Intelligent automation and AI solutions
Rising Tide AI provides intelligent automation solutions ranging from rapid-deployment pre-built products to fully bespoke development. We offer configurable off-the-shelf tools for email management, document processing, transcription, data capture, and quality assurance, or custom automation and AI functionality for organisations with complex, unique requirements using proof-of-concept validation and iterative development.
Features
- Pre-built products for rapid deployment of common automation needs
- Bespoke development for unique workflows and complex requirements
- Proof of concept validation before committing to full projects
- Natural language AI for understanding documents and communications
- Automate complex workflows with multiple steps and decision points
- Integration with existing systems and data sources
- Security designed for regulated environments
- Managed service delivery with monitoring and ongoing support
- Built on Azure, AWS, or Google Cloud infrastructure
- Flexible pricing agreed during scoping for all solution types
Benefits
- Automate repetitive activities and reduce manual handling errors
- Process higher volumes maintaining quality without additional resources
- Maintain consistent quality and accuracy across all automated workflows
- Respond to requests faster through immediate automated handling
- Track and audit every automated action for compliance requirements
- Handle complex decisions automatically using intelligent business rules
- Enable staff to focus on complex judgment-based work
- Integrate multiple systems so data flows automatically between them
- Understand content and context using natural language AI
- Validate solutions through proof of concept before full investment
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 9 0 8 2 2 6 7 5 2 1 2 9 5 2
Contact
RISING TIDE AI LTD
Iain McKeith
Telephone: 07555765647
Email: iain.mckeith@rising-tide.ai
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Robotic process automation
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- No. Our solutions are designed from the outset with error monitoring, and the ability to perform any necessary maintenance and updates in mind. Seamless updates with no downtime are a core component of our services.
- System requirements
- None
User support
- Email or online ticketing support
- Yes
- Support response times
- Initial response within 4 business hours for severity 1 issues during standard support hours (9am-5pm UK time, Monday-Friday). Response times vary by severity level and support tier. Enhanced support options available including 24/7/365 coverage.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support is structured around three levels, with specifics agreed based on operational requirements.
Standard Support provided in business hours (e.g., 9am-5pm weekdays) with defined critical response times, dedicated account managers, periodic reviews.
Enhanced Support provides extended coverage hours with faster response times, priority escalation, more frequent reviews, proactive monitoring.
Premium Support can provide round-the-clock availability options with rapid response, named support engineers, intensive support during critical periods.
Coverage hours, response times, review frequency, and costs are tailored to each solution's complexity and criticality. All levels include technical account managers and cloud support engineers for infrastructure issues. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Workshops or virtual calls are typically held to work through the solution and help the client team understand the rationale, approach, functionality and underlying technology of our solution.
For off-the-shelf products, we provide configuration workshops to set up business rules and workflows, followed by user training for end users and administrators. Training covers how to use the solution, interpret results, and handle exceptions.
For bespoke development, we start with proof of concept validation before full development. Training is designed specifically for your solution and delivered to all user groups.
We provide onsite training or remote training via video conference, depending on preference. Training is included in service setup and covers all aspects of using and managing the solution.
Each solution includes comprehensive user documentation, quick reference guides, video tutorials, and technical integration documentation.
All clients receive dedicated business and technical account managers who provide continued guidance beyond initial deployment. Refresher training is available when solutions are updated. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Our services process data transiently in line with GDPR principles. Data is processed and delivered to your systems, then removed from our infrastructure. We do not retain operational data after processing, so there is typically no client data requiring extraction at contract end. All processed outputs remain in your systems throughout.
Configuration of the system and associated inputs are owned by you at all times and can be extracted at any point in accordance with your data handling policies.
System logs recording processing activity, performance metrics, and audit trails are retained for the duration agreed in contract terms. Logs contain no personally identifiable information in line with security best practices.
Log files are available for extraction throughout the contract and at contract end, and can be audited at any time on request.
Data extraction processes, formats, and retention periods are defined during project setup and documented in contract terms. - End-of-contract process
-
End-of-contract arrangements are agreed during initial contracting, including notice periods, data handling, knowledge transfer, and transition support requirements.
Services operate on consumption-based pricing. When services are no longer required, they can be discontinued after the agreed notice period with no further financial commitments beyond that notice period.
Configuration data, business rules, and system documentation are provided to support potential migration to alternative providers.
Transition support can include knowledge transfer sessions, technical handover documentation, and assistance with service migration where required.
The specific end-of-contract process is tailored to each solution and documented in contract terms, ensuring clarity about responsibilities, timelines, and handover procedures from the outset. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Our browser-based interfaces are built either using responsive design or an alternate dedicated mobile experience where that is more appropriate. This means that there are typically no differences in functionality available through various devices, although information may need to be presented or rendered in a different way due to certain device limitations such as screen size.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- In order to monitor the ongoing performance of business processes and technology components within the managed service that we provide, we provide a service interface to provide near real-time information for most of our solutions.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- We test our software using a variety of screen readers and browsers. We are able to advise customers on the best combination of screen reader and browser technologies for each of our individual solutions.
- API
- Yes
- What users can and can't do using the API
-
Many of our services are designed to enhance existing business processes and applications with Artificial Intelligence and Machine Learning.
Those services are typically accessed via a secure API that we provide. Each customer will be provided with their own unique access credentials to securely access the API.
When the core service is being delivered via API, there are no limitations other than volumetric or other usage limitations that will form part of the agreement and contract. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Off-the-shelf products can be configured to match your business rules, workflows, and integration requirements. Configuration includes setting business logic, defining approval routes, mapping data fields, and connecting to existing systems. Configuration is performed by our technical team during setup, with ongoing adjustments managed through your account manager.
Bespoke solutions are developed specifically for your requirements, so customisation is built into the development process. Post-deployment, solutions can be reconfigured to accommodate changing business rules and workflows through defined change control procedures managed by our technical team.
Scaling
- Independence of resources
-
Solutions are built using Azure, AWS, and Google Cloud platforms. By utilising industry-leading cloud providers, our solutions are designed from the outset to ensure scalability is available on demand and peak loads from one client do not impact other clients.
Each solution operates in isolated environments with dedicated resources and separate data storage. Infrastructure isolation and auto-scaling are managed through cloud provider security controls, ensuring consistent performance regardless of other clients' activity.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Solutions provide metrics appropriate to their function including transaction volumes, processing times, success and error rates, and system performance. Dashboards display near real-time information for monitoring processes and identifying issues.
Off-the-shelf products include pre-built reporting. Bespoke solutions have metrics designed for your specific requirements.
Exception reporting alerts teams when errors occur. Metrics are accessible through web-based dashboards and can be exported for integration with your reporting systems. Specific metrics, reporting formats, and data retention periods are defined during project scoping. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Solutions process data transiently and deliver outputs to systems. Operational data does not require export as it is not retained after processing. Configuration data, business rules, and workflow definitions can be exported at any point during or after the contract. System logs and performance metrics are available for export in standard data formats. Export processes are defined during project setup based on data handling and archival requirements.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Solutions are built on Azure, AWS, and Google Cloud platforms, each with contractually guaranteed availability of at least 99.9% based on 24/7 operation.
Service level agreements and availability guarantees are defined with clients during project scoping based on operational requirements. Our solutions inherit the high availability, disaster recovery, and redundancy capabilities of cloud providers at service, data center, and regional levels.
We ensure that data remains within agreed regional boundaries in line with data sovereignty requirements, so services do not fail over to other geographies. Availability commitments, service credits, and regional constraints are documented in contract terms.
Outage reporting and service status information is available to clients through dashboards and account manager communication. - Approach to resilience
-
Solutions are built on Azure, AWS, and Google Cloud platforms designed with high availability, disaster recovery, and backup as core capabilities. Redundancy operates at service, data center, and regional levels to ensure continuity.
Our approach combines cloud provider resilience infrastructure with application-level design for fault tolerance. Solutions are architected to handle component failures, with automated recovery procedures and monitoring to detect and respond to issues proactively.
Data remains within agreed regional boundaries in line with data sovereignty requirements. Backup and recovery procedures are designed to maintain data integrity while respecting geographic constraints, ensuring services do not fail over to other regions.
Resilience requirements are assessed during project scoping and built into solution architecture. Regular testing and monitoring verify that resilience mechanisms function as designed. - Outage reporting
-
Outages and service issues are reported through multiple channels. Service status dashboards provide real-time information on system health and any ongoing incidents. Clients receive proactive notifications of outages affecting their services through email and direct communication from account managers for significant incidents.
