Care Leavers App
A digital app to help Local Authorities support care leavers transition into independence. Publish a digital local offer, info and advice; promote events & services; publish digital surveys; publish job, training & apprenticeships opportunities and communicate through secure messaging. Up to 100 languages. Each app is co-produced with care leavers.
Features
- Publish information and advice for care leavers in multiple languages.
- Create and publish unlimited digital surveys through the app.
- Promote events, activities and services for young people.
- Secure messaging including one-to-one video messaging.
- Send push notifications to all, or groups of, app users.
- Real time feeds of regional apprenticeships from Gov.uk
- Mental Health Hub, developed in partnership with The Mix
- Budget planning tool.
- Update content on 24/7 basis through administration system.
- Integration with Digital Pathway Planning tool.
Benefits
- Publish a local offer using young-person friendly tech.
- Reduce social isolation amongst young people leaving care.
- Encourage take up of services through raising awareness of organisations.
- Meet government legislation on digital accessibility.
- Help care leavers find apprenticeship and volunteering opportunities.
- Improve transition to adulthood and support reduction in NEETs.
- Involve care leavers in service design and support feedback.
- Real time feedback on app performance and outcomes.
- Help care leavers build skills and confidence through co-production.
- Supports early intervention, help identify problems early.
Pricing
£21,600 to £30,400 a licence a year
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
6 8 4 5 5 2 1 5 1 6 0 5 3 9 2
Contact
This is Focus Ltd
Simon Newing
Telephone: 01179498008
Email: simon.newing@thisisfocus.co.uk
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
Apps are available for iOS and Android only.
Administration system requires an internet browser. - System requirements
-
- Latest internet browser to access administration system
- Apps require Android v5.1+ or iOS v11+
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- Support requests are acknowledged same day during business hours. Support is not offered at weekends.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Technical support is accessed through our account management team during business hours via email or telephone. We do not employ tiered levels of support - all contracts receive the same level of technical support and support is included as part of contract costs.
Urgent queries that are preventing systems from operating as normal or resulting in unexpected downtime, are treated as priority and are responded to immediately. Other support queries are acknowledged within two business days, often sooner.
A service level agreement is included as part of any commission.
We offer an optional additional service of monthly development hours that can be spent on small items of work and amends that cannot be completed within the administration system, without the need for individual quotes.
Support is also available for previous versions and implementations of the Care Leavers App. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Each customer will be introduced to our dedicated project manager who will lead the team through setup and implementation, starting with creation of a comprehensive project plan including roles, responsibilities and milestone dates.
A kick-off meeting and site-mapping meeting will be arranged with key stakeholders and co-production and participation sessions with young people booked in. These sessions are held remotely with our client services and design teams.
Administration system training is held remotely and early in the project so that admins can start publishing content into their app.
Further assistance is provided through a library of screencasts within the administration system: short videos that walk administrators through regular tasks. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Video
- End-of-contract data extraction
- All data can be downloaded from the administration system as CSV files. A MySQL data dump can also be provided on request. Any data that requires removal will be destroyed following our ISO27001 operational procedure.
- End-of-contract process
- A closure date will be agreed and access to the administration system will be removed from that point. Apps will be removed from the appropriate app stores but will remain on user devices until they choose to uninstall. No further content updates will be possible. No additional costs apply.
Using the service
- Web browser interface
- No
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Screens and layouts are device-optimised.
- Service interface
- Yes
- User support accessibility
- WCAG 2.1 AA or EN 301 549
- Description of service interface
- Authorised administrators can use the service interface to complete various management tasks including full content updates for all installed apps. Admins can use the service interface to send push notifications to app users, manage user access, view and process user enquiries and view and download basic reports on app usage including aggregate data. Data can be downloaded as CSV files for local examination.
- Accessibility standards
- WCAG 2.1 A
- Accessibility testing
- Checking of the service interface code has been performed against front-end validator services, tests have also been completed to ensure the service interface is operable without a mouse and can be navigated efficiently using a keyboard / tab-based navigation.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
The name, branding, design and 'look and feel' of the app is customisable on a per-project basis and forms an important part of the co-production we undertake with care leavers.
All content within the app is entirely customisable including sections and pages of information and advice, events and activities, services and organisations, job opportunities, discounts and offers available from local businesses, contact details of leaving care teams and other relevant departments, surveys and other articles and resources.
The languages used to display content within the app is customisable, from a list of over one hundred supported languages.
Customisation is discussed during project initiation meetings and forms part of app build and setup. Ongoing customisation of content is achieved through the secure administration system.
