Skip to main content

Help us improve the Digital Marketplace - send your feedback

AFFINITY DIGITAL (TECHNOLOGY) LIMITED

Drupal CMS discovery, build, host, support and improve

Affinity is an experienced provider of open-source CMS's, Drupal development, support, hosting, migration for critical services and applications being one. We specialise in integration with line-of-business applications, thrive on complexity, and offer supporting services, utilising effective user-centric, GDS compliant methodologies. We are accredited with ISO27001, 9001 and Cyber Essentials Plus.

Features

  • 24/7/365 cover. Cyber Essentials Plus, ISO 27001 and 9001 accreditations.
  • Discovery process, helping buyers meet core principles around user needs.
  • Drupal 10 development and customisation.
  • Jira service desk, giving access to support technicians.
  • LOB system integration, CDN integration and CMS migration services.
  • WCAG 2.2 AA and Public Sector Bodies Accessibility compliance.
  • AWS hosting, with auto-scaling available. Automated security updates.
  • On-site or remote training with documentation.
  • Provides decoupled and API-first capabilities via JSON:API.
  • Drupal security hardening to give you greater levels of security.

Benefits

  • Open-source with no licensing requirements and support AWS integration.
  • Drupal security team provides proactive vulnerability management.
  • Excellent editor experience with Layout Builder and content workflows.
  • Accessibility built-in to help you meet WCAG requirements.
  • Provides reassurance by continually meeting security and compliance requirements.
  • Dedicated Drupal specialists available through our robust support system.
  • Rapid custom development for quick deployment to reduce costs.
  • Flexible SLAs to give you the expert support you need.
  • Multilingual capabilities for international audiences.
  • ISO27001, ISO9001 and CE+ accredited. GDPR ready, offering compliance support.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@affinity-digital.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 6 4 4 0 2 9 3 6 3 4 0 4 4 5

Contact

AFFINITY DIGITAL (TECHNOLOGY) LIMITED Jonathan Duval
Telephone: 01872 321177
Email: sales@affinity-digital.com

About your service

Service categories

Applications

Content workflow and management

Persuasive content management

  • Website Software
  • Digital Asset Management Applications

Enterprise portals and digital workspaces

  • Multi-Audience Portals
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Community cloud
  • Hybrid cloud
Service constraints
None
System requirements
  • Modern web browser with JavaScript enabled
  • Internet connection
  • No additional software or licences required

User support

Email or online ticketing support
Yes
Support response times
Our QMS states we will respond within 1 working day. However we can tailor our flexible SLA's to meet your unique requirements. For example our current contracts with the Cabinet Office have a priority list that ensures P1 issues are responded to within 30 minutes.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
The success of any support agreement is built around regular, timely, clear communication. Affinity prides itself on its open, honest and transparent ways of working.
Frequent dialogue, backed up with documentation, and Jira with its tailorable workflows and notification schemes, forms the backbone of our robust, well proven support process.
We tailor our support to your needs, providing technical account managers and cloud support engineers. We can support you 24/7/365, or business hours only, or anything between. Our basic support starts at £750 per month.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Affinity's support onboarding process ensures that critical objectives are identified and met, including gaining a full technical and operational understanding of the service, identifying and mitigating risks, and obtaining necessary system access.

A core objective of onboarding is to supply, to the service owner and their team, all necessary information and access to enable incidents to be reported and support requests to be raised effectively and efficiently. This is achieved by setting up the Jira service desk, granting access to all relevant users, and providing necessary guidance on how to raise and classify support requests. This ensures users are comfortable with the process before support begins.

A critical part of the process is establishing clear communication for incident management, aligned with the client’s organisational needs and priorities. Affinity focuses on establishing necessary workflows. To help users start using the service, we are also experienced in providing training to support teams through this process.

