Skip to main content

Help us improve the Digital Marketplace - send your feedback

AGILYX EMEA LTD

Vena - Planning, Budgeting and Forecasting Solution integrated with Excel

Vena's CPM platform combines deep FP&A planning capabilities, AI-powered reporting & analytics, flexible workflows & data governance with the productivity, collaboration & innovation of your Microsoft applications. Vena is natively integrated with Excel, Microsoft 365 and Open AI technologies to empower Finance teams - complete planning platform with enterprise-level scalability.

Features

  • Integrated software for business planning across the whole organisation
  • Consolidated reporting in real time
  • Workflow automation for key processes
  • Full audit trail of user inputs
  • Native integration with Excel
  • Ease of use, purpose-built for Finance without expensive third-party support
  • Dashboard reporting with embedded Microsoft Power BI
  • Visibility of financial and non-financial performance
  • Integrated AI agent that automatesFP&A, accelerates insights,Improves Decisions
  • Data and ERP source system agnostic. API's, native connectors, ETL

Benefits

  • Reduce cost of ownership in medium term
  • Increase user adoption and utilisation with familiar native Excel interface
  • Connect multiple data sources into a single source of truth
  • Increase visibility over key financial reporting and planning processes
  • Ensure data integrity and accurate reporting with real-time data refresh
  • Significantly reduce lead times for key processes including monthly closedown
  • Automate spreadsheet-based processes with full auditability and transparency
  • Automate business-wide processes with Vena’s applicability across multiple use cases
  • Lower your upfront investment and see value faster
  • Secure financial data with advanced security features and role-based permissions

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at julie.taylor@agilyxgroup.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 5 0 5 4 7 8 5 7 8 3 0 1 2 6

Contact

AGILYX EMEA LTD Julie Taylor
Telephone: 01628 637266
Email: julie.taylor@agilyxgroup.com

About your service

Service categories

Application Development and Deployment

Analytics and business intelligence

  • Business Intelligence
  • Advanced and predictive analytics
  • Location and geospatial data management and analytics
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
None that we are aware of
System requirements
Fully cloud-based platform accessed via web based application.

User support

Email or online ticketing support
Yes
Support response times
Maximum first response wait of 1 business day for severity C issues
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Via the support pages on our website or via the help feature embedded into our application
Web chat accessibility testing
Not known
Onsite support
Yes, at extra cost
Support levels
Standard Support Plan
Every customer has access to our Standard Support Plan for online and telephone support, including:
• 24/7 application monitoring
• Help desk phone and email support 24/5 Monday-Friday
• Unlimited case submissions
• Up to 3 Power Users to contact Vena support
• Maximum first response time of 1 business day for Severity C issues
• Access to the Vena Customer Portal, online videos, FAQs, user guides, and a community help forum in our knowledge base
• A dedicated Customer Account Manager to help recommend products, services and processes to help you get the most out of Vena

Extended Support Plan
For after-hours support and accelerated response times, our
Extended Support Plan combines all the services of our Standard Support Plan with:
• 24 Help Desk with on-call telephone support
• Maximum first response time of 5 hours for Severity A issues
Up to 20 Manager or Administrator users to contact Vena support.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Training is provided as well as a range of consulting services to assist with implementation and data import etc.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Vena offers multiple methods of data export to our customers, depending on your source systems, available resources and preferences:
1. Manual export via mass or queried export within the application
2. Automated/scheduled export of data via flat file format
3. Automated/scheduled export via Microsoft Power Automate
4. Automated/scheduled export via Vena’s open REST API
5. Automated/scheduled integration via Microsoft Data Factory in Fabric
Vena supports .csv format for data export from the Vena application.
End-of-contract process
Contracts are normally renewed on the contract anniversary. If a customer wishes to terminate the contract, then all customer data is permanently deleted.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Via Link

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Same functionality. Note that Vena does not have a separate mobile application. Rather, Vena users can easily log onto the application via any mobile device through their mobile browser.
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
The Vena API is a REST API that allows users to
• Retrieve template information
• Upload files to steps
• Create jobs
• Edit jobs
• Run jobs
• Export Data
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Vena provides a fully configurable set of tools that does not require code customisation. including data modelling, workflow management and template/report design, leveraging the capabilities of a native Excel interface. Customisations are not impacted by product upgrades. Some of the ways in which the Vena application may be customized/configured to meet business requirements are:

A sophisticated process designer that allows users to drag-and-drop their workflow process, including input steps, review steps, alerts and report access.
The ability for workflow messages to be customised.including autofill of specific data.
Ability to require managers to acknowledge receipt/review/approval of reports(s)
User permissions for access and security are controlled by the administrator and can be customised as needed.
The database can be fully configured to support tables & fields as required. Templates and reports are authored in a native Excel interface and can be completely customised.
Pre-formatted reports that can be leveraged as a starting point. Vena leverages a native Excel interface as the authoring environment, which allows clients to customize their reports as needed.
The ability to create and customise dynamic validation rules based on user inputs.
Data visualisation tools to improve visibility into processes and conditions, as well as discerning trends and projections.

Scaling

Independence of resources
As a multi-tenant SaaS platform, auto-scaling enables Vena to support unlimited concurrent users without performance degradation.

Analytics

Service usage metrics
Yes
Metrics types
System performance (e.g. system availability, outages, etc.) is available to customers via public URL. Customer tenant metrics, like usage, is available to share through the customer's designated Vena Account Manager
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Vena Solutions UK Ltd

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
Vena encrypts all client data at rest using AES-256 bit encryption. Passwords are also securely stored through one-way hashed (bcrypt) with salt.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Vena is source system agnostic and supports a full spectrum of data integration capabilities to connect and load data from any source systems, including ERPs/GLs, HRISs, CRMs and more. Vena offers multiple methods of data integration to our customers, along with Extract-Transform-Load (ETL) functionality, depending on your source systems, available resources, and preferences:
1. Manual export via mass or queried exportwithin the applicaton
2. Automated/scheduled export of data via flat file format.
3. Automated/scheduled export via Microsoft Power Automate
4. Automated/scheduled integration via Vena’s open REST API
5. Automated/Scheduledintegration via Microsoft Data Factory in Fabric
Data export formats
CSV
Data import formats
  • CSV
  • Other
Other data import formats
TDF

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
All data in Vena is encrypted in transit using TLS 1.2 and at rest using AES 256-bit encryption, backed by the AWS Key Management System (KMS).
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Vena uses reasonable efforts to make the Service available with a monthly uptime percentage of at least 99.5%, 24 hours per day, 7 days per week, in each case during any monthly cycle (the “Service Commitment”). Monthly uptime percentage is based on the number of minutes the system is unavailable outside of planned maintenance windows in a calendar month and between the hours of 9:00 AM to 8:00 PM, Monday to Friday, with holidays excepted. The Service is considered unavailable when the system/Service cannot be accessed by the Subscriber between the hours of 9:00 AM to 7:00 PM, Monday - Friday, due to a service provider problem. In the event that Vena does not meet the Service Commitment, Users will be eligible to receive a Service Credit as described below.

Service Credits are calculated as a percentage of the proportional monthly subscription value of the total subscription fees paid by Subscriber for the Service in accordance with the schedule below. The monthly uptime percentage is based on the number of minutes the Service is unavailable outside of planned maintenance windows in a calendar month.
• Service is unavailable between 90-360 minutes-10%
• Service is unavailable for more than 360 minutes-40%
Approach to resilience
Each Vena instance is distributed across at least three Availability Zones, which means all live data is replicated and distributed across at least three physical data centers in a different location within a given cloud region, ensuring high availability and resilience. As part of our data backup and DR approach, backups of customer data are replicated and stored in a second cloud region in the event of an entire region becoming unavailable.
Outage reporting
A public dashboard with emai alerts can be subscribed to – status.vena.io

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access is granted based on an employee's role based on principles of least privilege. Only the access that is required for the employee to perform their duties is granted. Only a limited group of Vena employees on the infrastructure team have access to infrastructure/systems hosting customer data, for the purposes of troubleshooting systems issues and performing maintenance. All access is audited and controlled through access management controls, such as API logs, two-factor authentication and VPN access to the environment. All backend operations to access any data (including backups) is logged.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
No audit information available
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Vena has successfully completed SOC 1 & SOC 2 Type II audits which were performed by Deloitte LLP. The examination was conducted in accordance with attestation standards established by the American Institute of Certified Public Accountants (AICPA).
Information security policies and processes
Vena employs a three lines of defense model to govern risk management. This model is widely used in the industry. Each of the three lines plays a distinct role within Vena’s control environment.

