Skip to main content

Help us improve the Digital Marketplace - send your feedback

Content Formula

Xoralia Policy & Procedure Management for SharePoint, Microsoft 365, Teams

Xoralia is easy-to-use policy and procedures management software built for SharePoint, Teams and Office365. Xoralia manages the whole policy lifecycle: policy creation, policy dissemination, gathering acknowledgements, quizzes and policy reviews. Xoralia is unique because it enables you to store your policies and controlled documents inside your own SharePoint environment.

Features

  • Mandatory policy notifications and reminders
  • Reporting and tracking
  • Target users and groups with mandatory reads and quizzes
  • Recurring policy reads (e.g. annually)
  • Manage policy creation, reviews and expiries
  • Store all your policies inside SharePoint
  • Single sign-on (no login or password)
  • Mobile app for front line workers (no M365 licence needed)
  • Comes with various SharePoint webparts and Microsoft Teams app
  • Works on mobile, tablet and desktop devices

Benefits

  • Minimise risk and achieve compliance
  • Keep an audit trail of all your employees' policy reads
  • Manage new employee onboarding
  • Reduce time spent distributing and tracking documents
  • Keep all your documents secure inside your Office 365
  • Leverage existing SharePoint policy libraries, groups and permissions
  • Manage the whole policy lifecycle
  • Intuitive interface makes it easy to find and read policies
  • Create a single source of truth for all your policies

Pricing

£0.50 to £41.25 a user a year

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at dhawtrey@contentformula.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

9 0 4 3 8 0 9 2 7 1 8 5 2 5 7

Contact

Content Formula Dan Hawtrey
Telephone: 020 4534 3460
Email: dhawtrey@contentformula.com

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
SharePoint, Teams and Office 365
Cloud deployment model
  • Public cloud
  • Hybrid cloud
Service constraints
None
System requirements
Microsoft 365

User support

Email or online ticketing support
Email or online ticketing
Support response times
Within 2 hours for P1 requests - system down
Within 4 hours for P2 requests - major impact
Within 12 hours for P3 requests - minor impact
Within 48 hours for P4 requests - trivial impact
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.1 A
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
The service comes with support included. This support provides a helpdesk in case there are any issues with the system and it is not working as expected. If helpdesk engineer is unable to resolve the issue we have two further levels of escalation up to a senior engineer. For refresher training, end user support etc. we provide comprehensive HowTos, documentation and videos on our website. Alternatively, the customer can purchase a bucket of hours to cover such support.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide remote training over Teams or Zoom.
We also provide online getting started guides and videos on our website.
We have also designed the tool to be highly intuitive so users can start using the tool using only tool tips built inside the tool.
The mobile app for frontline workers is super-easy to use
Service documentation
Yes
Documentation formats
  • HTML
  • Other
Other documentation formats
Video
End-of-contract data extraction
All your policy documents remain inside your Office 365 and SharePoint so there is no need to extract that data.
Read and reporting data can be downloaded as CSV files from within the reporting interface.
End-of-contract process
If a customer wants to cease receiving the service they can provide notice and the service will come to an end.
It is the customer's responsibility to download any reporting data prior to the expiry, but this is easy and quick to do.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Frontline workers get a native mobile app (no M365 licence required) so they can search, browse, read policies, acknowledge having read a policy and complete quizzes.

Users can also access a mobile-optimised Xoralia through their mobile browsers
Service interface
Yes
User support accessibility
WCAG 2.1 AA or EN 301 549
Description of service interface
The service interface is designed for admins of the system and provides the following features:
- Ability to change branding
- Ability to add or remove document libraries
- Ability to add or remove admin users
- Access system analytics
Accessibility standards
WCAG 2.1 AA or EN 301 549
Accessibility testing
We have tested the application for accessibility with WAVE evaluation tool and with Access Assistant for Chrome.
API
Yes
What users can and can't do using the API
The Xoralia API is powerful and fully featured. All features and functionalities available on the application are available through the API.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
It's possible to customise Xoralia in a number of different ways:
-The API allows developers to create custom applications using SharePoint, PowerApps and Azure.
-Because Xoralia is built for SharePoint and Office 365 power users and developers can use these tools to create additional custom components such as workflows.

Scaling

Independence of resources
The application automatically scales at times of high demand.
We also use stagger notification send outs so as to reduce load on the application

Analytics

Service usage metrics
Yes
Metrics types
Xoralia contains a series of reports which show how many people are using the tool, the documents they have read etc.
Reporting types
Real-time dashboards

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
Federal Information Processing Standard (FIPS) Publication 140-2
https://docs.microsoft.com/en-us/azure/security/fundamentals/encryption-atrest#:~:text=Azure%20Storage%20encryption%20for%20data,encryption%20with%20your%20own%20keys.
Data sanitisation process
Yes
Data sanitisation type
Deleted data can’t be directly accessed
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
Reporting data can be downloaded via the onboard CSV download feature.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We have a service uptime commitment of 99.7%
We provide service credits if we drop below our service uptime commitment.
Approach to resilience
Available on request
Outage reporting
We report significant outages by email.

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
All support and managerment interfaces that Xoralia utilises are permission controlled and require fully authenticated sessions.

Xoralia management interfaces are only enabled for explicitly defined users by a main Xoralia administrator.

Our support channels allow for explicit access to single support requests or views from the entire organisation.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • 2-factor authentication
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
No
Other security certifications
No

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
We have implemented ISO27001 but are not certified
Information security policies and processes
We have a number of information security policies in place which include:
Data sanitisation policy
Encryption policy
Password policy
Joiners and leavers process
Security vetting policy
Business continuity and disaster recovery policy
Risk management policy
Information classification policy
Internet and email conditions of use policy
Back procedures
USB drive policy
Data disposal policy
Remote access policy
Incident response policy
Software patching policy (incl. antivirus)
Information storage and transfer policy
PC audit procedure
Annual cyber security training

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All solution code is tracked through centralised source control and peer reviewed upon branch commit.

Any minor releases are assessed at a local level for the security impact and at each major version push a full security audit is undertaken.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
The Xoralia application infrastructure has been built with security at the forefront. All Azure services that are utilised are protected by both Azure Application Gateway Web Application Firewalls and Azure Virtual Networks. This ensures that only valid, secure traffic is passed on to Xoralia web apps and APIs.

Within the application itself, we have utilised the following technologies / techniques:

Azure SQL Auditing
Microsoft Defender for Cloud
Azure Transparent Data Encryption
Azure Key Vault

Xoralia is also has a vulnerability and penertration test periodically undertaken.

Security patches are deployed as and when they become available.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
The Xoralia application utilises Microsoft Defender for SQL and Azure Threat Detection services to ensure that all parts of the application are continually monitored.

As soon as a threat is detected, the technical teams at are alerted and respond accordingly.
Incident management type
Supplier-defined controls
Incident management approach
All services that form part of the Xoralia application are monitored 24/7 for performance and availability. Should there be an incident, it is added to our application status monitoring page here: https://xoralia.statuspage.io/

Users can raise reports through the dedicated support channels should they have an issue. Any updates are pushed back through the support channels as well as the dedicated status monitoring page

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Social Value

Social Value

Social Value

  • Fighting climate change
  • Covid-19 recovery
  • Tackling economic inequality
  • Equal opportunity
  • Wellbeing

Fighting climate change

Policies and procedures are a key component to an organisation's social and ethical stance, whether it is fighting climate change, tackling economic inequality, well being etc. Xoralia enables organisations to push out the latest versions of their ethical policies and procedures and ensure they are read and understood by their staff. This a key stepping stone in driving policy engagement and compliance.

Covid-19 recovery

Policies and procedures are a key component to an organisation's social and ethical stance, whether it is fighting climate change, tackling economic inequality, well being etc. Xoralia enables organisations to push out the latest versions of their ethical policies and procedures and ensure they are read and understood by their staff. This a key stepping stone in driving policy engagement and compliance.

Tackling economic inequality

Policies and procedures are a key component to an organisation's social and ethical stance, whether it is fighting climate change, tackling economic inequality, well being etc. Xoralia enables organisations to push out the latest versions of their ethical policies and procedures and ensure they are read and understood by their staff. This a key stepping stone in driving policy engagement and compliance.

Equal opportunity

Policies and procedures are a key component to an organisation's social and ethical stance, whether it is fighting climate change, tackling economic inequality, well being etc. Xoralia enables organisations to push out the latest versions of their ethical policies and procedures and ensure they are read and understood by their staff. This a key stepping stone in driving policy engagement and compliance.

Wellbeing

Policies and procedures are a key component to an organisation's social and ethical stance, whether it is fighting climate change, tackling economic inequality, well being etc. Xoralia enables organisations to push out the latest versions of their ethical policies and procedures and ensure they are read and understood by their staff. This a key stepping stone in driving policy engagement and compliance.

Pricing

Price
£0.50 to £41.25 a user a year
Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Organisations can have a fully functioning version of the service for as long as they like but limited to one policy document. We reserve the right to impose further trial restrictions e.g. on large organisations because of cloud resource costs.
Link to free trial
https://xoralia.com

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at dhawtrey@contentformula.com. Tell them what format you need. It will help if you say what assistive technology you use.