Skip to main content

Help us improve the Digital Marketplace - send your feedback

Symplicity Corporation

Symplicity Advocate Conduct

Advocate is a student conduct, complaints & appeals case management solution. Institutions process incidents and cases from the initial report until case closure. Case types range from harassment, sexual misconduct and discrimination to academic integrity or extenuating circumstances. In-built access & permissions ensure confidentiality throughout.

Features

  • Available anywhere, anytime
  • Anyone on campus can report an incident 24/7
  • Full end-to-end case management with assigned actions
  • Immediate support for those who suffered serious misconduct
  • Take immediate action against the responding party with precautionary measures
  • Interview planning and notes
  • Case worker guided through configurable workflow stages
  • Sanctions/outcomes for students found responsible of breaching conduct code
  • Handle behavioural misconduct, academic misconduct, campus security, and registry processes
  • Immediate export of entire case history for analysis

Benefits

  • Drive trust in the university, and improve safety on campus
  • Stay compliant with university policy avoiding legal disputes/negative press
  • Increased collaboration between students, university departments, 3rd parties
  • Rapid cloud deployment
  • Fully scalable to meet changing needs
  • Ensure data security and segregation whilst being GDPR compliant
  • Leverage our experience and learnings from 100s of global deployments
  • User reporting for real-time analytics / data trends

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jfleming@symplicity.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 6 7 2 5 3 2 7 7 3 2 0 2 1 1

Contact

Symplicity Corporation James Fleming
Telephone: 07917 842008
Email: jfleming@symplicity.com

About your service

Service categories

Applications

Content workflow and management

  • Capture
  • Document

Content services

  • Enterprise Content Management Applications
  • Content Sharing and Collaboration Applications

Persuasive content management

  • Website Software
  • Digital Adoption Platform

Enterprise portals and digital workspaces

  • Multi-Audience Portals
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Hybrid cloud
Service constraints
Symplicity solutions are delivered as cloud-based, SaaS platforms with no on-premises deployment. Solutions require a supported web browser and internet connectivity. Planned maintenance is performed periodically, usually outside peak hours, with advance notice, though brief service interruptions may occur. Support covers the Symplicity application only and follows contracted SLAs; customer infrastructure and end-user support remain the buyer’s responsibility. Functionality is optimised for modern desktop browsers, with limited support for legacy devices. Customisation is configuration-based rather than bespoke. Integrations depend on supported APIs and third-party systems. Data hosting regions, compliance obligations, and service evolution are governed contractually.
System requirements
An internet-enabled browser from the list of supported browsers

User support

Email or online ticketing support
Yes
Support response times
Issues are broken down into two categories:
• Priority 1: These issues include but are not limited to system outages OR impacts all systems in the same way OR is affecting workflow/processes for all clients. Response time for Priority 1 issues is within 2 hours.
• Priority 2: These issues consist of non-critical software bugs/glitches that might be either global or local and that does NOT affect daily work in system or productivity to complete major tasks. Response time for Priority 2 issues is within 8 hours.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AAA
Web chat accessibility testing
Symplicity incorporates accessibility testing into the design, development, and quality assurance of its web-based features, including web chat functionality where applicable. As part of this approach, Symplicity evaluates web chat components using commonly used assistive technologies to help ensure usability for individuals with disabilities. This includes testing with screen readers such as NVDA, JAWS, and VoiceOver, as well as keyboard-only navigation to confirm that users can access, initiate, and interact with web chat features without relying on a mouse.

Testing focuses on key accessibility considerations, including logical focus order, visible focus indicators, meaningful labels and instructions, appropriate ARIA roles, and clear status or error messaging. Browser accessibility tools and automated testing solutions may also be used to identify potential issues, which are then reviewed alongside manual testing results.

Where feasible, Symplicity incorporates feedback informed by real-world assistive technology usage patterns through internal testing, customer feedback, and usability reviews. Any accessibility issues identified are documented, prioritised, and addressed within regular development and remediation cycles. Accessibility testing is ongoing and is repeated when web chat functionality is enhanced or updated, supporting continued alignment with recognised standards such as WCAG 2.1 AA.
Onsite support
Yes, at extra cost
Support levels
The Symplicity Help Centre consists of:

Dedicated Implementation Manager (IM):

An IM is assigned to the customer at the very beginning of implementation and will guide them through 4 key phases:
1. Discovery and Planning
2. Building and Learning in Production
3. Training and Testing to Go Live
4. Go Live and Beyond

Dedicated Client Manager (CM):

Once full handover from the IM is complete, the CM will be a dedicated system expert who provides oversight of your account. In conjunction with Symplicity Support, the CM works with customers to resolve issues, ensure quality of service, provide additional training support, and maintain positive relationships with internal teams.

Symplicity Support:

The Symplicity Help Centre (SHC) is web-based and accessible 24/7. Customers will find set-up guides, cheat sheets, and video tutorials that will answer many of their questions about system functionality.

Customers can initiate help-tickets through the SHC for functional issues, bugs, other problems. All issue tickets can be viewed to add updates, re-open, or resolve them.

All support is included in the cost of the annual licensing fee.
Support available to third parties
No
AI chatbot
No

Onboarding and offboarding

Getting started
During implementation there are 4 key phases, with phase 1 and 2 focussing on information gathering, strategic review, building the system, watching online training modules and reading documentation available through the Help Centre.

Phase 3 will involve several working sessions focused on driving user effectiveness and enablement towards go-live. The regular Training and Testing Sessions conducted by your Implementation Manager will build on the knowledge gained so far and will focus on university specific processes, configuration and requirements.

Regular working sessions will be scheduled based on the availability of university resources. The working sessions for Phase 3 will involve walking through the end to end workflows and business processes which have been configured specifically for the Institution. These working sessions will be conducted remotely via video link or onsite as agreed. Remote sessions offer the advantage of supporting remote staff, recording of the session, and future reference for potential new staff.

During these working sessions, Symplicity will update and refine the configuration based on feedback during these sessions.

At completion of Phase 3, customers are prepared and ready for go-live.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
The robust reporting tool allows you to query all data within the system. Staff can then extract the data from the system into Excel spreadsheet format. As a professional service, your institution may request a data extract, in the form of a .sql (MySQL DB) file, at any time during the contract.

Another alternative is to extract data using the Access APIs. Please see https://www.symplicity.com/developer/accommodate for more information.
End-of-contract process
Customers can extract their data using the in-built reporting tool. Alternatively, they can request a complete copy of their database in an SQL format, this would entail an extra charge that would be bound to scoping by the Symplicity professional services team. Clients may also request a document dump of all user-uploaded files for an extra charge as well. Once the customer has retrieved any data from the software the instance will be deleted and the data will also be deleted (unless subject to any legal requirement to maintain data, securely archived, for any period of time).
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Symplicity Solutions are web-based and mobile responsive in their design therefore can be accessed and used on mobile devices.

All standard functionality is available to use on the desktop is available on mobile devices. The interface is fully mobile responsive meaning that it will be resized to fit the device that is being used.

On smaller devices such as smart phones, the left-hand menu items will become ‘hidden’ to make room for the main area of the screen, however it can be accessed by using a button to make it appear
Service interface
Yes
User support accessibility
WCAG 2.2 AAA
Description of service interface
Symplicity solutions are delivered through a secure, web-based service interface accessible via a standard browser with no local installation required. The interface supports role-based access, ensuring users see features and data appropriate to their permissions. It provides structured navigation, dashboards, and configurable workflows to support administrative and end-user tasks. Administrators can manage forms, permissions, communications, and reporting through configuration rather than custom code. The service interface supports integrations via secure APIs and standard protocols, including SSO. It also includes audit logging and system messaging, and is developed in line with accessibility best practices.
Accessibility standards
WCAG 2.2 AAA
Accessibility testing
Symplicity incorporates accessibility testing into the design, development, and quality assurance of its web-based features, including web chat functionality where applicable. As part of this approach, Symplicity evaluates web chat components using commonly used assistive technologies to help ensure usability for individuals with disabilities. This includes testing with screen readers such as NVDA, JAWS, and VoiceOver, as well as keyboard-only navigation to confirm that users can access, initiate, and interact with web chat features without relying on a mouse.