Scaling
- Independence of resources
- The administration system is hosted within a cloud-based infrastructure that can be scaled at any time to cope with demand and all instances, including databases, are segregated appropriately.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Real-time reports are available as part of the administration system and our account management team provide quarterly and annual summary reports. All reports cover the key essential app usage statistics in aggregate form and we also set individual project KPIs that are monitored pro-actively. Any specific reporting requirements can be discussed and catered for.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with SSAE-16 / ISAE 3402
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Admins are able to export all data from the administration system, downloadable as CSV files.
- Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
-
- JPG
- PNG
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- For the administration system we offer 99.5% availability. Service credits are offered should this uptime not be achieved. Availability for the apps are subject to terms and conditions provided by app store vendors.
- Approach to resilience
- The datacentre provides resilience through physical safeguards such as camera surveillance, biometric scanning, personnel screening and background checks and confidentiality agreements. Dual power paths run into the datacentre providing an uninterruptible power supply with additional contingency provided through onsite generators. The administration system is hosted within a cloud-based server infrastructure where resources can be easily scaled, or moved and restored across multiple cloud-based locations, even in the event of total site failure. Bandwidth is scalable and the server operates a load-balancer which provides secondary level of service should the primary server fail. We operate back-ups of all data on a nighty basis from three different locations, retaining data up to twelve months. Business continuity and disaster recovery form key parts of our ISO9001 operational procedures.
- Outage reporting
- Outages are reported by our account management team via email and phone and customers are communicated with throughout any outage, through to resolution.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Access to the web-based administration system is restricted and authenticated via username and password. The admin system uses TLS v1.2 to encrypt data in transit between server and browser.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus
- ISO/IEC 27001 accreditation date
- 8/9/2023
- What the ISO/IEC 27001 doesn’t cover
- All technical, security and operational aspects of this service are covered by ISO27001
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials
- Information security policies and processes
- We operate an ISO27001 certified information security management policy that applies to all technical security and operational aspects of our business. Day-to-day responsibility for the implementation of this policy lies with our Technical Director, supported by senior members of the technical team. This policy covers secure development practice, access control, data protection, business continuity and disaster recovery, staff awareness and training, password policy, remote working, use of company equipment, sub-contractors, software installation, use of personal devices, physical security, IT and security, acceptable use and information classification. Policies are reviewed annually by the senior management team who also ensure team members are aware of amendments and new content and their responsibilities to work within the scope of each policy, and this is externally audited annually as part of ISO9001 management review.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We follow secure development practice as part of ISO27001 operational procedures. Development work is version controlled using Github, peer reviewed by senior members of the technical team prior to deployment and subject to automated testing which prevents faulty code from entering the live environment. New versions of software and systems are subject to static code analysis.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management forms an important part of our ISO27001 operational procedures. We undertake regular penetration testing using an OWASP compatible tool and we would be happy to discuss additional third party testing. We also undertake further server security tests on a quarterly basis. Any critical vulnerabilities identified are applied same day in line with vendor recommendations, others of lower priority are scheduled in with other operational tasks.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring forms an important part of our ISO27001 operational procedures. Servers run with only necessary services available and all security patches installed and updated in line with vendor instructions. Servers are further protected via software firewalls and third party protection services to mitigate against possible threats. Our own server monitoring service provides additional regular checks such as server load, and reports unexpected activity to the technical team via email and SMS, who investigate immediately.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Formal incident management forms an important part of our ISO27001 operational procedures. Any incidents or suspected incidents should be raised with our account management team, via email or telephone, where they will then be reviewed by our technical team. Our account management team will ensure communication throughout through to resolution and major incidents will be escalated to our Technical Director.
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Tackling economic inequality
- Wellbeing
Tackling economic inequality
Through using the Care Leavers App, care experienced young people gain access to a much wider range of opportunities within education, training and employment.
The App provides young people with regional apprenticeship vacancies with new opportunities promoted daily.Wellbeing
Co-producing the Care Leavers App with care leavers gets young people involved in peer groups, community and helps them gain real-world skills such as teamwork. Getting involved with a co-production group helps build confidence and provides young people an opportunity to find out about careers in the digital sector.
The Care Leavers App includes a Mental Health Hub, with over 250 resources and articles that support young people's mental wellbeing - giving advice on topics including bullying, anxiety and self-harm - available on their devices on a 24/7 basis.
Pricing
- Price
- £21,600 to £30,400 a licence a year
- Discount for educational organisations
- No
- Free trial available
- No