Equal Experts UK Limited

UX Forms

UXForms is an enterprise-ready cloud platform for webform development that brings user research to the heart of building web-forms. Real-time data helps identify how well forms, design patterns and questions perform, so the effectiveness of changes are measurable. UXForms is perfect for rapid deployment of Coronavirus (COVID-19) pandemic solutions

Features

  • Government Digital Service (GDS) design patterns built-in
  • Conditional and branching form logic
  • Real-time analytics, data and dashboards of online behaviour
  • Complex and programmable form and field validation
  • Extensible and customisable builder via code
  • Can be integrated with any web-facing system
  • Fully internationalised and multilingual; supports UTF-8 throughout
  • Fully testable form design under revision control
  • Proven rapid development of Coronavirus (Covid-19) web solutions
  • Optimise the forms and go live on your own domain

Benefits

  • Publish online web forms quickly and easily
  • Fully conform to GDS’s design and style guide
  • Gather data on effectiveness of form questions
  • Learn which design patterns confuse your users
  • Learn which questions your users find difficult to answer
  • Quickly adapt your form online in response to empirical data
  • Prove complex form behaviour is correct via automated tests
  • Demonstrate a data-driven response to user needs
  • Multiple authors can work concurrently on the same on-line form
  • Rapidly recreate forms in multiple languages via intuitive builder

Pricing

£3,000 a licence a month

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at solutions@equalexperts.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

9 4 4 6 0 3 4 2 6 3 7 3 4 0 2

Contact

Equal Experts UK Limited Louis Abel
Telephone: +44 7968 157766
Email: solutions@equalexperts.com

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
None
System requirements
  • Scala version 2.11 is required to compile form definitions
  • An internet connection is required to compile form definitions

User support

Email or online ticketing support
Email or online ticketing
Support response times
Official support hours are 9am to 5pm, Monday to Friday, within which we promise to respond to questions within 2 hours.
We, of course, aim to respond as quickly as possible even outside these official support times.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
UX Forms' support is available independently on GCloud as UX Forms Consultancy. It provides experienced consultants who can help with all aspects of delivering great forms with UX Forms, whether that's to build and test complex digital forms more quickly than ever before, build integrations between UX Forms and your existing services and APIs or even integrate UX Forms with your internal revision control and build pipelines. Support is charged in accordance with our SFIA Rate Card.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
User documentation is provided.
Additionally customers may take advantage of UX Forms' support services to help them become experts in using UX Forms, quickly and efficiently.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
The definition of each form is created by the customer, so does not require extraction.
End user's answers of completed forms are automatically deleted from UX Forms' platform once they are sent to the client's systems, so no extraction upon the end of the contract is required.
End user's answers of partially completed forms can be provided upon request.
End-of-contract process
Access to UX Forms' services is terminated, and any forms and themes deployed by the customer are un-deployed and taken offline.

End users' answers to incomplete forms will be automatically deleted after the retention period configured by the customer.

There are no additional costs.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None. All features accessible via the desktop web interfaces are accessible via the mobile web interface.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Forms can be deployed and un-deployed through the interface, form author accounts can be managed, and users can view the extensive dashboard statistics provided for each form.
Accessibility standards
None or don’t know
Description of accessibility
Although UX Forms' interface does not meet any formal standard, it has been written with accessibility in mind. It uses semantic html on all pages, as well as degrading gracefully without javascript. A large number of WCAG 2.0's requirements are fulfilled although we have not formally assessed whether we meet all its criteria.
Accessibility testing
No formal testing
API
Yes
What users can and can't do using the API
Every regular action that is possible through the web interface is possible via UX Forms' APIs. Forms can be uploaded and deleted, as can themes. Only user management is restricted for use only via the web interface.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Forms deployed to UX Forms can be customised in almost every conceivable way.
The entire html, css and javascript payload is fully customisable. GDS's GOV.UK elements are provided out of the box and these can be extended and customised to deliver any user interface required.
Validation can be fully customised and it can even integrate with bespoke external systems to verify the user's answers.
Integrations can be written to connect to external, bespoke, systems at multiple points during a form instance's lifecycle, including submitting the completed form's answers back to the customer's own systems.

Scaling

Independence of resources
By leveraging our cloud provider's infrastructure, along with selected open source technologies to keep forms separate from each other, even within the same organisation.

