Epitaph
Epitaph is a comprehensive cemetery and crematorium management software that streamlines bookings, records, finance, and memorials. Cloud-hosted and paperless, it integrates digital mapping, genealogy, and inspection tools for efficient, compliant operations—accessible anytime, anywhere with expert support and seamless data security.
Features
- HeritEDGE Digital Mapping
- Training
- Paperless administration
- Funeral Director Booking Portal
- Integrated Finance Management
- InspectEDGE - Memorial inspections app
- Expert Support and Training
- Comprehensive Reporting and Statistics
Benefits
- Interactive maps with grave locations, memorials, and genealogical search tools.
- UK ICCM-qualified support with online training and helpdesk assistance.
- Fully digital workflow: stationery, emails, attachments, and mail merge.
- 24/7 online booking with digital signatures for statutory paperwork.
- Invoicing, credit control, and finance integration for easy administration.
- Integrated memorial inspections, photos, and records via InspectEDGE app.
- Reporting tools with export to PDF, Word, Excel, print, email.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 6 9 2 8 8 0 1 8 1 5 8 1 0 9
Contact
EDGE IT SYSTEMS LIMITED
Shane Pelchat
Telephone: 02476 667 337
Email: admin@edgeitsystems.com
About the service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Other
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Onsite services. All services are delivered remotely.
- System requirements
-
- Stable and reliable internet connection. Less than 1% packet loss
- Inspections app requires Android tablet which can be supplied
- Only accessed via devices with all available updates installed.
- Accessed only using devices with OS's still supported by manufacturer
User support
- Email or online ticketing support
- Yes
- Support response times
- During agreed service hours, response times average between 5 to 30 minutes
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Standard levels of support is provided to all users.
Support is provided as part of the contract and not supplied at an additional cost. We have inhouse developers so can provide product support and development support. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
A dedicated Project Manager is assigned to oversee the entire onboarding process. Responsibilities include developing a detailed project timeline, coordinating weekly internal and external progress meetings, and facilitating project initiation sessions. As part of onboarding, a comprehensive project plan is produced and approved by the customer, incorporating a tailored training schedule.
The standard onboarding phases typically include project timeline development and approval, project initiation, technical configuration, general configuration, training, data migration, and go-live. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
There are 2 options available for the end user at the end of the contract.
(1) The end user can subscribe to a reports only account, giving them access to the system in a read-only format provided on a 12 monthly cycle. This is charged seperately.
(2) Request the data, which will be supplied to the specified organisation via an encrypted SaaS service for a limited period of time, or, by an encrypted USB storage device which will be charged for on a time and materials basis.
The data will be supplied in the original database file format.
When the organisation has received the data, the copy on the servers managed by EDGE IT Systems Limited will be destroyed after 90 days.
Please note that the organisation is only licensed to use the database supplied for the sole purpose of extracting the data. The database design remains the property of EDGE IT Holdings (UK) Limited and the organisation is:
- prohibited from distributing the database to another organisation
- prohibited from updating or modifying the database design
- prohibited from updating the data in the database. - End-of-contract process
- After notice of non renewal of the contract, access will be revoked on the expiry date. Users have until the expiry date to make the necessary arrangements to export data from the system. Data will remain for 90 days after expiry after which point it will be destroyed. Export of data is possible and is charged seperately.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Onboarding and offboarding documentation is provided in digital format, primarily as PDF user guides and product manuals. These documents are accessible via a secure online portal and can also be shared directly with authorised users during the onboarding process.
Updated versions are made available as part of ongoing service support, ensuring customers always have access to the most current materials.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The Epitaph Bereavement Services system is not optimised for mobile devices; as a result, some screens and fields may appear oversized, requiring extensive scrolling and navigation. However, specific components, such as the Funeral Director Portal and inspection modules, are fully designed for mobile use and offer identical functionality to the desktop version.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The Epitaph service is accessed through a secure, web-based user interface and includes role-based authentication.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- Annual interface testing completed with WAVE Evaluation tool.
- API
- Yes
- What users can and can't do using the API
- XML feed for service times.
- API documentation
- No
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- The logon screen display can be customised to meet user preferences. Various interface views may be enabled or disabled to enhance operational efficiency and streamline system use.
Scaling
- Independence of resources
- Our service is hosted on a Terminal Server Gateway with a farm of three terminal servers, two live, and a third on standby. System configurations are load-balanced and optimised to ensure consistent performance, so users are not affected by the activity or demand of other users. This setup maintains reliable, responsive access, minimises latency, and ensures that system performance scales efficiently under varying workloads, providing all customers with a consistent and uninterrupted experience.
