Envelope MIS: Post 16 Education
Advanced cloud MIS ensuring DfE compliance via FIS-integrated validation. Automates ILR returns, funding calculations (AEB/Bootcamps), and audit evidence storage. Features real-time pivot reporting, BKSB assessment integration, and flexible enrolment. Built on secure architecture with OpenAPI connectivity to streamline college administration.
Features
- FIS-integrated ILR schema validation for accurate R1-R14 returns.
- Automated funding calculations for ASF, Loans, and Bootcamps.
- Audit workflow with secure AWS S3 digital evidence storage.
- Multi-channel enrolment with integrated payment gateway support.
- Real-time interactive dashboards for finance, attendance, and ILR.
- Curriculum tools for efficient room, tutor, and resource allocation.
- Learner progress tracking with BKSB, RARPA, and internal tools.
- Built-in CRM via Gov.UK Notify with automated triggers.
- Secure architecture featuring MFA, RBAC, and data encryption.
- OpenAPI 3.0 REST API for Moodle and finance integration.
Benefits
- Guarantees accurate DfE returns through rigorous schema validation.
- Maximises income by correctly calculating complex funding models.
- Streamlines audit compliance with instantly retrievable digital evidence.
- Increases learner uptake with flexible registration and instant payments.
- Enables data-driven decisions via real-time reporting and visualization.
- Optimises resource utilisation, preventing room and tutor clashes.
- Enhances learner outcomes by unifying attendance and progress data.
- Reduces dropouts through automated, timely communication triggers.
- Protects sensitive data with industry-standard security controls.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 3 9 6 1 8 3 2 6 7 1 7 2 1 7
Contact
EPACT LTD
Akam Rahimi
Telephone: +44 333 339 6626
Email: info@epact.app
About the service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Education
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- N/a
- System requirements
-
- Modern web browser (Chrome, Edge, Firefox, or Safari).
- Stable internet connection for real-time cloud access.
- JavaScript enabled for dynamic fee calculation and interface.
- Cookies enabled for secure session and CSRF protection.
- Valid email address for user notifications and alerts.
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 1 working day
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support Levels All customers receive Standard Support as part of the service. This includes:
Direct access to technical and functional support via email and our support ticketing system.
Availability:
UK business hours (Monday to Friday, 09:00–17:00, excluding public holidays).
Scope:
Incident resolution, software fixes, configuration guidance, and general service use queries.
Cost Standard Support is included in the annual licence fee at no extra cost.
We do not provide a dedicated Technical Account Manager. However, our support team comprises product specialists who provide expert guidance on configuration and deployment. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Onboarding & Discovery
We initiate the engagement with consultative discovery meetings to fully understand your specific operational requirements. Our team collaborates with stakeholders to configure the system, implementing necessary customisations, workflow settings, and branding to ensure the platform fits your organisation from day one.
Data Migration
Transitioning from legacy systems is fully supported by our technical team. We assist with the planning, mapping, and importation of existing data (such as learner records and course history) into Envelope, ensuring data integrity and continuity.
Training
We provide flexible training options tailored to your staff's needs:
Online Training
Live, interactive remote sessions delivered via Teams or Zoom.
Onsite Training
In-person workshops delivered at your campus or offices for hands-on guidance.
Documentation
All users have access to comprehensive digital manuals and user guides. These resources provide step-by-step instructions for key workflows, ensuring staff can confidently navigate the system independently. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
Self-Service Export
Users retain full ownership of their data and can extract key datasets at any time during the contract. The system includes built-in bulk export tools, allowing authorised staff to download comprehensive reports (including learner details, financial records, and ILR data) in standard, machine-readable formats such as CSV and Excel.
End of Contract
Migration Upon contract termination, we provide a full, managed exit service to ensure a smooth transition to your new provider. Our technical team performs a complete extraction of all database tables, converting them into a structured set of CSV files. This comprehensive data package is transferred to the client via a secure, encrypted file transfer method.
Data Destruction
Once the client has confirmed successful receipt and validation of the exported data, we initiate our secure data destruction protocol. All client data is permanently purged from our live production environments, and all associated backups are securely destroyed in compliance with GDPR and our data retention policies. - End-of-contract process
-
Included in the price
At the end of the contract, we provide a fully managed exit service at no extra cost. This standard offboarding package includes:
- Extraction of all database records (learners, financials, ILR data) and stored documents into structured CSV files.
- Encrypted handover of the data package to the client.
- Permanent deletion of all client data from our live servers and backups upon confirmation of receipt, in compliance with GDPR.
