Drupal CMS discovery, build, host, support and improve
Affinity is an experienced provider of open-source CMS's, Drupal development, support, hosting, migration for critical services and applications being one. We specialise in integration with line-of-business applications, thrive on complexity, and offer supporting services, utilising effective user-centric, GDS compliant methodologies. We are accredited with ISO27001, 9001 and Cyber Essentials Plus.
Features
- 24/7/365 cover. Cyber Essentials Plus, ISO 27001 and 9001 accreditations.
- Discovery process, helping buyers meet core principles around user needs.
- Drupal 10 development and customisation.
- Jira service desk, giving access to support technicians.
- LOB system integration, CDN integration and CMS migration services.
- WCAG 2.2 AA and Public Sector Bodies Accessibility compliance.
- AWS hosting, with auto-scaling available. Automated security updates.
- On-site or remote training with documentation.
- Provides decoupled and API-first capabilities via JSON:API.
- Drupal security hardening to give you greater levels of security.
Benefits
- Open-source with no licensing requirements and support AWS integration.
- Drupal security team provides proactive vulnerability management.
- Excellent editor experience with Layout Builder and content workflows.
- Accessibility built-in to help you meet WCAG requirements.
- Provides reassurance by continually meeting security and compliance requirements.
- Dedicated Drupal specialists available through our robust support system.
- Rapid custom development for quick deployment to reduce costs.
- Flexible SLAs to give you the expert support you need.
- Multilingual capabilities for international audiences.
- ISO27001, ISO9001 and CE+ accredited. GDPR ready, offering compliance support.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 6 4 4 0 2 9 3 6 3 4 0 4 4 5
Contact
AFFINITY DIGITAL (TECHNOLOGY) LIMITED
Jonathan Duval
Telephone: 01872 321177
Email: sales@affinity-digital.com
About your service
- Service categories
-
Applications
Content workflow and management
Persuasive content management
- Website Software
- Digital Asset Management Applications
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
-
- Modern web browser with JavaScript enabled
- Internet connection
- No additional software or licences required
User support
- Email or online ticketing support
- Yes
- Support response times
- Our QMS states we will respond within 1 working day. However we can tailor our flexible SLA's to meet your unique requirements. For example our current contracts with the Cabinet Office have a priority list that ensures P1 issues are responded to within 30 minutes.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
The success of any support agreement is built around regular, timely, clear communication. Affinity prides itself on its open, honest and transparent ways of working.
Frequent dialogue, backed up with documentation, and Jira with its tailorable workflows and notification schemes, forms the backbone of our robust, well proven support process.
We tailor our support to your needs, providing technical account managers and cloud support engineers. We can support you 24/7/365, or business hours only, or anything between. Our basic support starts at £750 per month. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Affinity's support onboarding process ensures that critical objectives are identified and met, including gaining a full technical and operational understanding of the service, identifying and mitigating risks, and obtaining necessary system access.
A core objective of onboarding is to supply, to the service owner and their team, all necessary information and access to enable incidents to be reported and support requests to be raised effectively and efficiently. This is achieved by setting up the Jira service desk, granting access to all relevant users, and providing necessary guidance on how to raise and classify support requests. This ensures users are comfortable with the process before support begins.
A critical part of the process is establishing clear communication for incident management, aligned with the client’s organisational needs and priorities. Affinity focuses on establishing necessary workflows. To help users start using the service, we are also experienced in providing training to support teams through this process.
We also work with the client to develop any run-books, routines or supporting documentation which is required internally to enable effective provision of the support and maintenance service. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Data is exported via encrypted SQL database dump, media files via secure SFTP, and content via JSON/XML. All transfers are conducted in accordance with ISO 27001:2022 procedures and Cyber Essentials Plus requirements. Full extraction support is provided within 30 days of contract end at no additional cost.
- End-of-contract process
- Upon contract termination, a formal 30-day transition period begins following written notification. All offboarding activities are conducted in accordance with our ISO 27001:2022 certified procedures and Cyber Essentials Plus requirements. During this period, we provide complete data extraction including full database exports in standard SQL format, media files via secure encrypted SFTP transfer, and content exports in JSON or XML formats. The complete GitHub repository, including full commit history and documentation, is transferred to the buyer's nominated organisation or incoming supplier. Knowledge transfer sessions are provided to support continuity, along with comprehensive documentation covering system architecture, configurations, and operational procedures. All credentials and access permissions are securely transferred or revoked as appropriate, with a full audit trail provided. Upon completion, all buyer data is securely deleted from our infrastructure with certified destruction confirmation provided in writing. Included in our price: standard data exports, secure file transfers, GitHub repository transfer, up to 30 days of transition support, knowledge transfer sessions, documentation package, and certified data destruction. Additional costs: extended transition support beyond 30 days, bespoke data migration to alternative platforms, custom export formats or transformation scripts, additional training for incoming technical teams, and parallel running of services during extended handover periods.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is fully responsive across all devices. Front-end websites and applications are mobile-first, touch-optimised and WCAG 2.2 compliant. Administrative interfaces provide full content editing and publishing functionality on mobile and tablet. Some complex administrative tasks (bulk operations, advanced configuration, detailed reporting) are optimised for larger screens for usability, though remain accessible on mobile. No functionality is restricted by device - differences relate to interface optimisation for screen size and input method.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Web-based interfaces accessed via standard browsers. The service provides: Administration dashboard - secure login with role-based access for content management, user administration, media handling, configuration and reporting. Public website/application - front-end interface delivered to end users, responsive across all devices and browsers. RESTful APIs - for integration with third-party systems, CRMs, ERPs and external data sources. All interfaces support HTTPS, modern browser versions and assistive technologies.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Interfaces are tested against WCAG 2.2 AA using automated tools (Axe, WAVE, Lighthouse, Pa11y) and manual testing with assistive technologies including JAWS, NVDA, VoiceOver and TalkBack screen readers, keyboard-only navigation, and screen magnification. Drupal's admin interface follows accessibility best practices with core accessibility features. Custom themes undergo accessibility review before deployment. User testing with assistive technology users is conducted during UAT, according to test plans specified based on digital service and project context. Issues are prioritised and remediated based on WCAG impact level.
- API
- Yes
- What users can and can't do using the API
- What users can do: Retrieve content, media, users and taxonomy via JSON:API. Create, update and delete content programmatically with appropriate permissions. Build decoupled front-ends using JSON:API or GraphQL. Integrate content with third-party applications, mobile apps and external systems. Custom REST resources can be developed for specific requirements. What users cannot do: Site configuration and module management is handled through the admin interface, not API. Theme changes require admin interface or deployment. Limitations: Write operations require appropriate permissions. Complex entity relationships may require custom serializers. Rate limiting and authentication configured per implementation based on client requirements.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- What can be customised: Content types, fields and data structures. Editorial workflows and approval processes. User roles, permissions and access controls. Admin interface via contributed modules. Front-end themes and templates. Views, blocks and Layout Builder components. Integrations via contributed modules or custom code. How users can customise: Admin interface: site settings, content structure, user permissions, workflow configuration and branding - no coding required. Developer customisation: PHP code for custom modules, themes, API extensions and bespoke functionality. Configuration management: version-controlled settings deployed through CI/CD pipelines. Who can customise: Editors: content and media within defined structures. Administrators: site settings, users, workflows and permissions via admin interface. Developers: modules, templates, custom functionality and integrations via codebase. Super administrators: full platform configuration and access management. Role-based permissions ensure users only access customisation appropriate to their level.
Scaling
- Independence of resources
-
Each client environment is provisioned on dedicated, isolated infrastructure within AWS, ensuring complete separation of compute, database, and storage resources. There are no shared resources between client environments. Auto-scaling policies automatically adjust capacity to meet demand, without impacting other clients.
Resource allocation includes guaranteed CPU, memory, and database connections per environment. Infrastructure monitoring alerts on capacity thresholds before performance impact occurs. Load balancing distributes traffic efficiently across resources. All separation controls are aligned with ISO 27001:2022 requirements and AWS Well-Architected Framework principles.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Service metrics include: uptime and availability monitoring, response time and performance statistics, storage utilisation, bandwidth consumption, user login activity and session counts, content publishing activity, API request volumes, and error rates.
