Togetherall Digital Mental Health Service
Togetherall (formally Big White Wall) is an award-winning digital mental health service. It offers a stepped-care model for adults experiencing mental distress: The Support Network: 24-7 professionally moderated peer support, self-management, art and writing therapies, Self-assessments and Self Guided Support courses.
Features
- Accessible 24/7/365
- Clinically moderated 24/7/365
- Safe, anonymous peer support
- Self Guided Support courses
- Self Assessments
- Personal Journal & Action tracking
Benefits
- Proven track record
- Clinically effective
- Provides choice and flexibility
- Full implementation support
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 4 7 4 9 9 1 4 5 8 6 6 7 2 0
Contact
TOGETHERALL LTD
Stephanie Evans
Telephone: 02046193976
Email: theteam@togetherall.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
Togetherall’s Support Network is compatible with all modern browsers and Operating Systems, including compatibility with mobile and tablet devices. Our website is NOT supported by versions of Internet Explorer. A message displays as applicable to advise users of this. It is completely accessible through Chrome, Firefox, Microsoft Edge and all Internet Explorer platforms version 11 or newer.
Users must be over the age of 16 to join Togetherall. - System requirements
- Modern web browser
User support
- Email or online ticketing support
- Yes
- Support response times
- We will try to answer queries within 48 hours. Please be aware that the mailbox is only monitored during working hours, from Monday to Friday, 9:00am to 5:00pm GMT. During national holiday periods, it may take slightly longer to get back to you.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support for the buyer: Account Manager onboarding package and support, including training for buyer staff as per contract.
Support for the user: theteam@togetherall.com email support for all customer support queries. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Togetherall provides a combination of training and user documentation during the implementation of the contract, which is delivered by both the Account Manager and the wider service and implementation team.
- Service documentation
- Yes
- Documentation formats
-
- ODF
- End-of-contract data extraction
- Regards end-user data: As the Data Controller for the data of its end users, Togetherall has a process for responding to data subject requests from these users. End users are made aware of their right to request access to their data in Togetherall’s publicly available privacy policy. This right may be exercised at any time, including the point after the contract has ended.
- End-of-contract process
- The client must provide 30 days written notice that they no longer wish to continue the agreement. After notice is received, the dedicated Account Manager would work with the named contact at the organisation to start the transitioning and handover process. This would include outlining the next steps with regards to access to the Togetherall platform as part of this transitioning period. If transitioning across to another organisation, or the agreement coming to an end, members will be directed through to the pathways of the new service, ensuring all members are made aware of existing mental health and wellbeing provisions they have access to. If members log-in to their Togetherall account after the transition period, then Togetherall’s operations and customer support team would notify all members that they no longer has access to Togetherall and will be provided with information of who they can contact if they need help. The directing of members to existing pathways of support if they need help ensures that the service is not immediately stopped which could negatively impact their help seeking and allows for those identified as vulnerable or at risk, to continue to be supported as part of the transitional period.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Accessibility requests can be made via the Account Manager and will be accommodated as required.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Togetherall’s Support Network is compatible with all modern browsers and Operating Systems, and pages are re-formatted and re-sized depending on the display.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Togetherall conducts load tests on the website as needed when forecasting scale-up requirements.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Togetherall will provide monthly updates detailing aggregated registrations and updates detailing the aggregate usage, activity and demographic profile of members.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Member requests to export data are processed through the customer service team at theteam@togetherall.com and transmitted securely to the user through their registered email address.
Regards client data: Togetherall is not a data processor for its clients, therefore Togetherall does not have an obligation to export data to clients. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- The service is available 24/7 with critical issue resolution of 4 hours from initial response. Service availability SLA is not provided for Togetherall, as the service is not a business critical system.
- Approach to resilience
- For our website hosting, AWS servers are located in a secure London data centre with minimal access to only those who are authorized by Togetherall, and additionally comply with AWS data centre escort policies. Additional information available on request.
