Skip to main content

Help us improve the Digital Marketplace - send your feedback

BOUNCE AGENCY LIMITED

SIM Community Safety Management

Cloud-based platform for managing any incident requiring a structured response. SIM Community Safety Manager enables rapid alerts via SMS, WhatsApp, and email, stakeholder coordination, and supports compliance with the Terrorism (Protection of Premises) Act 2025 (Martyn's Law). Used by venues and public bodies for real-time communication, escalation, and situational control.

Features

  • Incident alerts sent via SMS, WhatsApp and email.
  • Define and manage response protocols by incident type.
  • Add and manage stakeholders across partner organisations.
  • Interactive mapping for live situational awareness and incident tracking.
  • Briefing note builder for rapid multi-agency information sharing.
  • Track actions with time-stamped logs and audit trail.
  • Assign tasks to users with reminders and notifications
  • Support compliance workflows under the Terrorism (Protection of Premises) Act.
  • Role-based permissions control access to data and actions.
  • Export reports for debrief, review or compliance processes.

Benefits

  • Mass alerts via SMS, email & WhatsApp
  • Supports compliance with the Terrorism (Protection of Premises) Act 2025
  • Log, track and escalate incidents with full audit trail.
  • Assign roles and tasks automatically during live incidents.
  • Receive real-time notifications across teams and locations.
  • Streamline statutory reporting with structured templates and exports
  • View all active incidents on a live visual dashboard.
  • Conduct structured post-incident reviews and performance tracking.
  • Coordinate incident response remotely via mobile or desktop.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at admin@bounce-agency.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 8 9 9 1 8 7 3 8 5 6 6 6 2 0

Contact

BOUNCE AGENCY LIMITED Andrew Downie
Telephone: 02074917401
Email: admin@bounce-agency.com

About your service

Service categories

Applications

Production and operations

  • Other operations

Service industry and public sector operations

  • Healthcare
  • Education
  • Public Order and Safety
  • Police
  • Defence
  • Adult Social Care
  • Children's Social Care
  • Other
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Our service is delivered via public cloud and accessed through web browsers (Chrome, Edge, Safari, Firefox). A stable internet connection is required. No installation or plug-ins are needed. Planned maintenance is scheduled outside UK business hours with at least 5 working days' notice. Emergency maintenance is rare but may occur with shorter notice if necessary to address critical issues. The system is designed for desktop, tablet, and mobile browsers; however, certain complex admin features are best managed on larger screens. SMS and WhatsApp notifications require user phone numbers. For large-scale deployments (1,000+ contacts), additional onboarding time may be required.
System requirements
  • Stable internet connection
  • Modern browser: Chrome, Edge, Safari or Firefox.
  • JavaScript and cookies must be enabled.
  • SMS or WhatsApp access for alert delivery.
  • Email access to receive notifications and briefings.
  • No extra software, plug-ins or licences needed.
  • Works on desktop, tablet and mobile devices.

User support

Email or online ticketing support
Yes
Support response times
We respond to all support queries within 4 working hours during standard service hours (Monday–Friday, 09:00–17:00 UK time).
Response time commitments:

Critical issues: 4 hours (multiple users or core functionality affected)
High priority: 4 hours (individual users or specific features)
Medium priority: 8 hours (minor issues with workarounds)
Low priority: Next working day (enhancement requests, general queries)

Weekend and out-of-hours:
Queries received outside standard hours, including weekends and public holidays, are responded to by 10:00 on the next working day. Emergency support available by arrangement for critical contracts.
Response times measured from query submission.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We have conducted thorough testing of our web chat interface using multiple assistive technologies to ensure accessibility for all users.

Testing methods included:
- Screen readers: NVDA (Windows), JAWS (Windows), VoiceOver (macOS/iOS)
- Keyboard-only navigation without mouse input
- High-contrast modes (Windows High Contrast, browser extensions)
- Screen magnification software (ZoomText, Windows Magnifier)
- Voice control and speech recognition (Dragon NaturallySpeaking)

Testing was carried out by team members trained in assistive technology use, simulating real-world user scenarios including:
- Initiating chat sessions
- Reading and responding to messages
- Navigating chat history
- Accessing pre-chat forms
- Using emoji and attachments
- Managing notifications
- Closing and reopening conversations

Key accessibility features validated:
- All chat functions accessible via keyboard (Tab, Enter, Escape, Arrow keys)
- Screen reader announcements for new messages
- Clear focus indicators on interactive elements
- Sufficient colour contrast (4.5:1 minimum)
- Alternative text for visual elements
- ARIA live regions for dynamic message updates
- Logical tab order through interface

We have documented remaining limitations and maintain an accessibility roadmap. Testing occurs with each interface update to maintain WCAG 2.2 AA compliance. Our approach ensures inclusive support access for all users.
Onsite support
Yes
Support levels
We provide a single inclusive support level suitable for public sector organisations of all sizes. This includes access to our online ticketing system, email support, and telephone assistance during standard service hours (Monday to Friday, 09:00–17:00 UK time). All queries receive a response within 4 working hours.

