Totara (Learn, Engage and Perform)
Totara Learn (LMS), Totara Engage (LxP) and Totara Perform products can be used together or separately. Totara has incredibility rich set of functionality and Totara offers upto 80% cost savings compared with other platforms. Accipio is 5 x award winning Platinum Alliance Totara partner and supplies all three Totara products.
Features
- Create and manage eLearning delivery and assessment
- Wide mix of supported media (SCORM, Interactive Documents, HVP, Video)
- Enables social learning, collaboration, social networking and knowledge sharing
- Customisable branded Themes and Dashboards different types of audiences
- Personal development plans for targeted training, and full competency/goal management
- 360 degree feedback management
- Integrated interactive performance Dashboards for Corporate performance management
- Detailed reporting
- Integrate with third party authentication/HR systems, and OpenBadges
- Extend with the Accipio One plugin eco-system
Benefits
- Easily manage users, and track completion / competence / certification
- Provide access to interactive and engaging learning 24/7
- Manage classroom sessions for blended learning
- View real-time usage and completion monitoring
- No “vendor lock-in” and significant savings
- Managers can assign learning, and view completion data
- See what percentage has completed compliance training
- Manage performance
- Deploy a beautifully branded site learners want to visit
- Access the Accipio One plugin eco-system
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 5 6 6 8 9 8 6 3 4 3 6 9 9 8
Contact
Accipio
Sascha Benson-Cooper
Telephone: 02071172690
Email: ask@accipio.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
Human capital management
- Talent Management Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
-
Planned maintenance is required to keep the service secure and up to date. This includes operating system updates, Totara core upgrades and security patching. Where possible, maintenance is carried out outside of normal UK business hours and customers are notified in advance of any planned service interruption.
The service supports standard Totara releases and approved third-party plugins. Custom plugins or unsupported themes may be accepted subject to technical review but are not guaranteed to be compatible with future Totara upgrades.
The service requires users to access Totara via a modern, standards-compliant web browser and a reliable internet connection. - System requirements
-
- Modern browser
- Access to the internet
User support
- Email or online ticketing support
- Yes
- Support response times
- Normally within an hour. Our SLA is 24 hours, and much more rapidly for more urgent matters. This includes weekends.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We use ZenDesk for web chat who do the testing.
- Onsite support
- Yes, at extra cost
- Support levels
-
We have three support packages:
1) Pay as you go. This is a credit based support system, and covers advice and task delivery. 10 credits cost £850 ex VAT and last for 3 months. Each credit is worth up to 1 hour of work.
2) All you can eat. This is for unlimited "advice" on front end configuration for the named administrator.
3) Bespoke and end user support. We can create a bespoke support package to meet your needs. This could include on-site support, complete service management and training. Our fees start at £750 per day ex VAT. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Accipio provides a structured onboarding process to help customers start using Totara quickly and confidently. Each customer is assigned an implementation lead who coordinates platform setup, user access, integrations and data migration where required.
Users are supported with online documentation, administrator and user guides, and knowledge base articles covering common tasks and best practice. Remote training sessions are provided for administrators, course creators and support staff, with optional on-site or tailored training available if required.
Accipio also provides live support during go-live to ensure a smooth transition into service. After launch, ongoing support and refresher training are available through the service desk and scheduled reviews to help customers get the most from their Totara platform. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
At the end of the contract, customers can extract all of their data in standard, portable formats. Accipio provides an export of the Totara environment including the sitedata file store and a complete database dump containing users, courses, grades, activity data and configuration.
These exports can be used to restore the service into another Totara platform or for long-term archiving. Data is provided securely via encrypted download or secure transfer.
In addition, authorised users can export specific datasets at any time during the contract using Totara’s built-in reporting and export tools, including CSV and Excel downloads for users, enrolments, grades, activity logs and reports.
Accipio provides support during the off-boarding process to ensure data is exported successfully and in a format suitable for migration to another provider or for internal use. - End-of-contract process
-
At the end of the contract, Accipio works with the customer to complete a controlled off-boarding process. This includes providing a full export of the Totara platform, including the database and sitedata file store, so the service can be migrated to another provider or retained for archive purposes.
The standard contract price includes data export, reasonable support to assist with the off-boarding process, and secure retention of the service for an agreed handover period. Once the customer has confirmed that their data has been successfully received, the Totara environment and all associated backups are securely deleted in line with Accipio’s data sanitisation processes.
Optional additional services, such as data migration to a new Totara provider, extended retention periods, or bespoke data transformations, can be provided at an agreed additional cost if required.
This approach ensures customers can exit the service without lock-in while maintaining security and data integrity. - Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- No. There is an App that can be used too.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
- ZenDesk
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- ZenDesk do testing.
- API
- Yes
- What users can and can't do using the API
-
Accipio’s Totara Fully Managed Service provides access to Totara’s standard web service APIs (REST and SOAP) to allow integration with other systems.
Using the API, authorised users can create and manage user accounts, enrolments, courses and categories, upload and retrieve learning content, and access grades, activity completion and reporting data. The API can also be used to integrate identity providers, student record systems and other third-party platforms.
The Totara platform itself is provisioned and hosted by Accipio. Once the service is live, API access can be enabled by Accipio or by authorised administrators, who can generate API tokens and assign permissions for approved integrations. Customers can then use the API to automate the setup and ongoing management of users, courses and data.
The API allows customers to make operational changes within their Totara environment but does not provide access to the underlying hosting infrastructure or platform configuration. System-level functions such as operating system patching, Totara core upgrades, and the enabling or disabling of plugins are managed by Accipio and must be requested through support. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
How can users customise your service?
Accipio’s Totara Fully Managed Service can be customised to meet each organisation’s teaching, branding and operational requirements.
What can be customised
Customers can customise site branding (logos, colours and themes), course structures, user roles and permissions, enrolment methods, reporting, notifications and learning workflows. A wide range of standard Totara plugins can also be enabled to extend functionality.
How users can customise
Authorised customer administrators use Totara’s built-in administration interface to configure settings, manage users, create courses and apply branding. Standard Totara APIs can also be used to automate configuration, enrolments and data exchange with external systems. Requests for advanced changes, such as enabling additional plugins or modifying themes, are handled through Accipio’s support service.
Who can customise
Customisation is performed by authorised customer administrators and trainers within Totara. Platform-level changes that could affect security or stability, such as software upgrades or plugin approval, are managed by Accipio as part of the fully managed service.
Scaling
- Independence of resources
- Accipio guarantees independence of customer resources by deploying each Totara client into its own dedicated AWS account and isolated cloud environment. This ensures that compute, storage, networking and database resources are not shared between customers. As a result, activity, traffic spikes or heavy usage from one customer cannot impact the performance or availability of another. Within each AWS account, resources are sized and monitored specifically for that customer’s workload, with auto-scaling and capacity controls applied where appropriate. Continuous monitoring and alerting are used to identify and address resource constraints, ensuring each customer receives consistent, predictable performance regardless of other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Accipio provides service metrics to help customers monitor the performance and reliability of their Totara platform. These include platform availability, uptime, response times, system load, storage usage and backup status. Support metrics such as incident volumes, response times and resolution times are also available. Where applicable, customers can access usage metrics including numbers of active users, courses, and system activity through Totara’s reporting tools. Technical metrics are monitored continuously to support proactive maintenance and incident management. Summary reports can be provided on request or as part of regular service reviews to support governance, performance monitoring and service improvement.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export their data from Accipio’s Totara service using Totara’s built-in export and reporting tools and standard APIs. Authorised administrators and teachers can download course content, user lists, grades, activity logs and reports in common formats such as CSV, Excel and Totara backup files. Complete course backups, including content and enrolments, can be generated through the Totara interface for transfer to another Totara system. Data can also be extracted automatically using Totara’s web service APIs for integration with external systems or business intelligence tools. Accipio provides support to assist with large-scale or full-system exports where required.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Accipio guarantees 99.9% service availability per calendar month for each customer’s Totara platform, excluding scheduled maintenance. Availability is measured at the application level, covering access to the Totara web interface and core services.
The service is hosted on highly available AWS infrastructure with redundancy across multiple availability zones, continuous monitoring, automated failover and regular backup and recovery testing.
Planned maintenance that could affect availability is notified in advance and scheduled outside of normal UK business hours wherever possible.
If monthly availability falls below the 99.9% service level, customers are entitled to service credits applied to their next invoice. Credits are calculated as a percentage of the monthly service charge, increasing in line with the duration and severity of the outage. Details of credit thresholds and claims processes are provided in the service contract.
Accipio’s support team provides 24/7 monitoring and incident response to minimise downtime and restore service as quickly as possible in the event of a fault. - Approach to resilience
-
Accipio’s Totara service is designed for high resilience using AWS cloud infrastructure and a multi-layered availability model. Each customer environment runs in a dedicated AWS account with isolated resources, preventing failures or spikes in one tenant from affecting another.
The platform is deployed across multiple AWS Availability Zones, providing automatic protection against datacentre-level failures. Application servers, databases and storage are configured with redundancy and automated failover. Continuous monitoring and alerting enable rapid detection and response to issues.
Regular, automated backups are taken and stored securely in geographically separate locations. Backup and restore processes are tested to ensure data can be recovered quickly in the event of corruption, accidental deletion or system failure.
Infrastructure is managed using infrastructure-as-code and automated deployment pipelines, reducing configuration drift and enabling rapid rebuild of environments if required. Security patching, upgrades and maintenance are performed in a controlled and repeatable manner.
Detailed architecture, recovery objectives and resilience controls are available to customers on request. - Outage reporting
-
Accipio reports service outages and service status through multiple channels to ensure customers are kept informed. A service status dashboard is available to Accipio showing current system health, planned maintenance and any ongoing incidents affecting Totara environments.
Email notifications are sent to nominated customer contacts when an incident occurs, when there are significant updates, and when service is restored. Planned maintenance notifications are issued in advance.
Accipio’s support team also provides direct incident updates through the service desk, including impact, progress and estimated time to resolution.
Where required, incident and availability data can be provided through reports or shared dashboards for integration into customer service management or governance processes. API-based access to status data can be made available on request.
Post-incident reports are provided for major outages, detailing root cause, impact and actions taken to prevent recurrence.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support systems is restricted using role-based access control, least-privilege permissions and multi-factor authentication. Only authorised Accipio staff with a business need are granted access to customer environments, and access is approved, reviewed and removed through formal joiner, mover and leaver processes.
Administrative access to AWS and Totara systems is logged and monitored. Support channels such as the service desk and remote support tools are restricted to authenticated users and approved customer contacts. All access to management and support systems is auditable to ensure accountability and compliance with security policies. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Accipio operates a formal information security management framework covering confidentiality, integrity and availability of customer data. This includes policies for access control, data protection, incident management, vulnerability management, change management and business continuity.
Security responsibilities are defined and owned by senior management, with day-to-day controls implemented and monitored by Accipio’s technical and operations teams. Security risks, incidents and compliance issues are reported through an internal escalation and governance process to ensure they are reviewed, prioritised and resolved.
Access to customer systems is restricted to authorised personnel using role-based access controls, multi-factor authentication and logging. Changes to production systems follow documented change and approval processes.
Accipio uses AWS as its cloud infrastructure provider and aligns its technical controls with AWS security best practices, including network segmentation, encryption, monitoring and patch management.
Policies are reviewed regularly and staff receive security awareness training to ensure they understand and comply with Accipio’s information security requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Accipio manages configuration and change using documented change control and configuration management processes. All infrastructure, application components and configuration are defined and tracked using version-controlled infrastructure-as-code and configuration repositories, providing a full audit trail throughout the service lifecycle.
Proposed changes are logged, reviewed and approved before deployment. Each change is assessed for potential security, availability and data protection impact, including review of access controls, network exposure and compliance requirements. Changes are tested in non-production environments before release and are deployed using controlled, automated processes. Logs and monitoring are used to validate successful implementation and detect any issues after change. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Accipio operates a proactive vulnerability management process across infrastructure, operating systems, Totara core and installed plugins. Potential threats are identified through security advisories from Totara, AWS, operating system vendors, CVE databases and security mailing lists, as well as automated vulnerability scanning and monitoring.
Vulnerabilities are assessed for severity and impact on confidentiality, integrity and availability. High and critical risks are prioritised and remediated as soon as practicable, typically within hours or days, with patches tested before deployment. Lower-risk issues are scheduled into regular maintenance cycles. All remediation activity is logged and reviewed to ensure risks are tracked and addressed. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Accipio uses continuous protective monitoring across AWS infrastructure, operating systems and the Totara application. Logs, metrics and security events are collected and analysed to detect suspicious activity, unauthorised access, unusual traffic patterns and system anomalies. Automated alerts are generated for potential security incidents and reviewed by the operations team.
When a potential compromise is identified, it is investigated immediately, affected components are isolated if required, and remediation actions are applied. High-severity incidents are responded to on a 24/7 basis, with customers notified in line with incident management procedures. Monitoring and response actions are logged and reviewed to improve. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Accipio operates a defined incident management process covering service outages, security events and data protection incidents. Pre-defined runbooks are used for common incident types to ensure consistent and rapid response.
Customers can report incidents through the service desk, email or telephone, and incidents may also be raised automatically through monitoring and alerts. All incidents are logged, prioritised and tracked through to resolution.
Customers receive regular status updates during an incident and a post-incident report for major events. Reports include root cause, impact, actions taken and any follow-up improvements to prevent recurrence. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Accipio provides a free, time-limited demo Totara site for evaluation and testing. It includes standard Totara features but excludes live data, integrations, SLAs, support and production hosting. The demo is for trial purposes only. Full functionality and service levels are available under a paid contract.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 4%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 6%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Friday 11 April 2025
- What the ISO/IEC 27001 doesn’t cover
- Nothing
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Friday 11 April 2025
- What the ISO 9001 doesn’t cover
- Nothing
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 463ba2ac-9e96-442e-801f-7831d0de6dca
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 9e994128-8d00-447c-bafc-87223705f8e9
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
-