Skip to main content

Help us improve the Digital Marketplace - send your feedback

SHED COLLECTIVE LTD

Primary Care Platform

The Primary Care Platform is a secure, award-winning SaaS platform built with clinician input to support primary care networks and ICBs. It enables the rapid deployment of accessible, compliant and cost-effective digital services, with integrated tools for collaboration, pathway management, CPD tracking, resource sharing and quality assurance across primary care.

Features

  • Intuitive topic-based navigation for rapid access to clinical information
  • Powerful ElasticSearch engine with fuzzy logic and weighted keywords
  • CPD tracking system, integrated with Clarity and Fourteen Fish
  • Admin tools enabling content governance, service reviews, and bulletin publishing.
  • Quality alerting system for clinical updates and safety notices.
  • Bookmarking and favourites system to save and organise key resources.
  • Content modules supporting topics, services, news, events, and more.
  • Fully responsive, accessible interface optimised for clinicians and mobile devices.
  • Personalised User dashboards showing only relevant content.
  • Secure UK hosting with encryption, backups, and data protection compliance

Benefits

  • Enables clinicians to locate clinical pathways faster during patient consultations
  • Reduces time spent searching by delivering precise, intelligent search results
  • Simplifies professional development through CPD tracking and reporting.
  • Streamlines governance processes, ensuring content accuracy and administrative efficiency.
  • Improves productivity through immediate access to key clinical resources.
  • Enhances communication by facilitating local updates and information sharing.
  • Fully responsive, accessible interface optimised for the use of clinicians.
  • Increases focus by presenting only relevant content to each user.
  • Ensures compliance and data protection through secure, encrypted UK hosting.
  • Provides instant alerts, keeping clinicians informed of safety-critical updates.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@shedcollective.org. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 7 3 9 8 3 0 6 2 0 3 8 7 2 5

Contact

SHED COLLECTIVE LTD Gary Duncan
Telephone: 02077296043
Email: hello@shedcollective.org

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
None
System requirements
Requires an internet connection and a modern web browser

User support

Email or online ticketing support
Yes
Support response times
Yes. We provide email and online ticketing support during office hours (Monday to Friday, 9am–5pm, excluding public holidays). Support requests are logged, prioritised, and responded to within one working day, with urgent issues addressed the same day where possible. Critical faults affecting website access or key clinical functions are treated as Severity 1 and resolved as a priority. Non-critical issues are handled through the daily support retainer or scheduled within development time. Outside office hours, incidents are acknowledged on the next business day. Regular monitoring ensures prompt identification and resolution of issues to maintain service continuity.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
We provide tiered support through defined service levels, ensuring reliable and timely assistance. Support is available during office hours (Monday to Friday, 9am–5pm, excluding public holidays) via email and ticketing.

All support requests are prioritised according to severity:

Severity Level 1 – Critical issues: Major system failures or loss of key clinical functionality. Acknowledged immediately with a follow-up within four hours; resolution within eight hours during office hours.

Severity Level 2 – High priority issues: Non-critical but impactful faults; response within four hours and resolution within two business days.

Severity Level 3 – Minor issues: Cosmetic or low-impact faults; response within four hours and resolution within the next scheduled maintenance cycle.

Support is included within the standard contract through the Support Retainer, which reserves dedicated time each business day for monitoring, maintenance, and high-priority requests. Additional support or development time beyond the retainer is charged at the standard day rate.

A dedicated account manager oversees the relationship, ensuring consistent communication, progress tracking, and escalation when required. Technical support is delivered directly by our development and operations team, ensuring issues are resolved efficiently and in line with agreed service levels.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide comprehensive onboarding and training to ensure a smooth and confident transition onto the platform, delivered on-site or online. Our team works closely with each client to configure the system, customise it to local requirements, and migrate existing data securely and efficiently. We guide administrators through every stage of setup, including content structure, publishing workflows, and governance tools.
Dedicated admin training covers all aspects of content management, quality assurance, and ongoing maintenance, supported by clear documentation and reference materials. End users also receive a training document introducing the platform’s key features and customisation options, which administrators can distribute during onboarding.
Training sessions are delivered live, recorded, or in-person, and are tailored to each organisation’s configuration and operational needs. Our approach prioritises practical, hands-on learning to build confidence, ensure consistency, and enable each client to manage and maintain the platform effectively from day one.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
At the end of the contract, all client data can be securely exported in a structured, commonly used format such as CSV, XML, or JSON. Administrators can request a full data export through our support team, who ensure all information— including content, user records, and configuration data—is transferred safely and efficiently. We provide guidance throughout the extraction process to ensure continuity and compatibility with other systems. Once data has been successfully transferred, we confirm deletion from our servers in line with GDPR and data retention policies. No proprietary tools are required for data access or migration.
End-of-contract process
At the end of the contract, our team works closely with the client to ensure an orderly and transparent handover. We provide advance notice of contract expiry and support the client in planning data extraction and transition activities. Administrators are contacted to confirm preferred next steps, including data export formats, timescales, and access requirements. All users are notified of upcoming contract closure and advised of any changes to access or support.
Client data can be securely exported in standard formats such as CSV, XML, or JSON. Our support team assists with this process to ensure completeness, security, and compliance with GDPR. Once confirmation of successful extraction is received, all data is permanently deleted from our servers in line with our data retention policy.
Optional offboarding support - such as extended access, data migration assistance, or post-contract consultancy can be provided at additional cost if required.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is fully responsive and optimised for mobile use.
All features are accessible on mobile devices, though layouts may adjust for smaller screens.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Primary Care Platform is a secure, cloud-hosted application with two interfaces.

The Clinician Interface is fully responsive and optimised for desktop and mobile use, providing topic-based clinical content, powerful ElasticSearch, personalised dashboards, bookmarking, CPD tracking, and quality alerts.

The Admin interface is a secure portal protected by two-factor authentication (2FA). Administrators can manage all aspects of site content, including creating and reviewing content, publishing updates, managing content governance workflows, and sending bulletin emails. The admin system also provides oversight of user activity, local customisations, and content quality assurance.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
While formal testing with users of assistive technology has not yet been completed, accessibility has been considered throughout design and development. The interface follows WCAG 2.1 AA principles and has been reviewed internally using assistive technologies such as screen readers and keyboard navigation to ensure usability and compliance.
API
No
Customisation available
Yes
Description of customisation
The service offers flexible customisation options at both organisational and individual user levels. At the buyer level, the platform can be configured to align with each organisation’s branding, structure, and operational needs. Buyers can request adjustments to visual design elements such as logos, colour palettes, and imagery, as well as editorial layouts, topic structures, and functional modules. These changes are implemented in collaboration with our expert team, ensuring the platform reflects the organisation’s identity and supports its workflows and governance processes.

At the user level, individuals can personalise their own experience directly within the interface. Users are able to specify their role, locality, and areas of interest, enabling dashboards and content feeds to display only information relevant to their clinical area or responsibilities. This approach ensures that every user accesses a streamlined, efficient view of the most pertinent content, improving both usability and speed of access. Together, these two layers of configuration make the platform adaptable to diverse healthcare settings while maintaining consistency and ease of use across all devices.

Scaling

Independence of resources
Each client is provided with their own independently hosted instance on scalable cloud servers, ensuring performance and resources remain fully isolated. This separation guarantees that demand from one organisation cannot affect another. The infrastructure automatically scales to meet usage needs, maintaining consistent performance even during peak periods.

Load balancing and auto-scaling mechanisms ensure traffic is distributed efficiently, while continuous monitoring allows additional capacity to be provisioned dynamically if required. Data and configurations are securely separated at both application and database levels, ensuring operational independence and data integrity across all clients. This approach delivers a stable, reliable experience for every user.

Analytics

Service usage metrics
Yes
Metrics types
Customers will have access to service usage metrics covering traffic levels, user behaviour, content engagement, form activity and key performance indicators. A real-time analytics dashboard presents both high-level summaries and detailed insights. Customers can also request periodic or ad-hoc reports to monitor adoption, performance trends and overall service health.
Reporting types
Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Customers can export their data through a predefined set of on-demand data exports. Custom reports can also be produced and delivered on request. In addition, monthly disaster-recovery backups are generated and supplied to the customer's designated data storage location.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Our target service availability is 99.9% during office hours (Monday to Friday, 9am–5pm, excluding public holidays). Continuous monitoring and daily backups support uptime and enable rapid recovery in the event of disruption.

Availability and response commitments are defined within our Service Level Agreement (SLA). Faults are prioritised according to severity:
• Severity 1 (critical faults): resolution within 8 business hours
• Severity 2 (high-priority faults): resolution within 2 business days
• Severity 3 (minor faults): resolution within the next scheduled maintenance cycle

If guaranteed service levels are not met, service credits are applied based on the value of development time lost due to downtime.

The SLA excludes interruptions caused by third-party services outside our direct control, including (but not limited to) internet service providers, domain registrars, DNS providers, Cloudflare or equivalent edge-network services, upstream hosting infrastructure, and general internet outages. Such events are classified as force-majeure and are not subject to service credits.

Optional enhanced SLA packages are available, which provide faster response and resolution targets (for example, halving standard resolution times for Severity 1 and Severity 2 incidents).
Approach to resilience
The service is hosted on resilient cloud infrastructure using Google Cloud Platform (GCP), with backups stored securely on Amazon Web Services (AWS). Both providers operate multiple geographically separate data centres with built-in redundancy, ensuring high availability and minimal risk of data loss. The system architecture is designed for continuity, with automatic failover, load balancing, and hourly database backups to maintain consistent performance.

Backups are retained for 90 days and securely deleted in line with AWS data retention and sanitisation policies. Infrastructure health is continuously monitored, and any outages are addressed promptly in accordance with defined Service Level Agreements (SLAs).

Both GCP and AWS comply with recognised international standards, including ISO/IEC 27001 and SOC 2, providing robust physical, network, and operational resilience. Further details on the underlying datacentre resilience and architecture are available on request.
Outage reporting
Service availability is continuously monitored using automated tools such as Uptime Robot and Rollbar. These systems detect outages or performance issues in real time and automatically notify the technical team by email. Critical alerts are investigated immediately to ensure prompt resolution in line with our Service Level Agreements (SLAs). Outages are reported directly to the Customer’s designated contacts via email, including incident details and recovery updates. A full written report is provided following any significant incident. There is currently no public dashboard or API for outage reporting, but this information can be shared with authorised stakeholders on request.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Limited access network (for example PSN)
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted to authorised users with enforced two-factor authentication. Certain functions are additionally locked behind IP restrictions and are only available from approved networks, including NHS network traffic. Role-based permissions ensure users only access functions relevant to their role. Support requests require identity verification, and no configuration changes are made without confirmation from authorised contacts. These controls prevent unauthorised access to both management interfaces and support channels.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Limited access network (for example PSN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Our organisation applies a structured, risk-based approach to security governance, aligned with the UK Government’s Software Security Code of Practice and ISO/IEC 27001 principles. Security oversight is managed by senior leadership, with clear reporting lines to the Managing Director and project leads. Defined policies cover access control, data protection, incident response, and change management. Compliance is maintained through regular internal reviews, audits, and management reporting. Staff receive ongoing training on information security and data handling best practice, and adherence to policies is monitored through documented procedures and managerial oversight.
Information security policies and processes
Our organisation applies a structured, risk-based approach to security governance, aligned with the UK Government’s Software Security Code of Practice and ISO/IEC 27001 principles. Security is embedded across all development and operational processes, supported by defined policies for access control, data protection, incident response, and change management. Staff receive regular training on information security and data handling best practice, with responsibilities clearly assigned. Regular internal reviews ensure compliance with GDPR and other relevant standards. While not formally certified, our governance framework closely follows recognised international standards and meets public sector security expectations.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Our organisation follows a structured configuration and change management process to maintain service stability and security. All components are tracked through version control and documented change logs from development to deployment. Change requests are reviewed, tested, and approved before release, with each assessed for potential security, operational, and data protection impact. Security-related updates receive additional review from senior technical staff. Access to configuration and deployment systems is restricted to authorised personnel, and all actions are logged for traceability. Staged releases and rollback procedures minimise risk, ensuring changes are implemented safely and consistently across environments.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We maintain a proactive vulnerability management process to identify, assess, and mitigate threats. Potential risks are evaluated by severity and impact, with critical vulnerabilities prioritised for immediate action. Security patches are typically deployed within 24–72 hours, following testing to ensure stability. We monitor trusted sources such as the UK National Cyber Security Centre (NCSC), vendor advisories, and CVE databases to stay informed of emerging threats. This approach ensures timely remediation, minimises exposure, and maintains the security and reliability of our services.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use continuous monitoring to detect potential compromises or unusual activity within our systems. Logs from servers, applications, and network components are collected and reviewed to identify anomalies, failed login attempts, or suspicious behaviour. When a potential compromise is detected, it is immediately investigated by authorised technical staff, with containment actions taken to protect data and maintain service availability. Confirmed incidents are escalated according to severity and managed under our incident response procedure. High-risk incidents are addressed within hours, with full reporting and remediation completed as quickly as possible to minimise impact.
Incident management type
Supplier-defined controls
Incident management approach
We operate a defined incident management process to identify, report, and resolve security or service incidents promptly. Pre-defined procedures exist for common events such as system outages, unauthorised access attempts, or data integrity issues. Users can report incidents directly by email to the dedicated support address, where all submissions are logged and prioritised. Incidents are assessed by the technical lead, escalated as required, and managed in accordance with severity. Critical incidents receive immediate attention and post-incident reviews are completed to identify root causes, implement corrective actions, and prevent recurrence, ensuring continual improvement of service reliability and security.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@shedcollective.org. Tell them what format you need. It will help if you say what assistive technology you use.