Envelope: Apprenticeship Levy & Early Careers Management for Employers
Envelope optimises apprenticeship levy and early careers management. Features include 24-month levy expiration forecasting, automated DAS payment reconciliation, and secure provider portals to capture progress reports. Streamline operations with drag-and-drop forms, workflow automation, and advanced analytics. A cloud-native solution ensuring financial accuracy and total compliance visibility.
Features
- End-to-end apprenticeship tracking from enquiry to completion/withdrawal.
- Secure provider portal for direct, validated progress reporting.
- Drag-and-drop form builder with conditional logic and validation.
- Automated survey campaigns with scheduling and result analysis.
- Workflow automation engine with configurable triggers and alerts.
- Complete management of levy transfers and funding agreements.
- Specialised analytics dashboards for deep programme insights.
- Role-based access panels for admins, providers, and apprentices.
- Automated DAS payment reconciliation identifies financial discrepancies instantly.
- Visual 24-month levy expiration forecasting and tracking tools.
Benefits
- Cut progress reporting time by 80% with digital portals.
- Real-time dashboards ensure complete ESFA compliance visibility.
- Analytics enable data-driven improvements to provider performance.
- Unified communication hub streamlines messages to all stakeholders.
- Digital forms reduce onboarding times by up to 50%.
- Seamlessly manage multiple funding streams in one system.
- Reduce payment discrepancies by 95% via automated reconciliation.
- Proactive forecasting prevents unspent levy funds from expiring.
- Secure cloud hosting.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 8 8 0 2 3 2 1 3 0 9 0 0 1 4
Contact
EPACT LTD
Akam Rahimi
Telephone: +44 333 339 6626
Email: info@epact.app
About the service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Talent Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- N/a
- System requirements
-
- Modern web browser (Chrome, Edge, Firefox, or Safari).
- Stable internet connection for real-time cloud access.
- JavaScript enabled for dynamic fee calculation and interface.
- Cookies enabled for secure session and CSRF protection.
- Valid email address for user notifications and alerts.
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 1 working day
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support Levels All customers receive Standard Support as part of the service. This includes:
Direct access to technical and functional support via email and our support ticketing system.
Availability:
UK business hours (Monday to Friday, 09:00–17:00, excluding public holidays).
Scope:
Incident resolution, software fixes, configuration guidance, and general service use queries.
Cost Standard Support is included in the annual licence fee at no extra cost.
We do not provide a dedicated Technical Account Manager. However, our support team comprises product specialists who provide expert guidance on configuration and deployment. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Onboarding & Discovery
We initiate the engagement with consultative discovery meetings to fully understand your specific operational requirements. Our team collaborates with stakeholders to configure the system, implementing necessary customisations, workflow settings, and branding to ensure the platform fits your organisation from day one.
Data Migration
Transitioning from legacy systems is fully supported by our technical team. We assist with the planning, mapping, and importation of existing data (such as learner records and course history) into Envelope, ensuring data integrity and continuity.
Training
We provide flexible training options tailored to your staff's needs:
Online Training
Live, interactive remote sessions delivered via Teams or Zoom.
Onsite Training
In-person workshops delivered at your campus or offices for hands-on guidance.
Documentation
All users have access to comprehensive digital manuals and user guides. These resources provide step-by-step instructions for key workflows, ensuring staff can confidently navigate the system independently. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
Self-Service Export
Users retain full ownership of their data and can extract key datasets at any time during the contract. The system includes built-in bulk export tools, allowing authorised staff to download comprehensive reports (including learner details, financial records, and ILR data) in standard, machine-readable formats such as CSV and Excel.
End of Contract
Migration Upon contract termination, we provide a full, managed exit service to ensure a smooth transition to your new provider. Our technical team performs a complete extraction of all database tables, converting them into a structured set of CSV files. This comprehensive data package is transferred to the client via a secure, encrypted file transfer method.
Data Destruction
Once the client has confirmed successful receipt and validation of the exported data, we initiate our secure data destruction protocol. All client data is permanently purged from our live production environments, and all associated backups are securely destroyed in compliance with GDPR and our data retention policies. - End-of-contract process
-
Included in the price
At the end of the contract, we provide a fully managed exit service at no extra cost. This standard offboarding package includes:
- Extraction of all database records (learners, financials, ILR data) and stored documents into structured CSV files.
- Encrypted handover of the data package to the client.
- Permanent deletion of all client data from our live servers and backups upon confirmation of receipt, in compliance with GDPR.
Additional costs
If you require bespoke technical assistance beyond the standard data export, this is available as an additional service. These requirements are charged at the normal hourly rate. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
O Clear headings, consistent layout, and predictable sections
o Sufficient color contrast and readable font sizes
o Consistent terminology and predictable layouts
o Step-by-step guidance with clear outcomes
o Acronyms and technical terms are explained where used
o Logical reading and tab order
it supports accessibility features that help meet aspects of WCAG (like readable structure, contrast, keyboard navigation), and many basic accessibility best practices are followed by default.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
-
1. Web Browser Interface: A secure, responsive portal compatible with Chrome, Edge, Firefox, and Safari. It requires no installation and works across desktops, tablets, and mobiles. The interface features role-based dashboards, interactive analytics, and intuitive wizards to simplify complex compliance tasks.
2. REST API: A documented OpenAPI 3.0 interface for technical integration. This allows secure, automated data exchange with external systems using standard JSON, ensuring your MIS acts as a central source of truth without manual data entry. - Accessibility standards
- None or don’t know
- Description of accessibility
-
Key accessibility features include:
Keyboard Navigation:
All menus, forms, and interactive elements are fully operable using keyboard shortcuts, requiring no mouse interaction.
Screen Reader Support:
The interface uses semantic HTML and ARIA labels to ensure compatibility with standard screen readers (e.g., JAWS, NVDA, VoiceOver).
Visual Adjustments:
The design supports browser-based text resizing (up to 200%) without breaking the layout and adheres to compliant colour contrast ratios for users with visual impairments.
Responsiveness:
The layout automatically adapts to different devices and orientations. - Accessibility testing
-
To date, accessibility testing has been conducted internally by our development team using industry-standard assistive tools.
We validate compliance against WCAG 2.1 A using:
Automated Audits:
Google Lighthouse and Axe to verify colour contrast and ARIA tagging.
Screen Readers:
Internal simulation using NVDA and VoiceOver to check semantic structure.
Keyboard Navigation:
Manual verification of tab-indexing and focus states.
We have not yet conducted trials with external user groups but are committed to incorporating feedback from native users of assistive technology in our next major release cycle. - API
- Yes
- What users can and can't do using the API
-
Users can fully script their environment setup via the REST API to ensure rapid, consistent deployment. This includes automating user provisioning with SSO integration and defining granular Role-Based Access Control (RBAC) permissions programmatically. Developers can build dynamic data capture workflows by creating custom forms with conditional logic and validation rules directly through the API.
The API enables seamless bidirectional synchronisation with external HR and LMS systems, supporting full CRUD operations for apprentices, enrolments, and provider contracts. Users can automate complex financial processes by importing DAS payment files for instant reconciliation and managing levy transfers programmatically. The system also supports bulk CSV data imports and workflow automation to trigger custom actions based on real-time events.
It unlocks powerful insights by retrieving real-time data from six specialised analytics modules, including financial forecasting, cohort analysis, and compliance reporting. Users can also drive engagement by scheduling automated survey campaigns via the API, tracking response rates, and managing multi-channel communication (Email/SMS) to streamline stakeholder interaction. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Organisations can extend the data model by defining Custom Fields for any entity (apprentices, employers, etc.). The Drag-and-Drop Form Builder allows creation of bespoke data capture forms with conditional logic and validation. Users can configure Workflow Automations to trigger actions (Email/SMS) based on specific events or schedules. Additionally, users can define custom Roles & Permissions, rename system terminology via Placeholders, configure dropdown values, and save personalised Filter Presets for reporting.
All customisation is performed via the secure web interface using visual, no-code tools (e.g., visual form designers, checkbox permission matrices). Changes take effect immediately without deployment. For advanced integration, all configuration options are also accessible programmatically via the REST API.
Who Can Customise Access is governed by strict Role-Based Access Control (RBAC). Super admins have full access to all system settings and tenant configuration.
Scaling
- Independence of resources
-
The service is delivered using a multi-tenant architecture designed to ensure fair and consistent performance for all users. System resources are actively monitored and managed to prevent individual users or organisations from negatively impacting others.
The service uses capacity management, load balancing and performance monitoring to manage demand across tenants.
Where appropriate, usage controls and permissions are applied at tenant and user level to manage intensive operations and protect overall service performance. This ensures that all customers experience a stable and reliable service regardless of the activity of other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide comprehensive real-time metrics across three key areas:
1. Business Intelligence Dashboards track enrolment KPIs, learner demographics, attendance trends, and financial performance (revenue, cost-per-student, and contribution margins).
2. Compliance & Audit Monitors ILR data health, validation errors, and funding claims. A granular audit trail logs every data modification (User, Timestamp, Old/New Value) for full accountability.
3. System Activity Tracks API usage, user activity, and communication delivery rates (SMS/Email).
All metrics are accessible via interactive dashboard and charts. Data can be exported instantly to CSV/Excel or retrieved via API for external BI integration. - Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Users can independently export their data at any time via the secure web interface. All system reports, learner records, and financial data can be exported into open, non-proprietary formats (specifically CSV and Excel) for immediate use in other applications.
For automated or high-volume data extraction, the service provides a REST API (JSON). This allows external systems (such as BI tools or Finance software) to programmatically retrieve data without manual intervention.
In addition to self-service options, a full database export (CSV) is provided as part of the standard end-of-contract offboarding process to ensure seamless transition to alternative suppliers. - Data export formats
-
- CSV
- Other
- Other data export formats
- JSON via AP
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee a service availability of 99.9% during standard service hours, calculated on a calendar monthly basis. This excludes pre-notified scheduled maintenance windows, which are typically conducted outside of core UK business hours to minimise disruption.
Service Level Agreement (SLA) Our platform is hosted on resilient cloud infrastructure (e.g., AWS/Azure) with automated failover to ensure continuous operation. Availability is monitored 24/7/365. "Unavailability" is defined as the inability of all users to access the core application due to a fault within our control.
Compensation If we fail to meet the guaranteed availability levels in any given month, customers are eligible for Service Credits towards future billing. Credits are calculated as a percentage of the monthly subscription fee equivalent:
99.0% – 99.9%: 2% credit
95.0% – 98.9%: 5% credit
Below 95.0%: 10% credit
Claims must be submitted within 30 days of the incident via the support portal. - Approach to resilience
-
Our architecture spans a minimum of two physically isolated datacentres to protect against site-level failures.
We utilise managed infrastructure ensuring automatic OS patching and maintenance by AWS. AWS datacentres are compliant with ISO 27001, SOC 1/2/3. The system is designed for "redundancy by default" to eliminate single points of failure. Our services run on auto-scaling containers across multiple zones. Health checks occur every 30 seconds; if an instance fails, traffic is automatically rerouted by Load Balancers.
We use RDS MariaDB with Multi-AZ synchronous replication. In the event of a primary database failure, the system automatically fails over to a standby replica within 60–120 seconds.
Continuous replication combined with daily snapshots. Retention is configurable (up to 365 days via AWS Backup). S3 versioning protects against accidental deletion, backed by daily snapshots. All data is encrypted at rest using AWS KMS and in transit via TLS 1.2+.
We maintain Business Continuity and Disaster Recovery plans. We conduct quarterly backup verification and annual full disaster recovery simulations. Our standard Recovery Time Objective (RTO) is 4 hours, and Recovery Point Objective (RPO) is 1 hour. Procedures are in place for complete AZ failure (automatic recovery) and catastrophic region failure (manual failover). - Outage reporting
-
We provide proactive communication regarding service interruptions. In the event of a confirmed outage or significant degradation, email alerts are sent immediately to all registered system administrators. These notifications include an incident summary, expected resolution time, and regular updates until the service is fully restored.
Our infrastructure is monitored 24/7 using a combination of AWS CloudWatch (internal server health) and UptimeRobot (external synthetic monitoring). If UptimeRobot detects that the service is unreachable from the public internet, it triggers immediate alerts to our engineering team to begin rapid triage.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access is strictly controlled via Role-Based Access Control (RBAC) and mandatory Multi-Factor Authentication. We enforce the Principle of Least Privilege, ensuring users only possess permissions necessary for their specific role (e.g., Tutor vs. Finance). All sessions are encrypted via TLS 1.2+ with automatic inactivity timeouts, and every administrative action is logged in a tamper-evident audit trail.
Support requests are only accepted from pre-approved, authorised contacts. Our technical staff access client data strictly on a temporary, "need-to-know" basis solely to resolve active incidents. All internal access is logged, time-bound, and reviewed quarterly to ensure compliance with our security policies. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
We maintain a comprehensive ISMS aligned with ISO/IEC 27001:2022, comprising 20 formal policies covering Access Control, Risk Management, Incident Response, and GDPR.
Managing Director holds ultimate accountability and conducts quarterly security reviews. The also manage day-to-day operations, risk assessments, and internal audits.
Data Protection Officer (DPO) oversees GDPR compliance and breach notifications.
Technical team are responsible for secure development and infrastructure maintenance.
We ensure adherence to policies through:
Technical Enforcement:
We use AWS Security Hub and AWS Config to automatically audit configurations against CIS Benchmarks. Access is restricted via strict Least Privilege and mandatory MFA.
Governance:
Quarterly management reviews and annual internal audits verify control effectiveness against our Risk Register.
People:
All staff complete mandatory annual security training and must sign policy acknowledgements.
Monitoring:
24/7 threat detection via AWS GuardDuty and CloudTrail logging ensures full auditability of all user actions. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- \
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- \
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- \
- Incident management type
- Undisclosed
- Incident management approach
- \
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 68e27745-3447-4306-9efe-64a3404c2fae
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Working conditions which promote an inclusive working environment and promote retention and progression
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition