Digital Experience Platform
As an Umbraco Gold Partner, Kayo Digital delivers a Digital Experience Platform that helps organisations create inclusive, high-impact digital services people value. Built to be accessible, and future-ready, our platform unifies content, insight and user data, enabling you to engage audiences today while evolving with changing needs, expectations and technology
Features
- AI Search capabilities within the website
- Umbraco CMS version control
- Multilingual capabilities and is Welsh Language Standards compliant
- Ongoing support of Open Source CMS websites
- Multi stage approvals and content governance
- Open Source CMS secure managed EEA & UK hosting
- WCAG 2.2 accessibility audit tool in the CMS
- Modular, composable architecture
- Optimised for SEO & GEO & AI
- AI content creation within the backend of the CMS
Benefits
- CMS has no license fees as it's open source
- No vendor lock-in through open-source technology
- Lower long-term costs through modular architecture
- Strong governance with configurable workflows
- Faster content updates for non-technical users
- Website ready to grow with AI/SEO/GEO optimisation
- CMS is fully customisable for your organisation
- Ai search helps users find information faster and more accurately
- Built-in WCAG 2.2 accessibility compliance support
- Ai content creation speeds up content creation for busy teams
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 6 2 5 6 2 8 6 4 4 0 7 9 6 6
Contact
KAYO DIGITAL LIMITED
Harry Dance
Telephone: 01795 255600
Email: sales@kayo.digital
About your service
- Service categories
-
Applications
Content workflow and management
- Media Services
- Creative
Content services
- Enterprise Content Management Applications
Persuasive content management
- Website Software
- Digital Asset Management Applications
- Product Content Management Applications
- Content Marketing Applications
- Video Platforms
- Digital Adoption Platform
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Integrated Employee Workspaces
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- None
- System requirements
- None
User support
- Email or online ticketing support
- Yes
- Support response times
-
Response times are assessed against the Service Level Agreement during standard service hours, 09:00–17:00, Monday to Friday. Support is provided via the agreed channels during these hours only. Email and ticket-based support are not available outside of service hours, including weekends and UK Bank Holidays.
Emails sent to support@kayo.digital for general support queries will receive an update within 8 working hours Target - 90%
Weekends are considered out of hours and have different response times.
Out of hours services come at a separate cost to a standard support package. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Kayo Digital provides ITIL-aligned support for cloud-based digital services via telephone and online channels. A single point of contact service desk manages all incidents, service requests and technical queries, ensuring clear ownership and efficient resolution.
All issues are logged, prioritised and tracked in line with agreed Service Level Agreements (SLAs). Response times are defined by incident severity, with immediate logging and initial responses typically within 30 minutes to 1 service hour.
Standard support hours are 09:00–17:00 (UK time), Monday to Friday, excluding UK Bank Holidays.
With Kayo Digital's hosting and support, the agency provides regular updates, patches and continuous improvement. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Kayo Digital supports users through a structured onboarding and adoption approach, ensuring confident use of the platform from launch.
Before go-live, we provide a dedicated staging environment for testing and user acceptance testing (UAT). We can also deliver role-based training for content editors and administrators, tailored to client needs and delivered onsite or online. Training covers day-to-day CMS use, accessibility best practice, GEO/AI best practice, governance workflows and key platform features. All bespoke functionality is supported by clear user documentation to enable long-term ownership.
Following launch, clients benefit from a three-month hypercare period, with proactive monitoring, rapid issue resolution and additional guidance to refine workflows and performance.
After hypercare, users transition to our ongoing support desk and account management service, providing day-to-day assistance, technical support and strategic guidance to support continuous improvement and platform evolution. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
At the end of the contract, buyers retain full ownership of the CMS and all associated data. The platform is not proprietary to Kayo Digital, and there is no vendor lock-in.
As the buyer owns the CMS, data can be accessed and extracted directly at any time. Where support is required, Kayo Digital will assist with structured data extraction from Umbraco, including content, media assets, configuration data and any bespoke data models. Data can be provided in standard formats such as XML, JSON or CSV to support migration or archiving.
All data remains the property of the buyer at all times. Any extraction support is provided to ensure continuity, clarity and a smooth transition to another supplier or in-house team. Once offboarding is complete, access to Kayo Digital services is securely removed in line with agreed data protection and security procedures. - End-of-contract process
-
At the end of the contract, the service is offboarded in a controlled and transparent manner.
Any agreed handover activities are completed, including confirmation of access credentials, documentation of bespoke functionality and final service reporting. Once offboarding is complete, Kayo Digital securely removes its access to the platform in line with agreed security and data protection procedures.
There are no exit penalties or vendor lock-in. The process is designed to minimise disruption and ensure the buyer can continue to operate and evolve their digital service independently after contract end. - Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is designed and developed to work seamlessly across both mobile and desktop devices. We design and develop mobile, and test ensuring functionality, performance and accessibility are optimised for smartphones and tablets as well as larger screens. There is no reduction in features between devices; differences are limited to responsive layouts and interaction patterns that adapt automatically to screen size, touch input and usage context, providing a consistent and accessible user experience.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Yes. Buyers can customise the service to meet their specific organisational, user and governance requirements.
