Skip to main content

Help us improve the Digital Marketplace - send your feedback

Portals UK ltd

Sangix Appointments

Sangix Appointments: Secure platform for healthcare & other sectors. Supports 100% walk-in, pre-booked, or mixed clinics. Book via online portal or automated phone system. Includes calendar templates & reports. Supports Single Sign-On (SSO) and integrates with PAS.

Features

  • Book, view, cancel appointments on-line and by automated phone line
  • Reduce patient waiting time and eliminate staff overtime
  • One-click reporting, i.e. GP and ICB rebilling
  • Secure and stable cloud technology
  • Integrates with existing systems
  • Patient web Portal for patients to manage their appointments
  • Pre-booked appointments, walk-in and a mix of both
  • Efficient queue management
  • Call-in Screens and Self Check-in Kiosks

Benefits

  • Eliminate need for reception and staff dedicated to booking appointments
  • Remove hygienic risks related to paper-based systems
  • Prevents crowded waiting areas
  • Multiple check-in options including mobile app, kiosk, and reception desk
  • New features get released every quarter responding to customer feedback
  • Supports Single-Sign-On (SSO) - log in using existing Trust username
  • Patients can book online from their phone or PC
  • Patient web portal: patients can manage their appointments and data
  • Support for family accounts

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at vasuki.sanjeevan@sangix.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 8 3 5 7 6 6 3 4 5 8 2 3 2 1

Contact

Portals UK ltd Jiri Blazek
Telephone: 07531234264
Email: vasuki.sanjeevan@sangix.co.uk

About your service

Service categories

Applications

Production and operations

  • Other operations
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
N/A
System requirements
  • Requires stable internet connection to public Cloud services
  • Latest version of a modern browser required for full functionality
  • Users need a PC or tablet with internet connection

User support

Email or online ticketing support
Yes
Support response times
Response time is 2 working days.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We provide support during standard business hours on UK working days.
Remote Go-Live support via Microsoft Teams, or on-site if required, is included at no additional cost.
Ongoing operational support is provided through email and our service desk ticketing system as part of the annual subscription.
Additional on-site support after Go-Live is available at £800 per day.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Prior to Go Live - Online Training & User documentation
Go Live- On-site (or online) hands-on training during the first day of operation.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
The data are extracted from the database by vendor and provided to the client in a computer readable format.
Patients can add, update or remove their personal and appointment data from the web portal. They can also remove their account from the web portal.
End-of-contract process
Sangix Appointments is provided as an annual subscription. When the subscription expires, all data are extracted and provided to the client free of cost upon request in a computer readable format.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Email

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Patient experience is mobile first.
Staff portals can be used on mobile but is designed to work on desktops first.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service provides a secure web-based interface accessible through any modern browser. Staff use an intuitive administrative dashboard to manage appointments, queues, check-ins, users, and reporting. Patients access a dedicated web portal to view, book, and manage appointments. A kiosk interface supports on-site self check-in and arrival confirmation. All interfaces are responsive, accessible, and optimised for desktop, tablet, and mobile use. Role-based access controls ensure users only see appropriate functions. The service also exposes API endpoints for approved system integrations, enabling automated booking updates and external system connectivity.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
N/A
API
Yes
What users can and can't do using the API
API supports working with StarPrinterOnline service to print tickets and with an automated Telephone service so users can book, cancel and view appointments using automated phone service.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
The solution is highly customizable via staff portal.

Scaling

Independence of resources
The service is deployed on Google Cloud Platform using auto-scaling, fully managed serverless infrastructure. Compute resources scale independently based on each customer’s usage, ensuring that increased demand from one organisation does not affect others. Database resources are provisioned with performance isolation, and traffic is load-balanced across multiple instances. Multi-tenant data separation and rate-limiting ensure fair resource consumption across all users. Continuous monitoring automatically detects abnormal load and scales capacity as required. This architecture guarantees consistent performance and responsiveness regardless of demand from other users.

Analytics

Service usage metrics
Yes
Metrics types
Staff users can use a range of configurable reports.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
Less than once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Patients can copy their data from patient portal.
Staff can use built-in reports to export data.
Data export formats
Other
Other data export formats
Excel - XLSX
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We provide a 99.5% availability per year.
Approach to resilience
Our service running on Google Cloud Platform (GCP) is designed to be resilient through scalable architecture, redundant components, fault-tolerant design, automated monitoring, and healing mechanisms. We prioritize data protection with robust backup strategies.
Outage reporting
Email alerts, Slack notifications and texts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Staff users have different user roles that grant them access only to data and pages they need to see.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We follow the ISO 27001:2022 Information Security Policy and the following sub-policies:
Acceptable Use of Assets Policy
Access Control Policy
Backup Policy
Clear Desk and Clear Screen Policy
Communication Policy
Cryptographic Controls Policy
Information Classification, Labelling and Handling Policy
Mobile Devices Policy
Physical and Environmental Security Policy
Protection from Malware Policy
Protection of Personal Information Policy
Suppliers Policy
Remote Working Policy
Use of Intellectual Property Policy
Use of Software Policy
Microsoft 365 Acceptable Use Policy
Threat Intelligence Policy
Configuration Management Policy
Operational Controls Policy
Policy Review
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Our configuration and change management processes involve meticulously tracking the lifecycle of our software solution and evaluating changes for potential security implications. We maintain detailed records to monitor the evolution of each software version, ensuring transparency and accountability. Prior to release of a new version, all changes undergo rigorous testing and security assessments to safeguard against potential vulnerabilities and maintain the integrity of our systems.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Our vulnerability management process involves continuous assessment of potential threats to our services. We promptly deploy patches to address identified vulnerabilities, prioritizing the security of our systems. We stay informed about potential threats through a variety of sources, including security advisories, threat intelligence feeds, and industry best practices.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Our protective monitoring processes involve vigilant identification of potential compromises through continuous monitoring of system activities. In the event of a potential compromise, we promptly respond by investigating the incident, containing the threat, and initiating appropriate remedial actions. Our goal is to swiftly address incidents, minimizing their impact, and ensuring the security and integrity of our systems.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Our incident management processes encompass pre-defined procedures for common events, ensuring a structured and efficient response to incidents. Users can report incidents to our service desk via an email or electronic form, allowing for timely escalation and resolution. Following incident resolution, we provide comprehensive incident reports to stakeholders, fostering transparency and continuous improvement in our security practices.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Free trial of up to 6 months can be provide upon request.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
8%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Amtivo Group Limited T/A British Assessment Bureau Ltd.
ISO/IEC 27001 accreditation date
Wednesday 4 June 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at vasuki.sanjeevan@sangix.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.