Analytics

Service usage metrics
Yes
Metrics types
The UX Forms dashboard provides detailed data on every aspect of your forms. Track mean completion time, user errors and more to prioritise revisions and hone performance until every field is perfect.
Reporting types
Real-time dashboards

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Up to Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with SSAE-16 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Data sanitisation type
Deleted data can’t be directly accessed
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
UX Forms provides extensive customisation so end user's questions can be submitted to the customer's services as soon as they finish filling in a form. End user data is automatically deleted from UX Forms' service once it has been transmitted to the customer's systems.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • XML
  • JSON
  • A custom format unique to the customer
  • Any format that can be written by software
Data import formats
Other
Other data import formats
UX Forms does not currently support uploading form data

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
As UX Forms is fully customisable, even the way data is protected between the UX Forms' and the buyer's network is customisable. If required, specific connection mechanisms can be implemented with help from UX Forms.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Environments are segregated in to independent Virtual Public Clouds and, within each, services are deployed in to independent subnets.

Availability and resilience

Guaranteed availability
UX Forms will guarantee at least 99.95% uptime during any month.
Approach to resilience
This information is available upon request.
Outage reporting
Via email alerts.

Identity and authentication

User authentication needed
Yes
User authentication
Username or password
Access restrictions in management interfaces and support channels
Only individual, named, users can perform management actions within UX Forms. Actions available to users are controlled via role-based access which, in turn, is managed through UX Forms' dashboard.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Username or password
  • Other
Description of management access authentication
Management can also be performed via APIs, which are authenticated via API keys.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
At least 12 months

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Standards Institute
ISO/IEC 27001 accreditation date
08/05/2017
What the ISO/IEC 27001 doesn’t cover
Our Statement of Applicability is available upon request
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
Yes
Other security certifications
No

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
The Managing Director is accountable for ensuring that appropriate security and compliance controls are identified, implemented and maintained. The Managing Director ensures that:
Risks are managed and reduced in an informed manner;
All applicable legal and regulatory requirements have been identified and that compliance is maintained;
Appropriate resources are provided to implement and maintain the information security management system (ISMS);
All staff sign the information security agreement prior to joining and receive awareness training of all policies during induction, including the consequences of non-compliance.

Our information security policy set is aligned to ISO27001:2013. The Information Security Policy is available upon request.

UX Forms will ensure that:
Information is protected against unauthorised access;
Confidentiality of information is assured;
Integrity of information is maintained;
Regulatory and legislative requirements are met;
Business continuity plans are produced, maintained and tested as appropriate;
Third parties engaged in the support of UX Forms are required to comply with this Policy to support both UX Forms and our clients’ requirements;
Information security requirements are aligned with organisational strategies and objectives in support of both UX Forms and our clients’ expectations;
Information security is managed and continuously improved through a defined ISMS;

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
UX Forms runs a fully documented change management process, certified against ISO/IEC 27001:2013, which is actively reviewed and managed.

All components, including their infrastructure, networking and configuration, are under revision control. They are built, tested and versioned before being deployed through a continuous integration build pipeline.

Every prospective change to every component is assessed by a technical lead, which includes its potential security impact. All components are regularly reviewed against OWASP's secure coding practices.
Vulnerability management type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach
UX Forms regularly checks all of its libraries and dependencies against NIST's National Vulnerability Database and uses an ISO27001:2013 risk-based methodology to assess all threats.

Patches and software updates are treated no differently than any other change to UX Forms' platform and can be deployed via its continuous integration pipeline in minutes.

Information regarding potential threats and security alerts come from a number of sources, including UX Forms' hosting provider and a range of technical news platforms.
Protective monitoring type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach
UX Forms has a defined information security incident policy.
Comprehensive logging of all components is gathered in real time and is analysed to identify potential compromises.
Once an incident has been raised, a thorough investigation is immediately begun to understand its scope and severity. If there is reason to suspect the incident affects Personally Identifiable Information, then UX Forms' Data Protection Officer is informed and appropriate steps taken.
A detailed post-incident review is performed after every incident and its findings analysed to improve UX Forms' processes and practices.
Incident management type
Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach
UX Forms has a defined information security incident policy which sets out how incidents will be reported, managed, tracked and reviewed.

Incidents can be reported by anyone to support@uxforms.com.

UX Forms' incident response capability is not restricted to official support hours.

Full details of an incident affecting a customer will be shared confidentially with that customer.

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Public sector networks

Connection to public sector networks
No

Social Value

Fighting climate change

Fighting climate change

Equal Experts has an Environmental Policy and Roadmap for 2020-25 and our Carbon Reduction Plan is published on our website https://www.equalexperts.com/carbon-reduction-plan/. Our target is net-zero by 2035.

We complete the CCS CAESER (Corporate Assessment of Environmental, Social and Economic Responsibility) and associated assessments annually, most recently in January 2022. From these results, we identify and plan improvements, including improving KPIs and starting awareness training for all consultants and staff. Our goal is to continually improve and update our assessment score annually.

For G-Cloud contracts, we will:
>Build systems making extensive use of cloud services. Most systems we build use automated scaling of resources to ensure we minimise both cost and environmental impact of operation. We aim to migrate to more efficient resources and operational practices as cloud providers introduce them.
>Reduce travel impact
>Support remote working and provide access to tools like Zoom, Lucidchart and Miro to encourage and facilitate this and thereby reduce our carbon footprint. We have written an open-source “Remote Working Playbook” which is available to anyone via our website.

>Reduce the production of waste
>>Develop effective waste management and recycling procedures.
>>Dispose of unavoidable waste in a way to minimise its environmental impact.
>>Have a largely paperless office environment.

> Be as energy efficient as possible
>>Ensure lights are switched off or on automatic sensors, use natural light where possible
>>Ensure office equipment has automatic shutdowns.
>>Review procurement practices to ensure we benefit from any available energy offsets.
>>Ensure heating and cooling systems on premises are energy efficient.

We have reduced our office space significantly during 2020/1, including closing physical offices in Bristol, Lisbon, Sydney and Berlin. In the UK we have offices in Manchester, Leeds and London, allowing us to provide local resources for projects, thus reducing travel.
Covid-19 recovery

Covid-19 recovery

Equal Experts is committed to supporting recovery, focused on providing opportunities in high-growth sectors for those impacted negatively by COVID-19. Where applicable, we will:

>Use focused, unbiased recruitment practices to actively recruit new staff into highly skilled, well-paid roles to support the projects we win across the world.
>Run public meetups and host events for minority groups and people adversely affected by COVID-19, through retraining and return-opportunities, mentoring, development of technical skills, provision of CV and careers guidance, etc.
>Use resources local to our clients’ offices wherever possible. We fully endorse government initiatives to move work to regional hubs outside London to support jobs, economic growth and social values.

We have embraced remote-first practices for many years, actively supporting our clients and workforce to adapt to enforced working patterns when COVID-19 struck. We encourage individuals to choose best working practices and support them by:
>Providing access to alternative safe workplaces for staff who found working from home physically or mentally difficult during lockdown.
>Providing free counselling and advice.
>Defining family-friendly and dignity-at-work policies, encouraging healthy work/life balance.
>Risk-assessing workplaces to ensure COVID-19 secure practices are followed.
>Promoting flexible working patterns.
>Encouraging staff to take regular breaks, exercise, holidays, online team-events.

We anticipate staff will continue to work flexible patterns. As teams return to face-to-face working, we are engaging staff/clients to develop safe, sustainable working practices in offices, including:

>Monitoring/following updated UK Government guidelines for working safely during COVID-19.
>Undertaking health and safety risk assessments on all offices.
>Ensuring social distancing, pre-booked workplaces, regular cleaning and “Hands. Space. Face. Fresh Air” guidelines.
>Working closely with clients, reviewing and developing return-to-office plans/practices
>Adjusting core hours, reducing travel at peak times.
Tackling economic inequality

Tackling economic inequality

ENTREPRENEURSHIP AND TRAINING
For this framework, we will:
>Flow 70% of revenues to our Associate network (small, entrepreneurial businesses).
>Expand EE’s Evolve programme which mentors technology practitioners to become expert consultants.
>Participate in industry programmes, e.g. support AWS’ re:Start programme (part of the Civil Service Exceptions 1 list), offering paid internships to under-represented/disadvantaged groups; support and advise Code4000.org, a charity teaching coding skills to prisoners.
>Provide retraining and return-opportunities, mentoring, development of technical skills which address skills gaps, training through mock-up interviews, provision of CV and careers guidance.
>Onboard/upskill people from low socio-economic backgrounds, e.g. partnering with Sigma Labs (a benefit corporation).
>Where possible, we provide opportunities to employ and develop more people with protected characteristics in new skills relevant to the contract.
>Share knowledge and experience publicly via ExpertTalks and Open-Source Playbooks to develop disadvantaged groups’ skills.
>Partner with leading diverse communities, networks and ambassadors to identify suitable candidates e.g. SigmaLabs, Coding Black Females.
>Continue hosting events for minority groups including 10 Digital Ladies and Women Who Code.

DIVERSE SUPPLY CHAINS
Our partnering model directly supports SMEs and SEs, which we engage as specialist subcontractors. We identify new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals that can participate in our supply chain and those of our clients via:
>Procuring in a fair and open, PCR2015 manner.
>Establishing innovation programmes who identify and onboard new micro businesses.
>Encouraging Suppliers to diversify their supply chain in line with our goal to increase supply chain resilience.
>Increasing supply chain governance using recognised bodies such as sedex.com.
>Measuring and increasing staff characteristics and success in our associate/supplier diversity (e.g. %spend with each supply group across micro, SME, collectives; %of start-up suppliers still in business after three years).
Equal opportunity

Equal opportunity

EQUAL OPPORTUNITIES
Equal Experts has longstanding commitment to advancing diversity, equality and inclusion. We operate in ways that supports clients to deliver their Public Sector Equality duty under section 149 of the Equality Act 2010.

We will continue to:
>Run annual network-wide diversity and inclusion surveys in partnership with EqualPlus.
>Invest in workshops and training to help teams improve safety and inclusion.
>Host events for minority groups, such as 10 Digital Ladies and Women Who Code.
>Provide family-friendly and dignity at work policies – We are UK’s 2nd best place to work (Glassdoor, 2020).
>Continuously evolve recruitment processes to improve diversity, equality and inclusion, and provide unconscious bias training for our recruitment team.
>Engage Druthers, executive search specialists in building inclusive teams, to broaden our team diversity.
>Where possible, provide opportunities to employ and develop more people with protected characteristics in new skills relevant to the contract.
>Support individuals with protected characteristics, e.g. independent consultancy EqualPlus runs annual anonymous psychological safety surveys, supplemented by monthly team-health questionnaires.
>Make appropriate adjustments where practical to support and develop individuals with physical, mental and hidden disabilities.
>Regularly monitor our performance (e.g. Cabinet Office CAESER, B Impact Assessments) to help develop annual improvement plans.

MODERN SLAVERY
Equal Experts is covered by the Modern Slavery Act 2015. Our policy statement is published at https://www.equalexperts.com/modern-slavery-policy/, reviewed annually and updated when necessary. We complete the CCS Modern Slavery assessment annually, most recently in December 2021. Relevant policies, processes and procedures are reviewed annually (e.g. Employee Team Charter, Whistleblowing Policy, Code of Conduct for Suppliers).

We undertake due diligence when considering taking on new suppliers, and regularly review existing suppliers. This includes evaluating modern slavery risks. We are members of Sedex Global and use their services to review our extended supply chains and provide confidence to our clients.
Wellbeing

Wellbeing

HEALTH AND WELLBEING
Equal Experts promotes psychological safety, trust, inclusion and a “grown-up” culture throughout our workforce. We work closely with our clients to support the health and wellbeing of our team members, establishing onboarding practices and developing local team charters to ensure new recruits are welcomed and made to feel safe. We support the six standards of the Mental Health at Work Commitment and the Race at Work Charter.

>We run monthly team-health surveys, using results as a KPI for engagements.
>Equal Plus, an independent consultancy, regularly surveys our people's Psychological Safety. The results are published to our network of staff and suppliers and inform our executive team of potential risks.
>We have inclusive and accessible recruitment and retention practices to ensure people feel valued (Glassdoor ranked us 2nd best place to work in 2020). We offer flexible and remote working and encourage staff to take regular breaks, “Movement Snacks” (workstation exercises), holidays, online team-events.
>We provide awareness training and guidance through our policies, ExpertTalks and playbooks.
>We offer private medical cover for our UK employees and their families, including encouraging exercise and other preventative measures.
>We regularly host public online ExpertTalks on Health and Wellbeing, e.g. “Avoiding Burnout”.

INTEGRATED COMMUNITIES
>We foster an open, inclusive working culture e.g. 'no-blame' retrospectives help us learn from each other's perspectives.
>We hold socials and lean coffee sessions to ensure a welcoming culture that leads to better team bonding and working relationships.
>For physical health we have an annual Walkathon competition for staff, clients and partners, which encourages physical activity and raises money for charity (£45k in 2021).
>We encourage companies in our supply chain to implement measures to improve the physical and mental health and wellbeing of employees and implement standards in the Mental Health at Work commitment.

Pricing

Price
£3,000 a licence a month
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
The free trial grants full access to a non-production instance of UX Forms for 30 days. Any number of form authors, forms and submissions can be deployed, with the sole proviso that they are not for production use.

This trial can be extended at UX Forms' discretion.
Link to free trial
https://forms.aiken.uxforms.com/signup

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at solutions@equalexperts.com. Tell them what format you need. It will help if you say what assistive technology you use.