Skip to main content

Help us improve the Digital Marketplace - send your feedback

EPACT LTD

Envelope: Apprenticeship Levy & Early Careers Management for Employers

Envelope optimises apprenticeship levy and early careers management. Features include 24-month levy expiration forecasting, automated DAS payment reconciliation, and secure provider portals to capture progress reports. Streamline operations with drag-and-drop forms, workflow automation, and advanced analytics. A cloud-native solution ensuring financial accuracy and total compliance visibility.

Features

  • End-to-end apprenticeship tracking from enquiry to completion/withdrawal.
  • Secure provider portal for direct, validated progress reporting.
  • Drag-and-drop form builder with conditional logic and validation.
  • Automated survey campaigns with scheduling and result analysis.
  • Workflow automation engine with configurable triggers and alerts.
  • Complete management of levy transfers and funding agreements.
  • Specialised analytics dashboards for deep programme insights.
  • Role-based access panels for admins, providers, and apprentices.
  • Automated DAS payment reconciliation identifies financial discrepancies instantly.
  • Visual 24-month levy expiration forecasting and tracking tools.

Benefits

  • Cut progress reporting time by 80% with digital portals.
  • Real-time dashboards ensure complete ESFA compliance visibility.
  • Analytics enable data-driven improvements to provider performance.
  • Unified communication hub streamlines messages to all stakeholders.
  • Digital forms reduce onboarding times by up to 50%.
  • Seamlessly manage multiple funding streams in one system.
  • Reduce payment discrepancies by 95% via automated reconciliation.
  • Proactive forecasting prevents unspent levy funds from expiring.
  • Secure cloud hosting.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@epact.app. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 8 8 0 2 3 2 1 3 0 9 0 0 1 4

Contact

EPACT LTD Akam Rahimi
Telephone: +44 333 339 6626
Email: info@epact.app

About the service

Service categories

Applications

Enterprise resource management

Human capital management

  • Talent Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
N/a
System requirements
  • Modern web browser (Chrome, Edge, Firefox, or Safari).
  • Stable internet connection for real-time cloud access.
  • JavaScript enabled for dynamic fee calculation and interface.
  • Cookies enabled for secure session and CSRF protection.
  • Valid email address for user notifications and alerts.

User support

Email or online ticketing support
Yes
Support response times
Within 1 working day
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 A
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support Levels All customers receive Standard Support as part of the service. This includes:

Direct access to technical and functional support via email and our support ticketing system.

Availability:
UK business hours (Monday to Friday, 09:00–17:00, excluding public holidays).

Scope:
Incident resolution, software fixes, configuration guidance, and general service use queries.

Cost Standard Support is included in the annual licence fee at no extra cost.

We do not provide a dedicated Technical Account Manager. However, our support team comprises product specialists who provide expert guidance on configuration and deployment.
Support available to third parties
No

Onboarding and offboarding

Getting started
Onboarding & Discovery
We initiate the engagement with consultative discovery meetings to fully understand your specific operational requirements. Our team collaborates with stakeholders to configure the system, implementing necessary customisations, workflow settings, and branding to ensure the platform fits your organisation from day one.

Data Migration
Transitioning from legacy systems is fully supported by our technical team. We assist with the planning, mapping, and importation of existing data (such as learner records and course history) into Envelope, ensuring data integrity and continuity.

Training
We provide flexible training options tailored to your staff's needs:

Online Training
Live, interactive remote sessions delivered via Teams or Zoom.

Onsite Training
In-person workshops delivered at your campus or offices for hands-on guidance.

Documentation
All users have access to comprehensive digital manuals and user guides. These resources provide step-by-step instructions for key workflows, ensuring staff can confidently navigate the system independently.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Self-Service Export
Users retain full ownership of their data and can extract key datasets at any time during the contract. The system includes built-in bulk export tools, allowing authorised staff to download comprehensive reports (including learner details, financial records, and ILR data) in standard, machine-readable formats such as CSV and Excel.

End of Contract
Migration Upon contract termination, we provide a full, managed exit service to ensure a smooth transition to your new provider. Our technical team performs a complete extraction of all database tables, converting them into a structured set of CSV files. This comprehensive data package is transferred to the client via a secure, encrypted file transfer method.

Data Destruction
Once the client has confirmed successful receipt and validation of the exported data, we initiate our secure data destruction protocol. All client data is permanently purged from our live production environments, and all associated backups are securely destroyed in compliance with GDPR and our data retention policies.
End-of-contract process
Included in the price
At the end of the contract, we provide a fully managed exit service at no extra cost. This standard offboarding package includes:

- Extraction of all database records (learners, financials, ILR data) and stored documents into structured CSV files.

- Encrypted handover of the data package to the client.

- Permanent deletion of all client data from our live servers and backups upon confirmation of receipt, in compliance with GDPR.

Additional costs
If you require bespoke technical assistance beyond the standard data export, this is available as an additional service. These requirements are charged at the normal hourly rate.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
O Clear headings, consistent layout, and predictable sections
o Sufficient color contrast and readable font sizes
o Consistent terminology and predictable layouts
o Step-by-step guidance with clear outcomes
o Acronyms and technical terms are explained where used
o Logical reading and tab order

it supports accessibility features that help meet aspects of WCAG (like readable structure, contrast, keyboard navigation), and many basic accessibility best practices are followed by default.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
1. Web Browser Interface: A secure, responsive portal compatible with Chrome, Edge, Firefox, and Safari. It requires no installation and works across desktops, tablets, and mobiles. The interface features role-based dashboards, interactive analytics, and intuitive wizards to simplify complex compliance tasks.

2. REST API: A documented OpenAPI 3.0 interface for technical integration. This allows secure, automated data exchange with external systems using standard JSON, ensuring your MIS acts as a central source of truth without manual data entry.
Accessibility standards
None or don’t know
Description of accessibility
Key accessibility features include:

Keyboard Navigation:
All menus, forms, and interactive elements are fully operable using keyboard shortcuts, requiring no mouse interaction.

Screen Reader Support:
The interface uses semantic HTML and ARIA labels to ensure compatibility with standard screen readers (e.g., JAWS, NVDA, VoiceOver).

Visual Adjustments:
The design supports browser-based text resizing (up to 200%) without breaking the layout and adheres to compliant colour contrast ratios for users with visual impairments.

Responsiveness:
The layout automatically adapts to different devices and orientations.
Accessibility testing
To date, accessibility testing has been conducted internally by our development team using industry-standard assistive tools.

We validate compliance against WCAG 2.1 A using:

Automated Audits:
Google Lighthouse and Axe to verify colour contrast and ARIA tagging.

Screen Readers:
Internal simulation using NVDA and VoiceOver to check semantic structure.

Keyboard Navigation:
Manual verification of tab-indexing and focus states.

We have not yet conducted trials with external user groups but are committed to incorporating feedback from native users of assistive technology in our next major release cycle.
API
Yes
What users can and can't do using the API
Users can fully script their environment setup via the REST API to ensure rapid, consistent deployment. This includes automating user provisioning with SSO integration and defining granular Role-Based Access Control (RBAC) permissions programmatically. Developers can build dynamic data capture workflows by creating custom forms with conditional logic and validation rules directly through the API.

The API enables seamless bidirectional synchronisation with external HR and LMS systems, supporting full CRUD operations for apprentices, enrolments, and provider contracts. Users can automate complex financial processes by importing DAS payment files for instant reconciliation and managing levy transfers programmatically. The system also supports bulk CSV data imports and workflow automation to trigger custom actions based on real-time events.

It unlocks powerful insights by retrieving real-time data from six specialised analytics modules, including financial forecasting, cohort analysis, and compliance reporting. Users can also drive engagement by scheduling automated survey campaigns via the API, tracking response rates, and managing multi-channel communication (Email/SMS) to streamline stakeholder interaction.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Organisations can extend the data model by defining Custom Fields for any entity (apprentices, employers, etc.). The Drag-and-Drop Form Builder allows creation of bespoke data capture forms with conditional logic and validation. Users can configure Workflow Automations to trigger actions (Email/SMS) based on specific events or schedules. Additionally, users can define custom Roles & Permissions, rename system terminology via Placeholders, configure dropdown values, and save personalised Filter Presets for reporting.

All customisation is performed via the secure web interface using visual, no-code tools (e.g., visual form designers, checkbox permission matrices). Changes take effect immediately without deployment. For advanced integration, all configuration options are also accessible programmatically via the REST API.

Who Can Customise Access is governed by strict Role-Based Access Control (RBAC). Super admins have full access to all system settings and tenant configuration.

Scaling

Independence of resources
The service is delivered using a multi-tenant architecture designed to ensure fair and consistent performance for all users. System resources are actively monitored and managed to prevent individual users or organisations from negatively impacting others.

The service uses capacity management, load balancing and performance monitoring to manage demand across tenants.

Where appropriate, usage controls and permissions are applied at tenant and user level to manage intensive operations and protect overall service performance. This ensures that all customers experience a stable and reliable service regardless of the activity of other users.

Analytics

Service usage metrics
Yes
Metrics types
We provide comprehensive real-time metrics across three key areas:

1. Business Intelligence Dashboards track enrolment KPIs, learner demographics, attendance trends, and financial performance (revenue, cost-per-student, and contribution margins).

2. Compliance & Audit Monitors ILR data health, validation errors, and funding claims. A granular audit trail logs every data modification (User, Timestamp, Old/New Value) for full accountability.

3. System Activity Tracks API usage, user activity, and communication delivery rates (SMS/Email).

All metrics are accessible via interactive dashboard and charts. Data can be exported instantly to CSV/Excel or retrieved via API for external BI integration.
Reporting types
Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can independently export their data at any time via the secure web interface. All system reports, learner records, and financial data can be exported into open, non-proprietary formats (specifically CSV and Excel) for immediate use in other applications.

For automated or high-volume data extraction, the service provides a REST API (JSON). This allows external systems (such as BI tools or Finance software) to programmatically retrieve data without manual intervention.

In addition to self-service options, a full database export (CSV) is provided as part of the standard end-of-contract offboarding process to ensure seamless transition to alternative suppliers.
Data export formats
  • CSV
  • Other
Other data export formats
JSON via AP
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We guarantee a service availability of 99.9% during standard service hours, calculated on a calendar monthly basis. This excludes pre-notified scheduled maintenance windows, which are typically conducted outside of core UK business hours to minimise disruption.

Service Level Agreement (SLA) Our platform is hosted on resilient cloud infrastructure (e.g., AWS/Azure) with automated failover to ensure continuous operation. Availability is monitored 24/7/365. "Unavailability" is defined as the inability of all users to access the core application due to a fault within our control.

Compensation If we fail to meet the guaranteed availability levels in any given month, customers are eligible for Service Credits towards future billing. Credits are calculated as a percentage of the monthly subscription fee equivalent:

99.0% – 99.9%: 2% credit

95.0% – 98.9%: 5% credit

Below 95.0%: 10% credit

Claims must be submitted within 30 days of the incident via the support portal.
Approach to resilience
Our architecture spans a minimum of two physically isolated datacentres to protect against site-level failures.

We utilise managed infrastructure ensuring automatic OS patching and maintenance by AWS. AWS datacentres are compliant with ISO 27001, SOC 1/2/3. The system is designed for "redundancy by default" to eliminate single points of failure. Our services run on auto-scaling containers across multiple zones. Health checks occur every 30 seconds; if an instance fails, traffic is automatically rerouted by Load Balancers.

We use RDS MariaDB with Multi-AZ synchronous replication. In the event of a primary database failure, the system automatically fails over to a standby replica within 60–120 seconds.

Continuous replication combined with daily snapshots. Retention is configurable (up to 365 days via AWS Backup). S3 versioning protects against accidental deletion, backed by daily snapshots. All data is encrypted at rest using AWS KMS and in transit via TLS 1.2+.

We maintain Business Continuity and Disaster Recovery plans. We conduct quarterly backup verification and annual full disaster recovery simulations. Our standard Recovery Time Objective (RTO) is 4 hours, and Recovery Point Objective (RPO) is 1 hour. Procedures are in place for complete AZ failure (automatic recovery) and catastrophic region failure (manual failover).
Outage reporting
We provide proactive communication regarding service interruptions. In the event of a confirmed outage or significant degradation, email alerts are sent immediately to all registered system administrators. These notifications include an incident summary, expected resolution time, and regular updates until the service is fully restored.

Our infrastructure is monitored 24/7 using a combination of AWS CloudWatch (internal server health) and UptimeRobot (external synthetic monitoring). If UptimeRobot detects that the service is unreachable from the public internet, it triggers immediate alerts to our engineering team to begin rapid triage.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access is strictly controlled via Role-Based Access Control (RBAC) and mandatory Multi-Factor Authentication. We enforce the Principle of Least Privilege, ensuring users only possess permissions necessary for their specific role (e.g., Tutor vs. Finance). All sessions are encrypted via TLS 1.2+ with automatic inactivity timeouts, and every administrative action is logged in a tamper-evident audit trail.

Support requests are only accepted from pre-approved, authorised contacts. Our technical staff access client data strictly on a temporary, "need-to-know" basis solely to resolve active incidents. All internal access is logged, time-bound, and reviewed quarterly to ensure compliance with our security policies.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
We maintain a comprehensive ISMS aligned with ISO/IEC 27001:2022, comprising 20 formal policies covering Access Control, Risk Management, Incident Response, and GDPR.

Managing Director holds ultimate accountability and conducts quarterly security reviews. The also manage day-to-day operations, risk assessments, and internal audits.

Data Protection Officer (DPO) oversees GDPR compliance and breach notifications.

Technical team are responsible for secure development and infrastructure maintenance.

We ensure adherence to policies through:

Technical Enforcement:
We use AWS Security Hub and AWS Config to automatically audit configurations against CIS Benchmarks. Access is restricted via strict Least Privilege and mandatory MFA.

Governance:
Quarterly management reviews and annual internal audits verify control effectiveness against our Risk Register.

People:
All staff complete mandatory annual security training and must sign policy acknowledgements.

Monitoring:
24/7 threat detection via AWS GuardDuty and CloudTrail logging ensures full auditability of all user actions.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
\
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
\
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
\
Incident management type
Undisclosed
Incident management approach
\
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
68e27745-3447-4306-9efe-64a3404c2fae
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • Plans to engage the contract workforce in deciding the most important workplace issues to address
  • Ensuring new workers are informed of their right to join a trade union
  • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
  • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
  • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas

Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

  • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
Mission: Break down barriers to opportunity

By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

Policy Outcome 6: Employment and training: For those who face barriers to employment

  • Working conditions which promote an inclusive working environment and promote retention and progression
  • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
Mission: Build an NHS fit for the future

That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

  • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
  • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@epact.app. Tell them what format you need. It will help if you say what assistive technology you use.