Brand management software
BrandStencil is a cloud-based brand management software platform combining digital asset management, on-brand content creation and controlled distribution. It enables organisations to store, manage and reuse brand assets, create compliant materials from templates, manage case studies, and order branded materials, supporting consistent branding and efficient workflows across teams and partners.
Features
- Centralised digital asset management
- Template-based creation of on-brand materials
- Role-based access and permissions
- Controlled self-service content creation
- Case study and content asset management
- Support for digital and print workflows
- Ordering of branded materials through the platform
- Auditability of users and asset usage
- Browser-based SaaS with no local installation
- Ongoing updates and platform maintenance
Benefits
- Maintain consistent branding across teams and suppliers
- Reduce time spent on manual design and approvals
- Store and manage approved brand assets in one place
- Enable controlled self-service content creation
- Ensure compliance for case studies content usage
- Support digital and print content workflows
- Simplify ordering of branded materials
- Improve collaboration across distributed teams
- Reduce risk of outdated or non-compliant brand materials
- Lower operational overhead for communications teams
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 1 5 7 0 7 4 6 4 7 0 7 5 5 8
Contact
BRANDSTENCIL LTD
Melanie Burke
Telephone: 01273 112883
Email: melanie@brandstencil.com
About your service
- Service categories
-
Applications
Content workflow and management
- Creative
Persuasive content management
- Digital Asset Management Applications
- Content Marketing Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
The service requires internet access and a modern web browser.
The service does not support offline use.
Planned maintenance may require short periods of reduced availability.
Support is provided during UK business hours. - System requirements
-
- Internet access
- Modern, standards-compliant web browser (Chrome, Edge, Firefox or Safari)
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support is provided via a monitored email ticketing system and by phone during standard support hours (9.00am–5.00pm, Monday to Friday, excluding UK Bank Holidays and published closures).
Response time goals during standard support hours are:
• Business-critical issues: initial response within 1 hour
• Urgent issues: initial response within 4 hours
• Other requests: initial response within 1 business day
Outside standard support hours, the service is monitored for business-critical incidents only. Weekend response is limited to critical service issues. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 A
- Web chat accessibility testing
-
We use a third party system called HelpScout which tests their web chat for accessibility.
https://www.helpscout.com/company/legal/accessibility-statement/ - Onsite support
- No
- Support levels
-
Support levels provided
BrandStencil provides a standard support service to all customers.
Support is delivered via:
A monitored email ticketing system
Phone support during standard support hours
Support covers:
Service availability and platform issues
Template-related issues
Integration issues
General product and usage questions
Issues are prioritised based on severity, with defined response time goals during standard support hours.
Customers have a dedicated point of contact to coordinate support and issue resolution.
Cost of support levels
Standard support is included in the service subscription cost.
There is no additional charge for standard support.
Additional work outside the standard support scope (for example, configuration changes or template amendments) may be quoted separately where applicable.
Technical account management
Each customer has a dedicated account contact who acts as the primary point of contact for support and service-related queries.
A named technical account manager or cloud support engineer is not provided as a separate, chargeable role.
Technical support is delivered by the BrandStencil team as part of the standard service. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
BrandStencil provides onboarding and training to support customers in starting to use the service.
During setup and configuration, the BrandStencil team provides guided onboarding and ongoing, tailored training to ensure the platform is configured to meet organisational requirements.
Online training sessions are tailored to the customer’s configured workflows and templates and are available for Account Owners and Account Administrators.
Online end-user training sessions are also available where required.
Users have access to online help documentation and an in-platform chatbot that provides answers based on the help documentation. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
Customers can request an export of their data at the end of the contract.
This can include an extract of designs created from templates, customer-uploaded brand assets, and a packaged export of template HTML files.
Data extraction is carried out by the BrandStencil team and provided in commonly used, machine-readable formats.
Data extraction may be subject to an additional charge, depending on scope.
Following confirmation of successful extraction, customer data is securely deleted from the service. - End-of-contract process
-
At the end of the contract, the customer requests account closure and access to the service is disabled.