- Outage reporting
- Using email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Data access and changes to data access are restricted by role, and recorded and managed for all staff through Togetherall’s Change Management process.Togetherall’s role-based access to systems includes a process for issuing appropriate permissions upon joining, and removal of all system access on final day of employment.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
-
Data Security and Protection Toolkit (NHS Digital)
Togetherall has been assessed with a quality score of 87% by ORCHA and we are featured on the ORCHA App Library
Togetherall's hosting provider AWS are certified to ISAE 3402 and ISO 27001. - Information security policies and processes
- Togetherall complies with the Data Protection Act 2018, and complies with the UK General Data Protection Regulation (GDPR). Togetherall monitors awareness for all staff through mandatory annual IG training. Togetherall has an onboarding process to ensure compliance with all policies relevant to role, and carries out police checks for clinicians who have contact with vulnerable individuals. These security policies and processes include Togetherall’s Business Continuity Plan, Caldicott Plan, Confidentiality and Data Protection Policy, Change Management Process, IG Management Framework, Training Plan, Incident Response Policy and Procedure, Information Security Policy, and the System Security Policy. Togetherall retains audit logs for access to Personal Data, to ensure policies are followed.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Contained in the Change Management Process, which has been developed with external auditor who is an HSCN aggregator (Hytec). Change Management is a core requirement in complying with the annual audit for submitting the NHS Digital Data Security and Protection Toolkit, under criteria for development and implementation of new processes or information assets: https://www.dsptoolkit.nhs.uk/OrganisationSearch/NKQ01 All technical changes to Togetherall are logged through JIRA Issue and Project tracking software.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Regards IT estate, IT provider patches Microsoft and other 3rd party apps automatically using N-Able RMM tool (formerly Solarwinds RMM) deployed to each PC.
Regards the Togetherall service, all our platform servers under managed updates which means all software and application updates are automatically made. Penetration testing is arranged by Togetherall once per year, using an independent third party. Togetherall also conducts regular vulnerability scans for our platform and website throughout the year, pro-actively addressing critical and high-risk security vulnerabilities with priority in order to reduce the risk of such vulnerabilities being exploited. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Togetherall’s hosting provider Amazon Web Services (AWS) has their data centre protections certified to SSAE 3402. Togetherall hosts the site behind Amazon CloudFront (content distribution network). AWS' Web Application Firewall and DNS level protection provide protective monitoring tools for detection and prevention of common cyber attacks. Togetherall’s approach to intrusion prevention is to ensure that the virtual machines that are driving the platform are not exposed to the Internet and instead only open to load balancers that facilitate all communication with client browsers via port 443 a.k.a. HTTPS. Intrusion detection is ensured by real-time alerts from third-party security tools.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Togetherall’s Incident Response Policy includes procedures for preparation, detection, analysis, containment, recovery, and post-incident activities. The process operates 24/7 and includes data breach notifications within required timeframes. Monitoring alerts from third party security tools are reported in real time to Togetherall’s cyber incident team via third-party messaging tools. Moderators also monitor the site continuously and manually report suspicious activity or outages using the same tools. Togetherall prioritizes resolving incidents promptly and informs commissioners, affected populations, and regulators as required by law.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- EY CertifyPoint
- ISO/IEC 27001 accreditation date
- Tuesday 25 November 2025
- What the ISO/IEC 27001 doesn’t cover
- Because all Togetherall data is held on the AWS servers, ISO 27001 certification is obtained from AWS. Togetherall does not have ISO certification as an organisation.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- EY CertifyPoint
- ISO 9001 accreditation date
- Tuesday 25 November 2025
- What the ISO 9001 doesn’t cover
- Because all Togetherall data is held on the AWS servers, ISO 9001 certification is obtained from AWS. Togetherall does not have ISO certification as an organisation.
- Quality management systems (QMS)
- No
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Tuesday 25 November 2025
- CSA STAR certification level
- Level 2: CSA STAR Attestation
- What the CSA STAR doesn’t cover
- Because all Togetherall data is held on the AWS servers, CSA STAR certification is obtained from AWS. Togetherall does not have CSA STAR certification as an organisation.
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 8cf5c7f0-e8ca-45c4-8b4e-f8141b012be2
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- ORCHA Global Baseline Review certification
- Data Security and Protection Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Plans for positive actions with community groups.
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-