Thiscovery Online Communities
Thiscovery Online Communities is a customisable cloud-based platform enabling health and social care organisations to connect stakeholders, facilitate collaboration, and generate insights during transition and change. Features include activity streams, forums, polls, structured tasks, modular project spaces, resource libraries, and GDPR-compliant communications supporting co-design, peer learning, and sustained engagement.
Features
- Discussion forums enabling threaded conversations and knowledge-sharing among members
- Polls and voting tools for gathering member opinions and consensus-building
- Modular project spaces enabling specific engagement tasks within broader community
- Resource libraries for storing and sharing documents, toolkits, and materials
- GDPR-compliant communication tools
- Customisable community design including branding, style, and Code of Conduct
- Flexible access controls enabling private, public, or invitation-only community configurations
- Scalable infrastructure enabling communities to grow from small to large
Benefits
- Enables asynchronous participation allowing members to engage at convenient times
- Builds sustained engagement through dialogue beyond one-off consultation events
- Facilitates co-design bringing together lived and learned experience perspectives
- Reduces participation barriers by eliminating geographic proximity requirements
- Captures diverse perspectives through multiple engagement methods within one platform
- Fosters peer learning and knowledge-sharing among members over time
- Creates safe spaces through customisable Codes of Conduct and moderation
- Grows communities organically enabling gradual expansion as change evolves
- Reduces consultation fatigue through ongoing engagement rather than repeated surveys
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 7 3 3 3 9 9 5 6 7 4 0 9 0 5
Contact
THISCOVERY LTD
Gaurav Shrivastava
Telephone: 07747798968
Email: partnerships@thiscovery.org
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Education
- Adult Social Care
- Other
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Survey platform hosted on Voxco Online
- Cloud deployment model
- Public cloud
- Service constraints
- Technical support provided remotely during UK business hours (Monday-Friday, 9am-5pm GMT). 24/7 support not available.
- System requirements
- Browsers such as Edge, Chrome or Safari
User support
- Email or online ticketing support
- Yes
- Support response times
- Depends on the urgency of the question but generally within 24 hours for urgent queries and up to 3-4 working days for non-urgent questions.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
- We provide a standard support for the service during the hours of 9am-5pm GMT from Monday to Friday. For any critical issues we provide support outside of hours. For each client we have a designated manager who coordinates any technical issues with our technical team.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Dedicated programme manager provide admin and user training to the buyers. As a standard we include user guides and FAQs for admin and end users of the service. Additional training and ongoing support is available to the buyers as part of the ongoing management.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At the end of the contract the clients can request a copy of the database which we provide in encrypted format with instructions on how the database can be restored with the application.
- End-of-contract process
- At the end of the contract we ensure that all services are stopped and the application and database is backed up for secure transfer to the buyer. this is included in the price. If the buyer require additional services such as setting up the service in their cloud or specific data extracts then these are priced based on the need of the buyer
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- The document is provided in HTML as well as PDF. We can provide in alternative format if there is a specific need from the buyer.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The Thiscovery platform is fully responsive and optimised for mobile devices with no functional differences from the desktop version.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through standard desktop and mobile browsers such as Edge, Firefox, Chrome and Safari
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- None so far
- API
- No
- Customisation available
- Yes
- Description of customisation
- The modules included with the service allows user to customise the interface, look and feel and security settings
Scaling
- Independence of resources
- Each instance of the service is hosted on standalone application servers and database instances, this ensures there is no dependency on other instances.
Analytics
- Service usage metrics
- Yes
- Metrics types
- As part of the service basic service metrics is available to the buyer. If buyer need advanced metrics then this can be made available through an advanced module
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
- Other
- Other data at rest protection approach
- Our service is hosted on AWS and we rely on physical access control and encryption provided by the cloud provider. We follow best practice standards and ensure all data and application is secured and encrypted to the highest standard. In addition we do not provide direct access to the application server and database and is limited to specific IP and through secure SSH
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- The users can ask for their data to be made available to them through support. The buyer can request export of the database at any time.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- .db
- XLSX
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- PNG, JPEG, JPG
- GIF
- DOC and DOCX
- ODS
- PPT and PPTX
- PPS, PPSX
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Our cloud service is hosted on AWS and our SLA is aligned with theirs. Depending on the AWS service the uptime guarantee is between 99.9 to 99.99%
- Approach to resilience
- We backup database and application servers on daily basis and can restore the services quickly as and when required
- Outage reporting
- Email alerts are set up in AWS as well as an external uptime monitoring service send us alerts if there is any outage.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- Management of the service is IP restricted and access is provided through SSH which requires .pem for each authorised user
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Other
- Description of management access authentication
- IP restriction to only limited IP addresses belonging to the admin users
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We follow best practice security posture for the cloud service which is validated through penetration testing as well as Cyber Essentials Plus audit
- Information security policies and processes
- We have security documentation for overall set up of the service and we ensure we follow the best practice guidelines for setup and management of the service
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our service is based on HumHub open source application which is version controlled and updates are regularly available through GitHub. Any custom modules are version controlled through GitHub. Before releasing any update the application is tested in development environment and then staging environment before releasing in production instance.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We have security monitoring enabled on the application and database which sends alerts as soon as a threat is identified. The firewalls proactively blocks potential attempts to unauthorised access to the service
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We have security monitoring enabled on the application and database which sends alerts as soon as a threat is identified. The firewalls proactively blocks potential attempts to unauthorised access to the service. As soon as an alert is received we assess the threat and if required make changes to our firewalls.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Users report incidents through email and/or Teams channel. We provide incident reports to the buyer as soon as we have identified the issue and keep them regularly updated until it reaches resolution
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 12%
- Between £1,000,001 and £2,500,000
- 12%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 45ff70a9-e4a1-44ec-8467-d5737b0266de
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- F6df937c-ffcb-488f-b324-92d681e71cb6
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-