Skip to main content

Help us improve the Digital Marketplace - send your feedback

CiviQ

OpenConsult: Public Engagement Platform

OpenConsult is a secure, web-based consultation and engagement platform that helps public bodies plan, publish and manage public engagements end-to-end.

Features

  • Wide range of consultation types including questionnaires
  • Consultation response summarising and reporting. AI support also available (optional)
  • Interactive mapping and integration with ArcGIS Online
  • Features to support Planning consultation processes
  • Consultation-level visual dashboard reporting feedback for admins and public
  • Public and Private engagements
  • User response, account history and management pages
  • Easy to publish responses and enable query, sharing, download.
  • Engagement alerts to users
  • Workflow for input of responses received offline

Benefits

  • Publish simple to complex engagements including planning consultations
  • Import any map type
  • Present complex documents in an easy and accessible way
  • Promote early engagement through subscriptions to consultation alerts
  • Consultation content is easily accessible through the response form
  • Easily summarise, categorise and report on consultation responses
  • Easily pull data to MS backend systems
  • Easily publish responses for public viewing, query, download
  • AI support for processing responses with governance
  • Opportunity to explore new approaches to engagement with AI

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@civiq.eu. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 4 5 6 8 3 3 6 8 4 7 9 6 6 8

Contact

CiviQ Vanessa Liston
Telephone: +353861408681
Email: info@civiq.eu

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Other
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
There will be short windows of maintenance time when upgrades, new features, or fixes are rolled out.
System requirements
Customer needs a modern browser to access the platform

User support

Email or online ticketing support
Yes
Support response times
Initial response during working hours within one hour.

Resolution times are as follows:
Critical service outage < 4 hours
High priority issue <8 hours
Normal issue < 2 business days
Low issue <4 business days.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Standard Support is included with an annual subscription.

Hours: Monday–Friday, [09:00–17:00 UK time], excluding public holidays

Channels: Email + support portal

Coverage: Incidents, bug reports, “how-to” queries

Target response times:

P1 (Critical): response within 4 hours

P2 (High): response within 8 hours

P3 (Medium): response within 2 business days

P4 (Low): response within 4 business days

Target resolution approach: workarounds and fixes prioritised by severity and impact
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Online workshops are provided during the onboarding process.
An online support portal is provided with videos, How To guides, FAQs and a User Forum.
A self-training portal is also provided with tasks submitted to CiviQ for review and certification.
Customers also receive direct support in publishing their first engagement.
CiviQ provides a high-quality support service to all customers to ensure their success in using the service.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
Video
End-of-contract data extraction
All data is available by a Customer super user to download at the end of the contract.
End-of-contract process
An off-boarding meeting and access to download all response and user data is included in the price of the contract. Data can be downloaded in excel, PDF, Word and Zip formats. The API can also be used to extract these data.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
There are no differences.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
OpenConsult is accessed through a secured connection using HTTPS protocol. Users sign in to an online portal to configure and manage the service (for example: create and publish engagements and consultations, manage and message users, view responses, and run reports/exports). No software installation is required for standard use.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
OpenConsult is regularly tested with an accessibility expert who provides VPAT reports on the conformance of OpenConsult with accessibility requirements and any improvements required.
API
Yes
What users can and can't do using the API
A private API is available to pull all response data (representations, survey responses, map data) and respondent data to back end systems.

The API only works on a pull basis. There is no option to use the API to make changes to data on the platform.
API documentation
Yes
API documentation formats
  • ODF
  • Other
API sandbox or test environment
Yes
Customisation available
No

Scaling

Independence of resources
Tenant isolation: Each customer’s data is physically separated and stored in own cloud tenant account.

Autoscaling and capacity management: Our service scales horizontally based on load (application instances, workers)

Monitoring and alerting: We continuously monitor latency, error rates, queue depth, CPU/memory, and per-tenant usage. Automated alerts trigger scaling.

Analytics

Service usage metrics
Yes
Metrics types
Engagement volumes at consultation level: number of responses submitted; number of comments per consultation theme/question/chapter.
Audience statistics: metrics provided by Matomo Analytics. Accessed through their dashboard.
Operational metrics: support ticket volumes and response times, time between receiving, approving and publishing representations to consultations.
Reporting types
  • API access
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Administrators can use the platform's export function to export data on responses and user data. Super users only have access to download all response data from the platform.

End-users (public users) of the platform must request a copy of their data from the data controller. CiviQ will support the data controller in providing this information to end-users.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
OpenConsult 99.8% availability.

Service Commitment credits:
Monthly uptime
≤ 99.8% no credit
≤ 95 - 99.8.5% of monthly Fees (pro-rated)
<95%
Outside scheduled maintenance time

Service Request Service Credits
SLA Breach Category

Critical response/resolution delays – P1 & P2 tickets. Threshold per quarter 95%. Credit applied 5% credit of quarterly Fees (pro-rated)

All other tickets and requests P3 & P4. Threshold per quarter 90%. Credit applied - 2% credit of quarterly Fees (pro-rated)
Approach to resilience
Available on request.
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password
  • Other
Other user authentication
Email and password for end users. MFA for administrators. MFA can also be applied for end users. Bot protection ensures users are human.
Access restrictions in management interfaces and support channels
MFA, role-based access, need to know basis, access restricted by assigned teams to engagements.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password
  • Other
Description of management access authentication
SSO

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
No audit information available
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
ISO/IEC 27001 (aligned): We are aligned to ISO/IEC 27001 and operate an information security management approach consistent with ISO 27001 principles (for example: documented security policies and procedures, risk assessment and treatment planning, defined security roles and responsibilities, supplier/security review, incident management, and continual improvement). We are not ISO 27001 certified.
Information security policies and processes
CiviQ operates an information security management approach aligned to ISO 27001 principles.

Key Policies and processes:
• Information Security Policy
• Access Control & Acceptable Use
• Data Handling, Retention & Disposal
• Secure Development & Change Management
• Vulnerability & Patch Management
• Incident Management
• Backup & Recovery / Business Continuity
• Supplier Management
• Other supporting policies

Reporting structure:
• Security owner: the CEO is accountable for information security governance
• Security lead: The CTO maintains controls and reports security status/issues to the CEO.
• All staff and contractors are required to follow policies as a condition of access to systems and data.

Any security concerns are reported immediately to the security lead and escalated to the security owner. They are tracked through to closure.

We ensure policies are followed through measures including, among others:
• AWS-focused controls
• Strong access controls
• Joiner/mover/leaver checklist
• Secure SDLC including peer code reviews, separation of environments
• Vulnerability management
• Logging & auditability
• Backups & restore testing
• Incident response: documented steps, internal escalation path, and learnings from post-incident review to prevent recurrence.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We manage configuration and change through Infrastructure-as-Code and version control. AWS infrastructure is defined in CloudFormation templates stored in Git. Components are traceable via commit history, tagged releases and deployment logs. Application changes are made via pull requests and deployed using GitHub Actions, Each production release is linked to a specific commit.

We use separate environments (e.g., dev/staging/production). Each change is reviewed for security impact. IAM permissions/least privilege, network exposure (security groups/endpoints), secrets handling, logging/auditability and dependency risk are included in the security impact review. Rollbacks use prior releases/templates.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
CiviQ has an automated patch management process integrated into its deployment pipeline. Systems are patched regularly through deployments that use the latest stable images with automated updates. Host systems run update scripts on deployment, containers rebuild with latest packages, and RDS MariaDB receives automatic minor version updates during maintenance windows.

For application-level patches, we monitor security subscriptions and apply updates within our 14-day SLA, testing changes through Dev and Staging environments. Composer audit runs weekly to identify vulnerable dependencies. CiviQ monitors for zero-day vulnerabilities through Drupal security channels, extended support subscriptions, AWS bulletins, and our security team.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
CiviQ operates protective monitoring. A SIEM watches for exploitation attempts in real-time. Rules and correlation are used to generate alerts for events such as brute-force attempts, anomalous admin activity, unexpected configuration or file changes, and indicators of compromise.

Alerts are triaged by trained staff using documented runbooks.

Confirmed incidents follow our incident process: containment, eradication, recovery, and post-incident review (including improvements to controls and alerting).

Security logs and alerts are retained for an agreed period to support investigations and audit requirements.
Incident management type
Supplier-defined controls
Incident management approach
Incidents may be identified through protective monitoring (including alerts from SIEM), staff reports, or customer reports.

All suspected incidents are logged in a central ticketing system and assigned an initial severity based on impact and urgency.

CiviQ follows documented procedures to triage and contain incidents (for example: isolating affected components, blocking malicious activity, revoking credentials/tokens).

We preserve relevant logs and evidence to support investigation and root-cause analysis.

We implement corrective actions (patches, configuration changes, rule updates) and restore service using tested backup/restore and recovery procedures where required.

We validate that systems are functioning normally and that monitoring/alerts remain in place.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau
ISO 9001 accreditation date
Wednesday 31 January 2024
What the ISO 9001 doesn’t cover
All aspects of CiviQ's business and quality management processes are covered.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
1eff8ad9-b3fb-4d6f-a494-74b8d9f31749
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
9353a476-5693-4a47-badf-86e79a270f95
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@civiq.eu. Tell them what format you need. It will help if you say what assistive technology you use.