Clayverest
Clayverest is a PMO-focused delivery and assurance platform that turns fragmented project data into trusted insight. By improving data quality, automating reporting and highlighting risk, capacity and dependencies, it enables PMOs to move from manual reporting to proactive portfolio control, confident decision-making and earlier intervention
Features
- PMO-focused portfolio and delivery management platform
- Central data hub integrating multiple delivery tools
- Portfolio-level scheduling and roadmap capabilities
- Resource demand and capacity visibility by role
- Structured management of risks, actions and dependencies
- Scope and governance hierarchy management.
- AI-enabled reporting, insight and automation support
- Deployment, configuration and integration services
- Data migration, validation and governance setup
- Training, adoption and change management support.
Benefits
- Single, trusted delivery data source for PMOs.
- Reduced manual reporting and data consolidation effort.
- Improved data quality and reporting confidence.
- Clearer visibility of schedules, risks and dependencies.
- Better understanding of resource demand and constraints.
- Earlier identification of delivery risk across portfolios.
- Faster, more consistent management information production.
- Improved decision-making through AI-enabled insight.
- Scalable solution aligned to PMO maturity growth.
- Secure cloud deployment suitable for public sector use.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 8 5 2 6 6 8 1 9 5 2 3 8 4 6
Contact
PROGRAM PLANNING PROFESSIONALS LIMITED
Mark Sorrell
Telephone: 020 7462 0100
Email: uk.info@migso-pcubed.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Project and portfolio management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- There are no other foreseeable constraints to the Services (e.g. maintenance windows, level of customisation permitted, schedule for deprecation of functionality/features etc.)
- System requirements
-
- Microsoft Edge, Firefox, Chrome, Safari
- The consumer must have the ability to access internet
- Specific Log in accounts (licences)
User support
- Email or online ticketing support
- Yes
- Support response times
-
There are no contractually agree response times, although client specific agreements can be discussed. Our objective is always to respond to any issue as quickly as we can and to resolve it in a manner that aligns to its' severity.
There is limited support at week-ends, but as an aggregation, analysis, reporting application with no operational dependencies, the need for critical support in this timeframe is expected to be minimal - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
There are 4 levels of severity defined (Urgent, High, Medium, Low) and these are client assessed. Response to support queries raised online are not charged.
The level of support in terms of e.g. a technical account manager will depend on the client and on other relationships we have with them. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Envisioning workshops, training , change management, providing a dedicated delivery team and support where necessary. This is available in the PPM Deployment Service. There is also full documentation available online (HTML)
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- At the end of the contract all data is set to read-only. There is no automated extract. Clients can delete their workspace and this operation will delete all data related to that workspace. Clients can also request to get their data extracted and sent to them in typical standard formats.
- End-of-contract process
- At the end of the contract the application is no longer available to the client. Data is not erased, but not accessible by anyone. A client can request to reactivate their subscription. At any time, a client can delete their workspace(s) to clear all data and also request all data in extract format.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- All documentation is available online, via a browser.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
- The solution can be configured and set up to match project methods and process by client. As an example, statuses of tasks, assessment of project, colour pattern to match client identity.
Scaling
- Independence of resources
- This is a cloud based and shared infrastructure service. The Architecture is based on auto scaling model to always ensure high level performance (response times)
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Clayverest.com
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Their are multiple points within the application which allows clients to export their data. These are all clearly documented. There are no stndard export points outside the application.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- .XLS
- .PNG
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- .XLSX /.XLSB / XLSM
- .XML
- .MPP
- .SYLK
- .ODS
- .QPW
- .DBF
- .WQ*
- .UOS
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Web Application Firewall applied to prevent any attacks
Availability and resilience
- Guaranteed availability
- Service is available 24/7 and resilient to high level of load with scalable architecture
- Approach to resilience
- This data is available on request
- Outage reporting
- Outages both planned and un-planned are notified by email to registered owners of the solution. Planned outages can also be notified in the service itself
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Other user authentication
-
User access to interfaces is made possible with a user account.
Without an account, a user cannot access the service.
Access to the service is limited to authenticated and authorised users.
SSO can be set up to get authorised identity from multiple clients (Active Directory, Federated Identity such as Google, Facebook, …) - Access restrictions in management interfaces and support channels
- Access can be restricted based on the role of the user (administrator, Organisation Owner, Project Owner, Project roles). In addition, if the user does not have a user account, they are restricted from the service.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- In addition to the above there is a process of email verification at the point of sign-up i.e. preceding first actual connection.
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Processes and policies are defined and controlled to ensure at minimum compliance with ISO27001. Controls are in place to ensure processed are followed and under control. Continuous improvement is implemented to keep processes and policies evolving while organisation improves.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Change of organisation or changes in project scope for product development are managed through a process of change management.
Regular reviews are planned with according stakeholders to discuss and agree changes. These changes are integrated into project management to plan, execute, test and capitalised. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Security organisation is responsible of monitoring and managing vulnerability to ensure high level of security in the organisation, IT systems and products.
CICD is managing vulnerability detection to prevent any release including vulnerability inherent from the product or coming from dependencies - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Web Application Firewall and logs are implemented to ensure quick detection of vulnerability, errors or attacks. The WAF and the logging are both providing alerts to ensure reactivity on response to minimise adverse impacts for clients and users.
The IT System has an integrated Firewall and Anti-virus solution to anticipate, prevent and correct any vulnerabilities or attacks on the system.
As identified in other sections there are regular (multiple times per year) penetration tests. - Incident management type
- Supplier-defined controls
- Incident management approach
- There are specific processes defined and followed to track, solve and monitor incidents. The organisation is dedicated to it to ensure responsiveness and reactivity along all steps of the process. A process of communication is defined for any incident which needs to be communicated to clients. This process is compliant with ISO27001 and ISO9001 requirements.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- By default, we offer a one-month free trial period, with no commitment, so you can experience all the features of Clayverest. This is for all core features. More advanced features can be added by request
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Saturday 18 May 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Monday 1 September 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5e375087-3e21-4292-b145-bf6e7d7a3997
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 6e23110e-84ce-4fb6-a1f9-bb4a4e727af0
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
-