Skip to main content

Help us improve the Digital Marketplace - send your feedback

PROGRAM PLANNING PROFESSIONALS LIMITED

Clayverest

Clayverest is a PMO-focused delivery and assurance platform that turns fragmented project data into trusted insight. By improving data quality, automating reporting and highlighting risk, capacity and dependencies, it enables PMOs to move from manual reporting to proactive portfolio control, confident decision-making and earlier intervention

Features

  • PMO-focused portfolio and delivery management platform
  • Central data hub integrating multiple delivery tools
  • Portfolio-level scheduling and roadmap capabilities
  • Resource demand and capacity visibility by role
  • Structured management of risks, actions and dependencies
  • Scope and governance hierarchy management.
  • AI-enabled reporting, insight and automation support
  • Deployment, configuration and integration services
  • Data migration, validation and governance setup
  • Training, adoption and change management support.

Benefits

  • Single, trusted delivery data source for PMOs.
  • Reduced manual reporting and data consolidation effort.
  • Improved data quality and reporting confidence.
  • Clearer visibility of schedules, risks and dependencies.
  • Better understanding of resource demand and constraints.
  • Earlier identification of delivery risk across portfolios.
  • Faster, more consistent management information production.
  • Improved decision-making through AI-enabled insight.
  • Scalable solution aligned to PMO maturity growth.
  • Secure cloud deployment suitable for public sector use.

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at uk.info@migso-pcubed.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 8 5 2 6 6 8 1 9 5 2 3 8 4 6

Contact

PROGRAM PLANNING PROFESSIONALS LIMITED Mark Sorrell
Telephone: 020 7462 0100
Email: uk.info@migso-pcubed.com

About your service

Service categories

Applications

Enterprise resource management

  • Project and portfolio management
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
There are no other foreseeable constraints to the Services (e.g. maintenance windows, level of customisation permitted, schedule for deprecation of functionality/features etc.)
System requirements
  • Microsoft Edge, Firefox, Chrome, Safari
  • The consumer must have the ability to access internet
  • Specific Log in accounts (licences)

User support

Email or online ticketing support
Yes
Support response times
There are no contractually agree response times, although client specific agreements can be discussed. Our objective is always to respond to any issue as quickly as we can and to resolve it in a manner that aligns to its' severity.

There is limited support at week-ends, but as an aggregation, analysis, reporting application with no operational dependencies, the need for critical support in this timeframe is expected to be minimal
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
There are 4 levels of severity defined (Urgent, High, Medium, Low) and these are client assessed. Response to support queries raised online are not charged.

The level of support in terms of e.g. a technical account manager will depend on the client and on other relationships we have with them.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Envisioning workshops, training , change management, providing a dedicated delivery team and support where necessary. This is available in the PPM Deployment Service. There is also full documentation available online (HTML)
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
At the end of the contract all data is set to read-only. There is no automated extract. Clients can delete their workspace and this operation will delete all data related to that workspace. Clients can also request to get their data extracted and sent to them in typical standard formats.
End-of-contract process
At the end of the contract the application is no longer available to the client. Data is not erased, but not accessible by anyone. A client can request to reactivate their subscription. At any time, a client can delete their workspace(s) to clear all data and also request all data in extract format.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
All documentation is available online, via a browser.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
None or don’t know
API
No
Customisation available
Yes
Description of customisation
The solution can be configured and set up to match project methods and process by client. As an example, statuses of tasks, assessment of project, colour pattern to match client identity.

Scaling

Independence of resources
This is a cloud based and shared infrastructure service. The Architecture is based on auto scaling model to always ensure high level performance (response times)

Analytics

Service usage metrics
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Clayverest.com

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Their are multiple points within the application which allows clients to export their data. These are all clearly documented. There are no stndard export points outside the application.
Data export formats
  • CSV
  • Other
Other data export formats
  • .XLS
  • .PDF
  • .PNG
Data import formats
  • CSV
  • Other
Other data import formats
  • .XLSX /.XLSB / XLSM
  • .XML
  • .MPP
  • .SYLK
  • .ODS
  • .QPW
  • .DBF
  • .WQ*
  • .UOS

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Web Application Firewall applied to prevent any attacks

Availability and resilience

Guaranteed availability
Service is available 24/7 and resilient to high level of load with scalable architecture
Approach to resilience
This data is available on request
Outage reporting
Outages both planned and un-planned are notified by email to registered owners of the solution. Planned outages can also be notified in the service itself

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Other
Other user authentication
User access to interfaces is made possible with a user account.
Without an account, a user cannot access the service.

Access to the service is limited to authenticated and authorised users.

SSO can be set up to get authorised identity from multiple clients (Active Directory, Federated Identity such as Google, Facebook, …)
Access restrictions in management interfaces and support channels
Access can be restricted based on the role of the user (administrator, Organisation Owner, Project Owner, Project roles). In addition, if the user does not have a user account, they are restricted from the service.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Description of management access authentication
In addition to the above there is a process of email verification at the point of sign-up i.e. preceding first actual connection.

Audit information for users

Access to user activity audit information
No audit information available
Access to supplier activity audit information
No audit information available
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Processes and policies are defined and controlled to ensure at minimum compliance with ISO27001. Controls are in place to ensure processed are followed and under control. Continuous improvement is implemented to keep processes and policies evolving while organisation improves.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Change of organisation or changes in project scope for product development are managed through a process of change management.
Regular reviews are planned with according stakeholders to discuss and agree changes. These changes are integrated into project management to plan, execute, test and capitalised.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Security organisation is responsible of monitoring and managing vulnerability to ensure high level of security in the organisation, IT systems and products.
CICD is managing vulnerability detection to prevent any release including vulnerability inherent from the product or coming from dependencies
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Web Application Firewall and logs are implemented to ensure quick detection of vulnerability, errors or attacks. The WAF and the logging are both providing alerts to ensure reactivity on response to minimise adverse impacts for clients and users.

The IT System has an integrated Firewall and Anti-virus solution to anticipate, prevent and correct any vulnerabilities or attacks on the system.

As identified in other sections there are regular (multiple times per year) penetration tests.
Incident management type
Supplier-defined controls
Incident management approach
There are specific processes defined and followed to track, solve and monitor incidents. The organisation is dedicated to it to ensure responsiveness and reactivity along all steps of the process. A process of communication is defined for any incident which needs to be communicated to clients. This process is compliant with ISO27001 and ISO9001 requirements.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
By default, we offer a one-month free trial period, with no commitment, so you can experience all the features of Clayverest. This is for all core features. More advanced features can be added by request

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Saturday 18 May 2024
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation ISO Certification Limited
ISO 9001 accreditation date
Monday 1 September 2025
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
5e375087-3e21-4292-b145-bf6e7d7a3997
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
6e23110e-84ce-4fb6-a1f9-bb4a4e727af0
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at uk.info@migso-pcubed.com. Tell them what format you need. It will help if you say what assistive technology you use.