Skip to main content

Help us improve the Digital Marketplace - send your feedback

Evouchers

Evouchers

Evouchers is a secure digital platform for issuing and managing vouchers, prepaid cards and grants. Used by local authorities, charities and schools, it enables fast, controlled distribution of funds, full audit trails, flexible delivery by SMS or email, and robust reporting to support welfare and education programmes.

Features

  • Secure digital voucher and prepaid card issuance via web-based platform
  • Immediate voucher delivery by SMS, email, or secure printable formats
  • Centralised administration portal with role-based access and audit logging
  • Real-time tracking of ordered, issued, redeemed, and unredeemed vouchers
  • Configurable spend controls by retailer, category, value, and delivery
  • Bulk voucher creation through CSV upload & API link
  • Comprehensive reporting exports supporting financial reconciliation and compliance
  • UK/Ireland-hosted infrastructure with encryption, access controls, and GDPR compliance
  • High-availability service supporting large-scale welfare and education programmes
  • Integration-ready architecture supporting APIs and third-party service connections

Benefits

  • Distribute financial support quickly without manual processing or physical vouchers
  • Reduce administrative workload through automated issuance and bulk management tools
  • Maintain clear audit trails supporting compliance, transparency, and funding assurance
  • Control how funds are spent using configurable retailer category controls
  • Deliver support securely to recipients without requiring bank accounts
  • Monitor scheme performance in real time to improve decision making
  • Scale welfare and grant schemes rapidly without additional staffing requirements
  • Minimise fraud risk through access controls, validation, and reporting
  • Improve beneficiary experience through instant digital delivery and redemption
  • Support multiple programmes from one platform with consistent processes

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@evouchers.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 3 0 3 2 6 7 3 0 2 9 9 3 1 8

Contact

Evouchers Neil Roach
Telephone: 01638 438094
Email: tenders@evouchers.com

About the service

Service categories

Applications

Customer relationship management

  • Digital commerce
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Planned maintenance windows may temporarily restrict access, typically scheduled outside core UK working hours

Service availability is dependent on internet connectivity and supported web browsers

SMS and email delivery are subject to third-party telecommunications and email provider availability

Voucher redemption is subject to participating retailer networks and their operating hours

Some features, such as integrations, may require configuration and are not enabled by default
System requirements
  • Modern web browser supporting current security standards enabled
  • Reliable internet connection to access cloud-hosted service securely

User support

Email or online ticketing support
Yes
Support response times
Email and online ticketing support is available during UK business hours, Monday to Friday. Initial responses are typically provided within one working day. Weekend and bank holiday enquiries are monitored, with responses provided on the next working day unless urgent.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We test with common assistive technologies, including screen readers and keyboard-only navigation, to ensure usability without a mouse. Testing has focused on readable chat content, logical focus order, and compatibility with standard browser accessibility tools. Feedback has been used to address identified usability issues.
Onsite support
No
Support levels
Evouchers provides standard support as part of the service at no additional cost. Support is delivered via email and online ticketing during UK business hours, Monday to Friday. This includes assistance with platform usage, configuration, issue resolution, and incident management.

There is no charge for standard support.

Enhanced support arrangements, such as extended support hours or priority response, can be discussed and priced separately where required, subject to agreement.

Each buyer is provided with a named account contact. A dedicated technical account manager or cloud support engineer is not provided as standard, but specialist technical support can be made available for complex implementations if agreed as part of onboarding or ongoing service delivery.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Evouchers supports users through a structured mobilisation and onboarding process designed for rapid, low-risk deployment. Each buyer is supported by a named Account Manager and Implementation Manager from contract award through go-live.

Onboarding begins with a welcome and mobilisation call to confirm requirements, timescales, voucher types, delivery methods, reporting needs, and training schedules. The service is configured to buyer requirements, including branding, scheme rules, referral routes, eligibility logic (where applicable), and user access permissions.

Users receive online training sessions tailored to their role (for example administrators, partners, or schools). Training sessions are delivered remotely, recorded, and shared for future reference. Additional sessions are provided where needed during mobilisation or at peak periods.

Comprehensive user documentation and self-help resources are available, including FAQs, guidance videos, and downloadable materials. Ongoing support is provided via email, online ticketing, and web chat during core support hours, with resources scaled during high-volume periods.

This approach enables users to begin issuing vouchers quickly while maintaining confidence, governance, and operational consistency.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Users can extract their data directly from the service using standard reporting and export tools. Administrative users can download transactional, financial, and audit data in commonly used formats such as CSV prior to contract end.

On request, Evouchers can support a structured data export covering voucher issuance, redemption, balances, and reporting history to assist with reconciliation, audit, or transition to an alternative provider. Data extraction is supported during the contract exit period in line with agreed offboarding arrangements and data protection requirements.

After contract termination and completion of data extraction, customer data is securely retained and deleted in accordance with contractual terms and UK GDPR obligations.
End-of-contract process
At the end of the contract, Evouchers works with the buyer to support an orderly and controlled exit. Prior to contract expiry, authorised users can extract their data using standard reporting and export tools. On request, Evouchers can also provide a structured data export to support audit, reconciliation, or transition to an alternative provider.

Issued vouchers remain valid until their individual expiry dates, unless otherwise agreed. After contract completion and data extraction, customer data is securely retained and deleted in accordance with contractual terms and UK GDPR requirements.

The contract price includes:

Access to the Evouchers cloud-based platform
Standard onboarding and mobilisation support
Configuration of voucher schemes and delivery methods
Standard reporting and data exports
Email and online ticketing support during UK business hours
Contract exit support, including standard data extraction

Additional costs may apply for:

Extended or enhanced support arrangements outside standard service levels
Bespoke development, integrations, or non-standard configuration
Large-scale or bespoke data migration services
Additional services agreed outside the standard contract scope
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is accessed through a responsive web-based interface that adapts to desktop, tablet, and mobile devices. Core functionality is consistent across desktop and mobile.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a secure, web-based administrative dashboard. Authorised users can order and issue vouchers, manage users and permissions, configure schemes, and access real-time reporting and exports. The interface is designed for use via standard web browsers and does not require local software installation.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have tested with common assistive technologies, including screen readers and keyboard-only navigation, to ensure usability without a mouse. Testing has focused on readable chat content, logical focus order, and compatibility with standard browser accessibility tools.
API
Yes
What users can and can't do using the API
What users can do using the API

Set up / onboard (where API access is enabled): create or update scheme configuration values (for example voucher types, values, expiry rules), and establish credentials (API keys) for authenticated access.

Issue support: submit requests to create and send vouchers or payment instruments to recipients (for example via email/SMS) and provide recipient references and metadata.

Bulk operations: automate high-volume issuance from buyer systems instead of manual portal entry.

Status and reconciliation: retrieve issuance status, delivery status (where available), and redemption / settlement status to support reconciliation.

Reporting feeds: export transactional data to the buyer’s systems for audit and MI.

What users can’t do using the API

No unauthenticated access – all API calls require authorised credentials and permissions.

No bypassing governance controls – API actions must comply with configured scheme rules (for example value limits, expiry, spend controls).

No direct modification of historic financial records – completed / reconciled transactions are not editable (corrections are handled via adjustments and audit trails).

No access to other organisations’ data – strict tenant separation applies.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The service allows buyers to customise voucher schemes, delivery, and communications. Customisable elements include voucher types, values, retailer and spend restrictions, delivery methods, and the content of SMS and email messages sent to recipients. Reporting outputs and user roles can also be configured.

Customisation is completed through the secure web-based administrative dashboard. Authorised users can update scheme settings and edit SMS and email message templates using built-in configuration tools, without requiring technical development. Some automation may be supported via API where enabled.

Customisation is restricted to authorised administrative users within the buyer organisation. Role-based access controls ensure only permitted users can change scheme settings or recipient communications.

