Skip to main content

Help us improve the Digital Marketplace - send your feedback

KAYO DIGITAL LIMITED

Digital Experience Platform

As an Umbraco Gold Partner, Kayo Digital delivers a Digital Experience Platform that helps organisations create inclusive, high-impact digital services people value. Built to be accessible, and future-ready, our platform unifies content, insight and user data, enabling you to engage audiences today while evolving with changing needs, expectations and technology

Features

  • AI Search capabilities within the website
  • Umbraco CMS version control
  • Multilingual capabilities and is Welsh Language Standards compliant
  • Ongoing support of Open Source CMS websites
  • Multi stage approvals and content governance
  • Open Source CMS secure managed EEA & UK hosting
  • WCAG 2.2 accessibility audit tool in the CMS
  • Modular, composable architecture
  • Optimised for SEO & GEO & AI
  • AI content creation within the backend of the CMS

Benefits

  • CMS has no license fees as it's open source
  • No vendor lock-in through open-source technology
  • Lower long-term costs through modular architecture
  • Strong governance with configurable workflows
  • Faster content updates for non-technical users
  • Website ready to grow with AI/SEO/GEO optimisation
  • CMS is fully customisable for your organisation
  • Ai search helps users find information faster and more accurately
  • Built-in WCAG 2.2 accessibility compliance support
  • Ai content creation speeds up content creation for busy teams

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@kayo.digital. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 6 2 5 6 2 8 6 4 4 0 7 9 6 6

Contact

KAYO DIGITAL LIMITED Harry Dance
Telephone: 01795 255600
Email: sales@kayo.digital

About your service

Service categories

Applications

Content workflow and management

  • Media Services
  • Creative

Content services

  • Enterprise Content Management Applications

Persuasive content management

  • Website Software
  • Digital Asset Management Applications
  • Product Content Management Applications
  • Content Marketing Applications
  • Video Platforms
  • Digital Adoption Platform

Enterprise portals and digital workspaces

  • Multi-Audience Portals
  • Integrated Employee Workspaces
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
None
System requirements
None

User support

Email or online ticketing support
Yes
Support response times
Response times are assessed against the Service Level Agreement during standard service hours, 09:00–17:00, Monday to Friday. Support is provided via the agreed channels during these hours only. Email and ticket-based support are not available outside of service hours, including weekends and UK Bank Holidays.

Emails sent to support@kayo.digital for general support queries will receive an update within 8 working hours Target - 90%

Weekends are considered out of hours and have different response times.

Out of hours services come at a separate cost to a standard support package.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Kayo Digital provides ITIL-aligned support for cloud-based digital services via telephone and online channels. A single point of contact service desk manages all incidents, service requests and technical queries, ensuring clear ownership and efficient resolution.

All issues are logged, prioritised and tracked in line with agreed Service Level Agreements (SLAs). Response times are defined by incident severity, with immediate logging and initial responses typically within 30 minutes to 1 service hour.

Standard support hours are 09:00–17:00 (UK time), Monday to Friday, excluding UK Bank Holidays.

With Kayo Digital's hosting and support, the agency provides regular updates, patches and continuous improvement.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Kayo Digital supports users through a structured onboarding and adoption approach, ensuring confident use of the platform from launch.

Before go-live, we provide a dedicated staging environment for testing and user acceptance testing (UAT). We can also deliver role-based training for content editors and administrators, tailored to client needs and delivered onsite or online. Training covers day-to-day CMS use, accessibility best practice, GEO/AI best practice, governance workflows and key platform features. All bespoke functionality is supported by clear user documentation to enable long-term ownership.

Following launch, clients benefit from a three-month hypercare period, with proactive monitoring, rapid issue resolution and additional guidance to refine workflows and performance.

After hypercare, users transition to our ongoing support desk and account management service, providing day-to-day assistance, technical support and strategic guidance to support continuous improvement and platform evolution.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
At the end of the contract, buyers retain full ownership of the CMS and all associated data. The platform is not proprietary to Kayo Digital, and there is no vendor lock-in.

As the buyer owns the CMS, data can be accessed and extracted directly at any time. Where support is required, Kayo Digital will assist with structured data extraction from Umbraco, including content, media assets, configuration data and any bespoke data models. Data can be provided in standard formats such as XML, JSON or CSV to support migration or archiving.

All data remains the property of the buyer at all times. Any extraction support is provided to ensure continuity, clarity and a smooth transition to another supplier or in-house team. Once offboarding is complete, access to Kayo Digital services is securely removed in line with agreed data protection and security procedures.
End-of-contract process
At the end of the contract, the service is offboarded in a controlled and transparent manner.

Any agreed handover activities are completed, including confirmation of access credentials, documentation of bespoke functionality and final service reporting. Once offboarding is complete, Kayo Digital securely removes its access to the platform in line with agreed security and data protection procedures.

There are no exit penalties or vendor lock-in. The process is designed to minimise disruption and ensure the buyer can continue to operate and evolve their digital service independently after contract end.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is designed and developed to work seamlessly across both mobile and desktop devices. We design and develop mobile, and test ensuring functionality, performance and accessibility are optimised for smartphones and tablets as well as larger screens. There is no reduction in features between devices; differences are limited to responsive layouts and interaction patterns that adapt automatically to screen size, touch input and usage context, providing a consistent and accessible user experience.
Service interface
No
User support accessibility
WCAG 2.2 AA
API
No
Customisation available
Yes
Description of customisation
Yes. Buyers can customise the service to meet their specific organisational, user and governance requirements.