We also work with the client to develop any run-books, routines or supporting documentation which is required internally to enable effective provision of the support and maintenance service.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data is exported via encrypted SQL database dump, media files via secure SFTP, and content via JSON/XML. All transfers are conducted in accordance with ISO 27001:2022 procedures and Cyber Essentials Plus requirements. Full extraction support is provided within 30 days of contract end at no additional cost.
End-of-contract process
Upon contract termination, a formal 30-day transition period begins following written notification. All offboarding activities are conducted in accordance with our ISO 27001:2022 certified procedures and Cyber Essentials Plus requirements. During this period, we provide complete data extraction including full database exports in standard SQL format, media files via secure encrypted SFTP transfer, and content exports in JSON or XML formats. The complete GitHub repository, including full commit history and documentation, is transferred to the buyer's nominated organisation or incoming supplier. Knowledge transfer sessions are provided to support continuity, along with comprehensive documentation covering system architecture, configurations, and operational procedures. All credentials and access permissions are securely transferred or revoked as appropriate, with a full audit trail provided. Upon completion, all buyer data is securely deleted from our infrastructure with certified destruction confirmation provided in writing. Included in our price: standard data exports, secure file transfers, GitHub repository transfer, up to 30 days of transition support, knowledge transfer sessions, documentation package, and certified data destruction. Additional costs: extended transition support beyond 30 days, bespoke data migration to alternative platforms, custom export formats or transformation scripts, additional training for incoming technical teams, and parallel running of services during extended handover periods.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is fully responsive across all devices. Front-end websites and applications are mobile-first, touch-optimised and WCAG 2.2 compliant. Administrative interfaces provide full content editing and publishing functionality on mobile and tablet. Some complex administrative tasks (bulk operations, advanced configuration, detailed reporting) are optimised for larger screens for usability, though remain accessible on mobile. No functionality is restricted by device - differences relate to interface optimisation for screen size and input method.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Web-based interfaces accessed via standard browsers. The service provides: Administration dashboard - secure login with role-based access for content management, user administration, media handling, configuration and reporting. Public website/application - front-end interface delivered to end users, responsive across all devices and browsers. RESTful APIs - for integration with third-party systems, CRMs, ERPs and external data sources. All interfaces support HTTPS, modern browser versions and assistive technologies.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Interfaces are tested against WCAG 2.2 AA using automated tools (Axe, WAVE, Lighthouse, Pa11y) and manual testing with assistive technologies including JAWS, NVDA, VoiceOver and TalkBack screen readers, keyboard-only navigation, and screen magnification. Drupal's admin interface follows accessibility best practices with core accessibility features. Custom themes undergo accessibility review before deployment. User testing with assistive technology users is conducted during UAT, according to test plans specified based on digital service and project context. Issues are prioritised and remediated based on WCAG impact level.
API
Yes
What users can and can't do using the API
What users can do: Retrieve content, media, users and taxonomy via JSON:API. Create, update and delete content programmatically with appropriate permissions. Build decoupled front-ends using JSON:API or GraphQL. Integrate content with third-party applications, mobile apps and external systems. Custom REST resources can be developed for specific requirements. What users cannot do: Site configuration and module management is handled through the admin interface, not API. Theme changes require admin interface or deployment. Limitations: Write operations require appropriate permissions. Complex entity relationships may require custom serializers. Rate limiting and authentication configured per implementation based on client requirements.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
What can be customised: Content types, fields and data structures. Editorial workflows and approval processes. User roles, permissions and access controls. Admin interface via contributed modules. Front-end themes and templates. Views, blocks and Layout Builder components. Integrations via contributed modules or custom code. How users can customise: Admin interface: site settings, content structure, user permissions, workflow configuration and branding - no coding required. Developer customisation: PHP code for custom modules, themes, API extensions and bespoke functionality. Configuration management: version-controlled settings deployed through CI/CD pipelines. Who can customise: Editors: content and media within defined structures. Administrators: site settings, users, workflows and permissions via admin interface. Developers: modules, templates, custom functionality and integrations via codebase. Super administrators: full platform configuration and access management. Role-based permissions ensure users only access customisation appropriate to their level.

Scaling

Independence of resources
Each client environment is provisioned on dedicated, isolated infrastructure within AWS, ensuring complete separation of compute, database, and storage resources. There are no shared resources between client environments. Auto-scaling policies automatically adjust capacity to meet demand, without impacting other clients.
Resource allocation includes guaranteed CPU, memory, and database connections per environment. Infrastructure monitoring alerts on capacity thresholds before performance impact occurs. Load balancing distributes traffic efficiently across resources. All separation controls are aligned with ISO 27001:2022 requirements and AWS Well-Architected Framework principles.

Analytics

Service usage metrics
Yes
Metrics types
Service metrics include: uptime and availability monitoring, response time and performance statistics, storage utilisation, bandwidth consumption, user login activity and session counts, content publishing activity, API request volumes, and error rates.

Security metrics cover failed login attempts, access logs, and vulnerability scan results. Infrastructure metrics include CPU, memory, and database performance.

Monthly service reports are provided, detailing availability against SLA targets, incident response and resolution times against SLAs, incident summaries, and capacity trends.

All metrics are retained in accordance with ISO 27001:2022 requirements and are available for audit purposes.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export data via Drupal's JSON:API, direct database exports in SQL format, and content exports in JSON, XML, or CSV formats. Media assets are available via secure SFTP transfer. Full GitHub repository access is available for code and configuration. All exports can be performed on request or via scheduled automated delivery. Export support is provided in accordance with ISO 27001:2022 procedures.
Data export formats
  • CSV
  • Other
Other data export formats
  • API
  • JSON
  • XML
  • SQL database export
  • Other export formats by request
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON (Drupal migration format)
  • XML
  • Media files (JPEG, PNG, PDF, etc.)

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Availability SLAs are tailored to client requirements, typically ranging from 99.5% to 99.99%.
Availability is monitored via automated systems. Availability is measured, excluding scheduled maintenance, and reported monthly against SLA targets. We work with clients to define appropriate targets based on service criticality and budget.
Service credit structures are per contract, proportionate to the availability shortfall. Credits are applied to the following month's invoice upon a validated request.
Scheduled maintenance is performed during agreed low-traffic periods with notice as defined in the service agreement.
Enhanced SLAs are available, with dedicated resources allocated for mission-critical services.
Standard exclusions apply: scheduled maintenance, force majeure, third-party failures outside of Affinity's control, and buyer-caused issues.
Approach to resilience
Services are hosted on AWS infrastructure across UK data centres (eu-west-2, London region) providing high availability and resilience.
Infrastructure resilience includes: deployment across multiple Availability Zones for failover capability, automated load balancing distributing traffic across healthy instances, auto-scaling responding to demand and instance failures, and redundant network connectivity.
Data resilience includes automated daily backups with configurable retention periods, point-in-time database recovery capability, cross-zone database replication, and encrypted backup storage in geographically separate locations within the UK.
Application resilience includes containerised deployments enabling rapid recovery, infrastructure-as-code (IaC) enabling full environment rebuild, automated health monitoring with self-healing capabilities, and blue-green deployment strategies eliminating downtime during updates.
Monitoring and response includes: 24/7/365 automated infrastructure monitoring, alerting on performance degradation or failures, documented incident response procedures aligned with ISO 27001:2022, and defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) per service tier.
AWS data centres maintain SOC 2, ISO 27001, and CSA CCM certifications with physical security, fire suppression, and redundant power systems. Detailed resilience architecture documentation is available on request.
Outage reporting
Outages are reported through multiple channels to ensure timely client notification.
Jira service desk: An incident ticket is raised upon incident detection, with notification flows to ensure that all involved parties are kept informed and can collaborate if/where needed. This Jira service desk is available 24/7/365.
Email alerts: Automated notifications are sent immediately upon incident detection to designated client contacts, with timely updates throughout resolution, and ending in a post-incident summary.
Status page: A dedicated service status page provides real-time availability information and scheduled maintenance notifications.
Direct communication: A named account contact is available via phone and email during business hours, with out-of-hours escalation for priority 1 issues.
Incident reports: A full root cause analysis and remediation report is provided within five working days of major incidents, aligned with ISO 27001:2022 incident management procedures.
Monitoring: 24/7/365 automated infrastructure monitoring detects issues proactively, often leading to resolution before there is any client or user impact.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Management interfaces: Access is restricted to authorised personnel via role-based access controls (RBAC). Administrative access requires MFA and is limited to named individuals. Privileged actions logged with full audit trail. Access reviews conducted quarterly and upon staff changes. All administrator accounts are disabled immediately upon departure.
Support channels: Client identity is verified before discussing account-specific information via pre-agreed security questions or callback to registered contacts. Support requests logged with unique reference numbers. Sensitive information shared only via encrypted channels.
AWS console access restricted to senior technical staff with MFA enforced. All access aligned with ISO 27001:2022 controls and least-privilege principles.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Affinity maintains ISO 27001:2022 and ISO 9001 certified management systems, along with Cyber Essentials Plus accreditation, each being independently audited annually.
Our Information Security Management System (ISMS) includes comprehensive policies covering access control, data classification, incident management, business continuity, supplier security, and acceptable use. All policies are reviewed annually or following significant changes.
Reporting structure: The Technical Director holds responsibility for information security, reporting directly to senior leadership. Security incidents are escalated immediately through defined channels with root cause analysis and remediation tracking.
Policy compliance: This is ensured through mandatory staff security training on induction and periodically thereafter, regular internal audits against ISO 27001 controls, automated security scanning and monitoring, documented access reviews and leaver processes, and supplier security assessments.
All staff undergo security awareness training covering phishing, data handling, and incident reporting. Training completion is tracked and evidenced for audit purposes.
Continuous improvement is driven through regular management reviews, incident analysis, and a rolling programme of internal audits. Any findings are addressed through documented opportunities for improvement or corrective actions, in line with our ISO 9001 quality management processes and procedures.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Configuration and change management processes are aligned with ISO 27001:2022 Annex A controls and ISO 9001 quality management requirements. All changes follow documented procedures including: impact assessment, approval workflows, testing in staging environments before production deployment, rollback procedures for failed changes, and an audit trail of all configuration changes.
Infrastructure changes are managed through version-controlled Infrastructure-as-Code (Terraform) with peer review requirements. Application changes follow Git-based workflows with pull request reviews, automated testing, and controlled deployment pipelines.
AWS infrastructure compliance with CSA CCM v4.0 and SOC 2 provides additional assurance for underlying platform changes. Change records are retained for audit purposes.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Vulnerability management is aligned with ISO 27001:2022 and Cyber Essentials Plus requirements. Processes include: automated vulnerability scanning using Trivy, OWASP ZAP, and GitGuardian integrated into CI/CD pipelines, regular infrastructure scanning against CVE databases, dependency monitoring for third-party components, and regular penetration testing.
Remediation follows risk-based prioritisation: critical vulnerabilities are addressed within 24 hours, high within 7 days, medium within 30 days. Patching schedules are maintained for operating systems, platforms, and applications.
AWS infrastructure vulnerability management complies with CSA CCM v4.0 and SOC 2. All vulnerability assessments and remediation activities are documented and retained for audit purposes.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Identification: Continuous monitoring via AWS CloudWatch, GuardDuty, and Security Hub detects anomalous activity and unauthorised access attempts. Application logging captures authentication events and privileged actions. GitGuardian monitors for exposed secrets.
Response: Documented incident response procedures align with ISO 27001:2022. Incidents are triaged, contained, investigated, and remediated with clients notified promptly.
Response times: Critical incidents are responded to within 1 hour, client notified within 4 hours. High severity are within 4 hours. Medium severity are within 24 hours.
Post-incident root cause analysis provided within 5 working days for major incidents. All incidents logged per ISO 27001:2022 and Cyber Essentials Plus requirements.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Pre-defined processes: Documented runbooks for common incidents including service outages, security events, data breaches, and performance degradation. Procedures aligned with ISO 27001:2022 and categorised by severity with defined escalation paths and resolution timeframes.
Reporting incidents: Users report via dedicated support email, telephone, or support portal. All incidents logged immediately with unique reference number provided. Priority 1 incidents have direct escalation route to Technical Director.
Incident reports: Initial acknowledgement within 1 hour for critical issues. Status updates are provided throughout resolution. A full incident report delivered within 5 working days of resolution includes root cause analysis, remediation actions, and preventive measures.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
7.5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
12.5%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Thursday 4 September 2025
What the ISO/IEC 27001 doesn’t cover
None of our services or operations are excluded from our ISO/IEC 27001 certification.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau
ISO 9001 accreditation date
Thursday 4 September 2025
What the ISO 9001 doesn’t cover
None of our services or operations are excluded from our ISO 9001 certification.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
4d46a4c8-51d4-4fe0-8530-fe46abb009b0
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
99104770-28c1-4ee6-88c6-b937747954d3
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@affinity-digital.com. Tell them what format you need. It will help if you say what assistive technology you use.