Emergency or out-of-hours support can be arranged for contracts requiring critical coverage. Each customer is assigned a named support contact for continuity and familiarity.

Onboarding support is included as standard, covering account setup, permissions, branding, workspace configuration, and initial user training.

For clients requiring enhanced technical guidance, a dedicated Technical Account Manager (TAM) or Cloud Support Engineer can be provided for:
- Onboarding and implementation support
- Performance reviews and optimisation
- Integration planning and API guidance
- Custom development consultation
- Quarterly business reviews

This is available as a separate costed service, typically from £650/day depending on scope and duration.

We use a transparent support ticketing system, allowing users to set issue priority and monitor ticket status. Support performance is reviewed quarterly with enterprise customers to drive service improvements.

Our support model is designed to be clear, accountable, and tailored to the operational needs of NHS, education, and local authority users.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Standard implementation takes 3-4 weeks from order to go-live. We provide a comprehensive onboarding experience to help users start using the service confidently and effectively. This includes:
• Dedicated help website with walkthroughs, video tutorials, downloadable reference guides, and presentation packs for managers to train other users.
• Regular live online training (via Microsoft Teams or Zoom) for all user roles.
• Tailored onboarding workshops to configure the system around the buyer’s incident types, teams, and protocols.
• Collaborative protocol definition, where we work with customers to define their response workflows and stakeholder roles.
• Stakeholder engagement support, helping secure internal buy-in and alignment across departments.
• Role-based training and live documentation to support system administrators, frontline users, and senior decision-makers.
• Live setup support via email or chat.
• Optional onsite training is available for large deployments or specialist environments.

This approach ensures successful implementation, rapid adoption, and sustainable value from the outset.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At contract end, users can extract all data securely via the admin dashboard or request a full export from our support team.

Data included in exports:
- Incident records (past, present, and future scheduled)
- Response actions and task assignments
- Stakeholder contact lists and organizational hierarchies
- Response protocols and workflow configurations
- Briefing notes and communications history
- User accounts and permissions
- Audit logs and activity trails
- Documents and attachments
- System configurations and custom settings
- Alert delivery logs and notification history
- Map data and location information
- Reports and analytics data

Export options:
Data is provided in open, non-proprietary formats including CSV, JSON, XML, and PDF to support onward use or migration to alternative systems. Exports can be filtered by date range, incident type, or user group.

Security and support:
All exports are encrypted in transit (TLS 1.2+) and access-controlled via role-based permissions. We provide clear step-by-step guidance, export templates, and data dictionaries to ensure safe and complete data extraction.

There is no additional charge for standard end-of-contract data exports. Dedicated support is available throughout the process to assist the buyer's IT team. We schedule exports outside business hours to minimise operational impact.
End-of-contract process
At contract end, users receive advance notice and a clear offboarding plan. All client data can be extracted in common formats (e.g. CSV, JSON, PDF) at no extra cost. We provide full guidance to support secure export and migration of records, configurations, and audit history.

We support a smooth transition by offering read-only access for up to 30 days after contract expiry, free of charge. Optional post-contract services (chargeable) include:
• Bespoke data transformation or formatting
• Extended access to the live or read-only platform
• Technical consultancy to support migration to a new provider
• Formal decommissioning documentation and handover workshops

We collaborate with the client during offboarding to ensure stakeholders are supported and no disruption occurs. Where required, we assist in documenting internal response protocols, incident classifications, or workflows that have developed during contract delivery.

All accounts are securely deactivated at the end of the retention period (30 days), and data is deleted in line with our ISO 27001–compliant data destruction policy. Processes also align with NCSC guidance on secure data handling and disposal.

All activities are designed to reduce operational risk, maintain compliance, and ensure a professional, fully supported transition for the buyer.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is fully responsive and accessible via mobile browsers without loss of core functionality. Interfaces are optimised for smaller screens, touch navigation, and reduced bandwidth environments.

Some complex admin features (e.g., bulk user management, protocol configuration) are streamlined for mobile, but all critical tasks are available on both:
- Triggering incident alerts (SMS, WhatsApp, email)
- Viewing and updating incident status
- Accessing live dashboards
- Managing stakeholder contacts
- Creating and distributing briefing notes
- Completing escalation workflows
- Responding to notifications
- Accessing audit logs

Mobile interfaces prioritise rapid response for field operatives managing incidents from locations.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Our service includes a secure, browser-based interface with role-based access, supporting all major desktop and mobile web browsers. The interface features:

Intuitive dashboard with real-time incident status
Interactive mapping for situational awareness
Quick-access alert triggers and escalation controls
Stakeholder directory with contact management
Briefing note builder and templates
Mobile-optimised touch interface
Customisable widgets per user role
In-app notifications and alerts
Responsive design adapting to screen size
Dark mode for accessibility

No software installation required. Users access via standard HTTPS connection with single sign-on (SSO) support.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have conducted comprehensive manual and automated interface testing using tools such as Axe, WAVE, and Lighthouse to assess compatibility with screen readers (e.g. NVDA, JAWS, VoiceOver) and keyboard-only navigation.

Key user journeys tested for accessibility include:
- Triggering and managing incident alerts
- Navigating dashboards and situation maps
- Managing stakeholder contacts and protocols
- Creating and distributing briefing notes
- Completing escalation workflows
- Accessing help documentation
- Submitting support requests

We engaged users with visual impairments in structured testing sessions to validate:
- Colour contrast ratios (minimum 4.5:1 for text)
- Focus states and keyboard navigation order
- Alternative text for images and icons
- Screen reader announcements for dynamic content
- Form field labels and error messages
- Button and link descriptions
- Heading structure and landmark regions

Testing revealed and we addressed:
- Improved focus indicators on interactive elements
- Enhanced ARIA labels for complex components
- Optimised tab order for logical flow
- Added skip navigation links
- Ensured all functionality available via keyboard

Accessibility refinements were made in line with WCAG 2.2 AA standards. We conduct ongoing testing with each major release and maintain an accessibility statement detailing conformance status.
API
Yes
What users can and can't do using the API
Our secure RESTful API allows authorised users to integrate and interact with the system programmatically.

What users can do with the API:
- Trigger and manage incident alerts (SMS, WhatsApp, email)
- Retrieve and update stakeholder and protocol data
- Access system insights and incident response history
- Generate and push briefing notes or status updates
- Integrate mapping/location data into third-party systems
- Create and update incident records
- Query historical incident data
- Manage notification preferences

How users can set up and make changes:
- API keys and authentication tokens provided upon onboarding
- API access governed by role-based permissions for secure integration
- Documentation includes endpoint structure, sample requests/responses, and error handling
- Configure incident types, notification workflows, and stakeholder groups through the API
- Webhook support for real-time event notifications
- Bulk operations supported for data imports

Limitations:
- Some admin functions (e.g. user role creation, billing setup) restricted to web interface for security
- API usage rate-limited to 2,000 requests/hour for performance stability
- Data access limited to scope defined in each user's permissions

Full API documentation available in HTML and PDF formats with an API sandbox for testing.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Buyers can customise core elements of the service to suit operational needs.

What can be customised:
- Incident categories, severity levels, and response protocols
- Notification methods (e.g. SMS, WhatsApp, email)
- Stakeholder roles and access permissions
- Branding (logo, colour palette, email templates)
- Fields within briefing notes and status dashboards
- Alert escalation rules and time thresholds
- Response protocol templates and workflows
- User roles and permission levels
- Geographic zones and location hierarchies
- Report templates and dashboard layouts
- Integration settings (calendar, mapping, third-party systems)
- Notification preferences and delivery schedules

How users can customise:
- Via the system settings panel for authorised administrators
- Through onboarding workshops with our support team
- Using API endpoints for integrations and automation
- Through bulk import tools for large-scale configuration
- Via configuration files for advanced deployments

Who can customise:
- Buyers with administrative access
- Third-party integrators approved by the buyer
- Our support team, on request, for advanced configuration
- Technical leads during onboarding sessions

All customisations are preserved through system updates. Changes are version-controlled and can be rolled back if needed. Customisation changes are logged in audit trails for compliance.

Scaling

Independence of resources
We guarantee user independence through multi-tenant cloud architecture with logical and resource-level separation. Our infrastructure auto-scales based on individual customer demand, ensuring no performance degradation due to concurrent usage by other organisations. Each customer environment has dedicated application containers, isolated data storage, and bandwidth prioritisation. We continuously monitor system loads and apply resource throttling and traffic shaping to protect performance. Critical services use autoscaling groups and container orchestration to handle spikes without affecting others. This approach ensures service consistency, reliability, and responsiveness regardless of external demand.

Analytics

Service usage metrics
Yes
Metrics types
We provide a full suite of usage metrics via the admin dashboard and exportable reports. These include: number of incidents (by type/location), response and resolution times, stakeholder activity, protocol adherence, escalation rates, system uptime, user logins, and audit trails. Metrics can be filtered by date range, user group, incident type, or location. This supports internal reporting, compliance monitoring and performance reviews. Custom reporting is available. Metrics are downloadable in open formats (CSV and JSON), ensuring easy integration with BI tools and transparency. All data collection aligns with GDPR and security standards.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export all their data directly via the system’s secure admin interface or via an authorised API. Export formats include CSV, JSON, and PDF, enabling compatibility with common reporting, analysis, or backup tools. Exports include incident logs, response records, stakeholder lists, and protocol configurations. Bulk exports and filtered datasets are supported. On request, our support team can assist with structured exports or provide guidance to aid transition. All exports are encrypted in transit, and audit logs track every data extraction for security and compliance. Data handling processes align with ISO 27001 and NCSC secure data transfer principles.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • JSON
  • PDF/A
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • JSON
  • XML

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We guarantee 99.9% availability of the SIM Community Safety Management platform, measured monthly. This equates to a maximum allowable downtime of approximately 43 minutes per month. Our service level agreement (SLA) includes proactive monitoring, rapid incident response, and robust failover systems to ensure high resilience.

If availability falls below the guaranteed threshold in any given month (excluding scheduled maintenance windows, force majeure, or customer-induced issues), users will be eligible for service credits as follows:
• 99.0% – 99.89%: 5% service credit
• 95.0% – 98.99%: 10% service credit
• Below 95.0%: up to 50% service credit

Service credits are calculated as a percentage of that month’s fee and can be applied as a credit against future invoices. Customers can request a service credit by raising a support ticket within 10 business days of the affected month.

We host on AWS UK regions, which offer enterprise-grade resilience, availability zones, and real-time failover. All updates are deployed using zero-downtime deployment processes, and customers are notified of any planned maintenance in advance.

We continuously monitor uptime through automated dashboards and alerting systems, and reports are available on request or through the client portal.
Approach to resilience
Our service is designed with resilience and continuity at its core. We host the SIM Community Safety Management platform on AWS UK-based cloud infrastructure, which provides multiple layers of redundancy and failover across Availability Zones (AZs). These physically separate AZs are interconnected via low-latency links and enable us to distribute compute, storage, and database resources to eliminate single points of failure.

The service automatically scales to meet demand and reroutes traffic in the event of infrastructure failure. We use AWS services with built-in resilience, such as Amazon RDS (multi-AZ deployments), S3 (99.999999999% durability), and EC2 with auto-healing groups. Data is continuously replicated across secure zones and backed up regularly.

We implement automated monitoring, alerting, and failover processes to detect and respond to incidents in real-time. Disaster recovery procedures are tested regularly, and we can restore full functionality within a pre-agreed Recovery Time Objective (RTO) and Recovery Point Objective (RPO), guaranteed under 4 hours and 15 minutes, respectively.

All resilience design decisions align with the UK Government’s Cloud Security Principles, including asset protection and business continuity.

Full details of our infrastructure resilience design and disaster recovery processes are available on request to eligible buyers.
Outage reporting
We notify users of outages through multiple integrated channels to ensure prompt visibility and trust. Primary notifications are issued via automated email alerts to registered technical contacts and administrators. These alerts are sent immediately when any service degradation, partial outage or full outage is detected and include initial diagnostics, impact assessment and estimated time to resolution if available.

We maintain a dedicated, customer-accessible service status dashboard, which is updated in real time. This dashboard provides detailed, transparent information on current system status, components affected, incident history, and planned maintenance windows. It also allows users to subscribe to specific updates based on their role or system usage.

For enterprise buyers or integrators, we offer an optional status API, enabling integration of our service health information into your own dashboards or monitoring tools, and facilitating real-time automated polling of service status.

Following any outage, we publish incident summaries outlining cause, resolution steps, and mitigation measures. These are available through the dashboard and upon request.

Our outage reporting processes are designed to meet the needs of both operational and strategic stakeholders, support incident response planning, and ensure a high degree of transparency and accountability across all service tiers.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is strictly role-based and limited to authorised personnel only. We enforce Multi-Factor Authentication (MFA) for all administrative accounts and restrict access by IP where appropriate. User roles are defined by the principle of least privilege, with audit logs tracking all administrative actions. Support channels are segregated from production environments and access is logged and reviewed regularly. Sensitive data shared via support is encrypted in transit and at rest. Changes made via management interfaces are tracked through version-controlled logs, and suspicious access attempts trigger automated alerts for investigation.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
  • Other
Other security governance standards
Our service is hosted on AWS, which complies with ISO 27017, ISO 27018, SOC 2, and PCI DSS. We follow NCSC Cloud Security Principles and apply secure-by-design practices, including threat modelling, access control, and regular audits to ensure robust governance across development, deployment, and service operations.
Information security policies and processes
We follow a robust, risk-based information security management approach aligned to ISO/IEC 27001 principles. Our policies cover data protection, access control, encryption, secure software development, incident management, and business continuity.

All staff are trained on our information security policies at induction and through regular refresher sessions. Staff responsibilities are clearly defined in our Acceptable Use Policy and reinforced by contractual obligations and NDAs.

We operate a “secure by design” development approach, including regular vulnerability assessments, penetration testing, and adherence to NCSC Cloud Security Principles. Multi-factor authentication, least-privilege access, and encrypted data storage are enforced across all systems.

Security responsibilities are owned by the senior leadership team, with oversight from the Managing Director. A designated Security Lead manages policy compliance, incident response and risk reviews. Regular internal audits are conducted, and policy breaches are escalated to senior management immediately for investigation and remediation.

Incident response processes follow a structured approach: detection, triage, containment, eradication, recovery, and lessons learned. Serious breaches are reported to affected parties and regulators where applicable.

Security policies are reviewed quarterly or in response to major changes in threat landscape or service operations. Documentation is version controlled and securely stored with access logging.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
We operate a robust configuration and change management process aligned with ISO/IEC 27001 and CSA CCM v4.0. All service components are tracked throughout their lifecycle using a secure configuration management system. Change requests are logged, impact-assessed, security-reviewed, tested, and documented in line with government’s Operational Security principle. Every change is evaluated for risks to availability, confidentiality, and integrity. Approved changes are version-controlled and deployed using automated pipelines. Emergency changes are logged, reviewed retrospectively, and fully audited. The entire process ensures minimal service disruption, maintains secure service continuity, and supports traceability, with comprehensive records retained for audit and compliance purposes.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We follow a proactive vulnerability management process aligned to ISO/IEC 27001 and CSA CCM v4.0. Threats are identified through automated vulnerability scanning tools, threat intelligence feeds (including NCSC advisories), and vendor alerts. All vulnerabilities are risk assessed based on severity, exploitability, and service impact. Critical patches are deployed within 24 hours; high-severity issues within 72 hours; all others within a defined patching window. We monitor emerging threats daily and implement continuous security updates via DevSecOps practices. Vulnerability reports and mitigation actions are logged and reviewed monthly by our security team to ensure accountability and continuous improvement.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We use real-time monitoring and automated alerting systems (AWS CloudWatch, GuardDuty) to detect potential compromises, anomalous behaviour and unauthorised access attempts. All logs are centralised and continuously analysed against known threat patterns. On identifying a potential compromise, our security team initiates our documented incident response protocol within 15 minutes. This includes triage, impact assessment, isolation of affected systems, and root cause analysis. High-priority incidents are escalated immediately to senior engineers and, if necessary, to the customer. We maintain detailed audit trails and generate post-incident reports. Our monitoring and response procedures align with CSA CCM v4.0 and ISO/IEC 27001 standards.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We maintain pre-defined incident management processes for common events, including data breaches, service disruptions, and unauthorised access attempts. Users can report incidents via our online ticketing system, dedicated support email, or phone. All incidents are logged, triaged, and prioritised based on severity and impact. We follow defined escalation paths to ensure rapid response and resolution, including root cause analysis. Post-incident reports are shared with affected users and include a timeline, actions taken, and mitigation strategies. We maintain detailed incident logs for auditability and continual improvement, and align our processes with ISO/IEC 27035:2011 best practices.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
We offer a free 14-day trial of the full Serious Incident Manager system. Access is set up manually to ensure appropriate configuration. Core features are included: incident alerting, stakeholder management, response protocols, and dashboards. API access and exports are excluded. Onboarding support is provided. Trials may be extended on request.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
8%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
18%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Fccc8a9f-bf9c-4a21-a6d3-31bdfe3e82df
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
  • AWS ISO/IEC 27017:2015 – Cloud Security Controls
  • AWS ISO/IEC 27018:2019 – Protection of Personal Data
  • AWS SOC 1 / SOC 2 / SOC 3 reports
  • AWS CSA STAR Level 2 certification

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Plans for positive actions with community groups.
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at admin@bounce-agency.com. Tell them what format you need. It will help if you say what assistive technology you use.