Send Evidence
Send Evidence is a secure, cloud-based service that enables public sector organisations, such as police, councils, and fire, to send and receive digital information with third parties. It provides secure two-way exchanges, online payment capability, audit logging, and configurable data retention to meet operational and compliance requirements.
Features
- Secure two-way exchange of digital information with third parties
- Web-based access with no local installation required
- Role-based access controls
- Supports optional online payment as part of submission workflows
- Full audit logging of user activity
- Configurable data retention settings
- Secure storage of uploaded content
- Data export in common formats
- Fully managed hosting and maintenance
Benefits
- Enables secure and controlled information exchange
- Reduces reliance on email and physical media
- Supports compliance and audit requirements
- Removed physical collection and associated travel costs
- Electronic payments to be collected from external parties where required
- Increases speed of evidence transfer and collection
- Reduces operational risk associated with unmanaged submissions
- From no cost to public sector buyers
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 7 9 4 2 4 7 9 5 5 2 5 9 1 6
Contact
Send Evidence
Scott Fulton
Telephone: +447484117946
Email: enquiries@sendevidence.co.uk
About the service
- Service categories
-
Applications
Content workflow and management
Content services
- Content Sharing and Collaboration Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service requires an active internet connection and access to a modern, supported web browser. Planned maintenance may be required from time to time and will be communicated in advance where possible. Support is provided during UK business hours, with incident response available outside business hours for service-impacting issues.
- System requirements
-
- Modern, supported web browser
- Active internet connection
- JavaScript enabled
- Cookies enabled
- Secure HTTPS access permitted
User support
- Email or online ticketing support
- Yes
- Support response times
- Support requests are typically acknowledged during UK business hours. Response times are proportionate to the nature and impact of the issue. Service-impacting incidents may be responded to outside business hours where required.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
- The service includes a single standard support level, provided at no cost to public-sector buyers. Support is provided via email or online ticketing during UK business hours. Service-impacting incidents may be responded to outside business hours where required. There are no additional paid support tiers. A dedicated technical account manager or cloud support engineer is not assigned by default; the supplier provides appropriate technical support as needed.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- The service is designed to be intuitive and requires minimal training. Onboarding is supported by the supplier through an initial onboarding document and a structured set of questions to capture configuration requirements such as preferred URL, access controls, and workflow setup. The supplier configures the service accordingly and provides guidance via email-based support as required. No onsite training is required.
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Microsoft Word
- End-of-contract data extraction
- At the end of the contract, the supplier supports data extraction by providing the buyer with an export of their data in commonly used formats. Data extraction is coordinated with authorised organisational users to ensure completeness and security. The supplier will agree the scope and timing of the export with the buyer and provide the data via a secure transfer method. Data remains the buyer's property and can be exported prior to the contract end if required.
- End-of-contract process
- At the end of the contract, the supplier will agree on a contract end date with the buyer and support the orderly exit from the service. This includes providing a secure export of the buyer’s data in commonly used formats and confirming its completion. Following confirmation, buyer data will be securely deleted in accordance with agreed retention requirements. There are no exit fees. All standard end-of-contract activities, including data extraction and secure deletion, are provided at no cost to public-sector buyers.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is accessed via a web browser and is responsive to different screen sizes. Third parties can access the service on any device using a standard web browser without installing software. The desktop experience provides a larger interface, better suited to organisational users who review and manage higher volumes of information.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure, web-based user interface. Authorised organisational users access the service to request, manage and review information, while third parties access specific submission pages using a standard web browser. Where configured, submission workflows may include online payment, allowing external parties to complete submissions and associated payments in a single, secure process. The interface is designed to be simple and task-focused, with role-based access controls and responsive layouts for different devices.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Accessibility considerations are incorporated into the service's design and development, including support for keyboard navigation, screen reader compatibility, sufficient colour contrast, and responsive layouts. Informal testing has been carried out during development using browser-based accessibility tools and assistive technology features. Accessibility is reviewed as part of ongoing service improvement.
- API
- Yes
- What users can and can't do using the API
-
Send Evidence provides an application programming interface (API) to support integration with third-party systems where required. The API enables controlled interaction with core service capabilities to support operational and regulatory workflows.
Where implemented, the API may be used to manage authorised users, initiate and manage submission workflows, submit materials programmatically, and retrieve submission metadata and status information. API functionality is provided to support integration with external systems, including case management, licensing, and evidence platforms.
The API is not intended to replace the primary user interface and does not provide unrestricted access to all service features. Configuration of workflows, security settings, and administrative controls remains managed through the service interface or by the supplier.
API access, scope, and permitted actions are subject to agreed service configuration, authentication controls, and security policies. Rate limits and access restrictions apply to ensure service resilience and data protection compliance. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- The service supports limited configuration to meet buyer requirements without bespoke development. Submission forms, workflows, and basic branding elements are configured by the supplier in collaboration with authorised organisational users. Buyers can manage user access and permissions through the service interface and may optionally integrate with their directory service, such as Active Directory, where required. Core functionality, security controls, and user experience remain consistent across all deployments.