Security metrics cover failed login attempts, access logs, and vulnerability scan results. Infrastructure metrics include CPU, memory, and database performance.
Monthly service reports are provided, detailing availability against SLA targets, incident response and resolution times against SLAs, incident summaries, and capacity trends.
All metrics are retained in accordance with ISO 27001:2022 requirements and are available for audit purposes. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export data via Drupal's JSON:API, direct database exports in SQL format, and content exports in JSON, XML, or CSV formats. Media assets are available via secure SFTP transfer. Full GitHub repository access is available for code and configuration. All exports can be performed on request or via scheduled automated delivery. Export support is provided in accordance with ISO 27001:2022 procedures.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- API
- JSON
- XML
- SQL database export
- Other export formats by request
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON (Drupal migration format)
- XML
- Media files (JPEG, PNG, PDF, etc.)
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Availability SLAs are tailored to client requirements, typically ranging from 99.5% to 99.99%.
Availability is monitored via automated systems. Availability is measured, excluding scheduled maintenance, and reported monthly against SLA targets. We work with clients to define appropriate targets based on service criticality and budget.
Service credit structures are per contract, proportionate to the availability shortfall. Credits are applied to the following month's invoice upon a validated request.
Scheduled maintenance is performed during agreed low-traffic periods with notice as defined in the service agreement.
Enhanced SLAs are available, with dedicated resources allocated for mission-critical services.
Standard exclusions apply: scheduled maintenance, force majeure, third-party failures outside of Affinity's control, and buyer-caused issues. - Approach to resilience
-
Services are hosted on AWS infrastructure across UK data centres (eu-west-2, London region) providing high availability and resilience.
Infrastructure resilience includes: deployment across multiple Availability Zones for failover capability, automated load balancing distributing traffic across healthy instances, auto-scaling responding to demand and instance failures, and redundant network connectivity.
Data resilience includes automated daily backups with configurable retention periods, point-in-time database recovery capability, cross-zone database replication, and encrypted backup storage in geographically separate locations within the UK.
Application resilience includes containerised deployments enabling rapid recovery, infrastructure-as-code (IaC) enabling full environment rebuild, automated health monitoring with self-healing capabilities, and blue-green deployment strategies eliminating downtime during updates.
Monitoring and response includes: 24/7/365 automated infrastructure monitoring, alerting on performance degradation or failures, documented incident response procedures aligned with ISO 27001:2022, and defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) per service tier.
AWS data centres maintain SOC 2, ISO 27001, and CSA CCM certifications with physical security, fire suppression, and redundant power systems. Detailed resilience architecture documentation is available on request. - Outage reporting
-
Outages are reported through multiple channels to ensure timely client notification.
Jira service desk: An incident ticket is raised upon incident detection, with notification flows to ensure that all involved parties are kept informed and can collaborate if/where needed. This Jira service desk is available 24/7/365.
Email alerts: Automated notifications are sent immediately upon incident detection to designated client contacts, with timely updates throughout resolution, and ending in a post-incident summary.
Status page: A dedicated service status page provides real-time availability information and scheduled maintenance notifications.
Direct communication: A named account contact is available via phone and email during business hours, with out-of-hours escalation for priority 1 issues.
Incident reports: A full root cause analysis and remediation report is provided within five working days of major incidents, aligned with ISO 27001:2022 incident management procedures.
Monitoring: 24/7/365 automated infrastructure monitoring detects issues proactively, often leading to resolution before there is any client or user impact.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Management interfaces: Access is restricted to authorised personnel via role-based access controls (RBAC). Administrative access requires MFA and is limited to named individuals. Privileged actions logged with full audit trail. Access reviews conducted quarterly and upon staff changes. All administrator accounts are disabled immediately upon departure.
Support channels: Client identity is verified before discussing account-specific information via pre-agreed security questions or callback to registered contacts. Support requests logged with unique reference numbers. Sensitive information shared only via encrypted channels.
