OpenConsult: Public Engagement Platform
OpenConsult is a secure, web-based consultation and engagement platform that helps public bodies plan, publish and manage public engagements end-to-end.
Features
- Wide range of consultation types including questionnaires
- Consultation response summarising and reporting. AI support also available (optional)
- Interactive mapping and integration with ArcGIS Online
- Features to support Planning consultation processes
- Consultation-level visual dashboard reporting feedback for admins and public
- Public and Private engagements
- User response, account history and management pages
- Easy to publish responses and enable query, sharing, download.
- Engagement alerts to users
- Workflow for input of responses received offline
Benefits
- Publish simple to complex engagements including planning consultations
- Import any map type
- Present complex documents in an easy and accessible way
- Promote early engagement through subscriptions to consultation alerts
- Consultation content is easily accessible through the response form
- Easily summarise, categorise and report on consultation responses
- Easily pull data to MS backend systems
- Easily publish responses for public viewing, query, download
- AI support for processing responses with governance
- Opportunity to explore new approaches to engagement with AI
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 4 5 6 8 3 3 6 8 4 7 9 6 6 8
Contact
CiviQ
Vanessa Liston
Telephone: +353861408681
Email: info@civiq.eu
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- There will be short windows of maintenance time when upgrades, new features, or fixes are rolled out.
- System requirements
- Customer needs a modern browser to access the platform
User support
- Email or online ticketing support
- Yes
- Support response times
-
Initial response during working hours within one hour.
Resolution times are as follows:
Critical service outage < 4 hours
High priority issue <8 hours
Normal issue < 2 business days
Low issue <4 business days. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Standard Support is included with an annual subscription.
Hours: Monday–Friday, [09:00–17:00 UK time], excluding public holidays
Channels: Email + support portal
Coverage: Incidents, bug reports, “how-to” queries
Target response times:
P1 (Critical): response within 4 hours
P2 (High): response within 8 hours
P3 (Medium): response within 2 business days
P4 (Low): response within 4 business days
Target resolution approach: workarounds and fixes prioritised by severity and impact - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Online workshops are provided during the onboarding process.
An online support portal is provided with videos, How To guides, FAQs and a User Forum.
A self-training portal is also provided with tasks submitted to CiviQ for review and certification.
Customers also receive direct support in publishing their first engagement.
CiviQ provides a high-quality support service to all customers to ensure their success in using the service. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Video
- End-of-contract data extraction
- All data is available by a Customer super user to download at the end of the contract.
- End-of-contract process
- An off-boarding meeting and access to download all response and user data is included in the price of the contract. Data can be downloaded in excel, PDF, Word and Zip formats. The API can also be used to extract these data.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There are no differences.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- OpenConsult is accessed through a secured connection using HTTPS protocol. Users sign in to an online portal to configure and manage the service (for example: create and publish engagements and consultations, manage and message users, view responses, and run reports/exports). No software installation is required for standard use.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- OpenConsult is regularly tested with an accessibility expert who provides VPAT reports on the conformance of OpenConsult with accessibility requirements and any improvements required.
- API
- Yes
- What users can and can't do using the API
-
A private API is available to pull all response data (representations, survey responses, map data) and respondent data to back end systems.
The API only works on a pull basis. There is no option to use the API to make changes to data on the platform. - API documentation
- Yes
- API documentation formats
-
- ODF
- Other
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
-
Tenant isolation: Each customer’s data is physically separated and stored in own cloud tenant account.
Autoscaling and capacity management: Our service scales horizontally based on load (application instances, workers)
Monitoring and alerting: We continuously monitor latency, error rates, queue depth, CPU/memory, and per-tenant usage. Automated alerts trigger scaling.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Engagement volumes at consultation level: number of responses submitted; number of comments per consultation theme/question/chapter.
Audience statistics: metrics provided by Matomo Analytics. Accessed through their dashboard.
Operational metrics: support ticket volumes and response times, time between receiving, approving and publishing representations to consultations. - Reporting types
-
- API access
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Administrators can use the platform's export function to export data on responses and user data. Super users only have access to download all response data from the platform.
End-users (public users) of the platform must request a copy of their data from the data controller. CiviQ will support the data controller in providing this information to end-users. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
OpenConsult 99.8% availability.
Service Commitment credits:
Monthly uptime
≤ 99.8% no credit
≤ 95 - 99.8.5% of monthly Fees (pro-rated)
<95%
Outside scheduled maintenance time
Service Request Service Credits
SLA Breach Category
Critical response/resolution delays – P1 & P2 tickets. Threshold per quarter 95%. Credit applied 5% credit of quarterly Fees (pro-rated)
All other tickets and requests P3 & P4. Threshold per quarter 90%. Credit applied - 2% credit of quarterly Fees (pro-rated) - Approach to resilience
- Available on request.
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Other
- Other user authentication
- Email and password for end users. MFA for administrators. MFA can also be applied for end users. Bot protection ensures users are human.
- Access restrictions in management interfaces and support channels
- MFA, role-based access, need to know basis, access restricted by assigned teams to engagements.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Other
- Description of management access authentication
- SSO
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- ISO/IEC 27001 (aligned): We are aligned to ISO/IEC 27001 and operate an information security management approach consistent with ISO 27001 principles (for example: documented security policies and procedures, risk assessment and treatment planning, defined security roles and responsibilities, supplier/security review, incident management, and continual improvement). We are not ISO 27001 certified.
- Information security policies and processes
-
CiviQ operates an information security management approach aligned to ISO 27001 principles.
Key Policies and processes:
• Information Security Policy
• Access Control & Acceptable Use
• Data Handling, Retention & Disposal
• Secure Development & Change Management
• Vulnerability & Patch Management
• Incident Management
• Backup & Recovery / Business Continuity
• Supplier Management
• Other supporting policies
Reporting structure:
• Security owner: the CEO is accountable for information security governance
• Security lead: The CTO maintains controls and reports security status/issues to the CEO.
• All staff and contractors are required to follow policies as a condition of access to systems and data.
Any security concerns are reported immediately to the security lead and escalated to the security owner. They are tracked through to closure.
We ensure policies are followed through measures including, among others:
• AWS-focused controls
• Strong access controls
• Joiner/mover/leaver checklist
• Secure SDLC including peer code reviews, separation of environments
• Vulnerability management
• Logging & auditability
• Backups & restore testing
• Incident response: documented steps, internal escalation path, and learnings from post-incident review to prevent recurrence. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We manage configuration and change through Infrastructure-as-Code and version control. AWS infrastructure is defined in CloudFormation templates stored in Git. Components are traceable via commit history, tagged releases and deployment logs. Application changes are made via pull requests and deployed using GitHub Actions, Each production release is linked to a specific commit.
We use separate environments (e.g., dev/staging/production). Each change is reviewed for security impact. IAM permissions/least privilege, network exposure (security groups/endpoints), secrets handling, logging/auditability and dependency risk are included in the security impact review. Rollbacks use prior releases/templates. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
CiviQ has an automated patch management process integrated into its deployment pipeline. Systems are patched regularly through deployments that use the latest stable images with automated updates. Host systems run update scripts on deployment, containers rebuild with latest packages, and RDS MariaDB receives automatic minor version updates during maintenance windows.
For application-level patches, we monitor security subscriptions and apply updates within our 14-day SLA, testing changes through Dev and Staging environments. Composer audit runs weekly to identify vulnerable dependencies. CiviQ monitors for zero-day vulnerabilities through Drupal security channels, extended support subscriptions, AWS bulletins, and our security team. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
CiviQ operates protective monitoring. A SIEM watches for exploitation attempts in real-time. Rules and correlation are used to generate alerts for events such as brute-force attempts, anomalous admin activity, unexpected configuration or file changes, and indicators of compromise.
Alerts are triaged by trained staff using documented runbooks.
Confirmed incidents follow our incident process: containment, eradication, recovery, and post-incident review (including improvements to controls and alerting).
Security logs and alerts are retained for an agreed period to support investigations and audit requirements. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Incidents may be identified through protective monitoring (including alerts from SIEM), staff reports, or customer reports.
All suspected incidents are logged in a central ticketing system and assigned an initial severity based on impact and urgency.
CiviQ follows documented procedures to triage and contain incidents (for example: isolating affected components, blocking malicious activity, revoking credentials/tokens).
We preserve relevant logs and evidence to support investigation and root-cause analysis.
We implement corrective actions (patches, configuration changes, rule updates) and restore service using tested backup/restore and recovery procedures where required.
We validate that systems are functioning normally and that monitoring/alerts remain in place. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Wednesday 31 January 2024
- What the ISO 9001 doesn’t cover
- All aspects of CiviQ's business and quality management processes are covered.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 1eff8ad9-b3fb-4d6f-a494-74b8d9f31749
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 9353a476-5693-4a47-badf-86e79a270f95
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-