Praxis42 Compliance eLearning and Assessments
Praxis42 delivers eLearning and assessments that help organisations achieve workplace compliance. Our expert-developed courses, reporting tools and scalable platform support effective training delivery. We’ve helped over 10,000 organisations improve safety, competence and regulatory compliance.
Features
- Interactive library of health, safety and compliance eLearning.
- Integrated DSE Assessment tool for all employees.
- SCORM-compliant content for hosting on any LMS.
- Only supplier offering a SCORM DSE Assessment for third-party LMSs.
- Real-time reporting on all training activity and outcomes.
- Automated email reminders and learner notification engine.
- Multilingual courses supporting global workforces.
- Secure hosting for company documents, guidance and policies.
- Self-authoring assessment tool for any workplace activity.
- IOSH-approved and CPD-certified learning content.
Benefits
- Delivers engaging training that improves workplace compliance.
- Ensures employees meet DSE requirements quickly and consistently.
- Enables flexible learning delivery across any chosen LMS.
- Extends DSE compliance to organisations using external platforms.
- Provides instant insight into learner progress and compliance status.
- Reduces admin time with automated reminders and notifications.
- Centralises key documents for easier workforce access.
- Allows rapid creation of tailored workplace assessments.
- Demonstrates verified quality with recognised IOSH and CPD standards.
- Dedicated Account Manager for fully supported service
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 5 4 8 3 7 0 3 8 2 3 8 7 1 5
Contact
PRAXIS42 LIMITED
Tom Paxman
Telephone: 07818075181
Email: info@praxis42.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Education
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- All content is available as SCORM for hosting on any third-party LMS, including our unique DSE Assessment tool, the only SCORM-compliant DSE solution on the market designed for seamless external LMS integration.
- Cloud deployment model
- Private cloud
- Service constraints
- There are no service constraints
- System requirements
-
- Secure web connection
- Standard, up-to-date web browser
User support
- Email or online ticketing support
- Yes
- Support response times
- We aim to respond to all enquiries within 4 hours during our support hours of 9am–5pm, Monday to Friday (excluding bank holidays). Queries received outside these times, including weekends, are addressed promptly on the next working day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We have tested our web chat using assistive technologies, including screen readers and keyboard-only navigation. Testing focused on readability, focus order, ARIA labelling and overall usability to ensure the chat function is accessible to users with visual or motor impairments.
- Onsite support
- Yes
- Support levels
-
We provide a single support level included at no additional cost, covering technical queries, access issues and general service assistance. Support operates 9am–5pm, Monday to Friday (excluding bank holidays).
A dedicated account manager is provided for all customers to support onboarding, service use and ongoing relationship management.
We also offer an optional support resource for administrative or configuration tasks at £625 per day. This is not required for normal service operation.
We do not provide a cloud support engineer. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We provide a range of onboarding and support options to help users start using the service effectively. Organisations can access onsite training and setup support, where our team works directly with administrators to configure the system and train key staff. We also offer remote onboarding sessions, allowing administrators to receive guided setup assistance and training without the need for onsite visits.
To support ongoing learning, we maintain a comprehensive library of self-help video resources that can be accessed at any time. These videos cover core features, best-practice workflows, and common administrative tasks, enabling users to learn at their own pace.
Every organisation is also assigned a dedicated account manager, who provides on-demand support, guidance, and escalation assistance as needed. This ensures organisations have a consistent point of contact throughout their onboarding and ongoing use of the service.
Together, these options, onsite training, remote support, self-service resources and dedicated account management, ensure users have all the guidance they need to successfully adopt and operate the platform. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- Self Help videoes
- User tour feature within platform
- End-of-contract data extraction
-
At the end of a contract, administrators can extract all of their data directly from the system. SHINE supports full CSV exports across all key data sets, including users, organisational structures, course allocations, and detailed training records. Administrators can download these files through the standard reporting and export tools, ensuring they retain complete access to all information held in the system before access is removed.
If required, our support team can also provide guidance to ensure all data has been successfully exported. - End-of-contract process
-
At the end of a contract, organisations can extract all required data using the system’s built-in CSV export tools before access ends. If additional time is needed to complete offboarding activities, we offer optional contract extensions. These extensions allow continued access to the platform beyond the official end date so administrators can finalise data extraction, complete internal audits or transition processes, and ensure all records are retrieved.
Extension costs are charged on a pro-rata basis, either monthly or weekly, depending on the organisation’s needs. No other offboarding charges apply unless an extension is requested. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The application is fully responsive, providing the same core functionality on both desktop and mobile devices. Layouts and navigation automatically adjust for smaller screens, but no features are restricted or unavailable on mobile. The user experience is consistent across all device types.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
The SHINE API is REST-based and uses OAuth2 authentication. Clients receive a client ID and secret to generate access tokens, which are required for all API calls. Through the API, organisations can set up and automate provisioning processes by creating users in bulk, updating user details, activating or suspending accounts, and retrieving full user records for synchronisation with HR or identity systems.
The API also supports organisational structure management. Organisations can create up to 100 divisions per request, update division details, list all divisions, and assign or remove users with specific membership roles. Groups play a key role in licensing and course allocation.
For reporting and compliance, the API provides detailed training record retrieval, including enrolments, completions, expiry dates and scores. Organisations can also list courses assigned to them, assign courses to groups, and assign users to these groups to enrol them.
Limitations include the inability to create course content, modify training records, or exceed defined limits such as bulk-creation thresholds or rate-limit constraints. All training data is read-only, and some operations require appropriate administrative permissions. The API is designed for provisioning, structure management and reporting, not full learning content administration. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise multiple elements of the service. Platform administrators can apply corporate branding, including logos and colour schemes. All email templates are self-authoring, allowing full control over messaging, tone and event-based notifications such as reminders.
The assessment tool is fully customisable, enabling admins to define questions, workflows, qualifying criteria, risk scoring, outcomes and action assignments.
Course content can also be tailored to meet organisational requirements. Customisation is managed by authorised administrators within the platform.
Scaling
- Independence of resources
- We ensure users are not affected by the demand of others through the underlying Azure cloud infrastructure. SHINE is hosted on Microsoft Azure, which provides automatic scaling, load balancing and resource isolation. This means compute, storage and networking resources can scale dynamically based on demand, ensuring consistent performance during peak usage. Azure’s multi-tenant architecture also isolates workloads so that high activity from one organisation does not impact others. Continuous monitoring and autoscaling policies ensure capacity is adjusted proactively to maintain stable and reliable service for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We deliver usage and engagement metrics via built-in reporting. Administrators can access extensive data via dashboards and on demand reports such as number of active users, course enrolments and completions, group and division activity, and compliance-status summaries. These metrics support auditing, compliance tracking, and management reporting.
- Reporting types
-
- API access
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Users can export their data directly through the system’s built-in reporting and export tools. SHINE supports full CSV downloads across all key data sets, including users, organisational structures, course allocations, training records and completion history. Administrators simply select the relevant export option, and the system generates a CSV file that can be downloaded immediately.
For organisations integrating with external systems, data can also be retrieved via the REST API, which allows programmatic extraction of user information, division structures and detailed training progress. This supports automated data synchronisation or scheduled reporting. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We guarantee 99.9% service availability per calendar month, excluding planned maintenance windows that are notified in advance. The platform is hosted on Microsoft Azure, enabling high availability through redundant infrastructure and automated scaling. If availability falls below 99.9%, we will discuss appropriate service credits or remedial actions with the customer.
- Approach to resilience
-
Our service is designed with resilience in mind and is hosted on the Microsoft Azure cloud platform, which provides a highly available and fault-tolerant environment. Azure datacentres use redundant power, cooling, and networking, with multiple availability zones to ensure continuity in the event of hardware failure or localised disruption. Data is stored on geo-redundant infrastructure, ensuring it remains protected and recoverable even if a primary region becomes unavailable.
The service architecture uses load balancing, autoscaling and distributed components so that increased demand or individual component failures do not impact overall system availability. Continuous monitoring and automated failover capabilities further support resilience by identifying and mitigating issues before they affect users.
Azure’s physical datacentre controls and resilience measures comply with internationally recognised standards including ISO 27001, ISO 22301, CSA CCM and SSAE-18 / ISAE 3402.
More detailed architectural and infrastructure documentation can be provided on request. - Outage reporting
- We notify impacted customers directly by email if an outage or significant service disruption occurs. These notifications include details of the issue, expected impact, and ongoing updates until normal service is restored. We do not currently provide a public status dashboard or outage-reporting API.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
-
We apply strict role-based access controls across all management interfaces and support channels. Administrative functions are separated from standard user functionality, and only authorised personnel are granted elevated permissions. Access to management interfaces is provided over HTTPS, with all credentials hashed and salted before storage.
Support staff operate under the principle of least privilege and can only access customer environments needed to perform support tasks. All access changes are logged, monitored and removed as part of the employee offboarding process. - Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Our organisation is certified to Cyber Essentials Plus, which provides independently verified assurance of our security controls, including secure configuration, boundary protection, access management, patching and malware defence. The service is also hosted on Microsoft Azure, which maintains additional recognised certifications.
- Information security policies and processes
-
We follow a formal Information and Technology Security (ITS) policy framework that governs how data and systems are protected. Our ITS policy sets out controls for risk profiling, hardware and software security, cloud configuration, data access, encryption, backups, business continuity and data protection. The policy is owned and approved by the CEO and reviewed by the Operational Board of Directors, who are responsible for oversight and governance.
We ensure compliance through defined processes including risk registers, annual audits, security patching, employee training, controlled access to servers and databases, and enforced encryption for data at rest and in transit. Access to systems is tightly controlled via firewalls, MFA, hashed passwords and unique customer identifiers.
Employee responsibilities are reinforced at induction and during performance reviews, and all leavers have their access removed and devices securely handled. Annual audits and board reporting ensure the policy is followed and continuously improved. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We follow a formal Change Management Process that tracks all service components through their lifecycle. Every change is submitted via a Change Request Form, categorised, and logged in a central repository for full traceability. The Change Manager conducts risk and impact assessments, including security implications, before approval. Approved changes are developed and tested in a staging environment, with results documented. Deployments are scheduled with rollback plans in place, and all changes undergo a Post-Implementation Review to confirm success and capture improvements.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We manage vulnerabilities through ongoing monitoring, risk profiling and regular security updates. Risks are assessed and recorded in a formal risk register reviewed annually by the Operational Board. Our hosting partner, Lucid Systems, provides 24/7 monitoring of threats and maintains hardened FortiGate firewalls, applying security patches promptly as new vulnerabilities emerge. All changes, including security fixes, follow a structured Change Management Process with risk assessment, testing and controlled deployment. Threat intelligence comes from vendor security updates, monitoring tools and vulnerability testing within our dedicated security testing environment.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We use continuous protective monitoring to identify unusual activity, configuration changes or indicators of compromise across our systems. Potential compromises are detected through log monitoring, firewall protections, regular security patching and vulnerability assessments documented in our ITS policy. When an issue is identified, it is escalated to senior management, investigated immediately and actions are taken to contain, mitigate and resolve the threat.
All incidents follow a defined reporting and response process, with rapid investigation and communication to affected customers where required. We respond to potential compromises as soon as they are detected to minimise impact and maintain service integrity. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We follow a defined incident management process for identifying, reporting and resolving security events. Our ITS policy includes established procedures for handling common incidents such as data loss, unauthorised access or system issues. Suspected incidents are reported internally to senior management, who assess, investigate and take appropriate corrective action.
Users can report incidents directly to our support team, who escalate them according to severity. If an incident affects a customer, we notify them and provide updates as the investigation progresses. Formal incident reports are issued to impacted customers outlining the nature of the incident, actions taken and any follow-up measures. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We provide a full-access trial with all features and any requested library content. There is no fixed time limit, provided usage remains reasonable. Trials are for evaluation only and not intended for live production use or long-term data storage.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 15%
- Between £500,001 and £1,000,000
- 20%
- Between £1,000,001 and £2,500,000
- 22%
- Between £2,500,001 and £5,000,000
- 24%
- Over £5,000,001
- 28%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- SGS
- ISO 9001 accreditation date
- Wednesday 14 June 2023
- What the ISO 9001 doesn’t cover
-
Our ISO 9001:2015 certification covers the provision of health, safety and environmental management consultancy services and associated blended learning solutions, including eLearning and instructor-led training.
Activities not covered by the certification include our fire-related services, which are delivered under separate BAFE accreditation rather than ISO 9001. Therefore, any fire risk assessment or fire-specific consultancy elements fall outside the scope of the ISO 9001 certificate. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 7ea8543a-0e30-4031-8f87-fb0680801319
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-