Scaling

Independence of resources
Evouchers is delivered as a multi-tenant, cloud-based SaaS platform designed to scale with demand. The service uses logical tenant separation to ensure each customer’s data, configuration, and activity are isolated. Capacity is actively monitored and scaled to support peak usage periods, such as seasonal welfare schemes, without degradation for other users. Rate limiting and system safeguards prevent individual accounts from over-consuming shared resources. Regular performance monitoring and operational controls ensure consistent service levels across customers, even during periods of high volume or concurrent activity.

Analytics

Service usage metrics
Yes
Metrics types
The service records detailed user activity logs to support audit, governance, and compliance. Logged metrics include user identifiers, roles, timestamps, actions performed, orders created, voucher values, and status changes across the platform.

Authorised users can access activity data through reports and exports, enabling oversight of who performed specific actions and when. Logs support investigation, reconciliation, and assurance requirements and can be provided in standard export formats on request.
Reporting types
Reports on request
Resource tagging
No
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least every 6 months
Penetration testing approach
In-house
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Authorised users can export their data directly from the service using built-in reporting and export tools. Data can be downloaded in standard formats such as CSV, covering voucher issuance, redemption, and audit information. Exports can be generated on demand without requiring provider intervention.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Evouchers is provided as a cloud-based SaaS service designed for high availability. The service is monitored continuously and operated to support consistent access for users, including during peak demand periods.

Service availability targets and any associated service level agreements (SLAs) are defined within the customer contract or call-off agreement. Where an availability SLA is agreed, it typically excludes planned maintenance and events outside the provider’s reasonable control.

If agreed availability levels are not met, service credits may be applied in accordance with the terms set out in the relevant contract. Service credits are applied as a proportionate reduction against future invoices and represent the customer’s sole and exclusive remedy for availability-related service level failures.

Planned maintenance is scheduled outside core UK working hours wherever possible and communicated in advance.
Approach to resilience
Evouchers is delivered as a cloud-based SaaS service designed for resilience and continuity. The service is hosted on third-party cloud infrastructure that provides built-in redundancy across multiple availability zones within a UK region. This includes resilient compute, storage, and network components designed to tolerate component or zone-level failures.

The platform is monitored continuously, with automated alerts and operational procedures to respond to incidents and restore service. Regular backups are performed to protect customer data and support recovery in the event of failure.

Data centre resilience, including physical security, power, cooling, and disaster recovery controls, is provided by the cloud infrastructure provider and aligned with recognised industry standards. Further technical detail can be provided on request under appropriate confidentiality.
Outage reporting
Service availability and incidents are communicated directly to users through email notifications where an outage or service disruption affects customer access. Updates are provided during incidents and following resolution, as appropriate.

The service does not provide a public status dashboard or dedicated outage-reporting API. Customers can also report issues and receive updates through the online support ticketing system, which is monitored during core support hours.

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted through role-based access controls, ensuring users can only perform actions appropriate to their role. Administrative and privileged access requires multi-factor authentication and is limited to authorised personnel using managed devices. All access is logged and monitored.

Support channels are restricted to authenticated users associated with a customer account. Requests submitted via email, ticketing, or web chat are verified against registered contact details before account-specific information is disclosed. Sensitive actions are only completed following identity verification and appropriate authorisation, ensuring customer data is protected at all times.
Access restriction testing frequency
At least every 6 months
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Evouchers operates a comprehensive information security framework designed to protect the confidentiality, integrity, and availability of customer data. The service follows documented security policies and procedures covering access control, data protection, incident management, vulnerability management, change control, and business continuity. These policies apply across the entire service and to all supporting suppliers.

Information security oversight sits with senior management. Named individuals are responsible for information security and data protection, including a designated Data Protection Officer. Clear reporting lines ensure that security risks, incidents, and compliance issues are escalated appropriately and reviewed regularly.

Access to systems and data is controlled through role-based permissions, multi-factor authentication, and the principle of least privilege. All privileged actions are logged and monitored. Staff with elevated access undergo background checks and receive regular security and data protection training to ensure policies are understood and followed.

Compliance is maintained through regular vulnerability scanning, third-party penetration testing, incident response procedures, and periodic reviews of suppliers and sub-processors. Security incidents are managed through a documented incident management process and reported in line with contractual and UK GDPR requirements
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Evouchers operates documented configuration and change management processes covering the full service lifecycle. Service components are tracked through version control, configuration records, and environment separation between development, testing, and production. All changes are logged and traceable.

Proposed changes are assessed for operational and security impact prior to implementation. This includes consideration of data protection, access controls, service availability, and customer impact. Changes are tested in non-production environments before deployment and require approval by authorised personnel. Rollback procedures are defined to ensure service stability. Emergency changes follow expedited processes with post-implementation review.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Evouchers assesses potential threats through regular automated vulnerability scanning, third-party penetration testing, and continuous monitoring of service logs and alerts. Identified vulnerabilities are risk-rated based on severity, exploitability, and potential impact to customer data and service availability.

Patches and mitigations are prioritised accordingly. Critical vulnerabilities are addressed within 14 calendar days, with high and medium-risk issues remediated to defined timescales. Updates are tested in non-production environments before deployment.

Threat intelligence is informed by cloud provider security advisories, software vendor notifications, industry security bulletins, and guidance from recognised bodies such as the National Cyber Security Centre.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Evouchers operates continuous protective monitoring across the service to identify potential security compromises. Monitoring includes authentication events, privileged access, system errors, and service availability, with automated alerts for anomalous or suspicious activity.

When a potential compromise is identified, incidents are assessed and triaged by authorised personnel in line with documented incident management procedures. Containment and remediation actions are initiated promptly to reduce risk and prevent further impact.

Security incidents with potential customer impact are escalated immediately and managed in accordance with contractual obligations. Customers are notified without undue delay and, where applicable, within UK GDPR and regulatory reporting timescales.
Incident management type
Supplier-defined controls
Incident management approach
Evouchers operates documented incident management processes covering identification, assessment, containment, resolution, and post-incident review. Pre-defined response procedures are in place for common events such as service outages, security incidents, and delivery failures, enabling consistent and timely handling.

Users report incidents via email, online ticketing, or web chat. Incidents are logged, prioritised, and tracked through to resolution by authorised support staff.

Where an incident affects service availability or customer data, updates are provided to users during the incident, with a follow-up incident report issued where appropriate. Reports include a summary of impact, actions taken, and any preventative measures identified.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Evouchers provides free access to its software platform. This includes user access, scheme configuration, voucher ordering, reporting, and standard support. There is no time limit on platform access. Costs apply only to vouchers issued and any optional, non-standard services agreed contractually.
Link to free trial
Www.evouchers.com

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
1.0%
Between £250,000 and £500,000
1.0%
Between £500,001 and £1,000,000
1.0%
Between £1,000,001 and £2,500,000
1.0%
Between £2,500,001 and £5,000,000
1.5%
Over £5,000,001
1.5%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
BMTRADA
ISO/IEC 27001 accreditation date
Thursday 11 September 2025
What the ISO/IEC 27001 doesn’t cover
The Beyond Information Security Management System (ISMS) encompasses all
Beyond & associated company employees, listed Beyond associated company
office locations, Beyond & associated company owned technology and data
assets, and Beyond & associated company business processes that deliver
Beyond & associated company products and services.
Statement of Applicability v1.0
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
3241ea48-80bb-48a6-88dd-6b8d15a3e40f
Cyber essentials plus
Yes
Cyber Essentials Plus Certificate Number
13465664-55fc-47d3-96c0-2de353955d54
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
  • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
  • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
  • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
  • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Volunteering opportunities for staff
  • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
  • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling

Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

  • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
Mission: Make Britain a clean energy superpower

To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

  • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
Mission: Build an NHS fit for the future

That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

  • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
  • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
  • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
  • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@evouchers.com. Tell them what format you need. It will help if you say what assistive technology you use.