Analytics
- Service usage metrics
- Yes
- Metrics types
- A vast array of metrics and reports are available within Epitaph. These include, but are not limited to, national statistics, finacial statistics, cremation and burial statistics, grave usage, memorial sales and opportunities, staff audits, complaints and many more.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- If a regular data export is required, we provide a button to produce csv files. For adhoc exports any report can be exported to docx, pdf, xlsx format.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Xml
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Epitaph SaaS service is 99% available Monday to Friday, 8.00 a.m. to 6.00 p.m. and 95% available at all other times to allow for maintenance. These are target system availability figures, measured per calendar quarter (pro rata for the first quarter of the contract). These figures exclude circumstances wholly beyond the control of EDGE or agreed planned maintenance.
- Approach to resilience
- Available on request
- Outage reporting
- The Status of the service is available via https:///www.edgeITsystems.com/status . This webpage is maintained 24x7 with the latest status and details of outages during the last 30 days.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Administrator level access is only provided to site managers or above. Management level changes and changes to user access is only requested via a site manager using verified contact channels.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We take a practical, structured approach to security governance through clear roles, documented security policies and defined responsibilities for maintaining compliance. Senior management provides oversight and approves policies, while operational teams ensure controls are implemented day‑to‑day. Our trusted third‑party MDR/SOC supports governance by delivering continuous monitoring, incident reporting and actionable security insights. We enforce security through access controls, configuration standards, supplier oversight and regular reviews of policies and procedures. Training, incident learnings and ongoing improvement activities ensure we maintain a strong security posture aligned with organisational and regulatory expectations.
- Information security policies and processes
-
We operate an Information Security Policy covering physical and electronic information security, secure areas, equipment protection, cabling management, equipment maintenance, off‑site use, secure disposal, delivery and receipt controls, regular auditing, and compliance. It aligns with ISO/IEC 27001 principles and requires secure handling of PROTECT/RESTRICTED information, controlled access, asset inventories, and proper data erasure for disposal.
Policy governance assigns roles as follows: Responsible – Managing Director; Accountable – technical staff; Informed – employees, temporary staff and contractors. The CEO reviews the policy at least annually, and policy breaches may trigger disciplinary or legal action.
We enforce compliance through physical access controls (badges, sign‑in for visitors, CCTV), secure storage requirements, environmental protections for equipment, server‑based data storage, inventory management, access restrictions, encryption for off‑site devices, and routine security audits to validate effectiveness. Staff are required to follow required to review and sign off acceptance of policies and Data Protection responsibilities.
Our third‑party MDR/SOC enhances adherence by providing 24/7 monitoring, incident identification and reporting, supporting operational implementation of policy requirements. - Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All software development activites are tracked through a enhancements document, which outlines all releases since the introduction of the software. Each release has a unique version number and can be tracked for traceability. Security related changes are reviewed inline with our security policy and are only implemented once approval is received from director level. Third party inductry experts are used to advise and implement any changes, including but not limited to Kaseya: https://www.kaseya.com/ and Claranet: https://www.claranet.com/
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Our datacentre is managed using Datto RMM. This includes patch management and threat detection and response via MDR. Patches are installed when older than 30 days, unless categorised as critical or important security updates, which are installed on release. Potential threats are identified using our penetration testing, RMM, MDR and security updates provided by our thrid party suppliers.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We employ a trusted third‑party provider to deliver our MDR and integrated SOC services for the data centre. They conduct continuous protective monitoring across logs, endpoints, networks and cloud workloads, using behavioural analytics and threat intelligence driven detection to identify potential compromises. When suspicious activity is detected, their SOC analysts immediately investigate, validate the threat, and coordinate containment and remediation with our team. Monitoring operates 24/7, with triage initiated within minutes to ensure rapid response and minimise operational impact.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We use a third‑party MDR and SOC to deliver 24/7 incident monitoring and detection for our data centre. They follow pre‑defined processes and playbooks for common events such as malware, phishing and unauthorised access. Users report incidents through our service desk portal, email or phone, which automatically generates an incident ticket. When an incident occurs, the SOC investigates, validates the alert and coordinates containment and remediation with our team. We provide incident reports through our ITSM system, including updates during the incident and a post‑incident summary outlining impact, actions taken and recommended improvements.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- A free trial version of the system can be provided with 2 accounts, for a maximum of 14 days. No training or support is provided and it should be used as an area to test the software before implementation.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 1%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 1%
- Over £5,000,001
- 1%
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 8ffcff2a-bd8f-429d-99a5-a2841d75094a
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies