Skip to main content

Help us improve the Digital Marketplace - send your feedback

BRAMBLE HUB LIMITED

Bramble Hub - mycomplaints.ai

Mycomplaints.ai is an AI powered Complaints Management Solution. AI generated output is presented clearly, with context, requiring human review to progress from one stage to the next. It enhances the analysis, investigation, root cause identification, remediation and response processes, improving the timeliness, accuracy and efficiency of an organisation’s complaint handling.

Features

  • AI First, with human in the loop validation
  • Management of the complete complaints lifecycle
  • Enterprise grade SaaS solution
  • Designed and built by experts in complaints management
  • Process automation. Converts unstructured emails into structured case data
  • AI delivers comprehensive analysis of all key case information
  • Explainable outputs require human review and validation
  • Automation of proposed plan of action for agent review
  • Proposes redress, remedial actions and identifies systemic issues
  • Integrated with MS Teams, Microsoft Dynamics 365, Salesforce

Benefits

  • Efficient case creation, building a case from unstructured data
  • Reduced overhead of triaging case, analysing all relevant data
  • Allows agents to add value, reviewing AI analysis
  • Automation reduces time to process a case
  • Supports compliance, through delivery of timely responses
  • Can be tightly integrated with relevant internal systems

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at contact@bramblehub.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 8 7 6 6 5 6 9 8 6 9 3 5 2 1

Contact

BRAMBLE HUB LIMITED Geoff Couling
Telephone: +44 (0) 2077350030
Email: contact@bramblehub.co.uk

About your service

Service categories

Applications

Customer relationship management

  • Customer service
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Can be integrated with existing line of business systems or CRM solutions (e.g. Salesforce, Microsoft Dynamics 365) to deliver a dedicated complaints module.
Cloud deployment model
Public cloud
Service constraints
None
System requirements
The solution is delivered as an app in MS-Teams

User support

Email or online ticketing support
Yes
Support response times
Within 4 business hours hours on Working Days (09:00-17:00 Monday to Friday, excluding Bank and Public holidays in England). Tickets may be logged out of hours, but will receive a response on the next Working Day. Infrastructure in monitored and maintained on a 24x7x365 basis.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
We offer support as per our Service Level Agreement (SLA). The support is integral to the service and forms part of the fee that is paid for use of the service (i.e. there is no incremental fee). Support will be provided by a suitably qualified member of the support or development teams, as appropriate.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Remote training and access to online documentation
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Our commitment is that we will return to the Customer (or otherwise make available functionality for the Customer to download) a copy of the Customer Content in a commonly used, machine-readable format.
End-of-contract process
At the end of the contract, following the conclusion of any applicable Data Export Period (please see above), we will delete all Customer Content from our systems within the Data Deletion Period specified in the Key Terms of the contract, unless retention is required to comply with legal or regulatory obligations. We will ensure that deletion is performed in a secure and industry-standard-compliant manner.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
The API exists principally to integrate the complaints management solution with existing line of business or CRM solutions, to remove the need to duplicate data entry.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Capture additional attributes, modify AI prompts etc.

Scaling

Independence of resources
Ongoing automated monitoring of the hosting environment and scaling of the underlying virtual infrastructure as demand upon resources grows.

Analytics

Service usage metrics
Yes
Metrics types
A full analytical toolset is to be provided to review workload, internal compliance with SLAs, identify systemic issues etc
Reporting types
  • Real-time dashboards
  • Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Google Gemini provides the AI capability

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Degaussing

Data importing and exporting

Data export approach
In an industry-standard format.
Data export formats
Other
Other data export formats
  • Extract data and documents via API
  • On a case by case basis
Data import formats
Other
Other data import formats
  • Upload data and documents via API
  • On a case by case basis.

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Data moving between a buyer's network and the AWS infrastructure is protected via:
• Encryption in Transit.
• Protocol Standards. The organisation maintains a minimum standard of TLS v1.2 or higher.
• Trusted Certificates
• End-to-End Application Flow.

