Skip to main content

Help us improve the Digital Marketplace - send your feedback

EPACT LTD

Envelope MIS: Post 16 Education

Advanced cloud MIS ensuring DfE compliance via FIS-integrated validation. Automates ILR returns, funding calculations (AEB/Bootcamps), and audit evidence storage. Features real-time pivot reporting, BKSB assessment integration, and flexible enrolment. Built on secure architecture with OpenAPI connectivity to streamline college administration.

Features

  • FIS-integrated ILR schema validation for accurate R1-R14 returns.
  • Automated funding calculations for ASF, Loans, and Bootcamps.
  • Audit workflow with secure AWS S3 digital evidence storage.
  • Multi-channel enrolment with integrated payment gateway support.
  • Real-time interactive dashboards for finance, attendance, and ILR.
  • Curriculum tools for efficient room, tutor, and resource allocation.
  • Learner progress tracking with BKSB, RARPA, and internal tools.
  • Built-in CRM via Gov.UK Notify with automated triggers.
  • Secure architecture featuring MFA, RBAC, and data encryption.
  • OpenAPI 3.0 REST API for Moodle and finance integration.

Benefits

  • Guarantees accurate DfE returns through rigorous schema validation.
  • Maximises income by correctly calculating complex funding models.
  • Streamlines audit compliance with instantly retrievable digital evidence.
  • Increases learner uptake with flexible registration and instant payments.
  • Enables data-driven decisions via real-time reporting and visualization.
  • Optimises resource utilisation, preventing room and tutor clashes.
  • Enhances learner outcomes by unifying attendance and progress data.
  • Reduces dropouts through automated, timely communication triggers.
  • Protects sensitive data with industry-standard security controls.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@epact.app. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 3 9 6 1 8 3 2 6 7 1 7 2 1 7

Contact

EPACT LTD Akam Rahimi
Telephone: +44 333 339 6626
Email: info@epact.app

About the service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Education
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
N/a
System requirements
  • Modern web browser (Chrome, Edge, Firefox, or Safari).
  • Stable internet connection for real-time cloud access.
  • JavaScript enabled for dynamic fee calculation and interface.
  • Cookies enabled for secure session and CSRF protection.
  • Valid email address for user notifications and alerts.

User support

Email or online ticketing support
Yes
Support response times
Within 1 working day
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 A
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support Levels All customers receive Standard Support as part of the service. This includes:

Direct access to technical and functional support via email and our support ticketing system.

Availability:
UK business hours (Monday to Friday, 09:00–17:00, excluding public holidays).

Scope:
Incident resolution, software fixes, configuration guidance, and general service use queries.

Cost Standard Support is included in the annual licence fee at no extra cost.

We do not provide a dedicated Technical Account Manager. However, our support team comprises product specialists who provide expert guidance on configuration and deployment.
Support available to third parties
No

Onboarding and offboarding

Getting started
Onboarding & Discovery
We initiate the engagement with consultative discovery meetings to fully understand your specific operational requirements. Our team collaborates with stakeholders to configure the system, implementing necessary customisations, workflow settings, and branding to ensure the platform fits your organisation from day one.

Data Migration
Transitioning from legacy systems is fully supported by our technical team. We assist with the planning, mapping, and importation of existing data (such as learner records and course history) into Envelope, ensuring data integrity and continuity.

Training
We provide flexible training options tailored to your staff's needs:

Online Training
Live, interactive remote sessions delivered via Teams or Zoom.

Onsite Training
In-person workshops delivered at your campus or offices for hands-on guidance.

Documentation
All users have access to comprehensive digital manuals and user guides. These resources provide step-by-step instructions for key workflows, ensuring staff can confidently navigate the system independently.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Self-Service Export
Users retain full ownership of their data and can extract key datasets at any time during the contract. The system includes built-in bulk export tools, allowing authorised staff to download comprehensive reports (including learner details, financial records, and ILR data) in standard, machine-readable formats such as CSV and Excel.

End of Contract
Migration Upon contract termination, we provide a full, managed exit service to ensure a smooth transition to your new provider. Our technical team performs a complete extraction of all database tables, converting them into a structured set of CSV files. This comprehensive data package is transferred to the client via a secure, encrypted file transfer method.

Data Destruction
Once the client has confirmed successful receipt and validation of the exported data, we initiate our secure data destruction protocol. All client data is permanently purged from our live production environments, and all associated backups are securely destroyed in compliance with GDPR and our data retention policies.
End-of-contract process
Included in the price
At the end of the contract, we provide a fully managed exit service at no extra cost. This standard offboarding package includes:

- Extraction of all database records (learners, financials, ILR data) and stored documents into structured CSV files.

- Encrypted handover of the data package to the client.

- Permanent deletion of all client data from our live servers and backups upon confirmation of receipt, in compliance with GDPR.

Additional costs
If you require bespoke technical assistance beyond the standard data export, this is available as an additional service. These requirements are charged at the normal hourly rate.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
O Clear headings, consistent layout, and predictable sections
o Sufficient color contrast and readable font sizes
o Consistent terminology and predictable layouts
o Step-by-step guidance with clear outcomes
o Acronyms and technical terms are explained where used
o Logical reading and tab order

it supports accessibility features that help meet aspects of WCAG (like readable structure, contrast, keyboard navigation), and many basic accessibility best practices are followed by default.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
1. Web Browser Interface: A secure, responsive portal compatible with Chrome, Edge, Firefox, and Safari. It requires no installation and works across desktops, tablets, and mobiles. The interface features role-based dashboards, interactive analytics, and intuitive wizards to simplify complex compliance tasks.

2. REST API: A documented OpenAPI 3.0 interface for technical integration. This allows secure, automated data exchange with external systems using standard JSON, ensuring your MIS acts as a central source of truth without manual data entry.
Accessibility standards
None or don’t know
Description of accessibility
Key accessibility features include:

Keyboard Navigation:
All menus, forms, and interactive elements are fully operable using keyboard shortcuts, requiring no mouse interaction.

Screen Reader Support:
The interface uses semantic HTML and ARIA labels to ensure compatibility with standard screen readers (e.g., JAWS, NVDA, VoiceOver).

Visual Adjustments:
The design supports browser-based text resizing (up to 200%) without breaking the layout and adheres to compliant colour contrast ratios for users with visual impairments.

Responsiveness:
The layout automatically adapts to different devices and orientations.
Accessibility testing
To date, accessibility testing has been conducted internally by our development team using industry-standard assistive tools.

We validate compliance against WCAG 2.1 A using:

Automated Audits:
Google Lighthouse and Axe to verify colour contrast and ARIA tagging.

Screen Readers:
Internal simulation using NVDA and VoiceOver to check semantic structure.

Keyboard Navigation:
Manual verification of tab-indexing and focus states.

We have not yet conducted trials with external user groups but are committed to incorporating feedback from native users of assistive technology in our next major release cycle.
API
Yes
What users can and can't do using the API
Users can securely connect external applications (such as college websites or course directories) to the service. Through the API, users can automatically retrieve live configuration data, including course catalogues, delivery locations, and approved payment gateway settings. This ensures external systems always display accurate, up-to-date course information without manual synchronisation.

Making Changes The API enables real-time data capture and transaction processing. Users can:

Register Learners: Push student enrolment data (personal details, funding eligibility) directly from external web forms into the MIS.

Process Financials:
Trigger automated fee calculations based on learner status and update payment records instantly when external transactions occur.

The API is designed for data integration and capture, not system administration.

Administration:
Users cannot manage staff accounts, create new courses, or configure funding rules via the API; these tasks require the main web interface.

Data Restrictions:
Course content is read-only to ensure version control.

Workflow:
Users cannot withdraw students or process refunds programmatically.

Security:
Connections require daily automated re-authentication, ensuring high security for sensitive learner data.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Branding: White-label the learner portal by uploading logos, headers, and configuring contact details.

Communications: Edit automated SMS and email templates (e.g., enrolment confirmations, attendance reminders) using dynamic merge fields.

Operations: Define bespoke course categories, delivery locations, room inventories, and academic term dates.

Finance: Configure specific payment gateway credentials (e.g., Stripe, GOV.UK Pay) and default fee policies.

Reporting: Build and save personal report views using the interactive pivot tools to filter by specific funding streams or cohorts.

Customisation is self-service via the Dashboard. Intuitive configuration menus allow authorised users to toggle features, edit text, or upload assets using simple forms without requiring technical support or coding.

Super Admins retain full control over system-wide settings, financial integrations, and branding.

Scaling

Independence of resources
The service is delivered using a multi-tenant architecture designed to ensure fair and consistent performance for all users. System resources are actively monitored and managed to prevent individual users or organisations from negatively impacting others.

The service uses capacity management, load balancing and performance monitoring to manage demand across tenants.

Where appropriate, usage controls and permissions are applied at tenant and user level to manage intensive operations and protect overall service performance. This ensures that all customers experience a stable and reliable service regardless of the activity of other users.

Analytics

Service usage metrics
Yes
Metrics types
We provide comprehensive real-time metrics across three key areas:

1. Business Intelligence Dashboards track enrolment KPIs, learner demographics, attendance trends, and financial performance (revenue, cost-per-student, and contribution margins).

2. Compliance & Audit Monitors ILR data health, validation errors, and funding claims. A granular audit trail logs every data modification (User, Timestamp, Old/New Value) for full accountability.

3. System Activity Tracks API usage, user activity, and communication delivery rates (SMS/Email).

All metrics are accessible via interactive dashboard and charts. Data can be exported instantly to CSV/Excel or retrieved via API for external BI integration.
Reporting types
Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can independently export their data at any time via the secure web interface. All system reports, learner records, and financial data can be exported into open, non-proprietary formats (specifically CSV and Excel) for immediate use in other applications.

For automated or high-volume data extraction, the service provides a REST API (JSON). This allows external systems (such as BI tools or Finance software) to programmatically retrieve data without manual intervention.

In addition to self-service options, a full database export (CSV) is provided as part of the standard end-of-contract offboarding process to ensure seamless transition to alternative suppliers.
Data export formats
  • CSV
  • Other
Other data export formats
JSON via AP
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We guarantee a service availability of 99.9% during standard service hours, calculated on a calendar monthly basis. This excludes pre-notified scheduled maintenance windows, which are typically conducted outside of core UK business hours to minimise disruption.

Service Level Agreement (SLA) Our platform is hosted on resilient cloud infrastructure (e.g., AWS/Azure) with automated failover to ensure continuous operation. Availability is monitored 24/7/365. "Unavailability" is defined as the inability of all users to access the core application due to a fault within our control.

Compensation If we fail to meet the guaranteed availability levels in any given month, customers are eligible for Service Credits towards future billing. Credits are calculated as a percentage of the monthly subscription fee equivalent:

99.0% – 99.9%: 2% credit

95.0% – 98.9%: 5% credit

Below 95.0%: 10% credit

Claims must be submitted within 30 days of the incident via the support portal.
Approach to resilience
Our architecture spans a minimum of two physically isolated datacentres to protect against site-level failures.

We utilise managed infrastructure ensuring automatic OS patching and maintenance by AWS. AWS datacentres are compliant with ISO 27001, SOC 1/2/3. The system is designed for "redundancy by default" to eliminate single points of failure. Our services run on auto-scaling containers across multiple zones. Health checks occur every 30 seconds; if an instance fails, traffic is automatically rerouted by Load Balancers.

We use RDS MariaDB with Multi-AZ synchronous replication. In the event of a primary database failure, the system automatically fails over to a standby replica within 60–120 seconds.

Continuous replication combined with daily snapshots. Retention is configurable (up to 365 days via AWS Backup). S3 versioning protects against accidental deletion, backed by daily snapshots. All data is encrypted at rest using AWS KMS and in transit via TLS 1.2+.

We maintain Business Continuity and Disaster Recovery plans. We conduct quarterly backup verification and annual full disaster recovery simulations. Our standard Recovery Time Objective (RTO) is 4 hours, and Recovery Point Objective (RPO) is 1 hour. Procedures are in place for complete AZ failure (automatic recovery) and catastrophic region failure (manual failover).
Outage reporting
We provide a real-time public status dashboard hosted by UptimeRobot. This page displays the current operational status of the service, response time metrics, and historical uptime data. This allows users to independently verify system health at any time without needing to contact the helpdesk.

We provide proactive communication regarding service interruptions. In the event of a confirmed outage or significant degradation, email alerts are sent immediately to all registered system administrators. These notifications include an incident summary, expected resolution time, and regular updates until the service is fully restored.

Our infrastructure is monitored 24/7 using a combination of AWS CloudWatch (internal server health) and UptimeRobot (external synthetic monitoring). If UptimeRobot detects that the service is unreachable from the public internet, it triggers immediate alerts to our engineering team to begin rapid triage.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access is strictly controlled via Role-Based Access Control (RBAC) and mandatory Multi-Factor Authentication. We enforce the Principle of Least Privilege, ensuring users only possess permissions necessary for their specific role (e.g., Tutor vs. Finance). All sessions are encrypted via TLS 1.2+ with automatic inactivity timeouts, and every administrative action is logged in a tamper-evident audit trail.

Support requests are only accepted from pre-approved, authorised contacts. Our technical staff access client data strictly on a temporary, "need-to-know" basis solely to resolve active incidents. All internal access is logged, time-bound, and reviewed quarterly to ensure compliance with our security policies.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
We maintain a comprehensive ISMS aligned with ISO/IEC 27001:2022, comprising 20 formal policies covering Access Control, Risk Management, Incident Response, and GDPR.

Managing Director holds ultimate accountability and conducts quarterly security reviews. The also manage day-to-day operations, risk assessments, and internal audits.

Data Protection Officer (DPO) oversees GDPR compliance and breach notifications.

Technical team are responsible for secure development and infrastructure maintenance.

We ensure adherence to policies through:

Technical Enforcement:
We use AWS Security Hub and AWS Config to automatically audit configurations against CIS Benchmarks. Access is restricted via strict Least Privilege and mandatory MFA.

Governance:
Quarterly management reviews and annual internal audits verify control effectiveness against our Risk Register.

People:
All staff complete mandatory annual security training and must sign policy acknowledgements.

Monitoring:
24/7 threat detection via AWS GuardDuty and CloudTrail logging ensures full auditability of all user actions.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
\
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
\
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
\
Incident management type
Undisclosed
Incident management approach
\
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
68e27745-3447-4306-9efe-64a3404c2fae
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • Plans to engage the contract workforce in deciding the most important workplace issues to address
  • Ensuring new workers are informed of their right to join a trade union
  • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
  • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
  • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas

Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

  • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
Mission: Break down barriers to opportunity

By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

Policy Outcome 6: Employment and training: For those who face barriers to employment

  • Working conditions which promote an inclusive working environment and promote retention and progression
  • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
Mission: Build an NHS fit for the future

That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

  • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
  • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@epact.app. Tell them what format you need. It will help if you say what assistive technology you use.