AWS console access restricted to senior technical staff with MFA enforced. All access aligned with ISO 27001:2022 controls and least-privilege principles. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Affinity maintains ISO 27001:2022 and ISO 9001 certified management systems, along with Cyber Essentials Plus accreditation, each being independently audited annually.
Our Information Security Management System (ISMS) includes comprehensive policies covering access control, data classification, incident management, business continuity, supplier security, and acceptable use. All policies are reviewed annually or following significant changes.
Reporting structure: The Technical Director holds responsibility for information security, reporting directly to senior leadership. Security incidents are escalated immediately through defined channels with root cause analysis and remediation tracking.
Policy compliance: This is ensured through mandatory staff security training on induction and periodically thereafter, regular internal audits against ISO 27001 controls, automated security scanning and monitoring, documented access reviews and leaver processes, and supplier security assessments.
All staff undergo security awareness training covering phishing, data handling, and incident reporting. Training completion is tracked and evidenced for audit purposes.
Continuous improvement is driven through regular management reviews, incident analysis, and a rolling programme of internal audits. Any findings are addressed through documented opportunities for improvement or corrective actions, in line with our ISO 9001 quality management processes and procedures. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Configuration and change management processes are aligned with ISO 27001:2022 Annex A controls and ISO 9001 quality management requirements. All changes follow documented procedures including: impact assessment, approval workflows, testing in staging environments before production deployment, rollback procedures for failed changes, and an audit trail of all configuration changes.
Infrastructure changes are managed through version-controlled Infrastructure-as-Code (Terraform) with peer review requirements. Application changes follow Git-based workflows with pull request reviews, automated testing, and controlled deployment pipelines.
AWS infrastructure compliance with CSA CCM v4.0 and SOC 2 provides additional assurance for underlying platform changes. Change records are retained for audit purposes. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Vulnerability management is aligned with ISO 27001:2022 and Cyber Essentials Plus requirements. Processes include: automated vulnerability scanning using Trivy, OWASP ZAP, and GitGuardian integrated into CI/CD pipelines, regular infrastructure scanning against CVE databases, dependency monitoring for third-party components, and regular penetration testing.
Remediation follows risk-based prioritisation: critical vulnerabilities are addressed within 24 hours, high within 7 days, medium within 30 days. Patching schedules are maintained for operating systems, platforms, and applications.
AWS infrastructure vulnerability management complies with CSA CCM v4.0 and SOC 2. All vulnerability assessments and remediation activities are documented and retained for audit purposes. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Identification: Continuous monitoring via AWS CloudWatch, GuardDuty, and Security Hub detects anomalous activity and unauthorised access attempts. Application logging captures authentication events and privileged actions. GitGuardian monitors for exposed secrets.
Response: Documented incident response procedures align with ISO 27001:2022. Incidents are triaged, contained, investigated, and remediated with clients notified promptly.
Response times: Critical incidents are responded to within 1 hour, client notified within 4 hours. High severity are within 4 hours. Medium severity are within 24 hours.
Post-incident root cause analysis provided within 5 working days for major incidents. All incidents logged per ISO 27001:2022 and Cyber Essentials Plus requirements. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Pre-defined processes: Documented runbooks for common incidents including service outages, security events, data breaches, and performance degradation. Procedures aligned with ISO 27001:2022 and categorised by severity with defined escalation paths and resolution timeframes.
Reporting incidents: Users report via dedicated support email, telephone, or support portal. All incidents logged immediately with unique reference number provided. Priority 1 incidents have direct escalation route to Technical Director.
Incident reports: Initial acknowledgement within 1 hour for critical issues. Status updates are provided throughout resolution. A full incident report delivered within 5 working days of resolution includes root cause analysis, remediation actions, and preventive measures. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12.5%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Thursday 4 September 2025
- What the ISO/IEC 27001 doesn’t cover
- None of our services or operations are excluded from our ISO/IEC 27001 certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Thursday 4 September 2025
- What the ISO 9001 doesn’t cover
- None of our services or operations are excluded from our ISO 9001 certification.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 4d46a4c8-51d4-4fe0-8530-fe46abb009b0
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 99104770-28c1-4ee6-88c6-b937747954d3
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-