The soluton provides mechanisms to restrict the "pathway" between networks:
• IP Address Whitelisting.
• Fixed Egress IP.

Secure Integration and Messaging is implemented via:
• OAuth 2.0
• Electronic Messaging
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Service Availability of 99.9%. Service Credit regime for failure to achieve stated Service Availability - please see Service Level Agreement.
Approach to resilience
Mycomplaints Ltd uses the capabilities of the AWS public cloud architecture to configure a resilient solution. Further details can be provided upon request.
Outage reporting
A series of alarms and monitoring options exist for Mycomplaints Ltd operational staff. A public facing service availability monitor is made available to customers via the web.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
We restrict personnel access to customer systems through a comprehensive framework governed by the Principle of Least Privilege and a Need to Know basis. We employ effective:
• Personnel Vetting and Onboarding
• Technical Access Controls
• Single Sign-On (SSO) and MFA
• Role-Based Access Control (RBAC):
• Production Environment Isolation:
• AWS IAM Roles

Governance and Monitoring is achieved through:
• Segregation of Duties.
• Periodic Access Reviews.
• Automated Monitoring.

In the event of a role change or employment termination, a formal offboarding process is triggered.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
  • Other
Other security governance standards
PCI DSS
Information security policies and processes
Operation of systems in compliance with our ISO 27001 accreditation. A comprehensive Security White Paper is available upon request.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Mycomplaints ltd. employs a formalised framework for change and configuration management

The organisation categorises changes into two main types: planned (scheduled) and unplanned (emergency).

• All software developed for the platform is managed using Git.
• Changes must be tested in a staging environment prior to implementation.
• Changes undergo peer review and approval
• Access to implement changes in the production environment is strictly restricted.

Configuration Management

The organisation maintains established configuration baselines for critical infrastructure, including server hardening, endpoint device hardening, and firewall configurations.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Internal Vulnerability Assessments: We conduct regular internal vulnerability assessments, particularly after significant code releases or infrastructure updates. This includes checks for input validation flaws, common injection vulnerabilities, broken authentication/session management, insecure direct object references, and CSRF vulnerabilities.
Independent External Testing: We engage accredited third-party security firms to conduct annual penetration tests of our platform. Quarterly ASV (Approved Scanning Vendor) vulnerability scans are also performed in line with PCI DSS requirements. Findings from these tests are reviewed, prioritised, and remediated accordingly.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Audit Logging for Cloud Resources (AWS CloudTrail): All AWS management API calls are meticulously recorded. This is crucial for audit, compliance, and security analysis.
Network Traffic Logging (VPC Flow Logs): Provides detailed insights into IP traffic patterns to and from network interfaces in our virtual private cloud.
Threat Detection Service (AWS GuardDuty): This service continuously monitors for malicious activity and unauthorised behaviour.
Centralised Logging and Alerting (Amazon CloudWatch): System, application and security logs are consolidated in a centralised logging service.
Incident management type
Supplier-defined controls
Incident management approach
A structured framework exists for incident management to ensure that information security events are identified, communicated, and resolved in a timely manner.

Incidents are identified through two primary channels:
• Automated Threat Detection: The organisation uses services like AWS GuardDuty.
• Staff Reporting: All staff members, contractors, and third parties are required to report discovered security weaknesses or incidents promptly.

Specific protocols are in place for incidents involving sensitive or personal data.

Following the resolution of critical incidents, a post-mortem is conducted to determine the root cause and lessons learned.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
UKAS
ISO/IEC 27001 accreditation date
Tuesday 31 December 2024
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
UKAS
ISO 9001 accreditation date
Tuesday 31 December 2024
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
94c671e6-823b-4c1b-9e66-be61b04e765c
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
3b271556-6f71-40cd-bd60-169f03c35f6e
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at contact@bramblehub.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.