Refernet
Refernet is a referral management solution that helps build partnerships and enables referrals to be made securely between agencies and their partners. Clients include Citizens Advice, councils, charities, legal and money advice, healthcare and social prescribing services across the UK. Refernet is GDPR compliant and reports on activity and outcomes.
Features
- User friendly referral management with mobile friendly interface.
- Refer patient/clients between approved partner agencies, with full referral history
- System Administrator controls which agencies to include in their network
- Search and filter capabilities to find agencies
- Enhanced agency profiles including service scope and open hours
- Secure document and sensitive data sharing between service providers
- Option to include self-referral button on your own website.
- Report on referral activities and client/patient outcomes.
- Whitelabel product: allows for customer branding and user avatars.
- Comprehensive field sets for the referral form
Benefits
- Create and leverage national, regional and sub-regional partnerships
- Evidence your referral activity to help secure funding
- Record and monitor outcomes to enhance/support funding opportunities
- Record activity and report per agency and entire network
- Refer customers securely across the network
- Secure, GDPR compliant system for sensitive data handling
- Supports remote working of agency staff
- Avoids 'signposting' so clients don't have to repeat their story
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 2 0 1 2 0 0 2 7 9 2 6 8 1 0
Contact
Refernet
Steve Wheele
Telephone: 01273 244099
Email: info@viccariwheele.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Quarterly deployments of updates/features and planned periodic maintenance, outside office hours 9-5, typically at midnight or over the weekend. Customers are informed via a bulletin a couple of weeks in advance.
- System requirements
- Device that can run a modern web browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Telephone and email support during business hours Monday to Friday excluding bank holidays (9am-5pm) is provided for system administrators and we aim to respond within 4 business hours.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- Email and telephone support during business hours (9-5) is provided for functionality issues and usage. Support is provided by dedicated senior technical/training/commercial staff. Initial training is included in the license cost and any refresher training is at extra cost (as per pricing document).
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Refernet has an intuitive design that prompts users as they navigate the system and video tutorials are available.
Initial training is via Zoom/Teams and free of charge for 2 hours, delivered by Technical Director. There is no limit on attendees and can be recorded at no extra cost.
Customer Administrators typically then train new customer users, however additional training can be delivered by the Refernet Technical Director (on site or remote) at extra cost. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Video
- End-of-contract data extraction
-
System access can be maintained for up to 1 month for customers to add and remove data (within constraints of contract). Any additional needs can be discussed with client.
System and all data deleted 1 month after contract ends. - End-of-contract process
-
A data export function within the system allows the Adminsistrator to export all data, while other users can only export token information. Includes annonymised referral data.
Categories of advice and outcomes cannot be exported.
System and all data deleted 1 month after contract ends. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Documentation is checked using in-built accessibility checker tools. In particular we use bullet points and subheadings to give clear explanations and follow a linear logical layout. We avoid bold and underlined text (except for links), and large blocks of heavy text. We make sure text is a minimum size 12 and is left aligned.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There are only visual differences where the service has been optimised for different platforms, the functions all remain the same.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Web interface via secure login where users find and select an Agency to refer to, fill in a referral form, and send the referral to the chosen agency. Agencies are notified of activity via email and requested to login and respond. (no data is included with emails)
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
-
First phase pilots are being carried out in small client groups.
Each system that is commissioned includes a discussion with the client about their customers, user requirements, possible support services (such as assistive technology needs) any specific needs are discovered and agreed with at this point. We complete this on a case by case basis, dependent on requirement. - API
- No
- Customisation available
- Yes
- Description of customisation
-
Refernet is a whitelabel product, the customer area can be branded.
Via the admin portal, Administrators can disable and mandate referral form fields, categories of advice, outcomes fields, and micromanage which agencies can see or refer to other agencies.
Administrator's data inputs leads to customisation of homepage.
Scaling
- Independence of resources
- The Refernet service is monitored for resources and if any system is performing below estimated usage, we can scale our resources to accommodate and additional needs.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide data visualisation and a list view of:
- Number of referrals
- Open, accepted, updated referrals - as Agency
- Open, accepted, updated referrals - as User
Data can be viewed on dashboard or as a report, granularity and date range can be set.
Administrators can view number of Agency users. - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- A data export function within the system, which includes option to export all data.
- Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
-
- .jpg
- .doc
- .docx
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We have a 99% availability.
- Approach to resilience
-
Located in London EC1 datacenter, ISO27001 and PCI-DSS compliant.
Fully managed by a team of IT professionals, with dedicated account handling and SecOps teams on a 365/24/7 basis.
Full server snapshots daily and incremental backups every 4 hours.
Outage monitoring alerting the CTO, SecOps and Dev Team in the event of connection failure. Historic versions for Refernet (taken before any changes or features are deployed) are stored onsite at our alternative studio location. Access to this location is via a secure VPN and locked to our dedicated IP.
Our onsite studio is monitored 365/24/7. - Outage reporting
-
Administrators are alerted as soon as issue is detected, via email or phone call. Thr system will also show an error landing page.
A report is generated, available to customers if requested.
Refernet maintain a Disaster Recovery policy with procedures for anuy outage event.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- The Administraor interface is restricted to user accounts with relevant privileges, and accessed via a username and password.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- The CTO is responsible for the security and integrity of data held on Refernet systems by specifying, installing and maintaining adequate ICT equipment and security systems. However, all users have responsibility for the security and safety of Refernet and the information held on those systems.
- Information security policies and processes
-
Refernet are a small team with a simple reporting structure. We maintain the following information security policies, procedures and standards:
ICT Security Policy, Change Process Policy & Cyber Essentials.
All staff have taken the certified NCSC training provided by Hiscox CyberClear Academy. - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We assess potential threats by conducting an annual manual pen test and ad hoc automated pen testing. Threats are minimised by using software firewalls.
Patches to the operating system are deployed by the cloud hosting provider. Patches to the Refernet system are deployed quarterly for low-level risks and immediately for high-risk bugs including outside of normal business hours.
Our Disaster Recovery Policy sets out our response times. - Vulnerability management type
- Undisclosed
- Vulnerability management approach
-
We assess potential threats by conducting an annual manual pen test and ad hoc automated pen testing. Threats are minimised by using software firewalls.
Patches to the operating system are deployed by the cloud hosting provider. Patches to the Refernet system are deployed quarterly for low-level risks and immediately for high-risk bugs including outside of normal business hours.
Our Disaster Recovery Policy sets out our response times. - Protective monitoring type
- Undisclosed
- Protective monitoring approach
-
Malware, virus and performance monitoring software is conducted by the cloud hosting provider. Any malware or virus detected would be instantly quarantined on the server.
Failed log-in attempts are logged and monitored. Any data breach within the Refernet system will have an immediate response.
Response times are detailed within our Update Control Process. - Incident management type
- Undisclosed
- Incident management approach
-
Any incident will be flagged to Refernet via automated error emails. All incidents are managed in line with our Incident Policy which includes processes for common events. Our Disaster Recovery Policy refers to our process for informing customers about disasters and data breaches.
After any incident, an Incident Report is produced. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- A5f67948-c310-4cef-bf3e-b3c204ba74ab
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-