Skip to main content

Help us improve the Digital Marketplace - send your feedback

ELENI FINANCE

Forecasting

We provide financial and accounting software as a service. Our software helps to accurately aggregate multiple sources of actual cost and income data. The platform also dynamically forecasts future cost and income as well as benchmark performance, and provides performance insights.

Features

  • Real-Time Financial Reporting
  • Dynamic Forecasting
  • Performance Benchmarking
  • 360 degree Integration of CRM, ERP
  • Scenario Analysis
  • Actionable Insights
  • Working Capital Management
  • Cashflow Management
  • Dedicated Finance Team

Benefits

  • Securely connect bank and multiple systems
  • Customised Reporting Dashboards of Key Financial Information
  • Understand 'What-If' Scenarios
  • Get help with financial decisions i.e. investment & cost management
  • Learn from decisions made through actionable insights
  • Get recommendations to chart the best course of action
  • Get support from a dedicated team of experts
  • Predict future performance accurately and quickly

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at operations@eleni.finance. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 2 5 8 4 2 4 4 4 2 7 2 5 2 2

Contact

ELENI FINANCE Tawu Chipato
Telephone: 07493745063
Email: operations@eleni.finance

About your service

Service categories

Application Development and Deployment

Analytics and business intelligence

  • Business Intelligence
  • Advanced and predictive analytics
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Our software can be used with any software that has financial information i.e. ERPs, CRMs, booking software, banks etc.
Cloud deployment model
Private cloud
Service constraints
N/A
System requirements
  • Access to internet browser
  • Bank connection required for cashflow

User support

Email or online ticketing support
Yes
Support response times
Usually within 24 hours.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We have a dedicated expert team that is ready to support users. Our standard support is included as part of our service. However, there is additional support that can be provided, these will be costed separately depending on the support required.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We support users to start using the service through a structured onboarding and adoption approach.

First, we run a kick-off to confirm outcomes, stakeholders, data sources, security requirements and success measures. We then configure the tenant (organisation structure, mapping, calendars, currencies, permissions and approval workflows) and set up integrations via connectors and/or API. We load initial data (e.g. actuals, balances, cash positions and reference data) using validated import templates and automated checks, and we reconcile key totals to confirm accuracy.

Next, we provide role-based enablement: administrator setup guides, finance user training for planning/forecasting and reporting, and treasury user training for cashflow and liquidity processes. Training is delivered through live sessions and recorded materials, plus in-app guidance and example templates to accelerate first use (budgets, forecasts, dashboards and cashflow models).

We support early adoption with a pilot or phased rollout, regular check-ins, and a hypercare period after go-live to resolve issues quickly. Users can access help via documentation, a knowledge base, and support tickets with agreed response times. We also provide configuration handover so internal admins can manage ongoing changes independently.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
When the contract ends, users can extract their data in standard, usable formats without proprietary tooling.

Authorised administrators can export data directly from the user interface (e.g. reports, dashboards and underlying datasets) and/or use the API to retrieve the full set of customer data held within their tenant. Exports are provided in common formats such as CSV and Excel for tabular data, and JSON for API-based extraction. This includes configuration and reference data (e.g. entities, chart of accounts, dimensions), historical actuals, plans/forecasts, scenarios/versions, cashflow models and treasury datasets, plus audit/usage logs where contractually agreed.

We support an agreed offboarding plan and timetable, including confirmation of what will be exported, validation checks (e.g. record counts and reconciliation totals), and secure transfer methods (encrypted download and/or secure file transfer). If required, we can provide a final, complete extract aligned to a defined “as at” date.

After successful extraction and any agreed retention period, the tenant data is securely deleted in line with our data retention and disposal procedures, with deletion confirmation available on request.
End-of-contract process
At the end of the contract we follow an agreed offboarding process to ensure continuity, data access and secure exit.

We confirm the contract end date, any extension/renewal decision, and the exit timetable. Authorised users retain access until the agreed termination date (unless suspended for non-payment or security reasons). Before service access is removed, we support the customer to extract their data via the UI exports and/or API in standard formats (e.g. CSV/Excel/JSON), including reference/configuration data, historical actuals, plans/forecasts, scenarios and cash/treasury datasets. We can also provide a final “as at” extract and assist with validation (record counts and reconciliation totals).

We then disable integrations and API credentials, revoke user access, and complete secure deprovisioning of the customer tenant. Any customer support requests during offboarding are handled through normal support channels.

Following successful handover and any contractually agreed retention period, we securely delete customer data in line with our retention and disposal policy. Deletion confirmation can be provided on request. Where required by the contract, we also provide evidence of exit activities (e.g. offboarding checklist and completion statement).
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
Users can use our secure, versioned API to integrate their finance and data systems with our AI-driven performance management, planning, treasury and cashflow platform. Subject to role-based access controls, API users can: authenticate and access only their organisation’s tenant; ingest and synchronise finance data (e.g. chart of accounts, entities, actuals, balances, cash positions, currencies and dimensions) via batch or incremental loads; query and extract data for reporting/analytics (KPIs, liquidity/cash views, variance and forecast outputs); create and update planning artefacts (budgets/forecasts, assumptions, scenarios/versions where enabled); and automate integrations (e.g. status endpoints and optional webhooks/events where enabled) to support refresh, reconciliation and downstream workflows. All API activity is logged and auditable.

Users cannot: access other customers’ data or bypass tenant isolation; perform actions beyond their assigned permissions; bypass approval workflows, segregation of duties or audit trails; modify immutable audit logs; access underlying infrastructure/admin controls outside their tenant; retrieve stored secrets (e.g. connector or banking credentials); run arbitrary code or unrestricted database queries; or exceed protective service limits (e.g. rate, payload and concurrency limits) designed to maintain availability.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customise the service at both organisation and user level without code. They can configure organisational structures (entities, cost centres, departments), chart of accounts mappings, calendars/fiscal periods, currencies and consolidation rules. Users can tailor data models and reporting dimensions (tags/attributes), define KPIs and calculations, and configure dashboards, reports and templates to match internal performance packs. Planning and forecasting can be customised through driver-based models, assumptions, versioning, scenario sets and workflow stages (e.g. submit/review/approve), including role-based input forms per team. Treasury and cashflow can be tailored by defining bank account structures, cash categories, liquidity views, forecasting horizons, and reconciliation rules.

User access is configurable via role-based permissions, approval paths and segregation of duties. Integrations are configurable through connectors and/or API mappings, including import schedules, validation rules, error handling and data refresh frequency. Alerts and notifications can be set for thresholds and events (e.g. cash dips, variance breaches). Where enabled, customers can apply branding (logos/labels) and create saved views for different audiences. All configuration is controlled, auditable and can be managed by authorised administrators.

Our dedicated expert team can also help support where needed

Scaling

Independence of resources
We prevent impact through multi-tenant controls and elastic capacity. Each customer is tenant-isolated (data and requests are strictly scoped). We apply per-tenant API rate limits/quotas and throttling so one integration cannot consume disproportionate resources. The platform autos-scales to absorb demand spikes, and heavy workloads (imports, recalculations) run via queued background jobs with concurrency limits so interactive users remain responsive. We use caching, timeouts and circuit breakers to avoid cascading slowdowns, and continuously monitor latency and saturation with alerts and operational runbooks. Reserved capacity/dedicated environments are available if required.

