Xoralia Policy & Procedure Management for SharePoint, Microsoft 365, Teams
Xoralia is easy-to-use policy and procedures management software built for SharePoint, Teams and Office365. Xoralia manages the whole policy lifecycle: policy creation, policy dissemination, gathering acknowledgements, quizzes and policy reviews. Xoralia is unique because it enables you to store your policies and controlled documents inside your own SharePoint environment.
Features
- Mandatory policy notifications and reminders
- Reporting and tracking
- Target users and groups with mandatory reads and quizzes
- Recurring policy reads (e.g. annually)
- Manage policy creation, reviews and expiries
- Store all your policies inside SharePoint
- Single sign-on (no login or password)
- Mobile app for front line workers (no M365 licence needed)
- Comes with various SharePoint webparts and Microsoft Teams app
- Works on mobile, tablet and desktop devices
Benefits
- Minimise risk and achieve compliance
- Keep an audit trail of all your employees' policy reads
- Manage new employee onboarding
- Reduce time spent distributing and tracking documents
- Keep all your documents secure inside your Office 365
- Leverage existing SharePoint policy libraries, groups and permissions
- Manage the whole policy lifecycle
- Intuitive interface makes it easy to find and read policies
- Create a single source of truth for all your policies
Pricing
£0.50 to £41.25 a user a year
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
9 0 4 3 8 0 9 2 7 1 8 5 2 5 7
Contact
Content Formula
Dan Hawtrey
Telephone: 020 4534 3460
Email: dhawtrey@contentformula.com
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- SharePoint, Teams and Office 365
- Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
- Microsoft 365
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
-
Within 2 hours for P1 requests - system down
Within 4 hours for P2 requests - major impact
Within 12 hours for P3 requests - minor impact
Within 48 hours for P4 requests - trivial impact - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.1 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- The service comes with support included. This support provides a helpdesk in case there are any issues with the system and it is not working as expected. If helpdesk engineer is unable to resolve the issue we have two further levels of escalation up to a senior engineer. For refresher training, end user support etc. we provide comprehensive HowTos, documentation and videos on our website. Alternatively, the customer can purchase a bucket of hours to cover such support.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide remote training over Teams or Zoom.
We also provide online getting started guides and videos on our website.
We have also designed the tool to be highly intuitive so users can start using the tool using only tool tips built inside the tool.
The mobile app for frontline workers is super-easy to use - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Video
- End-of-contract data extraction
-
All your policy documents remain inside your Office 365 and SharePoint so there is no need to extract that data.
Read and reporting data can be downloaded as CSV files from within the reporting interface. - End-of-contract process
-
If a customer wants to cease receiving the service they can provide notice and the service will come to an end.
It is the customer's responsibility to download any reporting data prior to the expiry, but this is easy and quick to do.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Frontline workers get a native mobile app (no M365 licence required) so they can search, browse, read policies, acknowledge having read a policy and complete quizzes.
Users can also access a mobile-optimised Xoralia through their mobile browsers - Service interface
- Yes
- User support accessibility
- WCAG 2.1 AA or EN 301 549
- Description of service interface
-
The service interface is designed for admins of the system and provides the following features:
- Ability to change branding
- Ability to add or remove document libraries
- Ability to add or remove admin users
- Access system analytics - Accessibility standards
- WCAG 2.1 AA or EN 301 549
- Accessibility testing
- We have tested the application for accessibility with WAVE evaluation tool and with Access Assistant for Chrome.
- API
- Yes
- What users can and can't do using the API
- The Xoralia API is powerful and fully featured. All features and functionalities available on the application are available through the API.
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
It's possible to customise Xoralia in a number of different ways:
-The API allows developers to create custom applications using SharePoint, PowerApps and Azure.
-Because Xoralia is built for SharePoint and Office 365 power users and developers can use these tools to create additional custom components such as workflows.
Scaling
- Independence of resources
-
The application automatically scales at times of high demand.
We also use stagger notification send outs so as to reduce load on the application
Analytics
- Service usage metrics
- Yes
- Metrics types
- Xoralia contains a series of reports which show how many people are using the tool, the documents they have read etc.
- Reporting types
- Real-time dashboards
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
-
Federal Information Processing Standard (FIPS) Publication 140-2
https://docs.microsoft.com/en-us/azure/security/fundamentals/encryption-atrest#:~:text=Azure%20Storage%20encryption%20for%20data,encryption%20with%20your%20own%20keys. - Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Reporting data can be downloaded via the onboard CSV download feature.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We have a service uptime commitment of 99.7%
We provide service credits if we drop below our service uptime commitment. - Approach to resilience
- Available on request
- Outage reporting
- We report significant outages by email.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
All support and managerment interfaces that Xoralia utilises are permission controlled and require fully authenticated sessions.
Xoralia management interfaces are only enabled for explicitly defined users by a main Xoralia administrator.
Our support channels allow for explicit access to single support requests or views from the entire organisation. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We have implemented ISO27001 but are not certified
- Information security policies and processes
-
We have a number of information security policies in place which include:
Data sanitisation policy
Encryption policy
Password policy
Joiners and leavers process
Security vetting policy
Business continuity and disaster recovery policy
Risk management policy
Information classification policy
Internet and email conditions of use policy
Back procedures
USB drive policy
Data disposal policy
Remote access policy
Incident response policy
Software patching policy (incl. antivirus)
Information storage and transfer policy
PC audit procedure
Annual cyber security training
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All solution code is tracked through centralised source control and peer reviewed upon branch commit.
Any minor releases are assessed at a local level for the security impact and at each major version push a full security audit is undertaken. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
The Xoralia application infrastructure has been built with security at the forefront. All Azure services that are utilised are protected by both Azure Application Gateway Web Application Firewalls and Azure Virtual Networks. This ensures that only valid, secure traffic is passed on to Xoralia web apps and APIs.
Within the application itself, we have utilised the following technologies / techniques:
Azure SQL Auditing
Microsoft Defender for Cloud
Azure Transparent Data Encryption
Azure Key Vault
Xoralia is also has a vulnerability and penertration test periodically undertaken.
Security patches are deployed as and when they become available. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
The Xoralia application utilises Microsoft Defender for SQL and Azure Threat Detection services to ensure that all parts of the application are continually monitored.
As soon as a threat is detected, the technical teams at are alerted and respond accordingly. - Incident management type
- Supplier-defined controls
- Incident management approach
-
All services that form part of the Xoralia application are monitored 24/7 for performance and availability. Should there be an incident, it is added to our application status monitoring page here: https://xoralia.statuspage.io/
Users can raise reports through the dedicated support channels should they have an issue. Any updates are pushed back through the support channels as well as the dedicated status monitoring page
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
Policies and procedures are a key component to an organisation's social and ethical stance, whether it is fighting climate change, tackling economic inequality, well being etc. Xoralia enables organisations to push out the latest versions of their ethical policies and procedures and ensure they are read and understood by their staff. This a key stepping stone in driving policy engagement and compliance.Covid-19 recovery
Policies and procedures are a key component to an organisation's social and ethical stance, whether it is fighting climate change, tackling economic inequality, well being etc. Xoralia enables organisations to push out the latest versions of their ethical policies and procedures and ensure they are read and understood by their staff. This a key stepping stone in driving policy engagement and compliance.Tackling economic inequality
Policies and procedures are a key component to an organisation's social and ethical stance, whether it is fighting climate change, tackling economic inequality, well being etc. Xoralia enables organisations to push out the latest versions of their ethical policies and procedures and ensure they are read and understood by their staff. This a key stepping stone in driving policy engagement and compliance.Equal opportunity
Policies and procedures are a key component to an organisation's social and ethical stance, whether it is fighting climate change, tackling economic inequality, well being etc. Xoralia enables organisations to push out the latest versions of their ethical policies and procedures and ensure they are read and understood by their staff. This a key stepping stone in driving policy engagement and compliance.Wellbeing
Policies and procedures are a key component to an organisation's social and ethical stance, whether it is fighting climate change, tackling economic inequality, well being etc. Xoralia enables organisations to push out the latest versions of their ethical policies and procedures and ensure they are read and understood by their staff. This a key stepping stone in driving policy engagement and compliance.
Pricing
- Price
- £0.50 to £41.25 a user a year
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Organisations can have a fully functioning version of the service for as long as they like but limited to one policy document. We reserve the right to impose further trial restrictions e.g. on large organisations because of cloud resource costs.
- Link to free trial
- https://xoralia.com