Bramble Hub - mycomplaints.ai
Mycomplaints.ai is an AI powered Complaints Management Solution. AI generated output is presented clearly, with context, requiring human review to progress from one stage to the next. It enhances the analysis, investigation, root cause identification, remediation and response processes, improving the timeliness, accuracy and efficiency of an organisation’s complaint handling.
Features
- AI First, with human in the loop validation
- Management of the complete complaints lifecycle
- Enterprise grade SaaS solution
- Designed and built by experts in complaints management
- Process automation. Converts unstructured emails into structured case data
- AI delivers comprehensive analysis of all key case information
- Explainable outputs require human review and validation
- Automation of proposed plan of action for agent review
- Proposes redress, remedial actions and identifies systemic issues
- Integrated with MS Teams, Microsoft Dynamics 365, Salesforce
Benefits
- Efficient case creation, building a case from unstructured data
- Reduced overhead of triaging case, analysing all relevant data
- Allows agents to add value, reviewing AI analysis
- Automation reduces time to process a case
- Supports compliance, through delivery of timely responses
- Can be tightly integrated with relevant internal systems
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 8 7 6 6 5 6 9 8 6 9 3 5 2 1
Contact
BRAMBLE HUB LIMITED
Geoff Couling
Telephone: +44 (0) 2077350030
Email: contact@bramblehub.co.uk
About your service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Can be integrated with existing line of business systems or CRM solutions (e.g. Salesforce, Microsoft Dynamics 365) to deliver a dedicated complaints module.
- Cloud deployment model
- Public cloud
- Service constraints
- None
- System requirements
- The solution is delivered as an app in MS-Teams
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 4 business hours hours on Working Days (09:00-17:00 Monday to Friday, excluding Bank and Public holidays in England). Tickets may be logged out of hours, but will receive a response on the next Working Day. Infrastructure in monitored and maintained on a 24x7x365 basis.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- We offer support as per our Service Level Agreement (SLA). The support is integral to the service and forms part of the fee that is paid for use of the service (i.e. there is no incremental fee). Support will be provided by a suitably qualified member of the support or development teams, as appropriate.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Remote training and access to online documentation
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Our commitment is that we will return to the Customer (or otherwise make available functionality for the Customer to download) a copy of the Customer Content in a commonly used, machine-readable format.
- End-of-contract process
- At the end of the contract, following the conclusion of any applicable Data Export Period (please see above), we will delete all Customer Content from our systems within the Data Deletion Period specified in the Key Terms of the contract, unless retention is required to comply with legal or regulatory obligations. We will ensure that deletion is performed in a secure and industry-standard-compliant manner.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- None
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
- The API exists principally to integrate the complaints management solution with existing line of business or CRM solutions, to remove the need to duplicate data entry.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Capture additional attributes, modify AI prompts etc.
Scaling
- Independence of resources
- Ongoing automated monitoring of the hosting environment and scaling of the underlying virtual infrastructure as demand upon resources grows.
Analytics
- Service usage metrics
- Yes
- Metrics types
- A full analytical toolset is to be provided to review workload, internal compliance with SLAs, identify systemic issues etc
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Google Gemini provides the AI capability
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Degaussing
Data importing and exporting
- Data export approach
- In an industry-standard format.
- Data export formats
- Other
- Other data export formats
-
- Extract data and documents via API
- On a case by case basis
- Data import formats
- Other
- Other data import formats
-
- Upload data and documents via API
- On a case by case basis.
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
-
Data moving between a buyer's network and the AWS infrastructure is protected via:
• Encryption in Transit.
• Protocol Standards. The organisation maintains a minimum standard of TLS v1.2 or higher.
• Trusted Certificates
• End-to-End Application Flow.
The soluton provides mechanisms to restrict the "pathway" between networks:
• IP Address Whitelisting.
• Fixed Egress IP.
Secure Integration and Messaging is implemented via:
• OAuth 2.0
• Electronic Messaging - Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Service Availability of 99.9%. Service Credit regime for failure to achieve stated Service Availability - please see Service Level Agreement.
- Approach to resilience
- Mycomplaints Ltd uses the capabilities of the AWS public cloud architecture to configure a resilient solution. Further details can be provided upon request.
- Outage reporting
- A series of alarms and monitoring options exist for Mycomplaints Ltd operational staff. A public facing service availability monitor is made available to customers via the web.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
We restrict personnel access to customer systems through a comprehensive framework governed by the Principle of Least Privilege and a Need to Know basis. We employ effective:
• Personnel Vetting and Onboarding
• Technical Access Controls
• Single Sign-On (SSO) and MFA
• Role-Based Access Control (RBAC):
• Production Environment Isolation:
• AWS IAM Roles
•
Governance and Monitoring is achieved through:
• Segregation of Duties.
• Periodic Access Reviews.
• Automated Monitoring.
In the event of a role change or employment termination, a formal offboarding process is triggered. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
- PCI DSS
- Information security policies and processes
- Operation of systems in compliance with our ISO 27001 accreditation. A comprehensive Security White Paper is available upon request.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Mycomplaints ltd. employs a formalised framework for change and configuration management
The organisation categorises changes into two main types: planned (scheduled) and unplanned (emergency).
• All software developed for the platform is managed using Git.
• Changes must be tested in a staging environment prior to implementation.
• Changes undergo peer review and approval
• Access to implement changes in the production environment is strictly restricted.
Configuration Management
The organisation maintains established configuration baselines for critical infrastructure, including server hardening, endpoint device hardening, and firewall configurations. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Internal Vulnerability Assessments: We conduct regular internal vulnerability assessments, particularly after significant code releases or infrastructure updates. This includes checks for input validation flaws, common injection vulnerabilities, broken authentication/session management, insecure direct object references, and CSRF vulnerabilities.
Independent External Testing: We engage accredited third-party security firms to conduct annual penetration tests of our platform. Quarterly ASV (Approved Scanning Vendor) vulnerability scans are also performed in line with PCI DSS requirements. Findings from these tests are reviewed, prioritised, and remediated accordingly. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Audit Logging for Cloud Resources (AWS CloudTrail): All AWS management API calls are meticulously recorded. This is crucial for audit, compliance, and security analysis.
Network Traffic Logging (VPC Flow Logs): Provides detailed insights into IP traffic patterns to and from network interfaces in our virtual private cloud.
Threat Detection Service (AWS GuardDuty): This service continuously monitors for malicious activity and unauthorised behaviour.
Centralised Logging and Alerting (Amazon CloudWatch): System, application and security logs are consolidated in a centralised logging service. - Incident management type
- Supplier-defined controls
- Incident management approach
-
A structured framework exists for incident management to ensure that information security events are identified, communicated, and resolved in a timely manner.
Incidents are identified through two primary channels:
• Automated Threat Detection: The organisation uses services like AWS GuardDuty.
• Staff Reporting: All staff members, contractors, and third parties are required to report discovered security weaknesses or incidents promptly.
Specific protocols are in place for incidents involving sensitive or personal data.
Following the resolution of critical incidents, a post-mortem is conducted to determine the root cause and lessons learned. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- UKAS
- ISO/IEC 27001 accreditation date
- Tuesday 31 December 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- UKAS
- ISO 9001 accreditation date
- Tuesday 31 December 2024
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 94c671e6-823b-4c1b-9e66-be61b04e765c
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 3b271556-6f71-40cd-bd60-169f03c35f6e
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-