Compliance, Health & Safety, IT certification eLearning courses - ContentHub from Omniplex Learning
Omniplex Learning offers a range of self-paced, eLearning courses tailored for public sector organisations. Covering compliance, professional skills, business, and IT certifications, our courses ensure fast deployment of customised training. Choose from off-the-shelf training on our platform or self-hosted content libraries for greater control and integration.
Features
- Off-the-Shelf training/eLearning courses hosted by Omniplex Learning
- Off-the-Shelf training/eLearning courses self-hosted by customer
- For self-hosted content delivered by SCORM packages
- Access to 80 “GEL” courses designed for professional certification
- Access hundreds of short-form compliance and professional development eLearning courses
- Meets stringent security protocols, including data encryption, regular audits
- Adheres to data encryption protocols and compliance GDPR and ISO27001.
- Fully compatible with all standard web browsers and mobile platforms
- Full end-user support for Omniplex-hosted and self-hosted
- Categories include Compliance, CSR, Workplace Skills, Mental Wellbeing, Cyber Awareness
Benefits
- Start training immediately - We handle onboarding and management
- Certifications include ITIL, TOGAF, DevOps, PRINCE2, MSP, AgilePM, Change Management
- Centralise learning management in familiar environment to streamline user experiences
- Continually updated so keep onto of regulations
- Host content on your LMS for full reporting and control
- All courses support CPD
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 7 8 2 9 9 5 8 5 3 0 8 6 1 4
Contact
OMNIPLEX (GROUP) LIMITED
Andrei Grayson
Telephone: 08000 850550
Email: help@omniplexlearning.com
About your service
- Service categories
-
Applications
Content workflow and management
- Creative
Content services
- Content Sharing and Collaboration Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
-
- Operating Systems: Microsoft Windows 8 or higher, OSX, Linux
- Operating Systems Tablets: iOS13 or higher, Android 9.0 or higher
- Browser Settings: JavaScript enabled / Third-party cookies enabled
- Suggest a 1024x768px resolution on your desktop
- 0.5 Megabits per second - Required broadband connection speed
- Supported Desktop Browsers Microsoft Edge, Google Chrome, Safari, Firefox
- Operating Systems for Tablets and Smartphones: iOS12 / Android 8.0
User support
- Email or online ticketing support
- Yes
- Support response times
- Email or online ticketing
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Customer shall perform self-diagnosis of each incident and make a recommendation to Omniplex with regard to the severity level. Omniplex may re-categorise any incident based on additional information and shall communicate such re-categorisation to the Customer. Prior to reporting an incident, the Customer will have investigated and eliminated any internet or environment issues.
Cases are subject to established levels:
Urgent Critical: - production issue affecting all users, including system unavailability, with no workaround available.
High: Issue is persistent, affects many users and/or impacts core functionality or results in significant performance degradation with no reasonable workaround available.
Normal: Errors in functionality within the application, often accompanied by workarounds or affecting some but not all users.
Low:General inquiries on the use of the application; or cosmetic errors or incidents.
Urgent : 1 Business Hours first response. ETA- Within 5 Business Hours or within an agreed fixed time frame.
High: 1 Business Hours first response. ETA - As promptly as commercially feasible.
Normal: 2 Business Hours first response. As promptly as commercially feasible.
Low: 8 Business Hours first response. As determined by Omniplex Learning Support Team.
Outside UK business hours, organisations can raise urgent support tickets via the Docebo support portal. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Administrators are shown how to load and enrol users on to the platform (if using the hosted options).
If clients are taking the software only, they will receive the a SCORM versions for the files. - Service documentation
- No
- End-of-contract data extraction
- Users can extract their User data by creating custom reports and exporting the data in CSV, PDF or HTML formats.
- End-of-contract process
- Customer is given a set date by which they can extract their data to agreed timescales. Or they can pay for us to extract their data.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Courses can be used on mobile devices. If hosted by Omniplex Learning we utilise a Learning Management System that will adapt to device being used.
- Service interface
- No
- User support accessibility
- WCAG 2.2 A
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- If Omniplex Learning is hosting we utilise Docebo. Docebo is a SaaS-based LMS and is hosted on the Amazon AWS Public Cloud. Docebo uses a dedicated, state-of-the-art CDN. This CDN is a globally distributed network of servers that can replicate the static contents to a location (edge location) that is as close as possible to the final user’s location. This helps reduce latency and increase the speed of content navigation, as well as drastically increasing the concurrent supported users. Docebo offers both unlimited storage and unlimited bandwidth so there are no limits on scalability of the platform.
Analytics
- Service usage metrics
- Yes
- Metrics types
- If Omniplex Learning is hosting the files, admins can generate usage report on who has completed the courses.
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Access Group
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export their data either in summarised dashboards or by custom reports that show individual training metrics.