Customers may request an export of their data prior to contract termination. This can include designs created from templates, customer-uploaded brand assets and a packaged export of template HTML files.
Following account closure, customer data is retained for up to 30 days to allow for any agreed data extraction.
After this period, customer data is securely deleted from the service. Secure deletion is included in the contract price.
Data extraction and packaging is carried out by the BrandStencil team and may be subject to an additional charge depending on scope.
Any agreed additional configuration, customisation or development work requested at contract end is chargeable. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
BrandStencil is accessed through a secure, browser-based web interface.
Users log in to view, manage and download brand assets, create materials using templates, and access approved content.
Administrative users can manage templates, assets, user accounts and permissions through the same web interface.
No local software installation is required. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Accessibility is considered during design and development.
The service is tested using browser accessibility tools and manual checks against WCAG 2.1 AA criteria, including keyboard navigation and screen reader compatibility.
Accessibility issues raised by users are logged, reviewed and prioritised for remediation as part of ongoing improvement.
Formal third-party accessibility testing has not yet been undertaken. - API
- Yes
- What users can and can't do using the API
-
BrandStencil provides a restricted integration API that is used by the BrandStencil development team and approved partner development teams to support specific integrations.
The API is not publicly documented or self-service. Customers cannot independently set up the service or make configuration changes through the API.
Service setup and configuration are carried out through the browser-based web interface by authorised administrators, or by the BrandStencil team where integration work is required.
The API is designed to be extensible and is actively maintained and evolved to support additional integration requirements.
Use of the API is limited to agreed integration scenarios and is not intended for general customer access. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
BrandStencil is highly configurable and customisable to meet organisational requirements.
Customisation is provided across three levels:
Configuration – selecting and setting platform options such as user roles and permissions, template settings, content fields and feature toggles.
Customisation – adapting templates, workflows, user flows, interface theme, ordering processes, content structures and management information (MI) reports to align with organisational needs.
Development – implementation of new features or integrations where required, for example integration with procurement systems to support specific purchasing process flows.
Initial configuration and most customisation is carried out by the BrandStencil team as part of onboarding and ongoing service delivery.
Users with Account Owner or Account Administrator permissions can manage users, upload and organise assets, and manage content within the configured environment.
Scaling
- Independence of resources
-
BrandStencil is built on scalable cloud infrastructure designed to support multiple customers concurrently.
The service uses a multi-tenant architecture with logical separation of customer data.
Platform performance and capacity are monitored, and resources are scaled to meet demand.
This approach helps ensure that usage by one customer does not adversely affect other customers.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
BrandStencil provides usage and activity information to support service management.
This can include metrics such as:
Number of users and user activity
Template usage
Asset usage and downloads
Content and design creation activity
Ordering activity (where applicable)
Management information (MI) reports can be configured to meet customer requirements.
Additional reporting can be provided on request. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
-
BrandStencil does not currently apply application-level encryption to data at rest.
Data at rest is protected through logical separation of customer data, strict access controls, restricted staff access to production systems, and security controls provided by the underlying cloud hosting environment.
Access to data is limited to authorised personnel and systems only. - Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
End users can export individual designs they have created directly from the platform.
Account Owners and Account Administrators can request a broader export of customer data by contacting BrandStencil support.
Support-assisted exports can include designs created from templates, customer-uploaded brand assets and template HTML files.
Data export is carried out by the BrandStencil team and provided in commonly used, machine-readable formats.
Support-assisted data export may be subject to an additional charge depending on scope. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
BrandStencil monitors service availability continuously and automatically restarts the server if it goes offline.
The service has historically achieved availability in excess of 99%.
Planned maintenance may be scheduled with advance notice. Emergency maintenance is carried out only where necessary to protect service integrity.
We do not currently offer a formal availability SLA with financial penalties or refunds tied to specific availability percentages. Where service disruption occurs, incidents can be logged via standard support channels. - Approach to resilience
-
BrandStencil is built on cloud infrastructure designed to provide resilient service operation.
