Skip to main content

Help us improve the Digital Marketplace - send your feedback

Zendra Ltd

Zendra: Digital Health Platform for ADHD, Autism & Neurodivergence

Zendra Navigator is a software solution uniting clinicians, adults, parents, and teachers to deliver efficient, effective, and safer neurodevelopmental assessment and treatment at scale. Optimised for ADHD and Autism but condition-agnostic, it adapts to complex pathways requiring multiple stakeholders.

Features

  • One Unified Touchpoint: For clinicians, parents, patients, adults and teachers.
  • Automated Data Collection: Automatically collects assessments, tracks medication, and follow-ups.
  • Ambient Voice Documentation: Transcribes sessions in real-time, reducing administrative burden.
  • Medication Optimisation: Supports safer, data-driven prescribing and patient monitoring.
  • Unlimited Custom Reports: Generate assessment reports, GP letters, prescriptions quickly.
  • Highly Interoperable: Integrates with EHRs using open standards and APIs.
  • Streamlined Case Management: Tracks patient journey, outcomes, KPIs, and reminders.
  • Centralised Appointment Booking: Scheduling and reminders, integrates with existing systems.
  • Clinical-Grade Design: Follows strict clinical safety principles and best practices.
  • Rapidly Configurable: Digitises pathways with custom forms and workflows.

Benefits

  • Reduced Clinical Risk: Built on validated, evidence-based clinical protocols.
  • Improved Patient Outcomes: Secure portal supports guideline adherence and engagement.
  • Waitlist Reduction: Automated assessments and reminders reduce patient waiting times.
  • More Face-to-Face Time: Ambient voice transcription lets clinicians focus patients.
  • Reduced Administrative Burden: Simplifies documentation, coordination, and monitoring workflows.
  • Safer Prescribing: Optimisation engine enables safer, data-driven medication decisions.
  • Standardisation & Governance: Centralises care, enforcing local clinical guidelines consistently.
  • Centralised Communication: Unites clinicians, patients, families, and schools securely.
  • Seamless Integration: Connects with EHRs using open standards, avoiding duplication.
  • Rapid Deployment: Quickly deploys, digitising neurodevelopmental pathways without delays.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at thomas.coleman@zendrahealth.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 6 6 2 8 5 6 4 8 0 9 5 4 9 5

Contact

Zendra Ltd Thomas Coleman
Telephone: +447447188406
Email: thomas.coleman@zendrahealth.com

About your service

Service categories

Applications

Content workflow and management

  • Capture
  • Document

Content services

  • Content Sharing and Collaboration Applications

Persuasive content management

  • Website Software
  • Digital Asset Management Applications
  • Digital Adoption Platform

Enterprise portals and digital workspaces

  • Multi-Audience Portals
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Navigator can be used standalone or as part of Zendra Health's other products, such as Virtual Ward or third-party systems such as patient management systems, electronic health records, BI Tools and appointment scheduling solutions.
Cloud deployment model
Public cloud
Service constraints
No
System requirements
Chrome/Firefox/Safari browser or Microsoft Edge version 15+

User support

Email or online ticketing support
Yes
Support response times
Zendra Health's support response time and resolution time depends on the priority of the ticket raised.

Priority is categorised into Critical, High, Medium, Low and Query.

- Critical - Response time: 2 Hours during working hours, 3 hours outside of working hours. Resolution time: 12 hours.
- High - Response time: 4 Hours during working hours, 6 hours outside of working hours. Resolution time: 24 hours.
- Medium - Response time: 1 working day. Resolution time: 3 working days.

Low - Response time: 2 working days, Resolution time: 5 working days hours.

Query - Response time: 3 working days.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
24/7 support is available through customer helpdesk web portal, email and phone.

Zendra Health includes customer support services in our rates. Customer on-boarding and ongoing support is provided on-site and off-site through a dedicated client manager.

Zendra Health will collaborate with the organisation to determine the level of support required and create an appropriate plan to meet the needs.

Standard Daily Rate applies for custom support, see Pricing Model for details.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
On-site, off-site onboarding support and user documentation is provided to configure Navigator for the care team's needs and post-launch support.

Training protocols are in place to ensure staff are adequately trained, and a knowledge base provided within Navigator contains information and guides to Navigator functionality.

The Service has a Onboarding Standard Operating Procedure that outlines instructions as follows:

1) Determine if integration with existing healthcare systems is required and liaise accordingly.

2) Capture the information required for the patient's episode of care, from referral, triage, intervention/assessment, to discharge and the assessment forms required.

3) Capture the required clinical and operational KPIs.

4) Capture the case management views required

5) Capture the documents that need to be auto-generated (e.g. discharge summary, appointment letters)

6) Determine if other modules within Navigator (e.g. scheduling, alerts) are required and configure accordingly.

7) Governance and access control requirements are captured
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
In accordance to the Off-boarding Standard Operating Procedure, the user must contact Zendra Health DPO team to request their service to be off-boarded.

As part of the off-boarding process, the user may extract their data using the API provided by the Zendra Health.
End-of-contract process
All of the above is included in the price of the contract except for Migrating records to a different system which is a separate scope of work to be performed in a time and materials basis, as specified in Standard Daily rate in the Pricing Model.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Service is responsive to screen size. If service detects a smaller device, the side menu is collapsible under a 'hamburger' menu
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Users can access Navigator by visiting the Zendra's Navigator website using a supported web browser.

The Service Interface is a web-based Graphical User Interface (GUI) which is designed for be responsive for different screen resolutions. Once authorised, user can interact with the Service Interface on their web browser.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Zendra conducted interface testing with real users of assistive technology, including screen reader users (JAWS, NVDA) and individuals relying on keyboard-only navigation.

Feedback from these users was directly incorporated to improve navigation, form accessibility, labeling, and overall usability.

The platform is designed in accordance with WCAG 2.1 AA accessibility standards, ensuring that clinicians, parents, and carers with disabilities can access all features effectively.
API
Yes
What users can and can't do using the API
Navigator is built on top of an API that can be leveraged by users. Theoretically, the API can provide the exact same functionality provided by the Service User Interface.

API on-boarding Process - a user that require API access must contact Service's IT team to request access for API on-boarding specifying what API integrations are required. The request is reviewed the DPO team and if the request meets the on-boarding requirements and passes security review, API credentials are granted to the User with a level of 'least privilege' access using a granular role/privilege based access to the Service API.

Each API interaction requires a particular access-level privilege that may be associated with a user role. For example, a user may have read access to a particular API entrypoint but may not have write access and therefore would not have the privilege to perform updates for that particular interface.

API Documentation - The User can access the API Documentation web-based interface available on the Service OpenAPI Specification (OAS) which provides the ability to discover and understand the capabilities of the Service.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Navigator is a highly customizable system that allows care teams to configure and record information related to patients' episodes of care, clinical workflows, letter generation and patient portal content using an in-built content management system

Scaling

Independence of resources
Navigator is designed to scale horizontally by gracefully handle increased load by adding more resources such as servers or instances through auto-scaling.

Separation of concerns is in place to ensure that any potential heavy loads on the Service such as Analytics is isolated (separate read-only database instance) and does not impact other service critical areas.

Real-time performance monitoring is in place to identify any performance degradation in place.

Analytics

Service usage metrics
Yes
Metrics types
Navigator provides insights into platform usage, access control, clinical KPIs and operational KPIs.

i) Platform usage analytics includes number of care team users, no. of patients, page access count.

ii) Access control analytics includes number of active care team users , last active care team users.

iii) Clinical KPIs include patient breakdowns by age, demographic, diagnosis and much more.

iv) Operational KPIs include number of referrals, last seen, number of contacts, number of DNAs/CNAs, attended.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
KPI reports and forms can be exported to PDF and excel within the Service Interface. Users can export their data using the API interface.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
JSON format
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
JSON format

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Extra network isolation controls are in place to ensure that all traffic remains in private networks, is encrypted at all times whilst in transit.

Availability and resilience

Guaranteed availability
Zendra Health SLAs guarantee a minimum level of uptime for our service, typically expressed as a percentage of time that the service will be operational within a given period, such as 99.9% uptime per month. In the event that the service fail to meet these guaranteed levels of availability, Zendra Health offers refunds or service credits to affected users.

Refunds are processed automatically based on the duration and severity of the downtime experienced. Users are eligible for refunds if the service falls below the agreed-upon availability threshold, as specified in our SLAs. Refunds may be issued in the form of credits applied to future service fees or as monetary reimbursement, depending on the terms outlined in the SLA.
Approach to resilience
Documentation with regards to resiliency can be made available on request.
Outage reporting
Service can report outages using an automated tool that detects downtime in the system and emails users when there is system outage. Separately, a service dashboard exists which display uptime status.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Other user authentication
The Service support three-factor authentication which is the provision of:

1) A username and password, whereby password is checked on registration to ensure it not exposed as part of an existing data breach (pwned).
2) A One-Time Passcode that generated in a separate device (Authenticator App on the phone).
3) IP address of the deployed service (private network IP or VPN).
Access restrictions in management interfaces and support channels
Management Interfaces are protected by three-factor authentication which requires username/password, a one-time passcode and an IP address which is on the IP whitelist. Support channels have spam filtering in place and staff are trained in process customer support queries, with strict protocols in place to prevent inadvertent information disclosure.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Description of management access authentication
The Service uses role/privilege based access whereby each component on the Service Interface requiring the appropriate privilege in order to read and update. The principle of least privilege is applied to all user accounts.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials Plus
UK GDPR / Data Protection Act 2018 compliance
NIST Cybersecurity Framework
Information security policies and processes
As part of Zendra Health's IT Standard Operating Procedure, a comprehensive set of information security policies and processes to safeguard sensitive data and mitigate potential risks are outlined/documented. All employees are trained on the IT Security Policy and staff receive training to any modifications made to this.

Procedures are outlined for:

1) New accounts.
2) Account Lockout.
3) Account Reactivation.
4) Account Deletion.
5) Use of credentials.
6) Service On-boarding.
7) Service Off-boarding.

The following policies are outlined:
i) Network Security and VPN Acceptable Use Policy.
ii) Internet Usage Policy.
ii) Password Policy.
iv) Partner Security Guidelines Policy.
v) Backups Policy.
vi) Data Protection Policy.
vii) Incident Response Policy.
viii) Security Incident Response Policy.
ix) Handling Sensitive Data Policy including Data Processing, Handling and Retention.

As an ISO-13845 certified company, the Service maintains a Resource Management Standard Operating Procedure that outlines work instructions for the set-up and restoration of the IT cloud system, including the documentation of maintenance logs, with all equipment and software tools qualified and validated. Separately, all Suppliers are strictly qualified and validated as part of Supplier Management Standard Operating Procedure.

Senior management meets regularly to review key quality objectives related to customer satisfaction, resource capacity/supplier management.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
As an ISO 13485-certified company, Zendra Health has strict controls in place for configuration and change management processes.

All assets are uniquely traced within Equipment and Software tool logs, with each asset have been qualified and validated to ensure the asset meets the intended use from a performance and functional standpoint.

Each upgrade may trigger a re-qualification and validation of the assets, with all changes recorded as part of a Change Request Standard Operating Procedure. Controls are in place to perform continuous monitoring including vulnerability scanning, static analysis and multiple external audits are conducted annually to ensure continuous improvement.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Zendra Heath has a Cyber Security Standard Operating Procedure in place which must protect from damaging acts through the complete life-cycle of products and services.

Monitoring is performing across various sources such as NIST-NVD, Mitre CVE, Complaints, Vendors, Automated Security Vulnerability Scanning, External Pen Tests, Security Training, Research Boards, that generates inputs which are then Triage and screened for applicability. Using a risk-based approach, if the input is deemed applicable, a CVE score is applied. if the CVE score is critical, the patch is deployed immediately, otherwise a patch will be deployed within the next 2 days.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Zendra has Continuous Monitoring to analyse network traffic and analyse user activities on IT infrastructure, that generates inputs which are then Triage and screened for applicability. Using a risk-based approach, if the input is deemed applicable, a CVE score is applied. If the CVE score is critical, the patch is deployed immediately, otherwise a patch will be deployed within the next 2 days.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Monitoring is performing across various sources such as detecting system anomalies and monitor external threats such as TypoSquating, Complaints that generates inputs which are then Triage and screened for applicability. Using a risk-based approach, if the input is deemed applicable, a CVE score is applied. If the CVE score is critical, the patch is deployed immediately, otherwise a patch will be deployed within the next 2 days. An incident report is generated as part of the risk management review to determine whether root cause has been addressed and to prevent further reocurrence.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
A demo version of Zendra Navigator is available for trial purposes. Contact hello@zendrahealth.com for further information.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
8d223229-0267-4f45-808d-a62abe8956c5
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
95f8e442-b54d-4db8-a4f1-919877288975
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
    • Plans for positive actions with community groups.
    • Measures for making facilities used in the delivery of the contract available for community groups, education or training
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at thomas.coleman@zendrahealth.com. Tell them what format you need. It will help if you say what assistive technology you use.