The first line of defense lies with the business and process owners, like IT, Finance, HR and Vena’s Cloud Operations teams, which are responsible for maintaining effective controls and for executing agreed upon risk and control procedures on a day-to-day basis.

The second line is performed by our Corporate Security department and overseen by a Security Risk & Compliance committee, which supports management to help ensure risk and controls are effectively managed. This line performs risk management and compliance functions to help build and/or monitor the first line-ofdefense controls.

The third line of defense provides assurance to senior management and the board that the first and second lines’ efforts are consistent with expectations. Vena employs independent external auditors for our third line of defense. They are solely responsible for providing an independent opinion on the sufficiency of the internal controls with respect to the requirements specified within accepted industry standards such as SOC.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
The change management process requires that existing security control mechanisms are not negatively impacted prior to approval – adherence to existing controls is reviewed through automated build testing and manual peer core reviews.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Vena Cloud is a fully Infrastructure-as-code production environment deployed across several distributed AWS regions, providing us resiliency, reliability, recoverability and security. We routinely rotate in fresh AWS EC2 VMs on a weekly basis to pick up the latest, up-to-the-minute security releases and OS-level patches to ensure continuous compliance with critical OS-level vulnerabilities. All base images are scanned prior to deployment using automated vulnerability scans and any detected known vulnerabilities will halt the release.
Additionally, Vena regularly performs external penetration tests by an independent third party on an annual basis.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Vena employs Endpoint Detection & Response (EDR) on both corporate and infrastructure endpoints to provide advanced threat detection and response, mitigating risks such as malware, ransomware, and other advanced persistent threats. Additionally, Vena utilizes a third-party Managed Detection & Response (MDR) service that covers all assets with EDR agents installed. This service includes managed detection and response, incident investigation, forensics support, and proactive threat hunting.
For cloud infrastructure, logs are continuously monitored and analyzed by anomalous threat detection services like Microsoft Sentinel and AWS GuardDuty. Any alerts generated are promptly investigated, and necessary actions are taken to address potential threats.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Vena’s incident response framework provides the foundational processes for incident detection, management and recovery. The framework also establishes roles and responsibilities during an incident, including escalation procedures, incident classification criteria and response procedures. The foundations of the incident response framework were designed to meet the requirements laid out in ISO-IEC 27001:2013; specifically, the control objectives specified in A.16.1 Management of Information Security Incidents and Improvements.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Wednesday 15 January 2025
What the ISO/IEC 27001 doesn’t cover
The scope of this approval is applicable to: The design, development, provision and support of Unit4 software products and associated consultancy, technical and managed IT services. Statement of Applicability v2. The scope covers all UK activities, and also include Global activities, hosting, SaaS etc
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
QAS International
ISO 9001 accreditation date
Monday 10 November 2025
What the ISO 9001 doesn’t cover
We are exempt from M08 monitoring and Measuring equipment
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
SyberNet Self Assessed Certification
PCI DSS accreditation date
Saturday 14 January 2017
What the PCI DSS doesn’t cover
The service is deployed as a hosted service, via our partner SyberNet, who are required to run and maintain it in a PCI compliant environment. Sybernet are currently a Level 2 service provider with less than 300,000 transactions annually and so they complete an SAQ, a Quarterly scan by an ASV (they use Qualys as their Approved Scanning Vendor) and provide an attestation of compliance (AOC).
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
29a5e660-848c-4905-bd25-51c0df414642
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
  • ISO 270017
  • SOC 1 (type 1 and 2)
  • SOC 2

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at julie.taylor@agilyxgroup.com. Tell them what format you need. It will help if you say what assistive technology you use.