Evolutive CRM software / Management Information System for Public Sector
Evolutive is a leading software solution for the public sector. Features include; CRM, Enquiry Management, Workflow Management, Funding & Grants Management, Employment Programme / Employability Management and Participant Tracking, Advanced Reporting, Events Management, Online forms and more. Highly flexible system which can be customised to meet client requirements.
Features
- Client Relationship Management (CRM) / Customer Relationship Management (CRM)
- Enquiry management and workflow management
- Funding and grant management including online application forms
- Employment & Skills Programme management e.g. Connect to Work
- Advanced reporting and Microsoft Power BI integration
- E-newsletters and marketing
- Events management and online event booking portal
- Online surveys
- Commercial property database and online property search portal
- Online forms and digital signatures
Benefits
- Highly configurable and flexible system
- Automate and streamline key business processes
- Single view of contact/client relationship and journey
- Reduce time spent on analysing and manipulating data
- GDPR friendly tools
- Accessible across devices (desktop, tablet, smartphone) for efficient data entry
- APIs and supported integration with other systems
- Community-led development and inclusive system upgrades
- Scalable to meet ongoing requirements
- Unlimited UK based Helpdesk support
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 4 3 4 2 1 1 6 7 3 0 0 8 0 2
Contact
ALCIUM SOFTWARE LIMITED
Kevin Grimshaw
Telephone: 0114 349 1294
Email: info@alciumsoftware.com
About your service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Scheduled/planned maintenance and emergency maintenance are defined within the service contract.
- System requirements
-
- Microsoft Edge (latest supported version)
- Google Chrome (latest supported version)
- Safari (latest supported version)
- Firefox (latest supported version)
- MS Office 2016 or above
User support
- Email or online ticketing support
- Yes
- Support response times
-
Our helpdesk support service adheres to the ITIL Framework for IT Service Management. Service levels and response times are set out within our Service Level Agreement.
Our helpdesk aim to close out all enquiries on receipt of the initial contact. Our helpdesk operate Monday-Friday, 9am-5pm (excluding public holidays). - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Our dedicated support team are contactable via email and telephone Monday-Friday, 9am-5pm (excluding public holidays). We have a documented Service Level Agreement in place for the provision of our support services. This support is included as part of the annual licence.
A dedicated Account Manager is also assigned for each client as part of the implementation process and ongoing.
Initial user training is provided as part of the implementation/onboarding. Additional training (online and onsite) can be requested throughout the term of the contract, subject to additional cost. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We support users from the very start of their engagement - time is taken to understand the client's processes and requirements. A dedicated Account Manager is assigned to each client to guide them through the implementation process. Training is delivered onsite or online, depending on client preference, and is tailored to the client’s specific processes and requirements.
System Administrators receive additional role-specific training to ensure they can manage and configure the system effectively. All users are provided with comprehensive documentation and clear system guidance to support independent use of the service.
Ongoing support is available through our Account Managers and helpdesk team, via telephone, email, and online webinar sessions, ensuring users can quickly resolve questions or issues as they arise. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
In-built reporting facilities within the system allow for the export of data on demand in a range of formats. Integration with Microsoft Power BI also facilitates the export of data.
On expiry/termination of the contract, Alcium will provide a full copy of the database backup. This will be delivered to the client via a secure platform. - End-of-contract process
-
In-built reporting facilities within the system allow for the export of data on demand in a range of formats.
On expiry/termination of the contract, Alcium will provide a full copy of the database backup. This will be delivered to the client via a secure platform. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There is a portal version of Evolutive which has been specifically designed for use on portable/mobile devices. The portal is a streamlined version of the system which allows for efficient data entry.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Yes, the service provides a browser-based user interface (web portal) that allows users to access and manage customer data, configure settings, and generate reports. Users can securely log in from any standard web browser without additional software.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- In addition to automated and manual testing, the portal solution has been reviewed by a user of assistive technology from one of our client organisations, with their feedback directly informing product improvements.
- API
- Yes
- What users can and can't do using the API
-
Enquiries captured through external websites, such as online forms or newsletter sign-ups, can be fed into the system using the API.
The API also allows data to be extracted from Evolutive and sent to third-party websites, for example to support events or event bookings.
Advanced configuration or more advanced integrations may require support. Clients can contact their Account Manager or the Helpdesk team for guidance. - API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Evolutive is a flexible system which can be customised for each client. This includes system terminology, data fields, dashboards, reporting, enquiry profiles, user permissions, system settings etc.
The system is configured specifically for each client as part of the implementation process. As part of the training, clients are trained to configure the system themselves subject to sufficient System Administration rights.
Ongoing support for system configuration is included as part of the licence.
Scaling
- Independence of resources
- We use dedicated servers hosted on enterprise-grade cloud infrastructure within the UK (Microsoft Azure). We have our own dedicated environment. Each Evolutive site has its own separate database.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Yes, we can provide service usage metrics. Usage logs in CSV format can be provided, including information such as user logins and activity within the platform.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Evolutive has in-built tools to allow for advanced reporting and the exporting of data directly from the system. Data can be exported in a range of formats including Word, MS Excel, CSV and PDF. The system is also integrated with Microsoft Power BI which allows for the export of data.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Microsoft Word
- Microsoft Excel
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We target a service availability of 99.96% uptime, which is actively monitored through cloud monitoring tools. While we do not provide financial refunds if this level is not met, we maintain robust redundancy, failover, and monitoring processes to minimise downtime and ensure continuity of service for all users. Any service interruptions are logged and addressed promptly in accordance with our operational procedures.
- Approach to resilience
-
We use enterprise-grade cloud infrastructure with redundancy across power, networking, and cooling. Services are deployed with cross-region replication in UK-based data centres to reduce the impact of any single-site failure.
We have established recovery time and recovery point objectives to ensure rapid service restoration and minimal data loss. Detailed RTO and RPO information, along with further details of our datacentre setup and resilience measures, are available on request. - Outage reporting
- Notifications are primarily delivered via email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is secured via HTTPS with unique credentials. Role-based permissions, two-factor authentication, single sign-on (SSO), and optional IP restrictions ensure only authorised users can access the system.
Support is accessed via email/telephone to our Helpdesk, which is monitored by authorised staff, ensuring that client requests are handled securely and only by appropriate personnel. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Alcium Software is ISO 27001, Cyber Essentials, and Cyber Essentials Plus certified, following internationally recognised information security standards.
We maintain documented security policies covering data protection, access control, incident management, and risk management. Policies are reviewed regularly by a board-level Information Security Officer.
Employees report security incidents to their line manager, who escalates to the Information Security Officer as needed. Compliance is ensured through regular audits, staff training, and internal reviews. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We adhere to the ISO27001 change management process standards. We use a dedicated change management system where changes are reviewed for quality standards, including security issues/concerns. Changes are tracked and audited in the system. Insecure change requests are rejected. We have separate production and test environments.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We maintain a proactive vulnerability management process to protect our services and users. Potential threats are continuously monitored through trusted industry sources and security advisories. Regular vulnerability assessments are conducted with high and medium-risk issues prioritised for remediation. In addition, we commission an annual independent penetration test.
Patches and updates are applied promptly in accordance with risk severity, with critical security issues addressed as a matter of urgency.
Vulnerability scans follow recognised standards, including OWASP guidelines, and help ensure our services remain secure and resilient. Summary reports of recent assessments can be provided on request. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We maintain a proactive vulnerability management process to protect our services and users. Potential threats are continuously monitored through trusted industry sources and security advisories. Regular vulnerability assessments are conducted with high and medium-risk issues prioritised for remediation. In addition, we commission an annual independent penetration test.
Patches and updates are applied promptly in accordance with risk severity, with critical security issues addressed as a matter of urgency.
Vulnerability scans follow recognised standards, including OWASP guidelines, and help ensure our services remain secure and resilient. Summary reports of recent assessments can be provided on request. - Incident management type
- Supplier-defined controls
- Incident management approach
- In line with our ISO27001 accreditation, we have a formal documented Information Security Incident and Management Policy. All reported issues via email or telephone are logged on our internal system. Calls are assessed and given a priority status in line with our Service Level Agreement. Our ISIM Policy is reviewed regularly and issued to all employees.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Access can be given to a trial version of the software for an agreed period of time. Limitations may apply to certain functions of the system including emailing.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Certified International Systems
- ISO/IEC 27001 accreditation date
- Thursday 4 July 2019
- What the ISO/IEC 27001 doesn’t cover
- Certification covers our information security practices
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Certified International Systems
- ISO 9001 accreditation date
- Thursday 16 May 2019
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 628c199e-8c1e-4d66-bb11-b6776316af4a
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- D149e701-e00f-4a65-ae65-0c6cce2398ac
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-