Analytics

Service usage metrics
Yes
Metrics types
We provide service metrics via in-app dashboards and downloadable reports (and via API where required). Metrics typically include: availability/uptime and incident trends; performance (API response times, processing/import durations); data operations (last refresh time, import success/failure rates, validation errors and reconciliation status); integration health (connector status and error rates); security/audit (authentication events, role changes and export activity); support (ticket volumes, first response and resolution times); and adoption (active users, feature usage and workflow progress such as submissions/approvals). These metrics can be reviewed regularly as part of service governance.
Reporting types
Real-time dashboards
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users export data either through the application or via the API. In the UI, authorised users can export reports, dashboards and underlying datasets, including actuals, balances, cash positions, plans/forecasts, scenarios and assumptions, in standard formats such as CSV and Excel (and PDF for report outputs where required). Via the API, authorised administrators can programmatically extract all tenant data in JSON and apply filters (e.g. entity, period, version) for full or incremental extracts. All exports are controlled by role-based permissions and are logged for audit.
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
We guarantee 99.9% availability for the production service, measured per calendar month at the service boundary (web application and API). This equates to a maximum of 43 minutes unavailability per month.

Availability excludes:

Planned maintenance (scheduled outside normal UK business hours where possible, with advance notice)
Issues caused by the buyer’s networks/devices, third-party provider outages outside our control, or force majeure.

To meet this SLA we design for resilience (redundant components, automated monitoring/alerting, and failover across separate availability zones). If availability falls below the agreed SLA, we apply service credits* in line with the contract and provide incident reporting and RCA for material incidents.

If a buyer requires higher availability (e.g. 99.95%+), we can agree this through enhanced architecture and commercial terms.
Approach to resilience
Our service is designed for resilience using layered controls across architecture, operations and recovery.

Multi-AZ architecture (AWS): Production workloads run across multiple Availability Zones with redundant components to tolerate single-node or single-AZ failures.
Stateless, horizontally scalable services: Application tiers are designed to scale out automatically (autoscaling) so capacity increases during demand spikes and failed instances can be replaced quickly.
Resilient data layer: Datastores use managed, highly available AWS services with replication and automated failover; backups are encrypted and regularly verified with restore tests.
Isolation and fault containment: Network segmentation, least-privilege access, and rate limiting/circuit breakers reduce blast radius and prevent cascading failures from downstream dependencies.
Asynchronous processing: Heavy tasks (imports, recalculations) run via queued background jobs with retries and dead-letter handling, keeping the user experience responsive.
Continuous monitoring and response: Centralised logging/metrics/alerts (latency, errors, saturation) with on-call escalation, incident runbooks, and post-incident RCA and improvements.
Disaster recovery: Documented DR plans with defined RPO/RTO targets, tested periodically, covering regional recovery where required by the buyer.
Outage reporting
We report outages through multiple channels to ensure buyers are informed quickly and can track progress.

Status communications: We provide a service status page and/or email notifications to nominated contacts showing current status, impact, affected components and updates during an incident.
In-app notifications: Where appropriate, we display banners/messages in the application to inform users of service disruption and any workarounds.
Support channels: Buyers can raise or monitor incidents via our support desk; we issue incident tickets with timestamps, severity, and ongoing notes.
Update cadence: For major incidents we provide regular updates (e.g. every 30–60 minutes, or as agreed) until resolution.
Post-incident reporting: For material outages we provide a written incident report including timeline, root cause, customer impact, corrective actions and prevention measures, and we review this in service governance meetings.

Where required, we align communications to the buyer’s incident management process and escalation contacts.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted by least privilege and strong authentication. Admin functions are protected with granular RBAC, MFA for privileged users and (where required) SSO (SAML/OIDC). Management endpoints are hardened and protected with network controls such as IP allowlisting/VPN and WAF/rate limiting. Support access to production is time-bound and approval-controlled (just-in-time/break-glass), with segregation of duties. All admin/support actions (logins, role changes, configuration changes, exports) are fully audited and monitored. Support tickets are limited to authenticated, named customer contacts and are tenant-isolated; sensitive data is minimised/redacted and attachments are handled securely.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We operate a formal information security management framework with documented policies, procedures, and regular review. Key policies and processes include:

Security governance & risk management: security roles/ownership, risk assessment and treatment, policy review cycles, and supplier/third-party risk management.