The Umbraco CMS is highly configurable, allowing buyers to tailor content structures, templates, workflows, user roles and permissions. The platform supports modular, composable components, enabling functionality to be added, removed or adapted without replatforming.
Accessibility, SEO and sustainability tooling can be configured to align with internal policies and reporting needs. The service also supports integration with third-party systems such as CRM, AI, AI search, A/B testing, personalisation, analytics, identity and payment platforms.
Customisation is delivered within a controlled, supportable framework to ensure security, performance and long-term maintainability are maintained.
Scaling
- Independence of resources
-
Kayo Digital ensures users are not affected by demand from other users by hosting the service on a serverless cloud architecture.
Each customer operates within a logically separated environment, with dedicated CMS configuration, data and integrations. The serverless architecture automatically scales resources based on real-time demand, ensuring consistent performance during traffic spikes and periods of high usage without competition for fixed resources.
Service performance, availability and capacity are continuously monitored. This approach removes the risk of resource contention between customers and ensures reliable, resilient and predictable service delivery regardless of activity elsewhere on the platform.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We use:
GA4
Google Tag Manager
Google Data Studio (Looker Studio)
Umbraco Engage
We can also provide custom dashboard within the CMS for your organisation - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Dependent on what data is required, we can provide backups/exports as part of support or include an automated export as part of the site functionality.
- Data export formats
-
- CSV
- ODF
- Other
- Data import formats
-
- CSV
- ODF
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- 99.95% uptime for sites hosted on Azure
- Approach to resilience
- The service is designed for resilience using a serverless architecture hosted on Microsoft Azure. This approach provides built-in redundancy and high availability. Continuous monitoring, automated recovery processes and regular backups ensure the platform remains reliable and available during traffic spikes, infrastructure failures or periods of increased demand.
- Outage reporting
-
The service reports outages through a combination of automated alerts and proactive communication.
Outages and critical incidents trigger automated notifications via text message and email to the Kayo Digital support team, ensuring immediate awareness and response. Where an incident impacts customers, email updates are issued to affected users, providing confirmation of the issue, progress updates and resolution details.
The service does not currently expose a public status dashboard or customer-facing API for outage reporting. Instead, communication is handled directly to ensure timely, relevant and clear updates throughout the incident lifecycle.
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
- MFA / permissions
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Build environments are segregated into development, staging and production, with role-based access, version control and controlled release processes. Vulnerability management is proactive, including regular patching, dependency updates and monitoring, with issues prioritised and remediated based on risk. Secure-by-design principles are applied from the outset, covering access control, data minimisation and hardened Open Source CMS configurations. Communication is clear and structured, with defined escalation paths, named technical contacts and transparent reporting of risks, incidents and remediation actions.
- Information security policies and processes
-
Kayo Digital follows documented information security and data protection policies designed to protect client data and ensure service continuity. Our controls include access management, secure hosting within the UK and EEA, encryption, backup and recovery procedures, incident response processes and staff security training. We operate in line with UK GDPR requirements, supported by a formal Data Protection Policy and named Data Protection Officer, and apply secure-by-design principles across development, hosting and support activities.
Kayo Digital is Cyber Essentials certified, demonstrating that we meet the UK Government’s baseline requirements for protecting systems and data against common cyber threats. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Kayo Digital follows a controlled and auditable approach to configuration and change management.
Configuration is managed using version-controlled code repositories, with clear separation between development, staging and production environments. All configuration changes are documented and reviewed to ensure consistency, security and stability.
Changes are assessed for risk and impact before implementation and are delivered through a defined change process aligned to service requirements. Where appropriate, changes are tested in non-production environments prior to release. Deployment is planned to minimise disruption, with rollback procedures in place if required. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Kayo Digital uses a proactive vulnerability management process to protect the security and availability of the service. Potential threats are assessed through continuous monitoring, regular patching and automated alerts across the platform and its dependencies. Critical vulnerabilities are prioritised and patched as soon as fixes are available, while lower-risk updates are applied during planned maintenance. Threat intelligence is sourced from cloud platform security notifications, Umbraco security notifications and supplier updates.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We use transaction monitoring to continuously check that critical website functionality is operating as expected, helping to identify potential compromises, failures or abnormal behaviour early. Platform and service alerts are reviewed by our team as they arise.
When a potential compromise or issue is detected, it is triaged immediately via our support desk, assessed for impact and risk, and escalated to the appropriate technical specialists for investigation and resolution.
Response times are governed by the agreed Service Level Agreement (SLA), ensuring timely action based on severity, with clear communication and remediation throughout the incident lifecycle. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Kayo Digital operates a structured incident management process with pre-defined procedures for common events, including service outages, security incidents and performance degradation.
Incidents can be reported by users via the support desk using email or agreed support channels during service hours. All incidents are logged, prioritised and managed in line with agreed severity levels and SLAs.
When an incident occurs, users are kept informed through direct communication, including progress updates where appropriate. Following resolution, incident reports can be provided, outlining the cause, impact, actions taken and any preventative measures implemented. This approach ensures transparency, accountability and continuous service improvement. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 2eff670c-ac7f-404f-88a6-6284afe479df
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-