Skip to main content

Help us improve the Digital Marketplace - send your feedback

LOGEX HEALTHCARE ANALYTICS LTD

LOGEX Costing

The LOGEX Costing solution is an end‑to‑end PLICS system delivering transparent, standards‑compliant patient‑level costs with full BAU and SLR reporting. It offers deep benchmarking insights, NCC‑aligned costing, and rich analytics through intuitive dashboards — helping NHS teams optimise resources, compare performance, and make evidence‑based financial decisions with confidence.

Features

  • Complete Activity Based Costing Software
  • Fully compliant with the Costing Transformation Programme at all times
  • Fully transparent system allows complete traceability of costs
  • Ability to import, validate and transform data within the system
  • Includes in-built, easy to use dashboards
  • Generates output databases to also support any other BI tool
  • Meets the current and future requirements of the costing standards
  • Flexibility to handle individual requirements
  • Includes full audit trail of rules applied
  • Includes fully compliant extracts for National Cost Collection

Benefits

  • Ease-of-Use– Intuitive user interface removes the need for SQL.
  • Guaranteed Compliance– Meets all requirements for the National Cost Collection.
  • BI‑Ready Outputs– Export results seamlessly into any BI platform
  • Fast Processing– Quick calculation and exports accelerate your costing cycle
  • Standards Ready– Fully aligned with current and future costing standards
  • Better Decisions– Detailed, reliable costing insights support confident financial choices.
  • Reduced Burden– Managed service lightens workload for internal teams
  • Expert Support– Delivered by established, highly experienced costing consultants.
  • Flexible Modelling– Quickly adjust costing logic with fast, efficient configuration
  • Clear Insights– Dashboards with drill‑down unlock granular cost visibility

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at feico.ulrici@logex.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 3 8 0 7 0 7 1 3 5 4 4 7 7 0

Contact

LOGEX HEALTHCARE ANALYTICS LTD Marc Bijoux
Telephone: +44 (0) 7985 702963
Email: feico.ulrici@logex.com

About your service

Service categories

Applications

Enterprise resource management

  • Enterprise performance management

Financial

  • Financial and Accounting Applications
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
LOGEX Costing can be combined with LOGEX Income (for P&L management) and LOGEX Planning, Budgeting & Forecasting (for triangulated budget plans), for full financial control. When combined, the system empowers customers to identify, plan and monitor their Multi-year and Cost-Improvement Plans, using a single source of truth throughout the organisation.
Cloud deployment model
Public cloud
Service constraints
LOGEX Costing is provided as a SaaS-solution accessed via the internet. The service requires a supported web browser, user accounts, appropriate permissions, and a reliable internet connection. Routine on-site support is not included as standard. Implementation and support are primarily delivered remotely by LOGEX consultants using online collaboration tools. In-person meetings may be provided where required, subject to prior agreement and scheduling. Functionality and service levels are limited to the selected package (Basic, Advanced, or Professional). Optional features and tailored support can be made available by agreement but are not included as standard. Support is available Monday to Friday, 9am–5pm.
System requirements
  • Minimum recommended technical requirements provided based on discussions
  • An internet browser
  • An internet connection

