Go Vocal Digital Community Engagement & Consultation Platform
Go Vocal is a global leader in digital engagement, widely adopted across the UK. A one-stop hub for statutory consultations and ongoing engagement, it offers a complete toolbox of methods with robust, AI-powered analysis and reporting. Go Vocal enables governments and organisations to deliver inclusive and insight-driven decisions.
Features
- White label platform with fully customisable branding for all pages
- Regular and continuous user management, communications, and targeted mailing.
- AI-supported text analysis and built-in exportable reporting
- Cutting-edge technology including mapping, voting & handwriting recognition features
- Inclusive engagement combining digital, offline, and diverse resident input sources
- Content moderation using automated tools and manual review for safety.
- Seamless APIs integrating with PowerBI, ESRI, and other systems.
- Multilingual service offering manual and automated translations for broad accessibility.
- Scalable backend workflows managing multiple users with varied permissions effectively.
- Autonomous platform management allowing project creation and self-publishing rights
Benefits
- Centralise engagement for planning, housing, transport, healthcare, policy, insights teams
- Manage consultations from creation through analysis, reporting, and publication efficiently.
- Ensure every voice is heard using online & offline engagement.
- Easily organise and manage your community of residents effectively.
- Retain full autonomy over project creation, publishing, and analysis.
- Save time and resources with AI-powered analysis and reporting.
- Reduce consultation fatigue and easily close feedback loops.
- Stay compliant and meet your duty to consult promptly.
- Scale platform usage seamlessly across your organisation’s teams and projects.
- Integrate your engagement platform into wider digital infrastructure seamlessly.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 7 6 5 0 2 0 8 1 4 9 4 5 4 4
Contact
Go Vocal
Lora (Botev) James
Telephone: +447926764670
Email: lora@govocal.com
About your service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No known constraints.
- System requirements
-
- Modern web browser
- Internet connected device
User support
- Email or online ticketing support
- Yes
- Support response times
- We have different response times depending on the urgency of the query. They range from 9h for the highest priority and 5 business days for the lowest priority. The full response time options are outlined in our SLA.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We have carried out interviews with users with disabilities to understand restrictions.
- Onsite support
- Yes
- Support levels
-
Our comprehensive knowledge center (support.govocal.co) answers most of your frequently asked questions and offers useful resources to guide you more broadly. For more detailed questions, we are available via email, the built-in chat functionality on your platform or by phone.
Go Vocal provides technical support via a built-in Support Chat system, telephone and e-mail on weekdays from 8:00 to 18:00 GMT (“Support hours”), with the exception of public holidays in the United Kingdom.
The customer can launch a helpdesk ticket during Support Hours by adding it to the chat system, by calling [+44 79 2676 4670] or by emailing at any time [support@govocal.co].
In every pricing plan, an account manager (government success manager) is at your disposal. He or she can bring you in immediate contact with the development team or support desk when necessary. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We have developed a thorough onboarding process to guide you in three phases to the successful launch of your platform and first participation project(s): strategy, preparation and launch. Each phase includes a few workshops to help you and your team get to grips with the platform and boost its adoption rate among your communities. Sessions can be held online or face-to-face. We also provide extensive user documentation such as guides and checklists to help you better scope the objectives of your engagement platform.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Online knowledge base
- Built-in support guide
- Case Studies
- Blog
- Newsletters
- In App campaigns
- Ad Hoc advisory sessions
- Training sessions
- End-of-contract data extraction
-
Customers can extract all the data from the platform at any point during the duration of the contract.
Additionally, Go Vocal makes platform data available at no additional cost via a raw database transfer, compatible with the open source PostgreSQL database package.
Go Vocal has an exit policy to support clients who wish to cease using the solution. - End-of-contract process
-
At the end of the contract, Go Vocal will remove the customer's access to the platform and archive all existing projects. The platform and related data is deleted within 12 months but customers can ask for their own timeline on this. There is no additional cost involved.
The customer is given the opportunity to retrieve or request data. - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The end user interface of our solution is built mobile first to cater to mobile users both on phones and tablets. The structure of the front end is therefore optimised for mobile devices.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
In addition to the manual export of data, Go Vocal has a well-documented Application Programming Interface (API), so that other applications can exchange data with the software. This API is open so that the data in the platform can be offered in the form of open data. (e.g. for displaying data on a map).
The authentication uses the JWT standard and the login data can easily be obtained from Go Vocal. The documentation contains a complete list of possible operations, with examples. The API is constantly being expanded to unlock new functionalities. The documentation is also consistently kept up to date:
1. Read data
All data from ideas, comments, projects and users are made available for processing by external tools via our documented REST API.
2. Write data
In addition to reading data, the API also offers opportunities to create ideas and approve verifications of citizens. This creates many opportunities for the automated input of content from other systems in the city. One of the possibilities is an integration with the city's agenda software to automatically publish agenda items and reports of the city council or advisory councils on the platform. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- The Go Vocal platform can be customised by each customer to meet their specific needs. The main areas, which customers can personalise are: branding (logos, colours, visuals, etc), languages (the platform is multilingual), topics (to classify resident input), geographic data (map location and zoom levels for instance), registration fields (information requested of users when signing in), webpages (create certain custom pages). Customers also benefit from a modular toolkit that enables them to pick and choose from a toolbox of engagement methods for each specific project.
Scaling
- Independence of resources
-
The software solution has been built with redundancy. The delivery, application, and database layers consist of multiple servers that dynamically distribute workloads and can take over for each other if needed. To reduce the risk of multiple servers becoming unavailable simultaneously, they are physically located in separate zones within the data center.
The application servers use auto-scaling to handle peak demand. During periods of high load, the number of servers automatically increases to reduce overall system load, ensuring an optimal user experience with fast response times.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Go Vocal provides comprehensive engagement metrics to help organisations understand and act on public input. Quantitative data is presented through intuitive dashboards covering usage, visitor numbers, participant demographics, and levels of representativeness, giving clear insight into engagement reach and inclusivity. Complementing this, our AI-powered qualitative analysis identifies key themes, applies keyword tagging, summarises feedback, and detects trends, enabling faster, evidence-based decision-making. Together, these tools allow teams to monitor engagement performance, uncover meaningful insights, and report confidently on outcomes. With Go Vocal, both numbers and narratives are captured, visualised, and analysed to drive informed, transparent, and inclusive public engagement.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- At any time, all data can be exported by a single click by the client from the back end of their platform. Raw data is available in CSV format. Some data includes additional download formats such as PDF or image files.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLSX
- PNG
- SVG
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XLSX
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- The Services shall be available more than 99%, measured monthly, excluding scheduled maintenance. If Customer requests maintenance during these hours, any uptime or downtime calculation will exclude periods affected by such maintenance. Further, any downtime resulting from outages of third party connections or utilities or other reasons beyond Company’s control will also be excluded from any such calculation. Customer’s sole and exclusive remedy, and Company’s entire liability, in connection with Service availability shall be that for each period of downtime lasting longer than one hour, Company will credit Customer 5% of Service fees for each period of 60 or more consecutive minutes of downtime; provided that no more than one such credit will accrue per day. Downtime shall begin to accrue as soon as Customer (with notice to Company) recognises that downtime is taking place. To receive downtime credit, Customer must notify Company in writing within 24hours from the time of downtime, and failure to provide such notice will forfeit the right to receive downtime credit. Such credits may not be redeemed for cash and shall not be cumulative beyond a total of credits for one (1) week of Service Fees in any one (1) calendar month in any event.
- Approach to resilience
- This information is available upon request.
- Outage reporting
- Service outages are reported over email or by phone.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Administrators and project moderators need to authenticate in order to use the management interfaces and support channels. The application layer has a permission system that specifies access policies for every user role and every read/and write action on every data resource. These policies are automatically tested in every change to the application.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- Azure Directory
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Go Vocal is ISO27001 certified. As part of the certification, the company has put in place a number of ISMS policies. These policies operate under a strict change management policy and are reviewed at least once a year.
The policies included are:
- The Mobile Device, BYOD and Teleworking policy
- Password policy
- Human resources policy
- Clean desk and desktop policy
- Disposal and destruction policy
- Information transfer policy
- Information classification policy
- Access control for internal systems policy
- Change management policy
- Supplier management policy
- Incident management policy
- Product password policy
- Cryptography policy
- Backup policy
- Security procedures for product infrastructure policy
- Secure development policy
- Risk management policy - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Change management is performed according to our ISO27001 Change Management policy. An internal database, part of the technical knowledge base, tracks all services and code repositories used by the platform, including their deployment information, API serving and consumption. All applications are containerised and tracked through a centralised container registry. Security concerns are an explicit part of the specification documents of all new features or changes to existing features.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- The application source code is automatically monitored for CVEs using GitHub's vulnerability alerts database in any library dependencies, upgrading them as soon as possible. We release very frequently, about twice per week. Critical issues are released right away. Static code analysis detect known malicious patterns and blocks them from reaching production deployments.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Server and application access is monitored and anomalies trigger notifications to the support team. Platform administrators are in direct contact with our account managers through e-mail, phone and in-platform chat, which are in direct contact with the 2nd line technical team.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Our incident response plan described how to respond to high, medium and low-medium severity incidents, describing the priority and communication actions to take for each category of severity. For issues with critical severity, there's a critical response plan that gets highest priority. Platform administrators are in direct contact with our account managers through e-mail, phone and in-platform chat, which are in direct contact with the 2nd line technical team.
All incidents are anonymously archived in an incident log and proves to be a useful "lessons-learned" approach. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We provide a free trial environment. During this time prospects can test out almost all the functionalities in the back office of the platform.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2.5%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 2.5%
- Between £1,000,001 and £2,500,000
- 2.5%
- Between £2,500,001 and £5,000,000
- 2.5%
- Over £5,000,001
- 2.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI (IS 772254)
- ISO/IEC 27001 accreditation date
- Tuesday 20 September 2022
- What the ISO/IEC 27001 doesn’t cover
-
Covered: development, maintenance and delivery of the Go Vocal platform as software-as-a-service to customers.
Does not cover: / - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Af586c83-8242-4a11-b8cb-5f1de6ee805d
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
-