Children in Need Personal Education Plan (CIN-PEP)
Children in Need Personal Education Plan. We offer a fully managed data collection & monitoring service for Local Authorities to help safeguard and improve the outcomes for Vulnerable Children. Cohorts include Children in Need (CIN), Child-Protection (CP) plans and Children with an EHCP. Extension to our cloud-based platform ePEP Online.
Features
- CIN PEP Cloud-based secure platform accessible 24/7.
- Young Persons secure portal (voice of the young person).
- Parent & Carers portal for shared vulnerability alerts and notifications.
- Impacted Tracker for educational measuring and funding progress.
- Online Case Management / Overall CIN Plan and Safeguard Record.
- Attainment Collection module including including academic flight paths.
- Bespoke Report Builder & Analytic Dashboard for Real-time reporting.
- Developmental target recording including threshold alerts and notifications.
- On-going provision & discussion mapping for online supervision.
- ISO 27001 and ISO 9001 accredited platform
Benefits
- Secure online application to monitor educational outcomes for CIN.
- Improved attainment & attendance monitoring and data accountably.
- Enhancing communication and data sharing with supporting professionals.
- Automatic threshold and vulnerability alerts for improved safeguarding.
- Internal Virtual School Case Note facility for greater communication.
- Attendance collection and monitoring service reducing outsourced costs.
- Customisable privilege and control panel settings for total policy control.
- PEP Builder administration for self managing questions and additional sections.
- Individual school/provider attendance dashboard for clear report visualisation.
- AI progress tracker highlighting weak KPI's with suggest suggested interventions
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 7 6 0 2 7 6 1 9 9 9 5 9 0 1
Contact
EGOV SOLUTIONS LTD
Gary Daniels
Telephone: 0333 772 0944
Email: gary.daniels@egov.uk.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
- Project and portfolio management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The eGOVCloud service functions as a powerful standalone tool or as a fully integrated hub. Automatically syncing data from our attendance, attainment, and safeguarding modules eliminates manual entry and ensures PEP forms are always accurate. Furthermore, CIN data feeds directly into our analytics, providing stakeholders with real-time dashboards and reporting.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- Not Applicable - we conduct all updates and maintenance activities outside of core business hours to minimise disruptions. With our commitment to reliability, we guarantee a 99.9% uptime for our services, ensuring uninterrupted access for our clients.
- System requirements
-
- Internet Access
- Login Credentials
- Email Access
- Supported Internet Browser
User support
- Email or online ticketing support
- Yes
- Support response times
-
Response times:
Priority 1: The entire system is completely inaccessible. Response within 10 minutes maximum.
Priority 2: System operation is severely degraded, or major components are not operational, and work cannot reasonably continue response within one business hour.
Priority 3: Certain non-essential features of the system are impaired while most major components remain functional, response within two business hours.
Priority 4: Change requests or issues that are cosmetic and/or have little or no impact on the services - response within 12 business hours.
Clients will be provided with a 24/7 telephone number for resolving critical issues immediately. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AAA
- Web chat accessibility testing
- We test daily for zero-latency feel by sending messages in rapid-fire successions (5-10 per second). We see how fast a user can open the chat, type a query, attach a file, and close the window. We test while the browser’s "Network" tab is open. We check that no sensitive info is being stored in the browser's local storage, where a curious user might find it. We feed the chat aggressive phrases like "I already tried that," "Give me a human," or even technical jargon that a basic bot wouldn't understand. We test how quickly the system recognises it's out of its depth and offers a seamless handoff to a human before the user gets frustrated and closes the tab. We try to break the layout using long strings of text without spaces to ensure the chat window doesn't physically "stretch" or crash the browser.
- Onsite support
- Yes
- Support levels
-
We are committed to delivering exceptional support and aftercare to all our clients. Each client is assigned a dedicated account manager who serves as the primary contact for first-line support and expert advice. To foster a strong relationship, we strive to keep the same account manager throughout the contract, ensuring they develop a deep understanding of the client’s needs. Account managers conduct review meetings at least every four months to assess whether our services and software are meeting client requirements.
In addition to account managers, our 2nd-line support Service Desk Agents are available during standard business hours. These agents are trained to handle all technical and support inquiries and to maintain communication with clients until their issues are fully resolved.
As a hosted service, our technical team takes comprehensive responsibility for the configuration, maintenance, updates, and support of the cloud service throughout the contract period.
eGOV Solutions offers various support methods, including a help desk, online training, user documentation, training videos, webinars, and phone support. On-site training is provided during the implementation phase, with additional training available at no cost if needed.
We do not charge extra for support; it is included in the contract scope and the services provided. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
EGOV Solutions initiates every contract with an in-person kick-off meeting during the first week. This crucial session establishes the project’s foundation by covering implementation timelines and the Authority's specific data requirements. Our technical experts facilitate seamless data migration from third-party providers, ensuring all historical information, attachments, and case notes are successfully recovered and imported.
Stakeholders Virtual Schools explore our extensive "Golden Templates" catalogue, the industry's largest, to design bespoke PEP forms. A comprehensive service demonstration allows features to be tailored to specific needs. Our proven methodology, refined through 76 local authority rollouts, ensures an efficient transition with a cloud-based, user-friendly system that requires no local software installation.
To support users, we provide a range of training options, including virtual sessions, on-site workshops, online documentation, AI-generated videos, and interactive webinars. Clients gain immediate access to a secure parallel testing environment for validation and optional pilot stages. Primary administrators collaborate with our dedicated support team to finalise custom designs. After reviewing existing templates and validating new forms, the finalised configuration is transferred to the live platform.
This structured process concludes with agreeing upon a preferred start date, ensuring your team is fully equipped and confident to begin using the optimum CIN-PEP system. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- Clients can access and download their data at any time during the contract. Alternatively, data can be securely transferred to clients at the end of the contract upon request or included in the planned Exit Plan. We ensure that clients receive thorough support throughout the data export process, making it easy to retrieve any necessary information from the system.
- End-of-contract process
-
Contract exit options are integral to the overall contract definition. We engage in discussions with the client at the beginning and end of the contract to ensure all applicable statutory obligations are met. Upon the client's official request, we will permanently delete all data, ensuring compliance with GDPR regulations.
It's important to note that if additional work is required, along with the corresponding timelines, there may be extra charges for any necessary technical involvement or additional IT development. However, returning all data to the client in a standard CSV format is included in the contract scope at no additional cost. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
There is only a small difference between the Mobile and desktop services. The Desktop Strengths for (Administrators & Teachers).
Data Entry, Bulk uploading, and entering grades are much faster with a physical keyboard. Viewing large cohort charts, performance analytics, dashboards, and bespoke reports is much easier on the desktop service.
The Mobile Strengths (On-the-go Teachers):
Push Notifications: Instant alerts for absences and casenote updates. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
-
We provide a secure, web-based support service interface. This enables administrators to engage in direct communication with first-line support, dedicated account managers, and technical specialists. To facilitate rapid troubleshooting and development, the portal allows professionals to securely upload diagnostic materials, including screenshots and documentation, when requesting changes or reporting issues. Administrators can set priority levels and maintain a full chronological audit trail of all historical requests, updates, and system changes.
The platform features automated notifications and alerts users via the secure channel when requests are closed or developments are completed. This integrated approach ensures that reported issues are addressed immediately. - Accessibility standards
- WCAG 2.2 AAA
- Accessibility testing
-
We employ a "shift-left" testing approach, integrating WCAG 2.2 AAA compliance checks from the very beginning of the development lifecycle. Our team utilises a robust suite of automated and manual testing tools—including Axe and Lighthouse—to proactively identify and rectify accessibility issues during the code production phase.
Beyond automation, the interface undergoes rigorous testing with assistive technologies catering to visual impairments, such as reversed colors, high contrast, and grayscale modes, alongside thorough screen reader compatibility checks. To ensure real-world effectiveness, we engage real people using assistive tech to navigate our support ticket flow. These manual audits by users with diverse accessibility needs validate that core features—such as attaching materials, monitoring chronological updates, and receiving notifications—remain seamless for everyone.
Furthermore, these advancements are refined within our alpha and beta testing environments, which undergo internal validation and review by a select group of clients. - API
- Yes
- What users can and can't do using the API
-
Our API acts as a high-speed bridge between our core data and your preferred external tools. Designed specifically for Administrators and Technical Support teams who need to seamlessly move information from our system to third-party platforms for reporting, tracking, or deep analysis. You can feed data directly into your own databases, CRM, or third-party analytical tools without manual exports. You can pull all available data fields. We provide the raw data without filters so you can build your own custom dashboards and complex reports. While we don't place "data limitations" on what you can generate, there are still vital boundaries to keep the system safe: Only users with high-level Administrator or Technical Support credentials can access this API.
Setting up the service is straightforward:
1. Generate Your Credentials: From the Admin Dashboard, you’ll generate a unique API Key.
2. Connect Your Channel: Use our documentation to point your third-party system to our secure endpoints.
3. No Limits on Reports: Unlike other APIs that restrict what data you can see, our API allows you to request every available data point for your analytical needs.
If you need to update a record, you can send an update request through the API. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- ODF
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
EGOV Solutions provides extensive customisation through its eGOVCloud service, ensuring the platform aligns perfectly with each Local Authority’s unique statutory requirements. Users can fully tailor CIN PEP templates by adding custom sections, modifying lookup tables, and defining specific attainment models or SMART target frameworks.
To provide clients with greater control and oversight, pre-approved users can manage the following system configurations. Administrators can designate specific roles using the Roles Matrix and the Privileged Section from within the platform's Administration Tools. Designated Teacher, Social Worker) The responsibility for individual questions can be defined as mandatory fields to ensure data integrity before completion. Targeted Content: Administrators can apply role-based restrictions to forms and fields to ensure age-appropriate and need-based templates are maintained across all cohorts. Clients can select preferred Quality Assurance (QA) models and dictate exactly which data—such as SMART targets—roll over from one PEP to the next.
Administrators can generate bespoke reports using real-time filters and access personalised analytics dashboards to instantly visualise key performance indicators. Our technical staff will provide full assistance for any unique customisation, providing immediate access to a testing environment separate from the live platform to approve all changes and developments before deployment, at no additional cost.
Scaling
- Independence of resources
- High redundancy, auto-load balancing, and scalable bandwidth on demand. We monitor server performance and ensure high redundancy to deliver a fast service for users 24/7. Automatic load balancing ensures 100% service speed and scalability for all clients on our dedicated servers. Typical report load times are 2 to 3 seconds.
Analytics
- Service usage metrics
- Yes
- Metrics types
- System usage and performance statistics, database reporting including self-service activity logs for user accountability, and additional bespoke reports on request.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Authorised client users can export data for the vulnerable cohorts for which we provide CIN-PEPs. This functionality is accessible through the eGOVcloud web portal, which is available 24/7 for the duration of the contract. Users can apply filters to any reports within the reporting suite and export data in various formats, including:
XLSX
XML
CSV
PDF
DOCX
Users can choose from multiple options when exporting data from eGOVCloud, including:
Bespoke Self-Report Builder
Historical PEP Data
Attendance Data
Attainment Collection Data (including documents and images)
Exports can be tailored to specific formats prior to downloading, such as CSV, XLSX, and PDF. - Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- XML
- PNG
- JPEG
- DOCX
- EXCEL
- TSV
- SPSS
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- XMLX
- TSV
- EXCEL
- XLS
- HTML
- ODS
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- Egress secure email transfer.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We can guarantee a network connectivity SLA level of 99.98 % uptime/availability results in the following periods of allowed downtime/unavailability: Daily: 1m 26s Weekly: 10m 4s Monthly: 43m 49s Yearly: 8h 45m 56s. This is to allow for service security updates and full data backups scheduled from 00.01 every day. This allows us to guarantee 100% network connectivity and availability in normal daytime and extended working hours. We will refund the client one month's total costs if service is disrupted without a 3-minute response and resolution.
- Approach to resilience
- The eGOVCloud infrastructure is built on AWS, which offers multiple physically separated, isolated data centres with high availability and highly redundant networking. Load-balanced environment with scalable bandwidth on demand. All communications pass through our VPN, which is protected by a strict firewall. The backup system is managed in different ways: Hourly snapshots: copies of application servers and databases are automatically generated, creating a fast and secure restore point. The database failure system is fully automatic and does not require administrative intervention. Individual: a backup script is scheduled hourly to generate an individual file for each client, allowing quick access to restore or analyse data without affecting other clients. The data is stored in the AWS S3 storage service, with high durability and availability. All external backup files are mirrored on a storage service in a different UK data centre to ensure 99.98% uptime and secure disaster recovery.
- Outage reporting
- Outage reporting is automatically measured and monitored with the AWS data centre. Cloud performance, usage meters, availability alerts, triggers and notifications are immediately emailed to our internal technical team and actioned accordingly. We provide the client with access to their own performance dashboard and included them into alerts with a chosen designated security office
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Username or password
- Access restrictions in management interfaces and support channels
- All users must authenticate and verify their individual email address and password. Once verified they need to complete specific characters from a memorable word at a ISO/IEC 27034 standard. Failed results will be blocked after 3 attempts and will be recorded/alerted to the client and the eGOV Solutions support team. The user would need to contact the national eGOVCloud help number, 24/7, to request and lift restrictions, with additional verification.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
-
ISO 9001 accredited
Cyber Essentials Plus
CREST - Information security policies and processes
-
We systematically evaluate our information security risks, taking into account the impact of threats and vulnerabilities. Risks raised through internal and external audits are reviewed at management meetings by our information security manager and head of business. We design and implement a comprehensive suite of information security controls and other risk management measures to address potential security risks to new and existing CIN-PEP developments and services. We continually review and update our security policies in line with the ISO/IEC 27001 & ISO 9001 security management standards. We are ICO-registered (510362026) and Cyber Essentials Plus accredited. We adhere to the Data Protection Act (2018-Jan2026)/GDPR, the Freedom of Information Act 2000, and the Computer Misuse Act (1990).
Certification can be provided on request. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All changes are checked before implementation by the technical team then the technical lead within a secure testing environment. Following the ITSM framework guidelines all version control, code changes are ticket logged, itemised and timestamped. All code branch changes are recorded and linked to each developer for accountability. Code is then automatically checked using GitLab CI/CD and then finally checked and signed off by senior level 3 developer before pushing to the live environment.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We monitor a variety of sources, including the National Vulnerabilities Database, for new software vulnerabilities and vulnerability reports. The CIN-PEP application undergoes internal and/or external penetration testing. New vulnerabilities are risk-assessed and deployed to the live environment accordingly. Security risks can be addressed in under an hour.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We identify potential compromises and risks through using Anti-Virus software alerts configured to email triggers and notifications to our technical team and security officer. Technical availability is provided 24/7 365 day a year to ensure full detection protection is guaranteed. Once any compromise is detected a remedy is immediately implemented and timestamped, logged, followed by a risk assessment including the client.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We have pre-defined processes for common events detailed within our company security procedures. Incidents are reported by telephone, secure email, live support log and are all automatically allocated with a unique ID. Technical support monitor and receive support ID alerts 24/7 and will set the level of priority agreed by the client. All security incidents are actioned immediately by our security officer. We follow legal guidelines for everything else, most common events are responded, resolved within 1 hour. Incident reports are provided and discussed with the client at each review meeting, the client can access this report within the portal.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Public Services Network (PSN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO certification Ltd
- ISO/IEC 27001 accreditation date
- Thursday 15 January 2026
- What the ISO/IEC 27001 doesn’t cover
- Nothing our ISO covers extends to the full service environment.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO certification Ltd
- ISO 9001 accreditation date
- Monday 26 January 2026
- What the ISO 9001 doesn’t cover
- Nothing our ISO covers extends to the full service environment.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Thursday 15 January 2026
- CSA STAR certification level
- Level 2: CSA STAR Attestation
- What the CSA STAR doesn’t cover
- Nothing our CSA covers extends to the full service environment.
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Afb01af5-9bf0-49ed-b90f-61f9e6257a69
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 2b9a986d-0859-41f7-96a1-a92686f83e3c
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-