Skip to main content

Help us improve the Digital Marketplace - send your feedback

NEUROBRIDGE LIMITED

The Bridge (Neuroinclusion Support System) & Associated Software

A complete end-to-end neurodiversity support system providing live training workshops, bite-size e-learning skills modules, templates, guides and resources to support neurodivergent colleagues, building manager confidence, and reduce organisational risk. Includes condition-specific guidance (ASD, Dyslexia, ADHD & more), reasonable adjustments support/guidance, specific recruitment/HR guides, optional certification, MI data insights and more.

Features

  • Real-time reporting
  • Single Sign On (SSO)
  • Multi-Factor Authentication (MFA)

Benefits

  • End-to-end Neurodiversity support resources
  • Fast and Simple Implementation
  • Blended learning options
  • Reliable, practical, expert-accredited content
  • Tailored Resources for Managers, Neurodivergent colleagues & HR
  • Reasonable adjustments guidance
  • Increased staff wellbeing, productivity and retention.
  • Reduced organisational risk
  • Neuroinclusive recruitment practices
  • MI insights and data

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at simongoodison@neurobridge.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 1 5 6 8 4 1 6 1 2 6 4 4 7 4

Contact

NEUROBRIDGE LIMITED Simon Goodison
Telephone: 07957803977
Email: simongoodison@neurobridge.co.uk

About your service

Service categories

Applications

Enterprise resource management

  • Enterprise performance management

Human capital management

  • Core Human Resources Applications
  • Talent Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
N/A
System requirements
  • Internet connection to access The Bridge web application
  • Modern browser: Chrome, Edge, Firefox, Safari (latest versions)
  • JavaScript enabled; cookies permitted for secure authentication sessions
  • TLS 1.2+ supported; outbound HTTPS to platform domain allowed
  • Users require work email address for account provisioning
  • SSO requires OIDC identity provider configuration

User support

Email or online ticketing support
Yes
Support response times
Resolution times vary depending on the complexity and severity of the issue, ranging from 2 hours to 2 days.

Support is provided Monday to Friday, between 09:00 and 17:00 UK time, excluding public holidays in England and Wales. Outside of these hours, support is not guaranteed but may be provided for critical-impact incidents by prior agreement.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support is available to all customers as part of standard service, through an online ticketing system that supports email communication. This covers all ranges of technical issues from Forgotten Password to Critical Issues.

Each issue is allocated to a case manager who reviews and owns each issue.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We meet with nominated team members to understand their goals and what they want to achieve when using The Bridge. They are then provided with a 7 week onboarding email campaign highlighting how to make the most of the system in the early stages.

Online check-ins are encouraged to review usage and progress, and see how best NeuroBridge can support.
Service documentation
No
End-of-contract data extraction
When a contract ends, NeuroBridge follows a documented client offboarding process that ensures users can securely extract their data before access is revoked. Upon written termination or expiry, the offboarding process is initiated and clients are informed of the timetable and available export options. User access remains available during the offboarding window, allowing individuals to self-request a data export through the platform’s built-in export tools.

Data exports are generated using the platform’s WordPress data export mechanism, producing a structured ZIP archive containing both a human-readable HTML report and a machine-readable JSON file, supporting data portability. Exports use a two-step email verification process to confirm identity, and download links are time-limited with automatic deletion for security.

Where export requests are received by email, the Data Protection Officer oversees identity verification, approval, and fulfilment within standard GDPR timelines. NeuroBridge acts as an independent controller and does not transfer identified learner data to sponsoring organisations; only anonymised aggregate insights may be provided where applicable.

After the export window closes, access is revoked and data is securely erased in line with documented retention schedules, with deletion evidence captured and confirmed.
End-of-contract process
At contract expiry, termination, or non-renewal, NeuroBridge initiates a formal offboarding process. This includes confirming any legal holds, freezing non-essential configuration changes, and communicating the offboarding timetable to the client. Users are provided a window to export their personal data using self-service tools. Sponsor and administrative access is then revoked, and enterprise features are disabled. Personal data held on a “life-of-contract” basis is securely erased using automated platform tools, backups are allowed to age out naturally, and a Certificate of Data Deletion is issued to confirm completion. Identified learner data is not transferred to sponsors; only anonymised aggregate insights may be provided.

The contract price includes standard offboarding, user self-service data exports, secure erasure, access revocation, compliance logging, and confirmation of deletion. These activities are delivered as part of normal service operation and GDPR compliance. Additional costs may apply only where non-standard requests are made, such as bespoke data extracts outside the platform’s export tools, accelerated timelines beyond documented defaults, or support for manifestly unfounded or excessive data requests, in line with GDPR provisions. Any such costs are agreed in advance and documented transparently.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Layout only.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The Bridge is a web-based SaaS platform accessed via a browser. Users sign in to a role-based interface to utilise structured tools, complete learning modules, access guidance and templates to support neuroinclusive working practices. Administrators view aggregated and anonymised usage and engagement dashboards. The interface is mobile-responsive, supports keyboard navigation, and uses clear layouts and plain language to reduce cognitive load.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We carry out accessibility checks as part of release testing, including keyboard-only navigation, focus order/visibility, zoom up to 200%, and colour contrast checks. We test key user journeys (sign-in, navigation, module completion and downloads) using screen readers (for example NVDA and VoiceOver) and ensure forms and controls are labelled correctly. Issues are logged and prioritised for remediation, and we repeat checks after fixes. Where buyers have specific assistive technology requirements, we will validate critical journeys in their environment during onboarding.
API
No
Customisation available
No

Scaling

Independence of resources
We use AWS compute services with auto-scaling built-in to our architecture.

Analytics

Service usage metrics
Yes
Metrics types
Total Onboarded Users
Total Learners
Courses Complete
Modules Complete
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Cyber Essentials Basic, renews annually. This standard governs our encryption at rest posture, which is AES-256 at rest by default.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data using self-service tools within The Bridge platform. From their user profile, users submit a data export request, which triggers a secure export process. Admin-approved. the system generates a downloadable ZIP file containing both a human-readable HTML report and a machine-readable JSON file, supporting data portability. Exports use email verification to confirm identity, and download links are time-limited with automatic deletion for security. All requests and actions are logged automatically to demonstrate GDPR compliance, and exports are completed within the organisation’s one-month response commitment, typically much sooner.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The NeuroBridge Platform is available to Licensed Users on a 24/7 basis, subject to scheduled maintenance or events beyond NeuroBridge’s reasonable control.

NeuroBridge shall use reasonable endeavours to maintain Platform availability of 99.9% per calendar month, excluding scheduled maintenance windows
Approach to resilience
NeuroBridge designs resilience into its service through a risk-based operational resilience framework that protects service availability, data integrity, and continuity. Risks to service delivery are identified through system and supplier inventories, event-driven reviews, and monitoring of emerging threats. Material changes to the service are assessed before release, and resilience controls are reviewed at least annually and after significant incidents.

Service continuity is supported by provider-level redundancy and backup mechanisms, alongside an off-site disaster recovery tier for the platform. Production services use managed cloud infrastructure with routine snapshots, while encrypted off-site backups are retained with defined retention periods. Recovery objectives (RPO/RTO) are documented, tested periodically, and reviewed following material change. Disaster recovery procedures and restore testing are conducted at least annually to validate recoverability.

Operational resilience is reinforced through documented incident response procedures, vulnerability management with defined remediation timelines, and regular security and compliance reviews. Supplier concentration risk is actively managed through contractual safeguards, data residency controls, and annual assurance reviews. Where further detail on datacentre locations or infrastructure architecture is required, this information can be provided on request.
Outage reporting
A public dashboard.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Other user authentication
SSO (Vendor decides authentication policy)
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is tightly controlled using role-based access control and least-privilege principles. Administrative access is restricted to approved individuals, granted only after mandatory security training, and requires separate admin accounts where feasible. Strong authentication is enforced, including unique credentials and multi-factor authentication for privileged access. Access is reviewed periodically and revoked promptly on role change or departure. Administrative and support activities are logged, monitored, and audited, and misuse of access may result in disciplinary action or immediate revocation.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Description of management access authentication
Physical hardware tokens

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
NeuroBridge follows a risk-based information security framework designed to protect the confidentiality, integrity, and availability of data across all services. Governance and accountability are defined at executive level, with clear ownership of security policy, technical controls, and operational procedures. Security responsibilities apply to all employees and contractors and are reinforced through mandatory training, acceptable-use requirements, and documented joiner/mover/leaver processes.

We implement strong identity and access controls, including role-based access, least-privilege principles, secure password management, and multi-factor authentication where supported. Privileged access is restricted, approved, logged, and reviewed regularly. Endpoint and remote-working security controls are enforced to reduce risk from device loss or misuse.

Operationally, we maintain security monitoring, logging, vulnerability management, and incident response procedures, with defined escalation paths and post-incident review. Backup, disaster recovery, and business continuity arrangements are documented, tested, and reviewed at least annually.

All data processing activities, systems, suppliers, retention periods, and technical safeguards are documented within our Record of Processing Activities, supporting GDPR Article 32 compliance. Third-party suppliers and contractors are subject to defined security expectations, contractual safeguards, and compliance checks, including Cyber Essentials alignment where applicable.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
NeuroBridge manages configuration and change through a documented SDLC and change control process. Service components (application, configuration, and infrastructure) are tracked throughout their lifecycle using internal change records, versioning, and vendor update logs, providing traceability of what changed, when, why, and by whom. Changes are reviewed and approved before implementation, except for emergency security actions which are retrospectively logged. Changes with potential security or data-protection impact are assessed prior to release, tested in non-production where feasible, and may trigger updates to security or compliance documentation (e.g. DPIA or ROPA).
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
NeuroBridge operates a documented vulnerability management process to identify, assess, remediate, and verify security issues affecting its services. Potential threats are identified through multiple sources, including vendor security advisories, WordPress core alerts, Wordfence threat intelligence feeds, SBOM snapshots, and responsible disclosure reports. Vulnerabilities are prioritised using CVSS where available, adjusted for context such as exposure and exploitability. Critical and high-risk issues on internet-facing services are remediated within five working days, with faster action taken where active exploitation is suspected. All remediation actions are verified, logged, and reviewed for auditability.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
NeuroBridge operates continuous protective monitoring across its services using automated security tooling and defined review processes. Potential compromises are identified through working-daily Wordfence scans, real-time firewall and malware signature feeds, weekly blocked-threat reports, admin activity log reviews, and event-based triggers for suspicious behaviour. Alerts are triaged by the CTO, with material events escalated to the breach incident log. When a potential compromise is identified, containment and investigation begin within one hour, following the Breach Response Procedure. Incidents are assessed, logged, remediated, and, where required, reported to regulators and clients within defined statutory timelines.
Incident management type
Supplier-defined controls
Incident management approach
NeuroBridge operates pre-defined incident management procedures for common security and data protection events, including suspected breaches, account compromise, and unauthorised access. These are documented and rehearsed, with clear roles, escalation paths, and response timelines. Users can report incidents via email to the published security or support contact, or incidents may be identified through protective monitoring and admin alerts. All incidents are logged, investigated, and remediated in line with severity. Where required, incident reports are provided to affected clients, including impact, actions taken, and outcomes, and regulators are notified within statutory timeframes.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
1-week free trial access for up to 5 trial users.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Db9f6aa9-b91f-4d00-aef5-1308251743ea
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at simongoodison@neurobridge.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.