User support

Email or online ticketing support
Yes
Support response times
Whenever a request for support is received, we will send a confirmation of receipt within 15 minutes of submission. Support is available during business hours (Monday to Friday, 9am–5pm). This response time applies to all supported channels, including email, online ticketing, and telephone support. Response times refer to the time taken to acknowledge and begin addressing an enquiry, not full resolution. Urgent issues, such as service access or critical functionality concerns, are prioritised and acknowledged as soon as they are received within business hours. Response and resolution targets are clearly defined as part of the agreed service terms.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
LOGEX does not categorise support into varying levels or adjust the quality of service according to package. Every customer benefits from the same high standard of responsive, personalised support, with standard assistance available on weekdays from 09:00 to 17:00, accessible via email or phone. At LOGEX, our approach to support is highly personal, ensuring that every client receives expert assistance tailored to their unique requirements. Central to this commitment is the assignment of a dedicated consultant to every customer. Your dedicated consultant acts as your single point of contact, managing all support queries, coordinating additional services, and providing continuity throughout your partnership with LOGEX. This ensures that your needs are understood and addressed efficiently, fostering a relationship built on trust and in-depth knowledge of your organisation’s goals. Our on-site support encompasses a broad range of services, including hands-on implementation guidance, interactive workshops, comprehensive training sessions, proactive technical troubleshooting, and swift issue resolution. We pride ourselves on offering flexible support options, all meticulously adapted to each client’s circumstances. Importantly, For requests that extend beyond standard support, we offer different sizes of service bundles, allowing you to choose the level of additional support that best fits your organisation’s needs, preventing hidden costs.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We ensure onboarding is low-effort through a clear, structured process. New users receive access via a controlled provisioning workflow, with accounts created according to agreed role profiles and secured through MFA and least-privilege permissions. Our implementation team guides customers through initial configuration, data ingestion setup, validation checks, and key workflow familiarisation so they can begin using the service confidently. At the start, users receive tailored support, including online training sessions, optional onsite workshops, hands-on demonstrations, and role specific walk-throughs. They also gain access to our searchable knowledge base, containing user-guides, recorded webinars, best-practice materials, and troubleshooting articles to promote self learning. Onboarding timelines vary by organisation, but most customers complete the process within a few weeks. Support remains fully available throughout onboarding via email, ticketing, and scheduled check-ins with a dedicated consultant. We avoid vendor lock in by using standard formats and not requiring proprietary tools or specialist skills. If a user or organisation leaves the service, we provide clear offboarding guidance. Customers retain full ownership of their data and can export it in standard formats. After confirmation, all data is securely deleted in line with contractual retention periods. Offboarding steps are fully documented to ensure a smooth, responsible exit.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of a contract, users retain full control over their data and can extract all information held within the service, including activity datasets, pricing outputs, validation logs, and generated reports. Data can be exported at any time before contract closure, and extraction is supported by our team to ensure a smooth, complete transfer. Exports are provided in standard, non‑proprietary formats such as CSV, XLSX, or other mutually agreed formats, ensuring no vendor lock‑in and easy reuse in downstream systems. During the offboarding phase, our consultants assist with planning and validating the extraction to confirm accuracy and completeness. Once the client has confirmed successful receipt of all required data, formal offboarding begins. After extraction, LOGEX securely deletes all customer data, including backups, in accordance with contractual retention periods and data‑protection obligations. Data older than five years is automatically purged, but earlier deletion is performed immediately at the client’s request. A certificate of destruction can be provided on request for audit or compliance purposes. There are no exclusions beyond legal requirements: aggregated, non‑personal benchmarking outputs may remain available, but all identifiable customer data is fully removed. The exit process is documented, transparent, and designed to ensure a responsible, low‑effort transition.
End-of-contract process
At the end of the contract, the exit process is clear, predictable, and fully controlled by the customer. Contract termination follows the agreed notice period, during which we maintain normal service availability and provide support to plan a smooth transition. During this period, users can extract all required data in standard, non‑proprietary formats (e.g., CSV, XLSX), with our team available to assist in validating and completing the extraction. There are no exit fees unless additional, optional services are explicitly requested. When the contract ends, all user accounts are disabled in a controlled manner to prevent further access. Customers retain full ownership of their data throughout offboarding. After the customer confirms that all necessary data has been exported, LOGEX securely deletes all customer data—including backups—in line with contractual retention periods and data‑protection obligations. A formal certificate of destruction can be provided on request. Any aggregated, non‑personal outputs may remain available for reference, but no identifiable customer data is retained. The offboarding steps are documented and can include a final review call to confirm all obligations have been met. Our goal is to ensure a transparent, low‑effort exit with no lock‑in and full buyer control. There are no additional costs involved.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
All onboarding and offboarding documentation is provided in accessible HTML and PDF formats. HTML guidance is fully compatible with browser‑based accessibility features such as zoom, high‑contrast modes, screen readers and keyboard navigation. PDF versions are created using tagged, structured templates to support assistive technologies, including screen‑reader interpretation, adjustable text size, and reflow for mobile or enlarged views. Users can therefore adjust how they view the documentation based on their own accessibility preferences or tools. To support readability, we use clear language, consistent heading structures, and logical page layouts. Screenshots, diagrams and step‑by‑step instructions include meaningful descriptions to ensure they remain understandable for all users, including those using assistive technologies. Where required, we can provide documentation in alternative formats on request, such as simplified text, large‑print versions, or adapted copies for internal accessibility needs. Our consultants are trained to walk users through the materials verbally, via online meetings, phone calls or in‑person sessions, ensuring no user is excluded during onboarding or exit. All documentation is version‑controlled, reviewed regularly, and updated whenever features, workflows or support processes change. This ensures that both onboarding and offboarding remain clear, accurate and accessible for the full range of public‑sector users.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Users access the service securely through any modern web browser. After logging in, they land on a clear, role‑based start page showing relevant dashboards and key metrics. Navigation is simple via the sidebar menu and consistent, well‑structured screens. The interface is highly intuitive for non‑technical users, with clear labels, guided workflows, and minimal training required. For deeper analysis, users can easily switch between interactive graphs, pie charts, pivot tables, and detailed data views. This streamlined, accessible design supports efficient decision‑making and enables public‑sector users to quickly find insights and perform tasks with confidence.
Accessibility standards
None or don’t know
Description of accessibility
We verify compatibility with assistive technologies including screen-readers, browser-zoom, high‑contrast modes, and keyboard‑only navigation. Feedback has driven improvements such as clearer text alternatives, improved table-labelling, and more consistent heading structures for screen‑reader use. Each release, including accessibility‑specific updates, is validated through structured QA-testing.
In the upcoming year, we plan to implement full keyboard navigation across our product and will validate interaction logic through usability-testing to ensure alignment with WCAG 2.2-standards.
All feedback informs updates to shared interface components, ensuring consistency across products. We are expanding accessibility testing and periodic audits to keep improving, evidence‑based, and focused on public‑sector user needs.
Accessibility testing
We take a structured, iterative approach to accessibility testing, combining formal internal testing. Each release, including accessibility‑specific updates, is validated against our internal QA scripts. We also verify compatibility with commonly used assistive technologies such as screen readers, browser zoom, high‑contrast modes, and keyboard‑only navigation. Feedback has led to improvements including enhanced text for visual elements, improved table labelling, and more consistent heading structures to support screen‑reader navigation. In the upcoming year, we plan to implement full keyboard navigation across the product. Once delivered, we will validate the interaction logic through usability testing to ensure alignment with WCAG 2.2 keyboard navigation standards. All feedback informs updates to our shared interface components to ensure consistency and continuous improvement. Looking ahead, we are expanding our approach to accessibility testing and periodic audits, ensuring our accessibility enhancements remain ongoing, evidence‑based, and centred on the needs of public‑sector users.
API
Yes
What users can and can't do using the API
The system provides broad, secure access to underlying data outputs and reports. Through our API, Trusts can connect BI environments (e.g. Power-BI) directly to the Solution’s output database, enabling automated refreshes and deeper analysis. Although extensive in‑platform analytics are included, the API allows scheduled extractions (daily if required) into the Trust’s Data Warehouse for downstream reuse. Scope (what users can do): Users can ingest data via API endpoints supporting file uploads (DataConnect API), FHIR‑based clinical retrieval, and system‑to‑system integrations. All API interactions require time‑limited bearer tokens and follow structured ingestion pipelines. Users can also securely extract curated gold‑level datasets from the Data Lake for use in BI-tools (Power-BI, Tableau) or for local Data Warehouse. Extracts can be scheduled at any frequency, including daily. Boundaries (what users cannot do): Users cannot access or modify underlying infrastructure, databases, orchestration workflows, or internal processing logic (e.g., MapData, ValiData, Contract definitions). Governance, validation, and data‑residency rules cannot be bypassed. Access to raw bronze data is not permitted. Risk controls (security and permissions): API access uses API keys and OAuth2.0 tokens encrypted with TLS 1.2+. Role‑based authorisation ensures strict tenant‑level isolation. IP whitelisting, MFA, full audit logging, and time‑limited tokens provide additional security and accountability.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
LOGEX Costing provides extensive configurability and flexibility, enabling users to tailor the platform to their organisation’s specific requirements and structure. Users can create custom reports and analytics pages, allowing for a deep dive into data relevant to their team. These analytics may remain private or be shared with colleagues or departments, supporting collaborative insights and data-driven decisions. Administrators can set granular access levels for each user, controlling permissions based on information sensitivity and ensuring team members only access data and features pertinent to their roles, thereby enhancing both governance and security. Detailed data snapshots can be exported from LOGEX Costing for smooth integration with BI environments, supporting broader organisational analysis. The platform also facilitates unlimited scenario planning, allowing any situation to be modelled as required. Organisations are able to customise e.g. overhead allocations, cost-to-product allocations, resource definitions and configure data mapping to reflect internal structures and workflows, ensuring LOGEX Costing aligns with operational needs and strategic goals. With dedicated consultants and adaptable service options, clients receive ongoing expert support, guaranteeing that the platform continues to deliver value as requirements evolve.

Scaling

Independence of resources
Our service is architected so each organisation operates in a logically isolated environment, preventing one buyer’s activity from impacting another. Workloads run in separate namespaces and compute pools, with strict resource limits to avoid contention. Capacity is continuously monitored, and our cloud infrastructure scales automatically during peak demand to maintain performance. If usage increases suddenly, additional compute and storage resources are provisioned in real time. This ensures predictable performance, professional operation, and full assurance that demand from one user cannot degrade another’s experience.

Analytics

Service usage metrics
Yes
Metrics types
LOGEX provides detailed audit and activity logs for transparency and security. Metrics include user account actions (creation, modification, deletion), changes to access rights, and all login attempts (successful and failed) with timestamps and IP addresses. General user interactions with back-end systems and data changes, such as cost allocations, are also logged. These logs are continuously updated and accessible to authorised users for monitoring and compliance. Export options are available for reporting and analysis.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
Less than once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with SSAE-18 / ISAE 3402
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data at any time through the built‑in export functionality, which allows them to extract all datasets, outputs, reports, and validation results available in the platform. Exports are provided in common, non‑proprietary formats such as CSV and XLSX, ensuring full buyer control and no vendor lock‑in. Data exports are initiated directly by authorised users from within the interface, without requiring technical skills or additional tools. If needed, our support team can assist with planning or validating the export. There are no restrictions on when data can be exported, and all extraction steps are fully documented.
Data export formats
  • CSV
  • Other
Other data export formats
XLSX
Data import formats
  • CSV
  • Other
Other data import formats
XLSX

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
We guarantee a robust 99.95% service availability, measured and reported monthly to ensure transparency and accountability. This commitment excludes planned maintenance windows, which are carefully scheduled outside peak operational hours and communicated to customers well in advance to minimise any potential disruption. Our availability targets are not only realistic but are also underpinned by continuous, automated monitoring of service performance against agreed Service Level Agreements (SLAs). These SLAs are tailored to each customer’s specific requirements, ensuring that expectations and contractual obligations are clearly defined from the outset. In the event of unexpected incidents or outages, our expert support team is on hand to provide immediate assistance, working swiftly to restore full service and keep clients informed every step of the way. We don't offer any service credits or compensation in case the availability does not meet the 99.95% threshold. Importantly, there are no hidden exclusions, our approach is fully transparent, and customers retain full ownership of their data at all times.
Approach to resilience
LOGEX Costing is hosted on resilient Microsoft Azure in UK regions, ensuring data residency and high availability. We architect the service with segmented, containerised components and redundant paths to minimise single points of failure across ingestion, processing, and exports. Data is protected by encryption in transit (TLS 1.2+) and at rest (AES‑256); access is enforced through MFA, IP allow‑listing, and granular role‑based permissions. We continuously monitor capacity, performance, security and data pipelines, with proactive alerting and comprehensive audit logging. Backups run daily (differential) and weekly (full), with periodic hourly backups during peak processing; restores are tested regularly. If something goes wrong, our ISO 27001‑aligned incident response and business continuity procedures trigger rapid containment, investigation, customer communication and recovery, including failover to secondary UK locations where appropriate. Resilience is reviewed and improved through automated tests in acceptance before promotion to production, annual independent penetration testing, and recurring external audits (ISO 27001, Cyber Essentials Plus, NHS DSPT). Our design ensures the service is professionally operated, failures are anticipated and managed, and recovery is planned (not reactive) so buyers can rely on consistent availability and trustworthy outputs.
Outage reporting
LOGEX Costing uses continuous, automated monitoring across infrastructure, application, and data pipelines to detect anomalies and service degradation in real time. Alerts are triaged by our 24/7 operations team, and an outage is confirmed within minutes through diagnostic checks. Once verified, designated customer contacts receive prompt notification within 15 minutes via email and, where agreed, through the service portal. Initial communication includes the nature of the issue, affected components, estimated resolution time, and any immediate mitigation steps. For longer outages, we provide regular updates at agreed intervals, detailing progress, actions taken, and revised timelines. Planned maintenance is scheduled outside core hours (07:00–19:00, Monday to Friday, excluding English Bank Holidays) and communicated at least five working days in advance to minimise disruption. All outages, planned or unplanned, are documented in service reports and reviewed internally. Post incident reviews are conducted, and summaries are shared with customers, outlining root cause, corrective actions, and improvements to prevent recurrence. This structured approach ensures prompt notification, clear and ongoing communication, and professional handling throughout.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is limited to authorised administrators only and enforced through multi-factor authentication (MFA), unique credentials, and IP allow‑listing. Permissions follow strict role-based access control, segregating admin, super-user, and standard roles to uphold least-privilege principles. Access is granted via a documented approval workflow and revoked immediately upon role change or termination. Support channels are restricted to vetted personnel, with identity verification before any action. All access activities are logged and reviewed regularly, supported by automated alerts for anomalies. Quarterly audits and continuous monitoring ensure sensitive functions remain secure and controlled at all times.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
LOGEX operates under a formal Information Security Management System certified to ISO 27001, complemented by Cyber Essentials Plus and full compliance with the NHS Data Security & Protection Toolkit (registration 8K150). We are registered with the UK ICO (ZB512795), ensuring adherence to UK GDPR and all relevant data protection requirements. Policies cover access control, encryption, secure development, incident management, and data handling. These policies are documented, version-controlled, and reviewed at least annually, or sooner if regulations or risks change, by our appointed Information Security Officer, who holds overall accountability. Access to systems and data follows strict role-based permissions, enforced through MFA and least-privilege principles, with regular audits to maintain integrity. Staff awareness is embedded through mandatory onboarding training, annual refreshers, and targeted campaigns on emerging threats. Security incidents are managed via a formal process aligned with ISO 27001: detection, containment, investigation, remediation, and customer notification. Post-incident reviews drive continuous improvement. Compliance is validated through internal audits, external certification, penetration testing, and vulnerability scanning. Encryption (AES-256 at rest, TLS 1.2+ in transit) and segregation of environments ensure practical protection, not just policy.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Configuration and change management follow a formal process to ensure security and minimise disruption. All changes are reviewed and approved by a Change Control Board (CCB), including security representation, and only authorised personnel may implement them. Each change is documented and tracked in a ticketing system for auditability. Service components are recorded in a central configuration management database and monitored throughout their lifecycle. Updates are scheduled during maintenance windows and communicated in advance. Emergency changes follow an expedited but controlled, security‑reviewed process. Under ISAE control #2, we meet requirements to inform users of new data versions through a defined SOP.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We identify vulnerabilities through continuous automated scanning, software composition analysis, and scheduled penetration tests. Our dedicated security team monitors threat intelligence feeds and vendor advisories to stay ahead of emerging risks. Critical vulnerabilities trigger immediate patching under emergency change control; all other updates follow a defined two-week release cycle. Fixes are verified through automated regression tests and peer review before deployment. Ownership rests with our Information Security Officer, supported by DevSecOps engineers. Serious vulnerabilities invoke our ISO 27001-aligned incident response plan, including rapid containment, customer notification, and post-remediation validation to ensure timely, repeatable, and compliant risk mitigation.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We implement continuous protective monitoring using a web application firewall, intrusion detection, and SIEM tools to track traffic, authentication events, configuration changes, and data access patterns. Security-related events (such as failed logins, privilege escalations, and anomalous API calls) generate automated alerts reviewed by our 24/7 security team. Incidents are triaged by severity and critical issues are addressed within minutes under ISO 27001-aligned procedures. All activity is logged for audit and forensic analysis. Monitoring rules and thresholds are reviewed quarterly and enhanced based on threat intelligence, penetration test findings, and lessons learned, ensuring early detection, clear ownership, and continuous improvement.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Clients/Users can report incidents through various support channels (e.g. email/phone) to our support-team. Additionally, incidents are identified through continuous monitoring and staff reporting, then logged in our secure ticketing system for full traceability. Critical issues are escalated immediately to our Information Security Officer and response-team. Affected customers are notified within 24 hours via email and (if urgent) phone, including details of impact, mitigation, and expected resolution time. Resolution follows ISO 27001-aligned procedures: containment, investigation, remediation, and verification. Post-incident reviews capture root cause and lessons learned, driving policy updates and process improvements to prevent recurrence and ensure transparent, timely communication throughout.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We can provide a two‑week interactive demo environment of the LOGEX Costing tool. This general, limited‑functionality environment offers a hands‑on experience of key features and provides a clear, practical impression of the product’s value and usability.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Tuesday 7 January 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
757de5ec-8158-4151-ba9b-660d622dc1f2
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
878f7d48-8425-4f78-a2b0-a948d4aa0cc5
Other security certifications
Yes
Any other security certifications
  • Data Protection Registration Certificate (ICO)
  • NHS Data Security and Protection Toolkit

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at feico.ulrici@logex.com. Tell them what format you need. It will help if you say what assistive technology you use.