safedrop Secure Forms
Safedrop Secure Forms enable public sector teams to collect sensitive information safely and compliantly, without relying on email.
Receive citizen information, KYC/right to work/right to rent info, health and social care documents, case files and supporting evidence, financial information and payment details, CCTV footage and more.
Features
- Collect Sensitive data from anyone
- Secure file upload support for documents, images, video and more
- End to End Encryption
- GDPR, HIPAA compliant
- Configurable form fields
- Granular access controls
- True Zero Knowledge
- Custom Branding
- Simple form creation via a web based interface
- Receive files up to 1Tb
Benefits
- UK Owned & Hosted
- Military Grade security for your files
- Reduce risk of data breaches
- Improve trust for service users submitting data
- Enable faster more secure onboarding and case handling
- Only pay for active users
- Minimise administrative overhead for IT and Security teams
- Clear audit logs for compliance, investigations and FOI requests
- Receive files from anyone
- Scale without additional infrastructure
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 8 7 9 0 1 6 8 5 1 1 7 8 4 9
Contact
OD CONSULTANCY LIMITED
Angus Bradley
Telephone: 0207 739 4252
Email: enquiries@projectfusion.com
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
- Document
- EDiscovery and forensics
Content services
- Content Sharing and Collaboration Applications
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Integrated Employee Workspaces
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Safedrop OFFICIAL
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- No
- System requirements
- Any web browser supporting TLS 1.2 onwards
User support
- Email or online ticketing support
- Yes
- Support response times
- 15 minutes, 24 hours a day, 7 days a week.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Web chat is accessible directly from within the product and on the safedrop website. Users can reach out to our support teams and receive a response within 15 minutes (typically less than 3 mins).
- Web chat accessibility testing
- None
- Onsite support
- Yes, at extra cost
- Support levels
-
Users may contact our support team via telephone or email to support@safedrop.com for technical support. We will acknowledge the request by email within fifteen minutes of receipt. We will respond via email to the appropriate user and initiate addressing the request using reasonable endeavours within 4 Business Hours of initial contact. safedrop servers are automatically monitored every 3 minutes for up time. In the case of a critical failure, where the safedrop instance is not responding or accessible from any network, we will attempt to solve the problem using reasonable endeavours within 30 minutes of initial contact or notification by monitoring system.
Support is free, unless the client requires an onsite visit. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We provide online training videos in additional to providing users with documentation. We can also provide free online training sessions.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Users can easily download their data directly from safedrop within the app. Only authorised users can download data.
- End-of-contract process
- At the end of the contract we remind the client a month in advance that their contract is due to end. At this point they can choose to extend, or to shut down the service. We then remind the client a week before shut down that their service will be deleted. Clients can download their data free of charge. We are unable to assist with downloads due to the end to end encryption.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Currently users are able to access documentation in PDF or HTML format whilst using the supported accessibility features of their device.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The services are identical.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service interface is accessed via a web browser, and allows users to use the platform. It's accessible without the need for any installations or plugins.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
Users of assistive technology can use features built into their device including, but not limited to:
VoiceOver
Zoom
Magnifier
Speech: Speak Selection, Speak Screen, Highlight content, and Typing Feedback
Larger Text
Bold Text
Button Shapes
Increase Contrast
On/Off Labels - Accessibility testing
- None
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Logos and branding can be customised within the app
The form URL can be customised
The form can be embedded onto your own website
Terms of use that senders must accept can be customised - ideal for compliance with GDPR and other local legislation.
Security settings can be customised, the settings are enforced to your teams and users. ie. Add an access control list, or restrict the maximum expiry times your teams can select.
Scaling
- Independence of resources
- Bandwidth throttling.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We can provide data usage reports on request. User reports are available at anytime within the app.
Full audit trail reports are available through a reporting module within the app. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- End to End Encryption - data is encrypted before it is stored and remains encrypted at rest at all times. Encryption keys are managed securely and are not accessible to unauthorised parties including us.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Data can be downloaded from within the app provided the data hasn't expired or self destructed.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Native file types as uploaded
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- Native file types
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Safedrop will provide the Customer with at least ninety-nine.nine ninepercent (99.99%) Uptime for each safedrop Instance during each Month during the continuance of this Agreement. The Company shall remedy any breach of the warranty set out above by the provision of a credit against fees payable by the Customer for the safedrop Instance for the next following calendar month. Such credit will be equal to a percentage of the monthly Basic Price (not including additional surcharges, separate support fees, or any other additional fees charged to the Customer on account of additional services, if any) allocated to the particular safedrop Instance.The percentage credit is calculated as per the following formula:
Percentage of time in month for which service is available Credit percentage
99.99% or more None
98% TO 99.9% 20%
Below 98% 40% - Approach to resilience
- Available on request
- Outage reporting
- We receive an alert from our monitoring system, we then alert our clients key contacts by email/telephone.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- Passkey
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is restricted using a combination of technical and procedural controls based on the principle of least privilege.
Access rights are role-based, regularly reviewed, and revoked promptly when no longer required. All administrative access is logged and monitored.
These controls are defined and enforced as part of our ISO 27001 aligned Information Security Management System. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- ISO27001 - our policies are documented within our ISMS procedure and all staff sign a document to show they adhere to the policies.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Formal policies and procedures established which covers changes to all software, applications, systems, infrastructure, hypervisors, virtual machine images, databases, services, operations & facilities used
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Security sites and blogs checked daily manually for important updates.
Fortnightly automated check of services against vulnerabilities.
Monthly NESSUS scans.
‘Critical’ patches deployed same day
‘Important’ patches deployed within 1 week
‘Other’ patches deployed within 4 weeks of a patch becoming available
‘Critical’, ‘Important’ and ‘Other’ are aligned to the following common vulnerability scoring systems:
National Vulnerability Database Vulnerability Severity ratings: ‘High’, ‘Medium’ and ‘Low’ respectively. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Potential compromises are identified through logging, monitoring, alerting, vulnerability scanning and third-party disclosures. Incidents are handled through a defined incident management process aligned with ISO/IEC 27001, including triage, containment, investigation and remediation. High-severity incidents are responded to immediately, with actions typically initiated within hours, and all incidents are tracked to resolution and reviewed.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
Formal incident response plan.
All users and personnel reports incidents via trouble ticket.
All reported Information Security weaknesses, observations and occurrences are, immediately upon receipt, assessed and categorised. Reports are raised in the ISMS board. A record is made of the assessment.
The Information Security Manager (or other investigator) investigates the circumstances, and categorises the reported occurrence or observation into one of four categories: okay, event, incident or unknown.
Once incident contained, and required remedial action completed, the Information Security Manager prepares a report for the Management Review & Clients.
Incident reports to any affected clients within 72 hours. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
1 month free trial
Doesn't include API access
No branding options
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- CFA
- ISO/IEC 27001 accreditation date
- Friday 9 January 2015
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-