Skip to main content

Help us improve the Digital Marketplace - send your feedback

NEWTON'S TREE LTD

Newton's Tree

Newton’s Tree provides a vendor-neutral software platform that enables NHS organisations to select, evaluate, deploy, and monitor multiple AI systems. The service supports safe adoption of AI through standardised evaluation, integration with clinical systems, ongoing performance monitoring, and auditable governance to meet clinical safety and regulatory requirements.

Features

  • Continuous real-time post-deployment monitoring of AI applications
  • Sandbox Head-to-Head AI Testing Environment
  • Enterprise AI Registry Dashboard
  • AI Framework Contract
  • Vendor Neutral AI Application Marketplace
  • Professional Services for Medical AI
  • Enterprise AI Orchestration
  • AI Workflow setup and tooling

Benefits

  • Real-time monitoring of AI products for enhanced clinical safety
  • Test AI products on your local data before buying
  • View the status of all AI projects across your enterprise
  • Procure AI applications seamlessly
  • Expert support across the AI lifecycle
  • IT support for AI workflow setup
  • Expert oversight on the medical AI market

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@newtonstree.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 1 9 3 4 2 5 4 9 6 4 2 2 4 1

Contact

NEWTON'S TREE LTD Haris Shuaib
Telephone: 0773142199
Email: info@newtonstree.com

About the service

Service categories

Application Development and Deployment

Application platforms

Deployment centric application platforms

  • Application Server Software Platforms
  • Cloud Deployment-Centric Application Platforms
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
Newton's Tree shall use commercially reasonable endeavours to make the Platform available 24 hours a day, seven days a week, except for:
planned maintenance carried out during Newton's Tree's standard maintenance window specified from time to time; and
unscheduled maintenance, provided that Newton's Tree have given the Customer reasonable notice of the same in advance.
System requirements
  • Modern web browser (Chrome, Edge, Firefox, Safari supported).
  • Secure internet connectivity to NHS or customer network.
  • User authentication via NHS or organisation identity provider.
  • User authentication via NHS or organisation identity provider.
  • VPN or secure tunnel for protected system integration.
  • HTTPS/TLS enabled for secure platform access.
  • Antivirus and endpoint protection on user devices.
  • API access enabled for clinical system integration.

User support

Email or online ticketing support
Yes
Support response times
According to SLA with each customer. Typically support requests are acknowledged within 1-working day.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes
Support levels
Newton's Tree shall: Provide access to the deployment platform and ensure system uptime of 99.5% availability (excluding planned maintenance).

Maintain the necessary hardware to use the platform.

Deploy new versions/updates of the third-party AI applications within 5 business days of being received.

Ensure the platform integration and hosting function operate correctly.
Ensure the platform complies with GDPR and UK Data Protection regulations.

Monitor the AI applications hosted on Newton's Tree infrastructure to ensure compliance with technical requirements.

Provide technical assistance for onboarding to the platform and integration support.

Assign a designated point of contact for communication and escalation purposes; escalate third line support issues to third-parties.

Keep a list and all relevant details of reported incidents notified to Newton’s Tree, including those related to safety, and the remedial actions taken.

Newton’s Tree will write an incident report for any Material Adverse Event or Adverse Event that Newton’s Tree becomes aware of. Newton’s Tree shall, with respect to a material adverse event, forward its incident report to relevant third-parties within one workday and five days for other events.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Combination of onsite and online training, and user documentation for all relevant staff members. Newton's Tree also provides information on the internal staff role requirements to ensure platform deployment and onward utilisation are successful.
Service documentation
No
End-of-contract data extraction
At the end of the contract, users can extract their data in a structured, usable format to support continuity, audit, and record-keeping requirements.

Customers can export configuration data, evaluation records, monitoring outputs, reports, and audit logs through the service interface or via secure APIs. Data is provided in commonly used, non-proprietary formats such as CSV, JSON, or PDF, depending on data type.

Where required, Newton’s Tree can support a managed data export, coordinated with the customer’s digital and information governance teams, to ensure secure transfer and completeness. Data extraction does not require continued platform access beyond the contract end date, subject to agreed timelines.

Following confirmation of successful data extraction, customer data is securely deleted or returned in line with contractual terms, data processing agreements, and applicable data protection requirements.

The service does not impose technical barriers or excessive charges for data extraction, supporting transparency, portability, and vendor-neutrality.
End-of-contract process
At the end of the contract, Newton’s Tree works with the customer to support an orderly service exit. Platform access is maintained for an agreed period to allow completion of data extraction and transition activities. Users can export their data using the service interface or APIs, or through a managed export where required.

Once data extraction is complete and confirmed, access to the service is withdrawn and customer data is securely deleted or returned in accordance with contractual terms, data processing agreements, and applicable data protection requirements. Any ongoing integrations are decommissioned in coordination with the customer to avoid service disruption.

The service is designed to support exit without vendor lock-in.

The contract price includes use of the platform, standard configuration, user access, routine support, and end-of-contract data extraction using standard export tools.

Additional costs may apply for optional services such as bespoke integrations, extended data retention, complex managed data exports, or professional services to support migration or transition beyond standard exit activities. These are agreed in advance and priced transparently.

Using the service

Web browser interface
Yes
Supported browsers
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a secure, web-based user interface available via standard browsers. It provides role-based dashboards for clinical, digital, and governance users to evaluate, deploy, and monitor AI systems. The interface supports configuration, reporting, and audit functions, and integrates with existing clinical systems via secure APIs. No specialist software installation is required for end users.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The service interface has been designed in line with WCAG 2.2 AA principles, including keyboard navigability, sufficient colour contrast, clear focus states, and semantic HTML structure. Accessibility considerations have been incorporated during design and development reviews.

User testing has included internal testing with screen readers, keyboard-only navigation, and browser accessibility tools to validate usability for users with visual or motor impairments. Feedback from clinical and administrative users has been used to improve clarity, navigation, and form interactions. Accessibility testing is repeated as part of ongoing platform development, with issues logged and addressed through standard quality and product assurance processes.
API
Yes
What users can and can't do using the API
The service provides secure APIs to support integration with existing clinical, digital, and operational systems. Users can use the API to configure integrations, onboard AI systems, submit and retrieve evaluation metadata, manage deployment status, and access monitoring outputs and audit records.

The API can be used to support service setup activities such as registering systems, defining workflows, configuring data sources, and managing access permissions. Users can also make changes over time, including updating configurations, enabling or disabling AI systems, and retrieving performance and usage information.

The API does not allow customers to modify core platform logic, bypass governance controls, or alter clinical safety records once finalised. Access to API functions is controlled through authentication, authorisation, and role-based permissions. Some configuration and governance actions are restricted to authorised organisational administrators.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The service can be customised to meet the needs of individual organisations while maintaining a standard, governed platform.

Users can customise configuration settings including user roles and permissions, evaluation criteria, reporting views, workflows, and integrations with local clinical systems. Dashboards, alerts, and monitoring parameters can be tailored to organisational priorities and clinical use cases.

Customisation is performed through the web-based user interface and, where appropriate, via secure APIs. Configuration options are exposed as structured settings rather than code changes, ensuring consistency, safety, and maintainability.

Customisation activities are restricted to authorised users, typically organisational administrators or designated digital and clinical safety leads. End users access the service according to the roles and permissions defined by their organisation.

The service does not support customer modification of core platform logic or safety controls. This approach allows flexibility in use while preserving regulatory compliance, auditability, and service reliability.

Scaling

Independence of resources
Each customer is provided with a separate, dedicated instance of the service, including in cloud deployments. There is no multi-tenancy at the application or data layer. This ensures that usage, performance, and data access for one organisation cannot impact another.

Resources are provisioned and monitored per instance, with capacity sized to customer requirements. This approach guarantees workload isolation, predictable performance, and strong information governance, regardless of demand from other users.

Analytics

Service usage metrics
Yes
Metrics types
Quarterly Reviews: Newton’s Tree shall conduct quarterly service reviews to evaluate performance, incidents, and necessary improvements.

Uptime Reporting: Newton’s Tree will provide uptime and incident logs on request.
Reporting types
Reports on request
Resource tagging
No
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data directly through the web-based interface or via secure APIs. Exports include configuration data, evaluation records, monitoring outputs, reports, and audit logs. Data is provided in standard, non-proprietary formats such as CSV, JSON, or PDF. Where required, a managed export can be supported to ensure secure transfer and completeness, agreed with the customer’s digital and information governance teams.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • PDF
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • DICOM
  • FHIR
  • HL7

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Provide access to the deployment platform and ensure system uptime of 99.5% availability (excluding planned maintenance).

SLA breach and termination rights: If the SLA set out in this document are not met on a sustained basis, customers reserve the right to terminate the contract with 30 days written notice. This right may be exercised if the suppliers fail to meet the performance standards specified in the SLA following two consecutive quarterly reviews.
Approach to resilience
The service is designed for resilience through isolation, redundancy, and controlled recovery. Each customer operates on a dedicated instance, ensuring faults or load issues do not affect other users.

Where hosted in the cloud, the service is deployed on resilient infrastructure with redundancy across availability zones, automated backups, and monitored health checks. Where deployed on customer-managed or on-premise infrastructure, resilience is achieved through environment-specific architecture agreed with the customer, aligned to local business continuity and disaster recovery policies.

Regular backups, versioned configuration, and documented recovery procedures support rapid restoration in the event of failure. Infrastructure and application performance are continuously monitored, with alerts to support timely response.

Detailed datacentre and infrastructure resilience information can be provided on request.
Outage reporting
Service outages and service-impacting incidents are reported directly to affected customers. Notifications are provided via email alerts to nominated contacts.

Where appropriate, service status and incident updates can also be shared through agreed support channels. The service does not rely on a public status dashboard, as each customer operates on a dedicated instance.

Operational monitoring and alerting are in place to detect incidents promptly and support timely communication and resolution.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted through role-based access control and strong authentication. Only authorised personnel are granted administrative or support access, based on job role and least-privilege principles.

Management interfaces are protected using secure authentication mechanisms and network controls. Support access to customer environments is granted only when required, time-limited, and logged. All administrative and support activities are monitored and auditable. Access rights are reviewed regularly and revoked promptly when no longer required.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Security governance procedures in line with ISO 27001. Self-certified at this stage but. Newton's Tree also has a QMS in place to further align with internationally recognised governance standard.
Information security policies and processes
Newton’s Tree operates a formal information security management framework aligned with recognised standards, including ISO/IEC 27001 principles and NHS information governance requirements. Policies cover access control, data protection, incident management, risk assessment, supplier management, secure development, and business continuity.

Information security governance is overseen by senior leadership, with clear accountability for policy ownership and enforcement. Security responsibilities are defined within roles, and compliance is monitored through regular reviews, audits, and risk assessments. Incidents are logged, investigated, and reported through a documented incident management process, with escalation to senior management where required.

Policies are communicated to staff through onboarding and ongoing training, and adherence is reinforced through role-based access controls, change management, and secure development practices. Third-party suppliers and hosting providers are assessed to ensure they meet equivalent security standards.

Information security policies are reviewed and updated regularly to reflect changes in risk, regulation, and service architecture, supporting continuous improvement and compliance.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Newton’s Tree follows a structured configuration and change management process to maintain service integrity, security, and compliance throughout the service lifecycle.

Service components, including application code, infrastructure configurations, and integrations, are version-controlled and tracked through their lifetime using managed repositories and documented configuration records. Changes are logged, reviewed, and traceable from request through implementation and release.

Changes are assessed for potential impact on security, data protection, clinical safety, and service availability. Security assessments are performed for material changes, including review of access controls, data flows, and dependency risks. Higher-risk changes require approval from senior technical or security leads before deployment.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Newton’s Tree operates a structured vulnerability management process to identify, assess, and remediate security risks across the service.

Potential threats are assessed through a combination of automated vulnerability scanning, penetration testing, dependency monitoring, and architectural reviews.

Security patches and updates are prioritised according to risk. Critical and high-severity vulnerabilities are addressed as a priority and deployed as soon as practicable following testing, with defined internal response targets.

Information on potential threats is obtained from multiple sources, including security advisories from infrastructure and software suppliers, vulnerability databases (such as CVE listings), penetration testing reports, and monitoring alerts.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Newton’s Tree operates continuous protective monitoring to detect, respond to, and mitigate security incidents.

Potential compromises are identified through system and application logging, security alerts, health monitoring, and anomaly detection across customer environments. Logs and metrics are reviewed to identify unusual activity, unauthorised access attempts, or deviations from expected behaviour.

When a potential compromise is identified, it is triaged and investigated according to a documented incident response process. Access can be restricted, affected components isolated, and mitigations applied as required. Customers are informed in line with contractual and regulatory obligations.
Incident management type
Supplier-defined controls
Incident management approach
Newton's Tree has a pre-defined process for incident management which is outlines in SLAs with customers. We keep a list and all relevant details of reported incidents notified to Newton’s Tree, including those related to safety, and the remedial actions taken. Newton’s Tree will write an incident report for any Material Adverse Event or Adverse Event that Newton’s Tree becomes aware of. Newton’s Tree shall, with respect to a material adverse event, forward its incident report to relevant third-parties within one workday and five days for other events.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
3233f287-9c81-4268-bb6d-8aa86a7cd153
Cyber essentials plus
Yes
Cyber Essentials Plus Certificate Number
2f97e645-b8ed-4b80-a83a-26ad13ec1745
Other security certifications
No

Social value

Mission: Build an NHS fit for the future

That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

  • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
  • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
  • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
  • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@newtonstree.com. Tell them what format you need. It will help if you say what assistive technology you use.