Scaling
- Independence of resources
- The service is delivered using a scalable cloud infrastructure with logical separation between customers. Resource allocation is monitored and managed to ensure that one customer's usage does not adversely affect others. Capacity planning and automated scaling are used to maintain consistent performance as demand changes.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides basic usage metrics to authorised organisational users, such as submission volumes, user activity, and high-level service usage information. Metrics are provided to support operational oversight and service management and do not include analytical or predictive reporting.
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Data exports are supported by the supplier on request. Exports are coordinated with authorised organisational users and provided securely in agreed, commonly used formats. Data can be exported during the contract term and at contract end to support operational needs and service exit.
- Data export formats
-
- CSV
- Other
- Other data export formats
- ZIP archives containing original submitted files
- Data import formats
-
- CSV
- Other
- Other data import formats
- Original file formats as uploaded by third parties
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- The service is designed to be highly available and is hosted on resilient cloud infrastructure. The service is monitored and managed to minimise disruption. Planned maintenance is communicated in advance where possible. Formal service-level agreements for availability, including any remedies, are agreed as part of individual call-off contracts, where applicable.
- Approach to resilience
- The service is hosted on resilient public cloud infrastructure designed for high availability. It leverages redundancy, automated scaling, and monitoring to mitigate the impact of component failures. The underlying data centre environment is managed by a hyperscale cloud provider with built-in resilience, including redundant power, networking, and physical security controls. Service health is actively monitored, and issues are addressed in accordance with operational procedures. Further technical detail can be provided on request, where appropriate.
- Outage reporting
- Service availability is monitored continuously. When an outage or significant service issue is identified, affected customers are notified by email or phone. Updates will be provided as needed until the issue is resolved.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Other
- Other user authentication
-
Users authenticate using passwordless authentication mechanisms. Internal users may authenticate via identity federation with the organisation’s directory service (for example Microsoft Entra ID / Active Directory). Where federation is not used, users authenticate using time-limited, one-time access codes or secure magic links delivered to verified email addresses.
External users authenticate using secure, time-limited links or one-time codes sent to their email address. No static passwords are used. All authentication tokens are short-lived and single-use. - Access restrictions in management interfaces and support channels
- Access to management and administrative interfaces is restricted to authorised personnel only. Access is role-based and protected by multi-factor authentication. Administrative access is logged and monitored, and privileges are limited to the minimum required for operational support.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Other
- Description of management access authentication
- Access to management and administrative interfaces is restricted to authorised personnel only. Access is role-based and protected by multi-factor authentication. Administrative access is logged and monitored, and privileges are limited to the minimum required for operational support.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security governance is overseen by a named senior individual who is responsible for service security. The organisation follows a risk-based approach to security governance, aligned with recognised good practice, including secure development principles, access control, data protection, and incident management. Security considerations are embedded into service design, development, and operation, with responsibilities clearly defined. The security posture is reviewed regularly and updated as the service evolves and risks change.
- Information security policies and processes
- The organisation maintains information security policies and procedures covering areas such as access control, data protection, secure development, incident management, and acceptable use. Responsibility for information security is assigned to a named senior individual with overall accountability. Policies are communicated to relevant staff and are applied as part of day-to-day operations. Compliance is supported through defined processes, regular review of practices, and management oversight. Policies and processes are reviewed and updated as the service evolves and risks change.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Service components are version controlled and tracked throughout their lifecycle using defined development and deployment processes. Changes are planned, reviewed, and tested prior to deployment. The potential security impact of changes is considered as part of the change process, including assessment of access controls, data handling, and service availability. Changes are implemented in a controlled manner, with the ability to roll back if issues are identified. Oversight is provided by the service owners to ensure changes are appropriate and risks are managed.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Potential threats to the service are assessed through ongoing review of the application, underlying platform, and operational environment. Vulnerability information is gathered from cloud provider security advisories, software dependency updates, and relevant security bulletins. Identified vulnerabilities are assessed for risk and impact, and appropriate remediation is prioritised accordingly. Security patches and updates are deployed in a timely manner based on severity, following testing to minimise service disruption. Vulnerability management activities are overseen by the service owners and reviewed regularly as part of operational security processes.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is carried out through a combination of application logging, cloud platform monitoring, and operational oversight. Logs and alerts are reviewed to identify unusual activity or potential security issues. Where a potential compromise is identified, it is investigated promptly, and appropriate actions are taken to contain, remediate, and prevent recurrence. The response to incidents is prioritised by severity and potential impact, with service-impacting or security-related incidents treated as priorities.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The organisation has defined incident management processes for handling security and service-related incidents. Common incident types are handled using established procedures appropriate to their nature and impact. Users can report incidents via email or the service support channel. Incidents are assessed, prioritised, and responded to based on severity and potential impact. Where appropriate, affected users are kept informed of progress, and incident reports or summaries can be provided following resolution. Incident management activities are overseen by the service owners and reviewed to support continuous improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- The free version allows public sector users to securely send and receive evidence with third parties via a web browser. Core evidence exchange features are included. Trials are provided for a limited number of users within an organisation, agreed in advance, and subject to fair use and service terms.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain