COLIN ® as a Service (Press Office collaboration software)
COLIN® is an AI-infused secure online collaboration tool specifically designed for use by UK Government Press Offices. It benefits press officers by providing accurate up to date information to external requests from media outlets; an audit trail of conversations with journalists; and increases efficiency amongst the Media team.
Features
- Real-time data collaboration of press office data
- Tagging and advanced searching of press office records
- Integrated AI: draft Q&As, releases, lines, responses and more
- Auto-compilation of daily forecast records
- Contacts library of journalists for regular interactions.
- Virus scanning of uploaded assets
- Advanced Media Office task management
- Azure AD integration
- Integration with Roxhill Media contact management software possible
Benefits
- Rapid secure storage and retrieval of interactions with journalists.
- Centralised management of call logs, interview bids, forecasts and more.
- Advanced collaboration and drafting features.
- Workflow management for press officers providing accurate and consistent lines.
- Simple user interface - no training required.
- Mobile device optimised.
- Evergreen design - multiple free updates throughout contract.
- Used by majority of UK central government media offices.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 0 6 2 4 5 8 7 4 3 6 0 3 1 5
Contact
INTELOGY LIMITED
Andrew Tomlins
Telephone: 02037473506
Email: info@intelogy.co.uk
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
Being a cloud service, the system relies on access to the internet. All modern browsers are supported .
For multi-factor authentication, access to a mobile phone, office phone or the Microsoft Authenticator app is required. - System requirements
-
- Each user must have purchase a separate COLIN license.
- Each user must have a modern web browser.
- Each user must have access to the internet.
- User needs a secondary form of authentication (mobile, phone, app).
User support
- Email or online ticketing support
- Yes
- Support response times
-
Our help desk operates on UK Office hours only. Our response times are based on the following priority levels (as defined by the ticket raiser):
P1 – (Urgent) - 2 hours response;
P2 – (High) - 4 hours response;
P3 – (Normal) - 10 hours response;
P4 – (Low) - 10 hours response times. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
1) Standard support --> (inc. technical account manager and cloud support engineer): UK Office Hours Only.
2) Enhanced Out of Hours Support --> (On-call technical account manager for out of hours): price on application - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
1. Configuration workshop with the service owner
2. Security and configuration set up of the new instance of COLIN
3. Data loading of legacy data
4. Sign-off for go-live
5. Training workshop with end users (typically 45 minutes) - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- They can either run a report to extract all call logs directly into a spreadsheet but more typically we can provide a SQL backup database format.
- End-of-contract process
-
1. data export provided in SQL Bacpac format.
2. System kept operational for 30 days in read only mode
3. System deleted from the Cloud and any other customer data in existence removed from internal systems. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Pages scale to mobile device including a different menu.
Rich text editing of items such as forecasts is not possible via the mobile client. - Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- Yes
- Description of customisation
-
The customer can train the AI to respond in the tone of voice of their choice e.g. the leader of their organisation.
There 200 configuration options that the account manager will work with you on.
There is customisation of default templates for various types of records throughout the system.
There is customisation of the portal homepages.
Buyers can configure the use of various types of records as required.
Scaling
- Independence of resources
- Each COLIN instance operates within its own dedicated Azure resource pool, ensuring complete separation of compute, storage, and database resources. This isolation prevents any cross-tenant impact, meaning performance and availability for one customer are unaffected by the activity or demand of others. Azure’s resource governance and scaling features allow us to allocate and adjust capacity per instance as required, maintaining consistent performance. Continuous monitoring and proactive management further ensure that workloads remain stable and unaffected by other users’ usage patterns.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Trend analysis data on Call Logs and AI usage.
Number of Support Tickets Raised
Number of users registered - Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Press Office Solutions Limited
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- As a Senior Manager in the system, you can use the reporting function to export a user defined date range of call logs if required. If more data is required, a support ticket is required.
- Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- SQL
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
We mirror Microsoft Azure's availability guarantee and will directly pass on any refunds provided by Microsoft if service levels fall below their publicly stated levels (99.9%).
https://azure.microsoft.com/en-gb/support/legal/sla/summary/ - Approach to resilience
-
The Microsoft Azure platform provides a 14 day restore to point in time.
Further information is available on request. - Outage reporting
-
The following is available to us:
- a public dashboard https://azure.microsoft.com/en-gb/status/
- an API
- email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- MFA + Just-in-time authentication + IP address restrictions
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
We are working towards ISO27001 accreditation so we adopt the "Plan-Do-Check-Act" (PDCA) model, which is applied to all Information Security Management Systems (ISMS).
We have a set of policies defined at a Board level and all staff are contracted to follow them. They are available via our internal ISMS and any breeches of policies should be reported to our Operations Director who will decide on the course of action. Our policies are reviewed and adapted annually. All changes are highlighted to staff via internal meetings. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All changes are applied via standard processes. i.e.
A set of potential changes are assessed for inclusion in a point release of a new version. Assessment of risk, value to the end users, technical feasibility and complexity are taken into account and changes batched into priorities as a result. Changes are conducted on an internal development environment and tested with pre-defined scripts. The changes to application or configuration are then deployed by an authorised platform administrator to a staging environment, tested and signed off by a product manager, before repeating the process on a production environment in Azure. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Intelogy has configured the service through Azure Security Center to have constant monitoring and logging turned on for all nodes (web VMs and databases).
Any high priority threats are notified to our platform team instantly and action will be taken if possible and applicable at the soonest opportunity.
In addition, customers can access the following public status page:
https://azure.microsoft.com/en-gb/status - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Yes, we have a defined process for common events:
5.2 Detection
* Identification and reporting of the incident.
* Incident details must be captured.
* Categorization of incident.
* Classify the incident. High, Medium, Low
* Identification of stakeholder who all should be involved for managing the incident
5.3 Response
* Preventive action of the incident minimize the re-occurrence of the incident
* Corrective Action
5.4 Analysis
* Data collection
* Root Cause Analysis of the incident
5.5 Report
* Preventive action of the incident minimize the reoccurrence of the incident
* Learning communicated to either whole organisation and stakeholders - Incident management type
- Supplier-defined controls
- Incident management approach
-
Users can report incidents via phone, email and the helpdesk service.
Detection
* Identification and reporting of the incident.
* Incident details must be captured.
* Categorization of incident.
* Classify the incident. High, Medium, Low
* Identification of stakeholder who all should be involved for managing the incident
Response
* Preventive action of the incident minimize the re-occurrence of the incident
* Corrective Action
Analysis
* Data collection
* Root Cause Analysis of the incident
Report
* Preventive action of the incident minimize the reoccurrence of the incident
* Learning communicated to either whole organisation and stakeholders - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We offer a 30 day free trial to eligible organisations wishing to use the system before purchasing. They need to sign up to our user terms before inputting their data into the system. Full support and training is provided throughout.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 30%
- Over £5,000,001
- 40%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 94fe1d5d-42c6-4fd1-9e8a-4354344ecdb4
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 2ea592d2-831b-45df-8786-117854e250a0
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-