Service Level Agreement between the parties.
We provide incident reports in line with our "Incident Management Process policy"
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
Covid-19 recoveryCovid-19 recovery
The service promotes efficiency and automation within business, which in turn will provide economic growth as the country and economy recovers from the impacts of Covid-19
Pricing
- Price
- £600 a licence
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- A full instance of the platform can be made available for a 30 day period.