Testing focuses on key accessibility considerations, including logical focus order, visible focus indicators, meaningful labels and instructions, appropriate ARIA roles, and clear status or error messaging. Browser accessibility tools and automated testing solutions may also be used to identify potential issues, which are then reviewed alongside manual testing results.

Where feasible, Symplicity incorporates feedback informed by real-world assistive technology usage patterns through internal testing, customer feedback, and usability reviews. Any accessibility issues identified are documented, prioritised, and addressed within regular development and remediation cycles. Accessibility testing is ongoing and is repeated when web chat functionality is enhanced or updated, supporting continued alignment with recognised standards such as WCAG 2.2 AA.
API
Yes
What users can and can't do using the API
Symplicity solutions come with a range of REST APIs as a supported integration layer designed to connect the platform to other software solutions used on campus.

The following API services are available with Symplicity:

• Student: retrieval of information on an individual student or list all students. It also allows you to create new students and update existing students.

• Course: retrieval of information on an individual emergency contact.

• Student Schedule: retrieval of information on an individual or list of courses.

• Faculty: retrieval of information of a list of faculties and faculty staff members

Trained super users will have the tools required to set up APIs without interaction from Symplicity, we provide detailed technical information at the following link: https://www.symplicity.com/developer/accommodate

Where our customers do not have the technical skills to set up the API services, we offer consultancy services to do this work on their behalf. This would be scoped with the customer and an additional cost would apply.

The only limitation is where other systems may not be open to extracting data.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Symplicity Advocate offers a modern responsive web interface with support for system-level configurations and user personalisation.

All configurations within the system are available to users with admin privileges. The configurations range from branding, enabling/disabling modules and functionality areas, setting simple and pattern-based data fields values defaults, altering process behaviour for workflow control, all the way to integration configuration and granular permissions.

Access also allows for easy addition of custom attributes and definition of custom picklists and picklist values, all from the web admin control panel.

Examples of what can be customised in Access:

• Branding with University colours and logo
• Email/Letter templates
• Internal teams’ permissions and access to data
• Form layouts
• Field layout
• Picklist items

Only users that have been given the necessary permission may customise the system as described, allowing super users to maintain control.

Scaling

Independence of resources
Symplicity utilises Amazon Web Services (AWS) for our hosting and storage needs to ensure there is adequate capability to handle our entire user base. Each of our customers are logically separated and have their own database instances, this allows them to scale their operations as required and will ensures there will be no disruption from other institutions

Analytics

Service usage metrics
Yes
Metrics types
The Reporting Engine will report on any data to include default and custom field information, which includes usage information such as logins, user actions, or any other system changes. Managers can print reports or save them as an excel spreadsheet. Reports can be regenerated multiple times and can also be scheduled to automatically run. Additionally, the solution provides an event log to track all user actions.
Reporting types
API access
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Symplicity Advocate supports data extraction is a number of ways:
Reporting - Each time a report is generated it stores a copy with users having the option to export the data to excel for further/offline analysis.
Dashboard filter results – whether searching for students or case information, the results can be exported to Excel
Case information – all information relating to a case or investigation can be exported to pdf.
REST API’s – trained users may use APIs to extract data
Data export formats
  • CSV
  • Other
Other data export formats
  • Txt
  • Pdf
  • Excel
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • Txt
  • Excel

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The hosted software is accessible 24/7, with a 99.9% target uptime. 99.9% means that for 99.9% of the time during any calendar month, service shall be available. Unavailability is a condition in which customer’s users are unable to access the application. Unavailability does not include network availability due to: i) scheduled maintenance ii) inability of client to connect due to internet or telecommunication problems outside of the control of Symplicity iii) Any third-party applications or integrations, or customisations client has requested.
Approach to resilience
Symplicity utilises AWS for our hosting and storage needs. The Symplicity Virtual Private Clouds within the AWS infrastructure is designed for resilience and follow the AWS well-architected framework recommendations.
Outage reporting
Symplicity has a public dashboard, which can be seen by visiting: https://www.symptatus.com. Additionally, in the event there were to be a serious outage, Symplicity would send email alerts to primary contacts of the account.

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
The information that is stored and managed in Access is highly sensitive, even between teams within an institution. With this in mind, Access has very granular user permissions and case access controls to ensure that information is only accessed by those who need to.

User groups can be created with specific permissions attached, with individual users being attached to a group. Permissions apply to every aspect of Access and typically allow a user to create, view, edit, delete, archive information.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
At Symplicity, protecting our customers' data is an integral part of our trust and promotion in our organisation. We have a team of dedicated security professionals, working in partnership with all Symplicity employees, that have taken extensive steps to implement best practices and identify and mitigate risks on an ongoing basis. Ethics are at the core of Symplicity's Information Security Policies and Procedures and define how we operate as a company.

Symplicity has a dedicated information security team consisting of a full-time dedicated Information Security Officer (ISO) and a Security Specialist who works with the VP of Technology, the various Directors of Engineering, Design, and Infrastructure, as well as the IT team and the General Counsel’s Office, and who are responsible for the management of information security throughout the organisation.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Proposed changes are input into an Issue Tracking System, where they are tracked through their lifetime. The Product Team prioritises and develops detailed requirements. The Technical team designs solutions and presents options and costs. Once approved, the change is inserted into the Product Roadmap.

During implementation, independent code review and QA testing is performed on every change promoted through separate development, test, production environments. Once approved, changes are made available to customers. The stages of Solution Design, Code Review, Automated and Manual Testing, and Change Control safeguard quality and security of all changes.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Symplicity utilises the Qualys Cloud Platform to perform vulnerability management, benefiting from Qualys' large, up-to-date database of vulnerabilities (CVE’s). Symplicity can perform security assessments or penetration tests against our AWS infrastructure without prior approval from AWS.
Physical Penetration Testing is not applicable because AWS handles physical security. Symplicity does not perform Social Engineering Tests as part of our penetration testing strategy.

Reported vulnerabilities will be verified and addressed as follows:
• Critical – Responded to Immediately, remediated within 15 days
• High – Within 30 days
• Medium & Accepted Low – Within 90 days
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
AWS provides Symplicity with several tools that aid us in the identification of potential compromises. Additionally, Symplicity uses the Qualys Cloud Platform for protective monitoring. Symplicity responds immediately to incidents according to the Symplicity Security Incident Response Plan.
Incident management type
Supplier-defined controls
Incident management approach
Symplicity has a Security Incident Response Plan that is used for all incidents. Users report incidents by calling the Symplicity Help Desk, calling their Client Manager, or by submitting an issue through the online Symplicity Help Centre. If applicable, Symplicity provides reports via email or public release.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
9%
Between £500,001 and £1,000,000
12%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Prescient Security LLC
ISO/IEC 27001 accreditation date
Thursday 6 November 2025
What the ISO/IEC 27001 doesn’t cover
None. This service is fully within the scope of our ISO/IEC 27001 certification.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Monday 10 December 2018
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
None. This service is fully within the scope of our CSA STAR certification.
PCI certification
Yes
Who accredited the PCI DSS certification
Qualys
PCI DSS accreditation date
Wednesday 21 January 2026
What the PCI DSS doesn’t cover
None. This service is fully within the scope of our PCI DSS certification.
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jfleming@symplicity.com. Tell them what format you need. It will help if you say what assistive technology you use.