Skip to main content

Help us improve the Digital Marketplace - send your feedback

MCR SYSTEMS LIMITED

Symphony

Provision of SAAS EPoS Solution including integrated loyalty, stock and pre-order with integrated acquiring services for payment devices. Provision of integrated APP for loyalty, pre-order, cashless, voucher. Solution includes full SAAS Back office and is PCI compliant

Features

  • Enterprise Hospitality Management
  • PCI Complaint and ISO27001 Certified
  • Integrated Payments, loyalty and Stock
  • Full EPoS and Self Serve Kiosks
  • Stock Management
  • Realtime reporting and live dashboard
  • Off Premise and full UK Tier 1 Hosted Solution
  • Integrated Stock Management

Benefits

  • manage stock and inventory accurately
  • Full Live Dashboard enabling instant estate management
  • Fully integrated PCI Compliant Acquiring Solution
  • Full Hospitality solution includes live reporting
  • Web Based Management Tool secure with MFA
  • Integrated APP with Loyalty and Pre-Order

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at pjewell@mcr-systems.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 8 7 9 1 9 3 4 2 3 4 2 1 6 8

Contact

MCR SYSTEMS LIMITED Paul Jewell
Telephone: 0116 225 3462
Email: pjewell@mcr-systems.co.uk

About your service

Service categories

Applications

Enterprise resource management

  • Order management and orchestration
  • Enterprise performance management

Financial

  • Financial and Accounting Applications
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Full integration to 3rd party stock solutions such as Saffron and can manage patient feeding if necessary, integrated to loyalty platforms and PMS solutions and HR Solutions such as Fourth and integration to ERP platforms such as SAP, Agresso
Cloud deployment model
Private cloud
Service constraints
Requires secure segrated WIFI/LAN for provision of Payments in line with PCI Compliance. Software maintenance and upgrades are included in the contract and pushed outside of trading hours.
System requirements
  • Segregated WIFI or LAN for PCI Compliance
  • ESET Antivirus provided
  • NinjaMRM for full Cyber Essentials Plus Solution
  • Back office security is Password, MFA and Role based
  • Tier 1 UK Based Cloud Hosting

User support

Email or online ticketing support
Yes
Support response times
24x7 support can be provided with SLA dependent on call type 45mins with a Priority 1 "Can't trade"

Users can see ticket allocated and status, and update tickets but cannot change or manage the priority
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Full testing carried out with 11 Labs and Aircall before selecting Aircall following live trials across our NHS, MOD, University, and Private sector client base with selected customer profiles
Onsite support
Yes
Support levels
Full named Account Manager, Engineer on site support with 24hrs. Enhanced (24*7) support is an additional cost to standard support.

Standard Mon-Fri - £65 per device per annum
Till 11pm Mon-Fri - £85 Per device per annum
Mon-Sunday 9-5 - £120 Per device per annum
Mon-Sunday 24hr £195 per device per annum

Device would be a POS unit including peripherals such as Printer, draw, Payment device, scanner (Barcode/NFC) classed as a Bundle
Support available to third parties
No
AI chatbot
Yes

Onboarding and offboarding

Getting started
Allocated Prince 2 Project manager, sitge visit and analysis followed by full issue of SOW along with project plan. Regular milestone check-ins in line with the agreed plan. Full online/onsite trianing provided along with video overviews, wiki hows, training and video content embedded within the software along with FAQ's. All release notes accompanied with full illustrations and Video content. All documentation available to the customer electronically
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Agreed SOW, and a data extract provided in Xls. Customers have the option to consume via API the full data extract file to an SFTP server either customer hosted or MCR hosted on a daily basis to be consumed into your own data lake, meaning all historical data is already provided on a daily basis. This includes all data and all transactional data daily.
End-of-contract process
If you own the hardware the hardware remains in situ, access to all software is ceased. If hardware is rented then hardware is collected from site with SSD WEE Disposed off. An off boarding SOW is issued for agreement and the agreed process is followed.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Solution is mobile optimised, however its recommended that advanced config such as promotion set up, Loyalty programmes be done on a tablet or Laptop due to the size of screen.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Web based Symphony HUB and web based Live Dashboard available on all browsers and mobile devices, the live dashboard can contain a PowerBI plug in for custom dashboards
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The web tools are fully audited to WCAG2.2AA Standards and all software updates and releases undergoes full testing before global release.
API
Yes
What users can and can't do using the API
MCR has an open API both restful and SOAP. All uses of the MCR API's are via a scope, agreed SOW and under NDA in some circumstances. API's are used to access MIS systems within Universities for Student details for SSO and Catered allowances as examples.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Dashboard, User screens, User Dashboards, and User Reporting catalogues. All access is Hierarchal and role based with user permissions granted by the customer.

Scaling

Independence of resources
Customers receive access to own unique segregated data source on a multi-tenanted platform. MCR databases automatically reload on to alternative servers using the high availability servers so downtime is less then 1% across a 12 month period

Analytics

Service usage metrics
Yes
Metrics types
System Uptime
Support SLA
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Provision of API data extract daily to SFTP Server
On demand via reporting and downloaded via Xls, HTML, .CSV
Scheduled reporting to auto generate to a user or none user via email in the above formats.
Paid for dev data extract if necessary
Data export formats
  • CSV
  • Other
Other data export formats
  • HTML
  • API
  • Excel
  • PDF
Data import formats
  • CSV
  • Other
Other data import formats
  • Excel
  • API if from an approved 3rd party IE Stock Solution

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
MCR Systems hosting is via our hosting partner, GTT, who we are entering our 10th year in partnership with. We have a primary hosting centre near London and a live DR site in Slough. MCR databases automatically reload on to alternative servers using the high availability servers so downtime is less then 1% across a 12 month period. We have a full DR with defined RPO of 24 hours and RTO of 4 hours. Refunds are made in the form of service credits
Approach to resilience
Available on Request
Outage reporting
All live API's and all live connections to 3rd parties, plus all POS/Kiosk and applications are shown in the Live dashboard in realtime with users alerted to outages in realtime via the Service health monitor in the live dashboard

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Other user authentication
SSO and above options are available
Access restrictions in management interfaces and support channels
All access internally to any part of the solution by an MCR employee is role based and audited and same for customer access.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Description of management access authentication
SSO and above

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
ISO27001, Cyber Essentials, PCI
GDPR Policy
Data Retention and removal Policy
Disaster recovery Policy
Information security policy
Security Incident and response policy

Aiming to be certified/audited for ISO42001 - 2026
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
MCR Systems operates a formal change control process governed by a Change Approval Board (CAB). All changes that may impact information security, systems, or customer services are logged, risk-assessed, tested, and documented before implementation. Standard changes are reviewed at weekly CAB meetings, while emergency changes follow an expedited approval process. Low-risk changes are recorded for audit purposes. Each change includes an implementation plan, testing evidence, and rollback procedures, with final approval provided by authorised stakeholders to ensure controlled and secure delivery.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
MCR Systems maintains an ISO 27001 aligned vulnerability management process covering identification, assessment, and remediation of technical vulnerabilities. Threats are identified through regular penetration testing, automated vulnerability scanning, and continuous security monitoring. Vulnerabilities are risk-assessed using CVSS scoring, asset criticality, exposure, and exploit availability. Patches are deployed based on risk, with critical vulnerabilities remediated within defined timescales. Threat intelligence is obtained from accredited security testers, vendor security advisories, scanning tools, and trusted industry security sources.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
MCR Systems operates continuous protective monitoring using centralised logging and a 24/7 managed SIEM service. Security events are identified through real-time monitoring of servers, firewalls, cloud services, and user activity, with alerts generated for suspicious or anomalous behaviour. Potential compromises are investigated immediately by the SecOps team following a defined incident response process, including containment, evidence preservation, and remediation. Incidents are responded to promptly, with escalation and out-of-hours response available 24/7 to minimise impact and restore services quickly.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
MCR Systems operates a formal incident management process aligned with ISO 27001. Pre-defined procedures exist for common security events, including malware, phishing, data breaches, and unauthorised access. All users are required to report suspected incidents promptly to the SecOps team via defined reporting channels, with additional escalation from IT staff, service providers, and a managed SOC. Incidents are logged, investigated, contained, and resolved in line with documented procedures, with incident reports and lessons learned recorded and shared with relevant stakeholders as appropriate.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
POS Bundle EXCLUDES Payment Device - Basic Loyalty, Website ordering provision, full back office, live dashboard - up to 3 months
Link to free trial
On demand

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
7%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Intertek Certification Limited
ISO/IEC 27001 accreditation date
Thursday 31 August 2023
What the ISO/IEC 27001 doesn’t cover
HR, Payroll and Finance as carried out by our parent company.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Intertek Certification Limited
ISO 9001 accreditation date
Thursday 31 August 2023
What the ISO 9001 doesn’t cover
HR, Payroll and Finance as carried out by our parent company.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Claranet Ltd
PCI DSS accreditation date
Tuesday 8 April 2025
What the PCI DSS doesn’t cover
Everything PCI related is covered by this certification
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
0cbf5aa8-39d9-4366-a2fe-44f84701bd0b
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at pjewell@mcr-systems.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.