The service is hosted with enterprise-grade cloud providers operating geographically distributed data centres with physical security controls, redundant power and environmental protections.
Platform availability is continuously monitored, and automated recovery processes are in place to restore service if issues occur.
Regular backups are performed and retained to support data recovery.
BrandStencil maintains a documented Business Continuity and Disaster Recovery Plan, including defined recovery objectives for critical systems.
Further details of hosting architecture and resilience arrangements are available on request. - Outage reporting
-
BrandStencil provides a public status dashboard showing current service status.
If a service outage occurs, BrandStencil notifies Account Owners by email.
There is currently no outage reporting API or automated alert subscription.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is restricted to authorised personnel only.
Role-based access controls are used to ensure users can only access functions appropriate to their role.
Administrative access requires authenticated user accounts and is limited to named individuals.
Support channels are monitored and access is restricted to authorised BrandStencil staff.
Changes to access permissions are logged and reviewed. - Access restriction testing frequency
- Less than once a year
- Management access authentication
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials
- Information security policies and processes
-
BrandStencil operates an Information Security Policy that applies to all employees, contractors and partners who access BrandStencil systems and data.
BrandStencil is certified under the UK government’s Cyber Essentials scheme and follows the National Cyber Security Centre SaaS Security Principles.
We take a proportionate, risk-based approach to information security, embedding secure practices into day-to-day operations. Access to systems and data is controlled on a need-to-know basis using appropriate authentication and access controls.
Information security incidents are managed through a defined Cyber Security Incident Management Process. Staff are instructed to report suspected incidents to the Technical Director or another senior team member.
Automated backups and business continuity arrangements are in place and documented within our Business Continuity and Disaster Recovery Plan.
Security policies are reviewed regularly and security expectations are introduced during staff onboarding. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
BrandStencil follows documented configuration and change management processes to manage changes to the platform and supporting infrastructure.
Changes are planned, reviewed and tested before deployment.
Code changes are managed through version control and deployed using controlled release processes.
Configuration changes are restricted to authorised personnel.
Where appropriate, changes are scheduled to minimise disruption, and rollback options are available if issues occur.
Operational changes align with the principles of least privilege, separation of duties and auditability. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
BrandStencil uses a risk-based vulnerability management process.
Potential threats are identified through system monitoring, vulnerability scanning, periodic penetration testing, and review of application and infrastructure logs.
Security patches and updates are applied as part of routine maintenance, with high-risk vulnerabilities prioritised for faster remediation.
Information about emerging threats is obtained from cloud service providers, software suppliers, security advisories and industry best-practice guidance.
Identified vulnerabilities are logged, assessed and remediated, and security incidents are handled through the Cyber Security Incident Management Process. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
BrandStencil uses continuous monitoring of production systems and application logs to detect unusual activity or potential security issues.
Potential compromises may be identified through monitoring alerts, log review, vulnerability scanning, and reports from users or support requests.
When a potential compromise is identified, it is investigated by the technical team in line with the Cyber Security Incident Management Process, including containment, remediation and recovery as required.
Critical security incidents trigger immediate investigation during standard support hours. Other security issues are prioritised based on severity. - Incident management type
- Supplier-defined controls
- Incident management approach
-
BrandStencil has a documented Cyber Security Incident Management Process with pre-defined steps for common incident types, including detection, containment, investigation, remediation and recovery.
Users report incidents via the monitored support email address or by phone during standard support hours.
Incidents are logged, prioritised based on severity, and investigated by the technical team.
Account Owners are kept informed of significant incidents and, where appropriate, provided with an incident summary and outcome following resolution. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
BrandStencil offers a free demo account for evaluation purposes.
The demo account allows multiple users to access and review core platform functionality. It is provided for a limited period of up to three months.
Ongoing production use, configuration, customisation, and support are not included as part of the free demo.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 8e847606-6cb7-4178-847c-9038344af0a7
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Working conditions which promote an inclusive working environment and promote retention and progression
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-