Zendra: Digital Health Platform for ADHD, Autism & Neurodivergence
Zendra Navigator is a software solution uniting clinicians, adults, parents, and teachers to deliver efficient, effective, and safer neurodevelopmental assessment and treatment at scale. Optimised for ADHD and Autism but condition-agnostic, it adapts to complex pathways requiring multiple stakeholders.
Features
- One Unified Touchpoint: For clinicians, parents, patients, adults and teachers.
- Automated Data Collection: Automatically collects assessments, tracks medication, and follow-ups.
- Ambient Voice Documentation: Transcribes sessions in real-time, reducing administrative burden.
- Medication Optimisation: Supports safer, data-driven prescribing and patient monitoring.
- Unlimited Custom Reports: Generate assessment reports, GP letters, prescriptions quickly.
- Highly Interoperable: Integrates with EHRs using open standards and APIs.
- Streamlined Case Management: Tracks patient journey, outcomes, KPIs, and reminders.
- Centralised Appointment Booking: Scheduling and reminders, integrates with existing systems.
- Clinical-Grade Design: Follows strict clinical safety principles and best practices.
- Rapidly Configurable: Digitises pathways with custom forms and workflows.
Benefits
- Reduced Clinical Risk: Built on validated, evidence-based clinical protocols.
- Improved Patient Outcomes: Secure portal supports guideline adherence and engagement.
- Waitlist Reduction: Automated assessments and reminders reduce patient waiting times.
- More Face-to-Face Time: Ambient voice transcription lets clinicians focus patients.
- Reduced Administrative Burden: Simplifies documentation, coordination, and monitoring workflows.
- Safer Prescribing: Optimisation engine enables safer, data-driven medication decisions.
- Standardisation & Governance: Centralises care, enforcing local clinical guidelines consistently.
- Centralised Communication: Unites clinicians, patients, families, and schools securely.
- Seamless Integration: Connects with EHRs using open standards, avoiding duplication.
- Rapid Deployment: Quickly deploys, digitising neurodevelopmental pathways without delays.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 6 6 2 8 5 6 4 8 0 9 5 4 9 5
Contact
Zendra Ltd
Thomas Coleman
Telephone: +447447188406
Email: thomas.coleman@zendrahealth.com
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
- Document
Content services
- Content Sharing and Collaboration Applications
Persuasive content management
- Website Software
- Digital Asset Management Applications
- Digital Adoption Platform
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Navigator can be used standalone or as part of Zendra Health's other products, such as Virtual Ward or third-party systems such as patient management systems, electronic health records, BI Tools and appointment scheduling solutions.
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
- Chrome/Firefox/Safari browser or Microsoft Edge version 15+
User support
- Email or online ticketing support
- Yes
- Support response times
-
Zendra Health's support response time and resolution time depends on the priority of the ticket raised.
Priority is categorised into Critical, High, Medium, Low and Query.
- Critical - Response time: 2 Hours during working hours, 3 hours outside of working hours. Resolution time: 12 hours.
- High - Response time: 4 Hours during working hours, 6 hours outside of working hours. Resolution time: 24 hours.
- Medium - Response time: 1 working day. Resolution time: 3 working days.
Low - Response time: 2 working days, Resolution time: 5 working days hours.
Query - Response time: 3 working days. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
24/7 support is available through customer helpdesk web portal, email and phone.
Zendra Health includes customer support services in our rates. Customer on-boarding and ongoing support is provided on-site and off-site through a dedicated client manager.
Zendra Health will collaborate with the organisation to determine the level of support required and create an appropriate plan to meet the needs.
Standard Daily Rate applies for custom support, see Pricing Model for details. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
On-site, off-site onboarding support and user documentation is provided to configure Navigator for the care team's needs and post-launch support.
Training protocols are in place to ensure staff are adequately trained, and a knowledge base provided within Navigator contains information and guides to Navigator functionality.
The Service has a Onboarding Standard Operating Procedure that outlines instructions as follows:
1) Determine if integration with existing healthcare systems is required and liaise accordingly.
2) Capture the information required for the patient's episode of care, from referral, triage, intervention/assessment, to discharge and the assessment forms required.
3) Capture the required clinical and operational KPIs.
4) Capture the case management views required
5) Capture the documents that need to be auto-generated (e.g. discharge summary, appointment letters)
6) Determine if other modules within Navigator (e.g. scheduling, alerts) are required and configure accordingly.
7) Governance and access control requirements are captured - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
In accordance to the Off-boarding Standard Operating Procedure, the user must contact Zendra Health DPO team to request their service to be off-boarded.
As part of the off-boarding process, the user may extract their data using the API provided by the Zendra Health. - End-of-contract process
- All of the above is included in the price of the contract except for Migrating records to a different system which is a separate scope of work to be performed in a time and materials basis, as specified in Standard Daily rate in the Pricing Model.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Service is responsive to screen size. If service detects a smaller device, the side menu is collapsible under a 'hamburger' menu
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Users can access Navigator by visiting the Zendra's Navigator website using a supported web browser.
The Service Interface is a web-based Graphical User Interface (GUI) which is designed for be responsive for different screen resolutions. Once authorised, user can interact with the Service Interface on their web browser. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Zendra conducted interface testing with real users of assistive technology, including screen reader users (JAWS, NVDA) and individuals relying on keyboard-only navigation.
Feedback from these users was directly incorporated to improve navigation, form accessibility, labeling, and overall usability.
The platform is designed in accordance with WCAG 2.1 AA accessibility standards, ensuring that clinicians, parents, and carers with disabilities can access all features effectively. - API
- Yes
- What users can and can't do using the API
-
Navigator is built on top of an API that can be leveraged by users. Theoretically, the API can provide the exact same functionality provided by the Service User Interface.
API on-boarding Process - a user that require API access must contact Service's IT team to request access for API on-boarding specifying what API integrations are required. The request is reviewed the DPO team and if the request meets the on-boarding requirements and passes security review, API credentials are granted to the User with a level of 'least privilege' access using a granular role/privilege based access to the Service API.
Each API interaction requires a particular access-level privilege that may be associated with a user role. For example, a user may have read access to a particular API entrypoint but may not have write access and therefore would not have the privilege to perform updates for that particular interface.
API Documentation - The User can access the API Documentation web-based interface available on the Service OpenAPI Specification (OAS) which provides the ability to discover and understand the capabilities of the Service. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Navigator is a highly customizable system that allows care teams to configure and record information related to patients' episodes of care, clinical workflows, letter generation and patient portal content using an in-built content management system
Scaling
- Independence of resources
-
Navigator is designed to scale horizontally by gracefully handle increased load by adding more resources such as servers or instances through auto-scaling.
Separation of concerns is in place to ensure that any potential heavy loads on the Service such as Analytics is isolated (separate read-only database instance) and does not impact other service critical areas.
Real-time performance monitoring is in place to identify any performance degradation in place.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Navigator provides insights into platform usage, access control, clinical KPIs and operational KPIs.
i) Platform usage analytics includes number of care team users, no. of patients, page access count.
ii) Access control analytics includes number of active care team users , last active care team users.
iii) Clinical KPIs include patient breakdowns by age, demographic, diagnosis and much more.
iv) Operational KPIs include number of referrals, last seen, number of contacts, number of DNAs/CNAs, attended. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- KPI reports and forms can be exported to PDF and excel within the Service Interface. Users can export their data using the API interface.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
- JSON format
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- JSON format
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- Extra network isolation controls are in place to ensure that all traffic remains in private networks, is encrypted at all times whilst in transit.
Availability and resilience
- Guaranteed availability
-
Zendra Health SLAs guarantee a minimum level of uptime for our service, typically expressed as a percentage of time that the service will be operational within a given period, such as 99.9% uptime per month. In the event that the service fail to meet these guaranteed levels of availability, Zendra Health offers refunds or service credits to affected users.
Refunds are processed automatically based on the duration and severity of the downtime experienced. Users are eligible for refunds if the service falls below the agreed-upon availability threshold, as specified in our SLAs. Refunds may be issued in the form of credits applied to future service fees or as monetary reimbursement, depending on the terms outlined in the SLA. - Approach to resilience
- Documentation with regards to resiliency can be made available on request.
- Outage reporting
- Service can report outages using an automated tool that detects downtime in the system and emails users when there is system outage. Separately, a service dashboard exists which display uptime status.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
-
The Service support three-factor authentication which is the provision of:
1) A username and password, whereby password is checked on registration to ensure it not exposed as part of an existing data breach (pwned).
2) A One-Time Passcode that generated in a separate device (Authenticator App on the phone).
3) IP address of the deployed service (private network IP or VPN). - Access restrictions in management interfaces and support channels
- Management Interfaces are protected by three-factor authentication which requires username/password, a one-time passcode and an IP address which is on the IP whitelist. Support channels have spam filtering in place and staff are trained in process customer support queries, with strict protocols in place to prevent inadvertent information disclosure.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Other
- Description of management access authentication
- The Service uses role/privilege based access whereby each component on the Service Interface requiring the appropriate privilege in order to read and update. The principle of least privilege is applied to all user accounts.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
-
Cyber Essentials Plus
UK GDPR / Data Protection Act 2018 compliance
NIST Cybersecurity Framework - Information security policies and processes
-
As part of Zendra Health's IT Standard Operating Procedure, a comprehensive set of information security policies and processes to safeguard sensitive data and mitigate potential risks are outlined/documented. All employees are trained on the IT Security Policy and staff receive training to any modifications made to this.
Procedures are outlined for:
1) New accounts.
2) Account Lockout.
3) Account Reactivation.
4) Account Deletion.
5) Use of credentials.
6) Service On-boarding.
7) Service Off-boarding.
The following policies are outlined:
i) Network Security and VPN Acceptable Use Policy.
ii) Internet Usage Policy.
ii) Password Policy.
iv) Partner Security Guidelines Policy.
v) Backups Policy.
vi) Data Protection Policy.
vii) Incident Response Policy.
viii) Security Incident Response Policy.
ix) Handling Sensitive Data Policy including Data Processing, Handling and Retention.
As an ISO-13845 certified company, the Service maintains a Resource Management Standard Operating Procedure that outlines work instructions for the set-up and restoration of the IT cloud system, including the documentation of maintenance logs, with all equipment and software tools qualified and validated. Separately, all Suppliers are strictly qualified and validated as part of Supplier Management Standard Operating Procedure.
Senior management meets regularly to review key quality objectives related to customer satisfaction, resource capacity/supplier management. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
As an ISO 13485-certified company, Zendra Health has strict controls in place for configuration and change management processes.
All assets are uniquely traced within Equipment and Software tool logs, with each asset have been qualified and validated to ensure the asset meets the intended use from a performance and functional standpoint.
Each upgrade may trigger a re-qualification and validation of the assets, with all changes recorded as part of a Change Request Standard Operating Procedure. Controls are in place to perform continuous monitoring including vulnerability scanning, static analysis and multiple external audits are conducted annually to ensure continuous improvement. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Zendra Heath has a Cyber Security Standard Operating Procedure in place which must protect from damaging acts through the complete life-cycle of products and services.
Monitoring is performing across various sources such as NIST-NVD, Mitre CVE, Complaints, Vendors, Automated Security Vulnerability Scanning, External Pen Tests, Security Training, Research Boards, that generates inputs which are then Triage and screened for applicability. Using a risk-based approach, if the input is deemed applicable, a CVE score is applied. if the CVE score is critical, the patch is deployed immediately, otherwise a patch will be deployed within the next 2 days. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Zendra has Continuous Monitoring to analyse network traffic and analyse user activities on IT infrastructure, that generates inputs which are then Triage and screened for applicability. Using a risk-based approach, if the input is deemed applicable, a CVE score is applied. If the CVE score is critical, the patch is deployed immediately, otherwise a patch will be deployed within the next 2 days.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Monitoring is performing across various sources such as detecting system anomalies and monitor external threats such as TypoSquating, Complaints that generates inputs which are then Triage and screened for applicability. Using a risk-based approach, if the input is deemed applicable, a CVE score is applied. If the CVE score is critical, the patch is deployed immediately, otherwise a patch will be deployed within the next 2 days. An incident report is generated as part of the risk management review to determine whether root cause has been addressed and to prevent further reocurrence.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- A demo version of Zendra Navigator is available for trial purposes. Contact hello@zendrahealth.com for further information.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 8d223229-0267-4f45-808d-a62abe8956c5
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 95f8e442-b54d-4db8-a4f1-919877288975
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-