- Data export formats
-
- CSV
- ODF
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- To protect data while in transit, customer sessions to the Docebo web servers are transmitted utilizing Hypertext Transfer Protocol Secure (HTTPS) and Transport Layer Security (TLS) encryption protocols and allow for 2048-bit encryption. Docebo utilizes a trusted certificate authority to issue a TLS digital certificate to inform users that the Docebo website is secure.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- To protect data while in transit, customer sessions to the Docebo web servers are transmitted utilizing Hypertext Transfer Protocol Secure (HTTPS) and Transport Layer Security (TLS) encryption protocols and allow for 2048-bit encryption. Docebo utilizes a trusted certificate authority to issue a TLS digital certificate to inform users that the Docebo website is secure.
Availability and resilience
- Guaranteed availability
-
Unavailable/Unavailability means that all or the majority of the request for the Services are constantly timing out or failing with a server-side error code; and (b) with respect to unavailability of the configuration portal, that the portal is not available for log on for all end users. There shall be no unavailability because of (1) a failure of the customer to correctly configure the Services in accordance with the documentation and/or Omniplex’s instructions; (2) the unavailability of a specific web page; or (3) unavailability of one or more specific features while other key features remain available.
1.Docebo has established the Services such that they will be available at least 99.9% of the time, measured monthly.
2.If Docebo fails to achieve the availability percentage for two calendar months in any six month period, the customer shall be granted service credits in compensation. The value is calculated as percentage of the pro rata monthly charges paid by the Customer to Omniplex for Services under the applicable Order Form or SOW
3.Omniplex will apply Service Credits to the Customer’s account. In the event there are no further Fees owing under the Agreement, Omniplex shall issue the Customer a refund within 90 days. - Approach to resilience
-
The QA team tests new functionality and hot fix that the developers push into the codebase before they are deployed to a production environment. The standard QA review phase of the SDLC includes a suite of regression and security automated tests.
Unit testing is aimed at proving delivered code functions as designed and to verify that the application is resilient to potential issues outlined during threat modelling.
Security regression tests have combination of regression and security testing which ensures changes made to a system do not harm its security.
Manual code inspection, is performed where one member of the development team examines another developer’s code. - Outage reporting
-
“Excused Outage” means, any Unavailability that is due to:
a. Planned downtime. Planned downtimes are downtimes that are scheduled during “Maintenance Windows”.
b. Emergency downtime. With respect to emergency downtime, Omniplex shall provide the Customer with as much notice as practical under the circumstances and strives to provide seventy-two (72) hours advanced notice. In all cases, Omniplex shall provide a minimum of twenty-four (24) hours’ advanced notice of emergency downtime. Omniplex shall make commercially reasonable efforts to schedule emergency downtime in off peak hours (based on the Customer’s business hours).
c. Force Majeure. Any Unavailability caused by a Force Majeure Event.
“Non Excused Outage” means anything other than an Excused Outage.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access Management within the platform is configured by your Admins using the RBAC function within the platform. Docebo operates on the principle of least privilege.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- At Omniplex Learning an ISO 27001:2013 certification programme is in progress. As we are working toward ISO 27001, we follow the guidance outlined by these standards. The responsible person for Information Security is the Chief Financial Officer who then has in their team the Head of IT and Cyber Security. All polices and guidance are then distributed to the other Managers in the business to ensure their staff apply to the standards.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Docebo's change management policy and procedures have been established to our ISO standards. Docebo software development process is based on Agile principles coupled with continuous deployment process. The software development process encompasses new developments and changing requests. The latter can also be originated for maintenance purpose.
A systematic approach is applied to managing change and ensure that changes to customer-impacting aspects of any LMS Platform functionality are reviewed, tested and approved. Change management standards are based on established guidelines and tailored to each change request. Program change documents and security best practices are documented on Docebo's content and collaboration system." - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- A monthly report is run on Omniplex on the vulnerability of the organisation. This check is run by a 3rd party to identify any risks which are then catagorised into severity. Once identified, we have then a process in place to rectify any risks at a specific agreed level to be solved with 30-days.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use Mircosoft endpoint management that runs weekly checks for User device and application compliance. This is reported to the Executive fortnightly and the Board on a monthly basis.
- Incident management type
- Supplier-defined controls
- Incident management approach
- In the event of any GDPR issues, we have an named DPO. We have software that alerts the DPO of any potential incidents that are logged. All the incidents are then actioned and any outcomes logged and reported to Executive.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Users get a 14-day free trial of selected courses (limited to 5 courses).
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau Ltd
- ISO/IEC 27001 accreditation date
- Friday 19 September 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 53ab0fea-01f2-482b-8742-5a47c61d2476
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 3d59562c-b54e-48e3-97ba-4426723f9f21
- Other security certifications
- Yes
- Any other security certifications
- Docebo, Articulate, Vyond all hold SOC2
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Volunteering opportunities for staff
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-