Digital Compliance Monitoring Subscription
Sitemorse is a digital governance and quality-assurance platform that uses automation to audits websites, documents and digital services for accessibility, performance, code quality, links, privacy, SEO and content issues, delivering prioritised, role-based actions and integrates into CMS workflows, helping organisations improve compliance, reduce risk and maintain consistently high-quality digital experiences.
Features
- Comprehensive Assessments across Multiple Categories
- Accessibility Compliance Validation
- Code Quality Testing
- Link & Email Validation
- Performance Monitoring
- Spelling & Content Quality Checks
- Prioritisation Intelligence for Actions
- Role-based, Actionable Reporting
- Journey Monitoring / Web-Application Testing
- In-CMS Integration (inCMS™)
Benefits
- Continuous Compliance Monitoring
- Risk Reduction
- Prioritised Actionable Insights
- Role-Based Reporting
- Efficiency through Automation
- Improved Publishing Quality
- Long-Term Accountability & Audit Trail
- Cost-Effectiveness
- Benchmarking and Transparency
- Scalable & Integrated with Other Systems
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 7 8 3 2 3 2 1 5 4 0 0 3 6 4
Contact
Sitemorse
Laura Shilstone
Telephone: 020 7183 7500
Email: lshilstone@sitemorse.com
About your service
- Service categories
-
Application Development and Deployment
Software quality and life cycle
- Automated software quality
- Software change, configuration and process management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No.
- System requirements
- No system requirements - remote SaaS
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Within one working day GMT or 24 hours at weekends.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
1) Self-Service - £0
Raise tickets for technical issues
Access to monthly client only webinars
2) Managed Deployment - £4,250 / 3 mths
Deployment support & walkthrough of priorities
6 support calls/team calls on usage tailored to audiences
On-hand tech team for ad-hoc calls for any issue
Raise tickets for technical issues
Access to monthly client only webinars
3) Supported Contract - £3,500 / annum plus 15% of annual subscription
Raise tickets at leisure
On-hand tech expertise when required
Monthly private Q&A session tailored to audience
Access to monthly client only webinars - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide a support website and 3 walkthroughs tailored to users' needs: editorial, developmental and managerial.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- We do not retain any user data. If they wish to extract data at the end of their contract, we would take this on a case by case basis, depending upon the user needs.
- End-of-contract process
- We close down all user accounts, prohibit access and delete the data.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- We provide a dashboard on each individual website performance reporting which clients have in their service.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- During product development roadmap, we engage with external testers.
- API
- Yes
- What users can and can't do using the API
- This is a separate product we offer, over which we have full flexibility in order to tailor to the individual users' needs.
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Based on reporting requirements, users can customise the service to suit their needs.
Scaling
- Independence of resources
- We use cloud servers.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Within their dashboard, data can be extracted into XLS and PDF.
- Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- HTML
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
- 99.5%.
- Approach to resilience
- Available upon request.
- Outage reporting
- Email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Restrictions based on licence type.
- Access restriction testing frequency
- Never
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Standard protocols.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Everything is logged.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We pick these up straight away when alerted.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We have active monitoring.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We have processes in place.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 7%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 12%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-