The Bridge (Neuroinclusion Support System) & Associated Software
A complete end-to-end neurodiversity support system providing live training workshops, bite-size e-learning skills modules, templates, guides and resources to support neurodivergent colleagues, building manager confidence, and reduce organisational risk. Includes condition-specific guidance (ASD, Dyslexia, ADHD & more), reasonable adjustments support/guidance, specific recruitment/HR guides, optional certification, MI data insights and more.
Features
- Real-time reporting
- Single Sign On (SSO)
- Multi-Factor Authentication (MFA)
Benefits
- End-to-end Neurodiversity support resources
- Fast and Simple Implementation
- Blended learning options
- Reliable, practical, expert-accredited content
- Tailored Resources for Managers, Neurodivergent colleagues & HR
- Reasonable adjustments guidance
- Increased staff wellbeing, productivity and retention.
- Reduced organisational risk
- Neuroinclusive recruitment practices
- MI insights and data
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 1 5 6 8 4 1 6 1 2 6 4 4 7 4
Contact
NEUROBRIDGE LIMITED
Simon Goodison
Telephone: 07957803977
Email: simongoodison@neurobridge.co.uk
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
Human capital management
- Core Human Resources Applications
- Talent Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- N/A
- System requirements
-
- Internet connection to access The Bridge web application
- Modern browser: Chrome, Edge, Firefox, Safari (latest versions)
- JavaScript enabled; cookies permitted for secure authentication sessions
- TLS 1.2+ supported; outbound HTTPS to platform domain allowed
- Users require work email address for account provisioning
- SSO requires OIDC identity provider configuration
User support
- Email or online ticketing support
- Yes
- Support response times
-
Resolution times vary depending on the complexity and severity of the issue, ranging from 2 hours to 2 days.
Support is provided Monday to Friday, between 09:00 and 17:00 UK time, excluding public holidays in England and Wales. Outside of these hours, support is not guaranteed but may be provided for critical-impact incidents by prior agreement. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support is available to all customers as part of standard service, through an online ticketing system that supports email communication. This covers all ranges of technical issues from Forgotten Password to Critical Issues.
Each issue is allocated to a case manager who reviews and owns each issue. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We meet with nominated team members to understand their goals and what they want to achieve when using The Bridge. They are then provided with a 7 week onboarding email campaign highlighting how to make the most of the system in the early stages.
Online check-ins are encouraged to review usage and progress, and see how best NeuroBridge can support. - Service documentation
- No
- End-of-contract data extraction
-
When a contract ends, NeuroBridge follows a documented client offboarding process that ensures users can securely extract their data before access is revoked. Upon written termination or expiry, the offboarding process is initiated and clients are informed of the timetable and available export options. User access remains available during the offboarding window, allowing individuals to self-request a data export through the platform’s built-in export tools.
Data exports are generated using the platform’s WordPress data export mechanism, producing a structured ZIP archive containing both a human-readable HTML report and a machine-readable JSON file, supporting data portability. Exports use a two-step email verification process to confirm identity, and download links are time-limited with automatic deletion for security.
Where export requests are received by email, the Data Protection Officer oversees identity verification, approval, and fulfilment within standard GDPR timelines. NeuroBridge acts as an independent controller and does not transfer identified learner data to sponsoring organisations; only anonymised aggregate insights may be provided where applicable.
After the export window closes, access is revoked and data is securely erased in line with documented retention schedules, with deletion evidence captured and confirmed. - End-of-contract process
-
At contract expiry, termination, or non-renewal, NeuroBridge initiates a formal offboarding process. This includes confirming any legal holds, freezing non-essential configuration changes, and communicating the offboarding timetable to the client. Users are provided a window to export their personal data using self-service tools. Sponsor and administrative access is then revoked, and enterprise features are disabled. Personal data held on a “life-of-contract” basis is securely erased using automated platform tools, backups are allowed to age out naturally, and a Certificate of Data Deletion is issued to confirm completion. Identified learner data is not transferred to sponsors; only anonymised aggregate insights may be provided.
The contract price includes standard offboarding, user self-service data exports, secure erasure, access revocation, compliance logging, and confirmation of deletion. These activities are delivered as part of normal service operation and GDPR compliance. Additional costs may apply only where non-standard requests are made, such as bespoke data extracts outside the platform’s export tools, accelerated timelines beyond documented defaults, or support for manifestly unfounded or excessive data requests, in line with GDPR provisions. Any such costs are agreed in advance and documented transparently.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Layout only.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The Bridge is a web-based SaaS platform accessed via a browser. Users sign in to a role-based interface to utilise structured tools, complete learning modules, access guidance and templates to support neuroinclusive working practices. Administrators view aggregated and anonymised usage and engagement dashboards. The interface is mobile-responsive, supports keyboard navigation, and uses clear layouts and plain language to reduce cognitive load.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We carry out accessibility checks as part of release testing, including keyboard-only navigation, focus order/visibility, zoom up to 200%, and colour contrast checks. We test key user journeys (sign-in, navigation, module completion and downloads) using screen readers (for example NVDA and VoiceOver) and ensure forms and controls are labelled correctly. Issues are logged and prioritised for remediation, and we repeat checks after fixes. Where buyers have specific assistive technology requirements, we will validate critical journeys in their environment during onboarding.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- We use AWS compute services with auto-scaling built-in to our architecture.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Total Onboarded Users
Total Learners
Courses Complete
Modules Complete - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Cyber Essentials Basic, renews annually. This standard governs our encryption at rest posture, which is AES-256 at rest by default.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export their data using self-service tools within The Bridge platform. From their user profile, users submit a data export request, which triggers a secure export process. Admin-approved. the system generates a downloadable ZIP file containing both a human-readable HTML report and a machine-readable JSON file, supporting data portability. Exports use email verification to confirm identity, and download links are time-limited with automatic deletion for security. All requests and actions are logged automatically to demonstrate GDPR compliance, and exports are completed within the organisation’s one-month response commitment, typically much sooner.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The NeuroBridge Platform is available to Licensed Users on a 24/7 basis, subject to scheduled maintenance or events beyond NeuroBridge’s reasonable control.
NeuroBridge shall use reasonable endeavours to maintain Platform availability of 99.9% per calendar month, excluding scheduled maintenance windows - Approach to resilience
-
NeuroBridge designs resilience into its service through a risk-based operational resilience framework that protects service availability, data integrity, and continuity. Risks to service delivery are identified through system and supplier inventories, event-driven reviews, and monitoring of emerging threats. Material changes to the service are assessed before release, and resilience controls are reviewed at least annually and after significant incidents.
Service continuity is supported by provider-level redundancy and backup mechanisms, alongside an off-site disaster recovery tier for the platform. Production services use managed cloud infrastructure with routine snapshots, while encrypted off-site backups are retained with defined retention periods. Recovery objectives (RPO/RTO) are documented, tested periodically, and reviewed following material change. Disaster recovery procedures and restore testing are conducted at least annually to validate recoverability.
Operational resilience is reinforced through documented incident response procedures, vulnerability management with defined remediation timelines, and regular security and compliance reviews. Supplier concentration risk is actively managed through contractual safeguards, data residency controls, and annual assurance reviews. Where further detail on datacentre locations or infrastructure architecture is required, this information can be provided on request. - Outage reporting
- A public dashboard.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- SSO (Vendor decides authentication policy)
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is tightly controlled using role-based access control and least-privilege principles. Administrative access is restricted to approved individuals, granted only after mandatory security training, and requires separate admin accounts where feasible. Strong authentication is enforced, including unique credentials and multi-factor authentication for privileged access. Access is reviewed periodically and revoked promptly on role change or departure. Administrative and support activities are logged, monitored, and audited, and misuse of access may result in disciplinary action or immediate revocation.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- Physical hardware tokens
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
NeuroBridge follows a risk-based information security framework designed to protect the confidentiality, integrity, and availability of data across all services. Governance and accountability are defined at executive level, with clear ownership of security policy, technical controls, and operational procedures. Security responsibilities apply to all employees and contractors and are reinforced through mandatory training, acceptable-use requirements, and documented joiner/mover/leaver processes.
We implement strong identity and access controls, including role-based access, least-privilege principles, secure password management, and multi-factor authentication where supported. Privileged access is restricted, approved, logged, and reviewed regularly. Endpoint and remote-working security controls are enforced to reduce risk from device loss or misuse.
Operationally, we maintain security monitoring, logging, vulnerability management, and incident response procedures, with defined escalation paths and post-incident review. Backup, disaster recovery, and business continuity arrangements are documented, tested, and reviewed at least annually.
All data processing activities, systems, suppliers, retention periods, and technical safeguards are documented within our Record of Processing Activities, supporting GDPR Article 32 compliance. Third-party suppliers and contractors are subject to defined security expectations, contractual safeguards, and compliance checks, including Cyber Essentials alignment where applicable. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- NeuroBridge manages configuration and change through a documented SDLC and change control process. Service components (application, configuration, and infrastructure) are tracked throughout their lifecycle using internal change records, versioning, and vendor update logs, providing traceability of what changed, when, why, and by whom. Changes are reviewed and approved before implementation, except for emergency security actions which are retrospectively logged. Changes with potential security or data-protection impact are assessed prior to release, tested in non-production where feasible, and may trigger updates to security or compliance documentation (e.g. DPIA or ROPA).
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- NeuroBridge operates a documented vulnerability management process to identify, assess, remediate, and verify security issues affecting its services. Potential threats are identified through multiple sources, including vendor security advisories, WordPress core alerts, Wordfence threat intelligence feeds, SBOM snapshots, and responsible disclosure reports. Vulnerabilities are prioritised using CVSS where available, adjusted for context such as exposure and exploitability. Critical and high-risk issues on internet-facing services are remediated within five working days, with faster action taken where active exploitation is suspected. All remediation actions are verified, logged, and reviewed for auditability.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- NeuroBridge operates continuous protective monitoring across its services using automated security tooling and defined review processes. Potential compromises are identified through working-daily Wordfence scans, real-time firewall and malware signature feeds, weekly blocked-threat reports, admin activity log reviews, and event-based triggers for suspicious behaviour. Alerts are triaged by the CTO, with material events escalated to the breach incident log. When a potential compromise is identified, containment and investigation begin within one hour, following the Breach Response Procedure. Incidents are assessed, logged, remediated, and, where required, reported to regulators and clients within defined statutory timelines.
- Incident management type
- Supplier-defined controls
- Incident management approach
- NeuroBridge operates pre-defined incident management procedures for common security and data protection events, including suspected breaches, account compromise, and unauthorised access. These are documented and rehearsed, with clear roles, escalation paths, and response timelines. Users can report incidents via email to the published security or support contact, or incidents may be identified through protective monitoring and admin alerts. All incidents are logged, investigated, and remediated in line with severity. Where required, incident reports are provided to affected clients, including impact, actions taken, and outcomes, and regulators are notified within statutory timeframes.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- 1-week free trial access for up to 5 trial users.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Db9f6aa9-b91f-4d00-aef5-1308251743ea
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-