Additional costs
If you require bespoke technical assistance beyond the standard data export, this is available as an additional service. These requirements are charged at the normal hourly rate. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
O Clear headings, consistent layout, and predictable sections
o Sufficient color contrast and readable font sizes
o Consistent terminology and predictable layouts
o Step-by-step guidance with clear outcomes
o Acronyms and technical terms are explained where used
o Logical reading and tab order
it supports accessibility features that help meet aspects of WCAG (like readable structure, contrast, keyboard navigation), and many basic accessibility best practices are followed by default.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
-
1. Web Browser Interface: A secure, responsive portal compatible with Chrome, Edge, Firefox, and Safari. It requires no installation and works across desktops, tablets, and mobiles. The interface features role-based dashboards, interactive analytics, and intuitive wizards to simplify complex compliance tasks.
2. REST API: A documented OpenAPI 3.0 interface for technical integration. This allows secure, automated data exchange with external systems using standard JSON, ensuring your MIS acts as a central source of truth without manual data entry. - Accessibility standards
- None or don’t know
- Description of accessibility
-
Key accessibility features include:
Keyboard Navigation:
All menus, forms, and interactive elements are fully operable using keyboard shortcuts, requiring no mouse interaction.
Screen Reader Support:
The interface uses semantic HTML and ARIA labels to ensure compatibility with standard screen readers (e.g., JAWS, NVDA, VoiceOver).
Visual Adjustments:
The design supports browser-based text resizing (up to 200%) without breaking the layout and adheres to compliant colour contrast ratios for users with visual impairments.
Responsiveness:
The layout automatically adapts to different devices and orientations. - Accessibility testing
-
To date, accessibility testing has been conducted internally by our development team using industry-standard assistive tools.
We validate compliance against WCAG 2.1 A using:
Automated Audits:
Google Lighthouse and Axe to verify colour contrast and ARIA tagging.
Screen Readers:
Internal simulation using NVDA and VoiceOver to check semantic structure.
Keyboard Navigation:
Manual verification of tab-indexing and focus states.
We have not yet conducted trials with external user groups but are committed to incorporating feedback from native users of assistive technology in our next major release cycle. - API
- Yes
- What users can and can't do using the API
-
Users can securely connect external applications (such as college websites or course directories) to the service. Through the API, users can automatically retrieve live configuration data, including course catalogues, delivery locations, and approved payment gateway settings. This ensures external systems always display accurate, up-to-date course information without manual synchronisation.
Making Changes The API enables real-time data capture and transaction processing. Users can:
Register Learners: Push student enrolment data (personal details, funding eligibility) directly from external web forms into the MIS.
Process Financials:
Trigger automated fee calculations based on learner status and update payment records instantly when external transactions occur.
The API is designed for data integration and capture, not system administration.
Administration:
Users cannot manage staff accounts, create new courses, or configure funding rules via the API; these tasks require the main web interface.
Data Restrictions:
Course content is read-only to ensure version control.
Workflow:
Users cannot withdraw students or process refunds programmatically.
Security:
Connections require daily automated re-authentication, ensuring high security for sensitive learner data. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Branding: White-label the learner portal by uploading logos, headers, and configuring contact details.
Communications: Edit automated SMS and email templates (e.g., enrolment confirmations, attendance reminders) using dynamic merge fields.
Operations: Define bespoke course categories, delivery locations, room inventories, and academic term dates.
Finance: Configure specific payment gateway credentials (e.g., Stripe, GOV.UK Pay) and default fee policies.
Reporting: Build and save personal report views using the interactive pivot tools to filter by specific funding streams or cohorts.
Customisation is self-service via the Dashboard. Intuitive configuration menus allow authorised users to toggle features, edit text, or upload assets using simple forms without requiring technical support or coding.
Super Admins retain full control over system-wide settings, financial integrations, and branding.
Scaling
- Independence of resources
-
The service is delivered using a multi-tenant architecture designed to ensure fair and consistent performance for all users. System resources are actively monitored and managed to prevent individual users or organisations from negatively impacting others.
The service uses capacity management, load balancing and performance monitoring to manage demand across tenants.
Where appropriate, usage controls and permissions are applied at tenant and user level to manage intensive operations and protect overall service performance. This ensures that all customers experience a stable and reliable service regardless of the activity of other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide comprehensive real-time metrics across three key areas:
1. Business Intelligence Dashboards track enrolment KPIs, learner demographics, attendance trends, and financial performance (revenue, cost-per-student, and contribution margins).
2. Compliance & Audit Monitors ILR data health, validation errors, and funding claims. A granular audit trail logs every data modification (User, Timestamp, Old/New Value) for full accountability.
3. System Activity Tracks API usage, user activity, and communication delivery rates (SMS/Email).
All metrics are accessible via interactive dashboard and charts. Data can be exported instantly to CSV/Excel or retrieved via API for external BI integration. - Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Users can independently export their data at any time via the secure web interface. All system reports, learner records, and financial data can be exported into open, non-proprietary formats (specifically CSV and Excel) for immediate use in other applications.
For automated or high-volume data extraction, the service provides a REST API (JSON). This allows external systems (such as BI tools or Finance software) to programmatically retrieve data without manual intervention.
In addition to self-service options, a full database export (CSV) is provided as part of the standard end-of-contract offboarding process to ensure seamless transition to alternative suppliers. - Data export formats
-
- CSV
- Other
- Other data export formats
- JSON via AP
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee a service availability of 99.9% during standard service hours, calculated on a calendar monthly basis. This excludes pre-notified scheduled maintenance windows, which are typically conducted outside of core UK business hours to minimise disruption.
Service Level Agreement (SLA) Our platform is hosted on resilient cloud infrastructure (e.g., AWS/Azure) with automated failover to ensure continuous operation. Availability is monitored 24/7/365. "Unavailability" is defined as the inability of all users to access the core application due to a fault within our control.
Compensation If we fail to meet the guaranteed availability levels in any given month, customers are eligible for Service Credits towards future billing. Credits are calculated as a percentage of the monthly subscription fee equivalent:
99.0% – 99.9%: 2% credit
95.0% – 98.9%: 5% credit
Below 95.0%: 10% credit
Claims must be submitted within 30 days of the incident via the support portal. - Approach to resilience
-
Our architecture spans a minimum of two physically isolated datacentres to protect against site-level failures.
We utilise managed infrastructure ensuring automatic OS patching and maintenance by AWS. AWS datacentres are compliant with ISO 27001, SOC 1/2/3. The system is designed for "redundancy by default" to eliminate single points of failure. Our services run on auto-scaling containers across multiple zones. Health checks occur every 30 seconds; if an instance fails, traffic is automatically rerouted by Load Balancers.
We use RDS MariaDB with Multi-AZ synchronous replication. In the event of a primary database failure, the system automatically fails over to a standby replica within 60–120 seconds.
Continuous replication combined with daily snapshots. Retention is configurable (up to 365 days via AWS Backup). S3 versioning protects against accidental deletion, backed by daily snapshots. All data is encrypted at rest using AWS KMS and in transit via TLS 1.2+.
We maintain Business Continuity and Disaster Recovery plans. We conduct quarterly backup verification and annual full disaster recovery simulations. Our standard Recovery Time Objective (RTO) is 4 hours, and Recovery Point Objective (RPO) is 1 hour. Procedures are in place for complete AZ failure (automatic recovery) and catastrophic region failure (manual failover). - Outage reporting
-
We provide a real-time public status dashboard hosted by UptimeRobot. This page displays the current operational status of the service, response time metrics, and historical uptime data. This allows users to independently verify system health at any time without needing to contact the helpdesk.
We provide proactive communication regarding service interruptions. In the event of a confirmed outage or significant degradation, email alerts are sent immediately to all registered system administrators. These notifications include an incident summary, expected resolution time, and regular updates until the service is fully restored.
Our infrastructure is monitored 24/7 using a combination of AWS CloudWatch (internal server health) and UptimeRobot (external synthetic monitoring). If UptimeRobot detects that the service is unreachable from the public internet, it triggers immediate alerts to our engineering team to begin rapid triage.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access is strictly controlled via Role-Based Access Control (RBAC) and mandatory Multi-Factor Authentication. We enforce the Principle of Least Privilege, ensuring users only possess permissions necessary for their specific role (e.g., Tutor vs. Finance). All sessions are encrypted via TLS 1.2+ with automatic inactivity timeouts, and every administrative action is logged in a tamper-evident audit trail.
Support requests are only accepted from pre-approved, authorised contacts. Our technical staff access client data strictly on a temporary, "need-to-know" basis solely to resolve active incidents. All internal access is logged, time-bound, and reviewed quarterly to ensure compliance with our security policies. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
We maintain a comprehensive ISMS aligned with ISO/IEC 27001:2022, comprising 20 formal policies covering Access Control, Risk Management, Incident Response, and GDPR.
Managing Director holds ultimate accountability and conducts quarterly security reviews. The also manage day-to-day operations, risk assessments, and internal audits.
Data Protection Officer (DPO) oversees GDPR compliance and breach notifications.
Technical team are responsible for secure development and infrastructure maintenance.
We ensure adherence to policies through:
Technical Enforcement:
We use AWS Security Hub and AWS Config to automatically audit configurations against CIS Benchmarks. Access is restricted via strict Least Privilege and mandatory MFA.
Governance:
Quarterly management reviews and annual internal audits verify control effectiveness against our Risk Register.
People:
All staff complete mandatory annual security training and must sign policy acknowledgements.
Monitoring:
24/7 threat detection via AWS GuardDuty and CloudTrail logging ensures full auditability of all user actions. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- \
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- \
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- \
- Incident management type
- Undisclosed
- Incident management approach
- \
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 68e27745-3447-4306-9efe-64a3404c2fae
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Working conditions which promote an inclusive working environment and promote retention and progression
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition