Skip to main content

Help us improve the Digital Marketplace - send your feedback

BUILDEMPIRE LIMITED

Totara Perform, Performance and Talent Management

BuildEmpire, a Totara Platinum Partner, delivers Totara Learn, Engage and Perform for the UK public sector. Trusted by NHS Trusts and public sector organisations, we provide secure, scalable platforms aligned to the latest Totara releases, with configurable and bespoke solutions tailored to public sector learning and performance needs.

Features

  • Appraisals: Configurable performance review cycles
  • Goals management: Set and track organisational goals
  • Feedback tools: Continuous feedback and check-ins
  • Competency frameworks: Manage skills and capability structures
  • Evidence capture: Link learning to performance outcomes
  • Reporting dashboards: Performance and capability insights
  • Skills tracking: Identify skills gaps and development needs
  • Workflow automation: Approvals and notifications
  • SMART goals: AI-assisted SMART goal creation
  • Coaching support: Enable coaching conversations

Benefits

  • Better performance conversations: Support continuous improvement
  • Clear priorities: Align goals to public sector outcomes
  • Stronger capability: Address skills gaps proactively
  • Evidence-based decisions: Link learning to performance
  • Reduced admin: Automated workflows save time
  • Consistent processes: Fair reviews across teams
  • Improved retention: Support growth and progression
  • Better workforce planning: Skills and capability insight
  • Strong governance: Clear audit trails
  • Measurable impact: Track outcomes confidently

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at commercial@buildempire.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 1 7 0 1 5 6 2 4 9 5 2 5 6 0

Contact

BUILDEMPIRE LIMITED Felicity Fiore
Telephone: 0161 641 2434
Email: commercial@buildempire.co.uk

About your service

Service categories

Applications

Enterprise resource management

  • Enterprise performance management
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
The service extends Totara Learn as the core learning management system. It integrates social and collaborative learning capabilities formerly delivered through Totara Engage and can be further extended with Totara Perform for performance management, appraisals, feedback and coaching, providing a unified talent experience platform.
Cloud deployment model
Public cloud
Service constraints
Planned maintenance is scheduled in advance and designed to minimise disruption. The platform is accessed via a modern web browser and does not require specific hardware. Configuration options are agreed during onboarding to meet customer requirements.
System requirements
Entirely SaaS based, requires a working supported browser

User support

Email or online ticketing support
Yes
Support response times
Our support team is available Monday to Friday, 8:00am to 5:00pm (excluding UK Bank Holidays). During these hours, queries can be raised via email or our web portal and are prioritised based on severity. Initial response times range from approximately one hour for high-priority issues to up to 48 hours for lower-priority requests. Response times are measured during core support hours from the point a request is logged. Requests received outside core hours are responded to at the start of the next business day. Out-of-hours support can be provided by prior agreement, subject to additional charges.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Users can initiate real-time conversations with support staff via web chat during support hours, send messages, receive responses, and access relevant help resources. For complex queries, users may be directed to alternative support channels such as email or the support portal.
Web chat accessibility testing
N/A
Onsite support
Yes, at extra cost
Support levels
We provide responsive support designed to meet the needs of public sector organisations throughout the service lifecycle.

Standard Support is included within the subscription fee and provides access to email and web portal support during core business hours, alongside online guidance and resources for system administrators. Requests are prioritised by severity to ensure timely resolution.

Implementation and Onboarding Support is delivered by dedicated implementation specialists who work with customers to configure the platform, support data migration, and enable a successful go-live. This includes tailored implementation planning and deployment support.

Each customer is assigned a dedicated Implementation Specialist, Project Manager, and Customer Success contact, who act as the primary points of contact. They provide ongoing service oversight, regular reviews, and coordination of support activities, ensuring the platform continues to meet organisational needs.

Offboarding Support is available to support contract exit, including data export, reporting, and platform decommissioning activities.

All standard support and customer success management are included within the subscription cost, with no limits on support requests. Optional out-of-hours or enhanced support can be provided by agreement where required.
Support available to third parties
No
AI chatbot
No

Onboarding and offboarding

Getting started
We support customers through a structured onboarding and adoption process designed to ensure a smooth start and long-term success.

Following contract award, customers are supported by a dedicated implementation specialist and project manager who work collaboratively to understand organisational requirements and agree an implementation plan. This typically begins with an initial discovery workshop to confirm scope, configuration, data migration, and timelines.

Implementation specialists support system setup, configuration, and migration activities, while ensuring the platform is ready for go-live. Customers receive online training sessions for administrators and key users, with sessions recorded and supported by user documentation for ongoing reference. Training covers day-to-day administration, reporting, and platform usage.

Once live, customers are supported by a customer success contact who provides ongoing guidance, adoption support, and regular reviews to help maximise value from the service. Optional onsite training or workshops can be provided by agreement where required.

Throughout onboarding, users are guided on how to access support, raise queries, and make effective use of platform features, ensuring a confident and supported transition into live use.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
When a contract ends we ensure customers are able to fully extract the data they need.

Initially we would inform them they have a certain amount of time to extract their data themselves should they wish. System administrators have access to all user data held in the system and can extract by their preferred method. They are also able to run any number of system reports and export these from the LMS as a comprehensive record of all system data.
End-of-contract process
Upon the completion of the Initial Contract Term, you have the option to extend for an additional period. BuildEmpire will work with you to provide a quote for the subsequent term.

We are committed to facilitating a smooth exit process for customers who request to leave our service. Upon confirmation of a customer's decision to leave, we will send Off-Boarding correspondence via email. This will include details of the products not being renewed, the cessation date of access, steps involved in the Off-Boarding process, and contact information for a designated individual within BuildEmpire for any inquiries.

Our standard off-boarding procedure does not incur any costs for customers.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile experience is optimised for learning, collaboration, and content consumption, including course access, progress tracking, and notifications. The desktop service provides the full administrative and configuration functionality, including advanced reporting, system configuration, and user management.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a secure, web-based interface available via modern browsers. It provides a role-based user experience for learners, managers, and administrators, with configurable dashboards, intuitive navigation, and integrated reporting. The interface supports responsive access across devices and can be branded and configured to meet organisational requirements.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Accessibility for the platform is assured through a combination of platform-level accessibility assessment and controlled service configuration.

Totara, as the core platform provider, has undertaken structured accessibility assessment and publishes detailed accessibility documentation and an Accessibility Conformance Report (ACR). This work covers platform support for assistive technologies, including keyboard navigation, screen readers, and accessible interaction patterns, and informs ongoing improvements across releases.

BuildEmpire aligns service delivery to this accessibility framework by deploying and configuring the platform in line with published accessibility guidance. This includes the use of accessible themes and layouts, adherence to supported accessibility features, and guidance to customers on creating accessible learning content and user experiences within the platform.
API
Yes
What users can and can't do using the API
Our service provides REST-based APIs that allow customers to integrate the platform with other systems and automate key processes.

Using the API, users can programmatically manage users, enrolments, course data, learning records, and synchronise data with external systems such as HR, identity management, and reporting tools. APIs can be used to support initial configuration activities, including user provisioning and data import, as well as ongoing updates such as role changes, enrolments, and status updates.

The API supports secure authentication and follows documented standards to ensure reliable integration. Changes made via the API are subject to the same permission controls and validation rules as changes made through the user interface.

Advanced system configuration, user interface customisation, and some administrative settings are not available via the API and must be managed through the platform’s administrative interface. API usage is intended to complement, not replace, standard platform administration and is designed for integration and automation rather than full system setup.
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The platform can be customised to reflect organisational structure, branding, and ways of working.

Customers can configure the platform using built-in administrative tools. This includes custom branding and themes, dashboards, learning catalogues, roles and permissions, learning pathways, programmes, certifications, workflows, notifications, and reports. Administrators can tailor user experiences for learners, managers, and administrators without requiring code changes, enabling organisations to adapt the platform as needs evolve.

Configuration can be managed by authorised customer administrators through the service interface and applied across departments, teams, or tenant structures where required.

Where additional flexibility is needed, BuildEmpire provides bespoke development and integration services. This may include custom plugins, workflows, reports, integrations with external systems, or user interface enhancements. Bespoke work is delivered by BuildEmpire’s specialist development team and agreed through structured implementation or change processes.

This combination of self-service configuration and optional bespoke development ensures the service can be adapted to complex public sector requirements while remaining secure and supportable.

Scaling

Independence of resources
The service is delivered on a modern, scalable cloud platform designed to provide a consistent experience for all users. Capacity is planned and managed to support growth and peak usage, ensuring reliable performance across organisations. The platform is continuously monitored and maintained to deliver a stable, high-quality service, allowing users to work confidently without being impacted by changes in demand.

Analytics

Service usage metrics
Yes
Metrics types
Administrators can access metrics covering user activity, course enrolments, completions, progress, certifications, compliance status, and learning outcomes. Usage data can be viewed at organisational, departmental, or user level to support monitoring and reporting requirements. Reports can be scheduled, filtered, and exported to support internal governance, audits, and management reporting.

The service also provides visibility of platform usage trends, including active users, content engagement, and participation over time. Metrics can be used to identify adoption levels, skills development, and areas requiring intervention.

Access to metrics is role-based, ensuring that only authorised users can view or manage reporting data.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Totara

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Totara is GDPR compliant and has the ability for an individual user to export all data linked to them. The format of each item of exported data is equivalent to its storage method in the application's database (e.g. course names/completion dates, or numerical values that represent status). Totara also provides capabilities for export in the application (e.g. Report Builder, Record of Learning). This approach can be useful for an individual wanting, for example, to take their completion data (courses, competencies, certifications) with them to a new employer.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
BuildEmpire commits to a minimum monthly availability of 99.9% for the Service.

The platform is available 24*7, ensuring accessibility to users at any time. However, periodic maintenance, scheduled in advance, results in brief downtime, lasting only a few minutes. These maintenance activities are planned to occur outside of our customer's regular business hours, minimising disruption to users, and advance notification is provided to all customers to ensure seamless transition and minimal impact on operations.
Approach to resilience
Our service is designed with resilience in mind, hosted in modern cloud environments with accredited providers. Our hosting architecture ensures scalability and robustness. Detailed information on our datacenter setup is available upon request.
Outage reporting
We utilise a public dashboard for outage reporting and also send email alerts to affected customers, providing updates on resolution progress.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
We enforce strict access control measures to safeguard our management interfaces and support channels:

- Users are granted access rights and permissions strictly based on their job roles, ensuring they have access only to necessary assets and systems.
- Regular reviews of user access rights are conducted to verify that permissions remain appropriate and in line with job responsibilities.
- Privileged accounts are selectively assigned to individuals requiring them for administrative tasks, minimising potential security risks.
- Management systems incorporate secure logon and authentication mechanisms, such as 2FA (Two-Factor Authentication), to enhance protection against unauthorised access attempts.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Our Information Security Management System is anchored in the ISO 27001 framework, ensuring robust cybersecurity and privacy measures. A suite of comprehensive policies outlines information security processes, roles, and responsibilities for all stakeholders.

New team members undergo thorough security training, refreshed annually to ensure continuous awareness and compliance. Oversight is provided by the Senior Management Team, responsible for policy implementation and continuous monitoring. Departmental leaders enforce policy adherence within their teams, ensuring compliance among their staff. Additionally, all employees are responsible for identifying and reporting any non-conformances to the Data Protection Officer.

Biannual audits of the ISMS validate its ongoing effectiveness, providing insights for refinement as needed.

Through these measures, we demonstrate a steadfast commitment to information security, safeguarding our organisation, our clients, and their stakeholders against potential threats.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Our robust change management processes rigorously assess all changes for potential functional and security impacts. Utilising task tracking software ensures adherence to protocols and enables thorough auditing. Prior to deployment to the testing environment, all code changes undergo review by a separate team member. Testing occurs in an isolated environment before deployment to the live environment. Throughout the process, we maintain full transparency and communication with our clients, ensuring they are informed every step of the way.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Our vulnerability management process includes continuous risk assessments through our ISO-27001 ISMS processes. We swiftly address potential threats:

- High-risk vulnerabilities are promptly mitigated upon identification.
- Development and deployment of fixes occur as soon as practicable.
- We maintain subscriptions to industry-leading sources for threat intelligence.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We ensure the security of our platform environments through vigilant protective monitoring:

- Potential compromises are identified through firewall services monitored by our database partner, AWS. Suspicious activities trigger immediate reports for investigation.
- Our support team conducts regular reviews of client platforms and access event logs. Additionally, clients have access to event logs to monitor changes to platform data.
- Reports of suspicious activity undergo immediate investigation using our ISO 27001 security incident processes. All incidents are thoroughly assessed, resolved, and promptly communicated to clients.
Incident management type
Supplier-defined controls
Incident management approach
We maintain structured incident management processes to swiftly and effectively address events:

- Our Information Security Management System includes a documented Incident management procedure, enabling systematic handling of all events.
- Users have multiple channels to report incidents, either via email or through the customer's project portal.
- Incidents are diligently recorded in the customer's communication log and undergo thorough investigation. Root cause analysis is conducted, and corrective actions are identified and tracked until completion.
- Incident reports are communicated to customers through the project portal as appropriate, ensuring transparency and timely updates.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Available upon request, our demonstration portal allows users to explore platform functionality, including site navigation, course catalogue browsing, and reporting. Contact commercial@buildempire.co.uk for access.
Link to free trial
https://buildempire.co.uk/book-demo/

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Approachable Certification
ISO/IEC 27001 accreditation date
Saturday 12 October 2024
What the ISO/IEC 27001 doesn’t cover
Our ISO/IEC 27001 certification does not cover customer-managed environments, end-user devices, or physical premises not operated or controlled by BuildEmpire. Physical security controls are applied proportionately and are limited to the scope of our remote-first operating model and the third-party data centres and cloud infrastructure we use.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
3ef295e4-4b24-43f4-a18f-ddff0afe923f
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
20304a0b-8ceb-49db-a50e-e2f0ebe9ec4e
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at commercial@buildempire.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.