The Umbraco CMS is highly configurable, allowing buyers to tailor content structures, templates, workflows, user roles and permissions. The platform supports modular, composable components, enabling functionality to be added, removed or adapted without replatforming.

Accessibility, SEO and sustainability tooling can be configured to align with internal policies and reporting needs. The service also supports integration with third-party systems such as CRM, AI, AI search, A/B testing, personalisation, analytics, identity and payment platforms.

Customisation is delivered within a controlled, supportable framework to ensure security, performance and long-term maintainability are maintained.

Scaling

Independence of resources
Kayo Digital ensures users are not affected by demand from other users by hosting the service on a serverless cloud architecture.

Each customer operates within a logically separated environment, with dedicated CMS configuration, data and integrations. The serverless architecture automatically scales resources based on real-time demand, ensuring consistent performance during traffic spikes and periods of high usage without competition for fixed resources.

Service performance, availability and capacity are continuously monitored. This approach removes the risk of resource contention between customers and ensures reliable, resilient and predictable service delivery regardless of activity elsewhere on the platform.

Analytics

Service usage metrics
Yes
Metrics types
We use:
GA4
Google Tag Manager
Google Data Studio (Looker Studio)
Umbraco Engage
We can also provide custom dashboard within the CMS for your organisation
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Dependent on what data is required, we can provide backups/exports as part of support or include an automated export as part of the site functionality.
Data export formats
  • CSV
  • ODF
  • Other
Data import formats
  • CSV
  • ODF
  • Other

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
99.95% uptime for sites hosted on Azure
Approach to resilience
The service is designed for resilience using a serverless architecture hosted on Microsoft Azure. This approach provides built-in redundancy and high availability. Continuous monitoring, automated recovery processes and regular backups ensure the platform remains reliable and available during traffic spikes, infrastructure failures or periods of increased demand.
Outage reporting
The service reports outages through a combination of automated alerts and proactive communication.

Outages and critical incidents trigger automated notifications via text message and email to the Kayo Digital support team, ensuring immediate awareness and response. Where an incident impacts customers, email updates are issued to affected users, providing confirmation of the issue, progress updates and resolution details.

The service does not currently expose a public status dashboard or customer-facing API for outage reporting. Instead, communication is handled directly to ensure timely, relevant and clear updates throughout the incident lifecycle.

Identity and authentication

User authentication needed
No
Access restrictions in management interfaces and support channels
MFA / permissions
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Build environments are segregated into development, staging and production, with role-based access, version control and controlled release processes. Vulnerability management is proactive, including regular patching, dependency updates and monitoring, with issues prioritised and remediated based on risk. Secure-by-design principles are applied from the outset, covering access control, data minimisation and hardened Open Source CMS configurations. Communication is clear and structured, with defined escalation paths, named technical contacts and transparent reporting of risks, incidents and remediation actions.
Information security policies and processes
Kayo Digital follows documented information security and data protection policies designed to protect client data and ensure service continuity. Our controls include access management, secure hosting within the UK and EEA, encryption, backup and recovery procedures, incident response processes and staff security training. We operate in line with UK GDPR requirements, supported by a formal Data Protection Policy and named Data Protection Officer, and apply secure-by-design principles across development, hosting and support activities.

Kayo Digital is Cyber Essentials certified, demonstrating that we meet the UK Government’s baseline requirements for protecting systems and data against common cyber threats.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Kayo Digital follows a controlled and auditable approach to configuration and change management.

Configuration is managed using version-controlled code repositories, with clear separation between development, staging and production environments. All configuration changes are documented and reviewed to ensure consistency, security and stability.

Changes are assessed for risk and impact before implementation and are delivered through a defined change process aligned to service requirements. Where appropriate, changes are tested in non-production environments prior to release. Deployment is planned to minimise disruption, with rollback procedures in place if required.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Kayo Digital uses a proactive vulnerability management process to protect the security and availability of the service. Potential threats are assessed through continuous monitoring, regular patching and automated alerts across the platform and its dependencies. Critical vulnerabilities are prioritised and patched as soon as fixes are available, while lower-risk updates are applied during planned maintenance. Threat intelligence is sourced from cloud platform security notifications, Umbraco security notifications and supplier updates.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use transaction monitoring to continuously check that critical website functionality is operating as expected, helping to identify potential compromises, failures or abnormal behaviour early. Platform and service alerts are reviewed by our team as they arise.

When a potential compromise or issue is detected, it is triaged immediately via our support desk, assessed for impact and risk, and escalated to the appropriate technical specialists for investigation and resolution.

Response times are governed by the agreed Service Level Agreement (SLA), ensuring timely action based on severity, with clear communication and remediation throughout the incident lifecycle.
Incident management type
Supplier-defined controls
Incident management approach
Kayo Digital operates a structured incident management process with pre-defined procedures for common events, including service outages, security incidents and performance degradation.

Incidents can be reported by users via the support desk using email or agreed support channels during service hours. All incidents are logged, prioritised and managed in line with agreed severity levels and SLAs.

When an incident occurs, users are kept informed through direct communication, including progress updates where appropriate. Following resolution, incident reports can be provided, outlining the cause, impact, actions taken and any preventative measures implemented. This approach ensures transparency, accountability and continuous service improvement.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
2eff670c-ac7f-404f-88a6-6284afe479df
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@kayo.digital. Tell them what format you need. It will help if you say what assistive technology you use.