As part of our managed service approach, we monitor services continuously to identify and address performance issues before they impact operations. Where intervention is required, we notify affected clients with incident details, expected resolution timeframes, and progress updates.
Post-incident reports are provided documenting the cause, impact, resolution actions, and measures taken to prevent recurrence. Outage history and service performance metrics are available through client dashboards for ongoing transparency.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
-
We provide role-based access control and privileged identity management for management and support channels. Clients provide a named list of authorised users permitted to access support and management capabilities. These users receive individual access credentials.
Access is restricted to named, authorised personnel only. User lists can be updated as staffing changes occur. Multi-factor authentication is available for enhanced security where required.
All access to management interfaces and support channels is logged for audit purposes, creating traceable records of administrative actions and support activities. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
We hold Cyber Essentials Plus certification and are working towards ISO 27001. We adopt a risk-first approach with security designed into solutions from the outset, following principles including least privilege access, data protection in transit and at rest, secure logging, regular reviews, two-factor authentication, and secure passwords.
All staff understand security responsibilities and incident reporting procedures. The board retains ultimate security responsibility with a named director accountable for governance,
Security policies are reviewed regularly based on emerging threats and regulatory requirements. - Information security policies and processes
-
We maintain comprehensive information security policies covering data handling, access controls, incident management, secure development, business continuity, and acceptable use.
Every employee and contractor is responsible for reporting security incidents or suspicions immediately to the security officer, ensuring incidents are properly recorded. The incident management team provides rapid response to resume normal operations safely. The board oversees incident management with ultimate responsibility for security.
Security incident response includes immediate assessment, containment, investigation, resolution, and documentation. Severe incidents and potential data breaches are reported to affected clients within one business day.
Our policies address confidentiality through access restrictions and encryption, integrity through data validation and audit trails, and availability through redundancy and disaster recovery procedures.
Policies are communicated to all staff during onboarding and through regular security awareness training. Compliance is monitored through access logs, security reviews, and incident tracking. Policy adherence is a condition of employment and contract terms for all personnel.
Policies are reviewed annually and updated based on emerging threats, regulatory changes, security assessments, and lessons learned from incidents. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
We use DevOps practices with fully automated deployment to minimise human error. Source code and deployment artifacts are held under version control. Infrastructure-as-code manages all production assets, ensuring system state is known and previous states can be restored if needed.
Releases are security and functionally tested using automated scripts. Test suites are enhanced over time so identified issues cannot reoccur. Full release notes are provided to clients for all changes.
Configuration changes follow defined change control procedures. Changes are tested in non-production environments before deployment. Emergency changes have expedited approval processes while maintaining documentation and rollback capabilities. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Solutions use serverless and managed services from Azure, AWS, and Google Cloud, inheriting security practices and vulnerability management from industry-leading cloud providers who manage infrastructure patching and security updates.
We monitor security advisories for software dependencies and apply patches promptly. Automated dependency scanning identifies vulnerable components during development. Critical vulnerabilities are addressed immediately with expedited deployment.
Penetration testing is conducted annually by external organisations. Findings are prioritised by severity and remediated according to agreed timelines, with verification through retesting.
Vulnerability management includes continuous monitoring, regular security assessments of application code, and staying current with security patches. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Our managed service includes proactive monitoring to ensure systems operate within normal parameters. Automated monitoring detects unexpected or atypical behavior indicating potential compromise, including failed authentication attempts, unusual access patterns, performance anomalies, and security events.
When potential compromises are identified, incident response procedures are initiated immediately. This includes assessment, containment, investigation, and resolution. All staff understand incident identification and reporting procedures.
Response times vary by severity. Critical security incidents receive immediate attention. Severe incidents and potential data breaches are reported to clients within one business day, with ongoing updates until resolution. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
We follow an ITIL-based incident management process to minimise impact on client operations. Pre-defined procedures exist for common incident types including service outages, performance degradation, security events, and data processing errors.
Automated monitoring identifies incidents proactively before business operations are affected. Clients can report incidents via email and phone support during business hours, with emergency contact procedures for critical issues outside standard hours.
Incidents are categorised by severity with defined response times. All clients receive monthly incident reports. Post-incident reports are provided for significant incidents, documenting cause, impact, resolution, and preventive measures. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2%
- Between £250,000 and £500,000
- 3%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- E929f40f-db74-41bf-948c-38062e698023
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-