Jadu Central and Central Lite
Jadu Central provides easy content management tools with robust governance, rich APIs for developers and microsite capabilities. It supports responsive design for accessibility on all devices. Additionally, it enables digital transactions, with non-technical tools for creating customer forms and developer tools for system integrations, including CRM and payment services.
Features
- Design tailored workflows with intuitive visual tools for publishing content.
- Ensure security with detailed access controls and comprehensive audit trails.
- Deploy multiple microsites easily with flexible multi-site capabilities.
- Edit content effortlessly with customisable WYSIWYG tools and user permissions.
- Organise data repositories and allow user contributions for structured content.
- Embed third-party content seamlessly into customisable components on homepages.
- Enhance user experience with personalised landing pages and visitor logins.
- Highly secure forms: encrypted data transfer and storage.
- Integration-ready with CRM, payments, databases and more.
- Manage multilingual sites with translation workflows and automated notifications.
Benefits
- Secure, scalable, extensible enterprise CMS for robust content management solutions.
- Accessible content, robust workflow, governance controls for engaging functionality.
- Secure, resilient hosting ensuring uninterrupted service and data protection.
- Engaging, personalised web experience enhancing user interaction and satisfaction.
- One-stop service channel, seamlessly integrated with other Jadu products.
- User-friendly interface, reducing dependency on technical staff for system management.
- Developer API facilitates easy system modification, extensions for tailored solutions.
- Replace manual processes and drive savings through transactional channel shift.
- Create accessible forms meeting WCAG standards, enhancing user experience.
- Customer data handled and stored securely for data protection compliance.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 7 2 5 8 5 8 0 0 3 4 6 2 7 6
Contact
NETCALL TECHNOLOGY LIMITED
Maston Daniel
Telephone: 0330 333 6100
Email: bid.team@netcall.com
About your service
- Service categories
-
Applications
Content workflow and management
Content services
- Enterprise Content Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
- A modern web browser is required to access the service
User support
- Email or online ticketing support
- Yes
- Support response times
- Response and resolution times depend on the nature and severity of the issue reported. Our first response to tickets typically ranges from under 1 hour and within 3 hours, depending on the nature and priority. On-call engineers monitor for service availability / P1 style issues 24/7/365. Our wider service levels for the response and resolution of issues are contained within our Service Support SLA document.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Our modern interfaces are developed using the Pulsar user interface framework are tested using desktop screenreader software, and our text editor supports a variety of screenreaders including JAWS, VoiceOver, NonVisual Desktop Access (NVDA) and ChromeVox. Additional testing has been undertaken to confirm that animated backgrounds in the software do not trigger seizure in individuals with Photosensitive epilepsy.
- Onsite support
- Yes, at extra cost
- Support levels
- We provide a level of support which is built into the monthly subscription cost. This provides an online help desk and ticketing system available 24/7 with telephone support during business hours (8am-6pm, Monday to Friday, except English Bank Holidays). On-call engineers will respond to critical availability issues outside of standard business operating hours. Our support SLA is included in the terms of service document. Our help desk is staffed with dedicated support engineers, with Operations engineers and other technical experts becoming involved to resolve support issues as necessary. Every customer has a dedicated Customer Support Analyst. An enhanced level of support (including out of hours deployments and some professional services) is available for an additional monthly premium. See lot 3 for further details.
- Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- We provide certified training for administrators, consisting of both Foundation Training (Online), and Practitioner Training (Webinar). We can optionally lead with the build of the first digital service at a cost. Additionally there is an online implementation guide and online user manuals.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- Tools are provided to export data from within the application. Form structures can be exported as ZIP files, workflows as JSON files, user submitted data can be exported in CSV and XML format. Any other form data not accessible via the export tools provided in the application can be exported via database export.
- End-of-contract process
-
On contract expiry, your platform becomes unavailable and all public-facing forms are taken offline. No further usage or subscription charges will apply. You will have access to your platform for export purposes only, for 30 days post contract expiry. After the 30 day period all content and data will be deleted permanently.
Should you require data migration assistance, Jadu is happy to provide professional services. An exit plan and quote will be provided on request. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The platform uses responsive web design to allow the same interfaces to adapt and be displayed on devices of different dimensions. This means that both desktop and mobile users can access the same features in the same place, giving a consistent experience across all a user's devices.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Our modern interfaces are developed using the Pulsar user interface framework. The platform uses responsive web design to allow the same interfaces to adapt and be displayed on devices of different dimensions. This means that both desktop and mobile users can access the same features in the same place, giving a consistent experience across all a user's devices.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Our modern interfaces are developed using the Pulsar user interface framework are tested using desktop screenreader software, and our text editor supports a variety of screenreaders including JAWS, VoiceOver, NonVisual Desktop Access (NVDA) and ChromeVox. Additional testing has been undertaken to confirm that animated backgrounds in the software do not trigger seizure in individuals with Photosensitive epilepsy.
- API
- Yes
- What users can and can't do using the API
- Jadu Central supplies both a PHP and RESTful XML API. The PHP API is fully functional, allowing both read and write of application data. The RESTful XML API allows users with an authorised API key to access publicly available content already published to the website.
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- A broad range of settings can be adjusted from within the application user interfaces. Additional custom functionality can be developed to extend the core feature set. For forms and website components, skinning is possible through web template design.
Scaling
- Independence of resources
- Monitoring tools are used to measure usage of the application and where necessary additional resources can be added.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Data Export allows you to bulk export received forms data from Jadu Central for processing and MI reporting.
- Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
- Other
- Other data at rest protection approach
- The hosting infrastructure and any associated storage / backups upon which the platform is implemented are encrypted. Sensitive data is also encrypted by the Platform as it is written to the database: - Any data submitted by a member of the public, including their personal details, form submissions, form attachments uploaded, case data (where the given case field is configured as 'sensitive') - The personal details of internal users of the system - IP addresses - API access credentials. Any passwords are stored as hashes created using adaptive, one-way password hashing.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Through the service application interface.
- Data export formats
-
- CSV
- Other
- Other data export formats
- XML
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- CSV import into directories
- Form import in zip file format
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- Data exchange within various internal networks may use a combination of IPSec VPNs, SSH, TLS or Encrypted RDP protocols. Data at rest is stored encrypted.
Availability and resilience
- Guaranteed availability
- Our service availability target is 99.9% (as measured over the subscription period) excluding planned maintenance. Our SLA is contained within our terms of service.
- Approach to resilience
- The network is resilient. Application resilience is dependent upon the options chosen by the customer, our PLATINUM hosting option incorporates a specific High Availability (HA) option for those requiring additional resilience. Further information is available on request.
- Outage reporting
- We use a set of monitoring solutions which notify our teams of any outages using a selection of dashboards, email alerts, Slack notifications and SMS messages. We maintain a public dashboard.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
- Federated Authentication (SAML)
- Access restrictions in management interfaces and support channels
-
Management interfaces are restricted based on the role or specific permissions assigned to a given user account.
Support channels are restricted to named users for whom a username is created and provided. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
-
Federated authentication (via SAML or LDAP)
Native username and password, with optional 2FA
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- ISO 9001:2015
- Information security policies and processes
- Jadu has a Security Council, within which sits Jadu's CTO and SVP Legal & Commercial who are both executive directors and responsible parties on relevant matters of security to their own areas. Jadu’s security governance framework has been designed in accordance with ISO 27001. Full details are broken down and contained in Jadu’s ISO 27001 Operating Manual and Information Security Policy, both available by request. Jadu staff will follow the processes as detailed in our "Incident Management Policy" and "Incident Management Procedure" documents for any security incidents. The security council will review any such incidents and conformances at their quarterly review meeting.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Initial service configuration is committed to repositories. Commits to repositories undergo peer review. Any future configuration changes are first tested on DEV systems from where they are deployed to UAT and finally after customer approval to LIVE.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Continuous scanning of all Jadu managed infrastructure is in place via AWS Security Hub and AWS Control Tower. AWS Security Hub cloud security posture management (CSPM) service performs security best practice checks, aggregates alerts, and enables automated remediation. Control Tower monitors that all accounts align with established, company-wide compliance policies. Jadu's operations team are subscribed to Common Vulnerabilities and Exposures (CVE) reports via www.cve.org. Monthly patching cycles operate for hosted customer infrastructure, staggered by one week to allow testing prior to application to PROD. Critical / zero-day vulnerabilities will receive expedited rollout usually within 24-48 hours to all hosting infrastructure.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Internal and external monitoring systems monitor server health in real time. A web application firewall protects from various web attacks. Infrastructure is constantly monitored by an IDS solution provided by AlertLogic. Suspicious activities are analysed by AlertLogic engineers. If malicious the offending IP will get a default 24h shun. Continuous scanning of all managed infrastructure is in place via AWS Security Hub and AWS Control Tower. Jadu's operations team are subscribed to Common Vulnerabilities and Exposures (CVE) reports via www.cve.org. Critical / zero-day vulnerabilities will receive expedited rollout usually within 24-48 hours, in addition to monthly patching.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Jadu processes are detailed in our Incident Management Policy and Procedure documents. Incidents may be reported via portal, telephone, or raised by our service desk on customers’ behalf. Jadu will analyse the incident, gathering information (from log files, investigations etc). Senior management are notified and the incident is escalated according to defined procedures. Timelines are captured of discussions, investigations, and actions. Incident reports are compiled and shared with the customer with further actions and any long term resolutions possible to prevent recurrence. All incidents are reviewed by our security council quarterly. This process is subject to external audit via ISO27001.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Wednesday 9 July 2025
- What the ISO/IEC 27001 doesn’t cover
- The scope of Netcall's ISO27001 covers the entire business. There is one control listed in the Statement of Applicability which is not applicable and that is control A8.30 Outsourced Development, as Netcall does not outsource any development of Netcall's product portfolio or any associated services.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- NQA
- ISO 9001 accreditation date
- Monday 11 December 2023
- What the ISO 9001 doesn’t cover
- Our ISO 9001 certification applies to the entire organisation within the scope of our Business Management System (BMS). The certification specifically covers documented policies, procedures, templates, forms, and other controlled documents maintained in the BMS and listed in the official document register. These documents are subject to ISO 9001 requirements for review, approval, and version control. Items outside this, such as informal working notes, draft materials, or team-specific procedures, work instructions, guides and operational documentation, are not covered by the certification. While these may support operational activities, they do not form part of the audited and controlled system.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 3038ebf9-ed3a-463d-94d8-db9a291c4efd
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Cc81f920-af0a-4b1c-ab27-e222ef04c275
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-