Access control: least privilege, role-based access control, MFA for privileged access, joiner/mover/leaver processes, and regular access reviews.

Secure development (SDLC): secure coding standards, peer review, automated testing, dependency management, and vulnerability management (scanning, triage, remediation SLAs).

Data protection: data classification/handling, encryption in transit and at rest, key management, retention and secure disposal, and privacy-by-design.

Security monitoring & logging: centralised logs, audit trails, alerting for suspicious activity, and regular review of security events.

Incident management: documented incident response plan, escalation/on-call, containment and eradication procedures, customer communications, and post-incident RCA.

Change & configuration management: controlled changes, segregation of duties, environment hardening, patch management, and configuration baselines.

Business continuity & disaster recovery: backup policy, recovery objectives (RPO/RTO), DR testing, and continuity plans.

Security awareness: staff onboarding training, annual refreshers, and targeted training for engineering and support roles.

These policies are supported by evidence (logs, runbooks, testing outcomes, training records) and are applied across our AWS-hosted production environment.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We use formal configuration and change management to control risk and maintain stability. Configuration is defined and tracked in version control using Infrastructure-as-Code, with standard security baselines, least-privilege access, segregation of duties and monitoring for configuration drift. Changes follow a controlled lifecycle: request and scope, impact/risk and security assessment, peer review and approval, testing in non-production, and deployment via CI/CD with automated checks and rollback capability. Emergency changes use an expedited process with retrospective review. All changes are logged with an auditable record (who/what/when), and major issues trigger RCA and improvements.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We assess threats using continuous monitoring and risk-based triage: findings from vulnerability scanning (infrastructure/configuration), CI/CD security testing (SAST) and dependency scanning (SCA) are validated and prioritised by CVSS severity, exploitability, exposure (internet-facing), and business impact, informed by threat modelling and logs/alerts. We deploy patches via controlled CI/CD and emergency change procedures: Critical issues are mitigated immediately and patched as fast as practicable (typically within 24–72 hours), High within days, and others in scheduled releases. Threat intelligence comes from AWS Security Bulletins/Advisories, vendor CVEs/NVD, dependency alerts, penetration tests, and coordinated disclosure reports.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We identify potential compromises via centralised logging and alerting across our application and AWS environment (e.g. failed logins/MFA events, admin/role changes, API usage anomalies, data exports, CloudTrail/WAF activity and network signals). Automated detections flag behaviours such as credential stuffing, privilege escalation, unusual IP/geo access and abnormal data volumes. When detected, we follow incident runbooks: triage/validate, contain (disable accounts/keys, block IPs, isolate workloads), preserve evidence, eradicate (patch, rotate credentials/keys), and recover safely. We provide buyer communications, RCA and corrective actions for material incidents. On-call responders triage high-severity incidents within 15–60 minutes.
Incident management type
Supplier-defined controls
Incident management approach
We operate a documented incident management process with pre-defined runbooks for common events (e.g. service degradation/outage, security alerts, failed integrations/data loads). Users report incidents via our support desk (ticket/email/portal) and named escalation contacts; critical issues can be escalated by phone/on-call route where agreed. Incidents are triaged by severity, assigned an owner, and managed through containment, fix and recovery, with regular updates to nominated contacts and (if used) a status page/in-app banner. For material incidents we provide an incident report including timeline, impact, root cause, actions taken, and corrective/preventive measures (RCA), shared via email/support ticket and reviewed in governance meetings.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
We do not provide a free version. Buyers receive a contracted service with agreed features, environments, support and SLAs. Trials or proofs of concept can be offered by agreement, typically time-limited and provided on a non-production basis with restricted functionality, data volumes and support, and subject to our standard terms.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
3%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
7%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
12%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at operations@eleni.finance. Tell them what format you need. It will help if you say what assistive technology you use.