Hazard Reporting Module - Health and Safety Software
Hazard Reporting Module is a cloud-based web and mobile tool for capturing workplace hazards via app, browser or QR code. Users add photos, video, location and notes. Configurable forms and workflows route issues, create actions and track completion. Dashboards and reports provide trends. Export unified PDF evidence packs. Integrates HR/CRM/SharePoint.
Features
- Report hazards via mobile app, web portal or QR code.
- Attach photos, video and documents to every report.
- Out-of-the-box and configurable hazard reporting forms.
- Conditional fields show only relevant questions.
- Form/workflow builders for routes, approvals and actions.
- Schedule audits, inspections and investigations.
- Map-based assignment and tracking by site/location.
- Drill-down dashboards with charts, filters and exports.
- One-click PDF packs combining forms and evidence.
- APIs integrate with HR, CRM, SharePoint and SSO.
Benefits
- Spot and resolve hazards faster with real-time reporting and alerts.
- Reduce risks and injuries through proactive identification and actions.
- Improve data quality with standardised digital forms and evidence.
- Cut admin time by removing paper, rekeying and manual follow-up.
- Strengthen compliance with auditable workflows, dashboards and PDFs.
- Increase accountability with clear owners, deadlines and action tracking.
- Enable consistent reporting across departments, sites and contractor
- Make better decisions using trend analysis and drillable insights.
- Boost engagement by making reporting simple on any device.
- Support ESG goals by reducing paper, travel and duplicated effort.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 9 1 6 5 8 5 1 1 3 2 0 4 9 0
Contact
Ultan Technologies Ltd
Cathal Brady
Telephone: +35312530680
Email: info@ultantechnologies.com
About your service
- Service categories
-
Applications
Production and operations
- Production and grid management
- Other operations
Service industry and public sector operations
- Healthcare
- Education
- Public Order and Safety
- Police
- Defence
- Social Security Administration
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
No major limitations or constraints that the buyer should know about.
Our service is a cloud-based software application; we manage and support the mWorkerCIS System (web and mobile apps) rather than buyers’ underlying hardware, networks, or third-party security tools.
The service is designed for all major modern browsers and common mobile devices.
Tested Android version: 12+
-Device requirements:
-CPU 1 x 1.2 GHz+
-RAM 1 GB+
-Storage 2GB+
Tested iOS version: 13+
Tested devices:
-iPad 2+
-iPhone 8+
Other devices/versions can be used.
The platform is highly configurable no-code; we support authorised users to configure templates and workflows. - System requirements
-
- Modern web browser: Chrome, Edge, Firefox, Brave or Safari supported.
- Supported mobile: iOS and Android
- Optional offline mobile use requires periodic connectivity to sync.
- Devices must allow app storage and required permissions enabled.
- Buyers manage user identity; SSO optional with supported providers.
- Administrative users need rights to manage roles and permissions.
- SharePoint upload requires Microsoft 365 tenancy and appropriate permissions.
- Mobile devices should support camera for evidence capture attachments.
User support
- Email or online ticketing support
- Yes
- Support response times
-
At no additional cost, we provide support during normal working hours (Monday-Friday, 09:00-17:30). Within these hours, we typically acknowledge and respond to questions withinn 1 hour to 4 hours, depending on the agreed SLA and the incident priority. Support tickets can be logged anytime.
Weekend and out-of-hours responses are not included as standard; however, for Priority 1 (P1) and P2 critical incidents, we may respond and work to restore service outside normal hours where required. For an additional annual support fee, we can provide extended support up to 24/7, including evenings and weekends, with response targets aligned to contracted SLA. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Testing has been carried out by our ticketing system partners - Zendesk. See https://www.zendesk.com/company/policies-procedures/accessibility/.
- Onsite support
- Yes, at extra cost
- Support levels
-
Support levels are aligned to each buyer’s requirements and SLAs. Standard Support (included in user licensing) provides an ITIL-aligned Service Desk delivering Level 1 and Level 2 support via telephone, email and a web ticketing system, Monday-Friday 09:00-17:30.
Support is generally included in the licence fee; licensing costs depend on licence types and volumes, with discounts at higher user counts.
Premimum enhanced support (e.g. 24/7 cover, reduced response & resolution times) is available for an additional annual support fee. We run service reviews and provide KPI reports against the agreed SLA.
We provide a named Customer Account Manager and Support Manager/Service Transition lead; a dedicated Technical Account Manager/Cloud Support Engineer can also be provided. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We help users start using the service through a structured onboarding and adoption approach aligned to the buyer’s implementation plan and user roles.
Implementation onboarding: We run initial discovery and setup sessions to confirm processes, roles/permissions, reporting needs, and configuration approach (templates, workflows, dashboards).
Role-based training: We provide remote training as standard for administrators, configurators and end users. This includes hands-on sessions covering day-to-day use (mobile and web), and deeper configuration training for Super Admins/Power Users. Onsite training can be provided where required (additional cost, depending on location and scope).
User documentation: We supply user guides, quick-reference materials and in-product guidance to support common tasks (logging in, completing forms, evidence capture, corrective actions, reporting).
Train-the-trainer: We can enable buyer champions to deliver internal training and support, supported by our team as needed.
Go-live support: We provide hypercare during go-live, with increased support availability, monitoring, and rapid issue triage to ensure a smooth transition.
Ongoing support and refreshers: We offer refresher training, new-starter sessions, and periodic best-practice reviews to support continuous improvement and adoption. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- Word
- Excel
- End-of-contract data extraction
-
Users can extract their data through a managed offboarding process agreed with the buyer. We will confirm the required scope (for example form submissions, evidence files, history, user and reference data, and reporting outputs) and the target formats. Data is typically provided in common export formats such as CSV/XLSX for structured datasets and PDF for audit-reports, uploaded files, with additional formats (for example JSON) available where appropriate. Where the buyer requires bulk export, we can provide data extracts via secure transfer mechanisms.
If the buyer has integrations or a reporting warehouse, we can also support extraction via the service API where enabled, subject to access controls and agreed rate limits. We will provide guidance on interpreting the exported data, including field definitions and any relevant data relationships, to support migration to another system.
On request, we can agree a staged extraction approach (for example, an initial validation extract followed by a final extract on termination) to minimise operational risk. Following successful handover and confirmation, we will securely delete or anonymise remaining buyer data in accordance with contractual terms, retention requirements, and applicable data protection obligations. - End-of-contract process
-
At the end of the contract, we follow an agreed offboarding plan to ensure continuity and protect buyer data. We will confirm the termination date, agree exit timelines and responsibilities, and support the buyer to extract their data in the required formats (for example CSV/XLSX for structured datasets and PDF for reports, and/or API-enabled extraction where applicable). Once the buyer confirms successful receipt of the final extract, we will disable user access, remove or revoke integration credentials, and complete secure data deletion or anonymisation in line with the contract, agreed retention requirements, and applicable data protection obligations. Where needed, we can run a staged approach (validation extract followed by final extract) to reduce operational risk.
Included in the contract price: contracted access to the web and mobile applications for licensed users; standard service operation, maintenance and updates; standard support aligned to the agreed SLA; and standard offboarding coordination including provision of an agreed standard data extract.
Additional-cost(where-required): enhanced support (for example extended hours/24x7 beyond-standard-scope); onsite training or extended adoption/hypercare beyond the agreed implementation plan; complex or bespoke data extraction (non-standard formats, significant transformation, repeated extracts); and professional services for migration activities, bespoke integrations, or custom reporting beyond standard exit assistance. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Other
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is available via mobile app and desktop web app, with role-based access controlling permissions. The mobile app is optimised for field use: locating assigned work, completing forms/audits, capturing evidence (e.g., photos/videos/voice recording/documents/notes), submitting records on-site, and viewing configured dashboards and previous submissions. It can also support navigation to a job on a map where enabled. The web app provides full administration and management, including no-code configuration (templates, scoring, workflows), user/role management, reporting, dashboards, and data oversight. Forms can also be completed in the web app on laptops/PCs and tablets, and the web app works on mobile browsers.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is delivered through a responsive web application (for administration, configuration, reporting and dashboards) and native mobile apps (for field data capture, completing forms/audits, and submitting evidence). Access is role-based and can be tailored by the buyer. Users interact via intuitive menus, task lists, configurable forms, workflow prompts, and searchable records, with PDF report generation, graphs and tables in dashboards, and optional integration points (e.g., email/SharePoint/CRM/SSO/HousingMgtSystem upload/download where enabled). The web app can also be used on tablets and mobile browsers.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We conduct accessibility validation on core user journeys using keyboard only navigation, screen reader checks, and zoom/reflow testing. We verify that navigation, form completion, error messaging, and status updates are operable and correctly announced, and we log and remediate any issues (e.g., focus management and labelling). We can include assistive-technology users in buyer UAT where required.
- API
- Yes
- What users can and can't do using the API
-
Our service provides an API to support integration with buyer systems and automate data exchange. Using the API, authorised users can typically create, retrieve and update operational records such as form/audit submissions, associated evidence metadata, corrective actions/status updates, and relevant reference data (where enabled). Users can also extract data for reporting or to populate downstream systems, and support integration patterns such as pushing completed records to external repositories or triggering follow-on processes where configured.
The API is not designed for full platform configuration. Core no-code setup, creating and maintaining templates/forms, scoring models, workflows, dashboards, and role/permission models, is normally completed via the web application to ensure appropriate governance, validation, and auditability. Some administrative functions may be exposed only on request and subject to controls.
API access is protected through authentication and role-based authorisation, ensuring users can only access data and functions permitted for their role. Limitations can include rate/throughput controls to protect platform performance, constraints on bulk operations, and restrictions on destructive actions (for example deletion) or high-risk configuration changes to reduce the likelihood of accidental or unsafe updates. We provide API documentation and support buyers during integration design, testing, and deployment as part of implementation or an integration project. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- ODF
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise the service extensively using no-code-configuration-tools, with governance enforced through role-based permissions.
Buyers can configure audit/form templates (sections-questions-response-types-validation-rules-mandatory-fields), scoring and weighting models, thresholds-&-risk ratings, workflow stages (for example review/approval), notifications and automated alerts, corrective action processes (categories, assignment rules, escalation, due dates), dashboards and KPIs, reports and filters, operational reference data (such as sites/locations, teams, asset lists), and user roles/permissions including access by site, region or function.
Customisation is primarily completed through the web application’s configuration interface. Authorised users use guided screens to design and amend templates, adjust logic and workflows, and publish changes. Configuration changes can be validated using the buyer’s governance approach (for example peer review, test users, or a staged rollout) before release to wider users. Where integrations are in place, specific data mappings and automation rules can be configured as part of an agreed integration work package.
Customisation is typically carried out by nominated buyer administrators (e.g., Super Admins/Power Users) who have received training and are granted configuration permissions. Standard users can complete audits, submit evidence and manage assigned actions, but cannot change configurations unless explicitly permitted. We provide guidance and support to buyer configurators and can assist with complex configuration where required.
Scaling
- Independence of resources
- We protect users from other customers’ demand through tenant isolation and platform controls. Each buyer’s data and access is logically segregated with role-based permissions. The service runs on scalable cloud infrastructure with load balancing and capacity monitoring to maintain performance headroom. We apply throttling/rate limiting and queue controls to APIs and background processing so that high-volume activity from one tenant cannot exhaust shared resources. We continuously monitor availability, latency, throughput and error rates with automated alerting and proactive incident response. Where appropriate, heavy processing is handled asynchronously to prevent impacts on interactive user journeys.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide service metrics covering platform availability, incident and request volumes, response and resolution performance against SLA, priority breakdown (P1-P4), backlog and ageing, repeat incidents, and trend analysis. Operational metrics can also include user adoption/activity (logins and submission volumes), workflow throughput, action volumes/overdues, and KPI performance where configured. Metrics support governance, continual service improvement, and auditability, and can be tailored to the buyer’s reporting needs.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Other
- Other data at rest protection approach
- We protect data at rest through encryption and strict access controls. Customer data stored in databases, file/object storage and backups is encrypted on the underlying storage media using strong cryptography, ensuring data remains unreadable without authorised keys. Encryption keys are managed securely with controlled access, separation of duties and key rotation practices. The hosting environment uses data centres with robust physical security and independently audited operational controls (for example SSAE-18 / ISAE 3402-aligned assurance provided by the underlying cloud provider). Additional safeguards include tenant segregation, least-privilege role-based access, secure secrets management, and comprehensive logging/monitoring of administrative activity and data access.
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users export data using role-based, permission-controlled options. In the web application, authorised users can export lists and reporting views (e.g., submissions, corrective actions, KPI/report outputs) to common formats such as CSV/XLSX. Audit/job reports can be generated and downloaded as PDFs and, where configured, distributed automatically (e.g., email or SharePoint upload). Where enabled, buyers can also extract data programmatically via the service API for integration with reporting platforms or data warehouses, subject to authentication and rate limits. For large-scale needs (e.g., migration/end-of-contract), we can provide managed bulk extracts via secure transfer in agreed formats.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- Excel
- Word
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Excel
- API
- Any File Uploads (Images/Audio/Voice)
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- All traffic between user devices (web and mobile) and our service is encrypted using TLS 1.2+ with modern cipher suites and certificate-based authentication. We enforce secure HTTPS endpoints (no downgrade to legacy protocols), and we maintain certificate lifecycle management (renewal/rotation) to ensure continued protection. Legacy SSL/TLS (<1.2) is not supported. Where required, we can also support additional network controls such as IP allow-listing for some processes at the service boundary (subject to buyer having fixed egress IPs).
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
-
Firewalling and security groups: Only required ports/protocols are permitted between components (least privilege).
Private service endpoints: Internal services are not exposed publicly unless necessary, reducing attack surface.
Monitoring and detection: Centralised logging, alerting, and intrusion/threat detection support rapid identification and response.
Administrative access controls: Privileged access is restricted, MFA, audited, and protected using strong authentication and secure management channels.
Availability and resilience
- Guaranteed availability
-
We guarantee 99.9% service availability per calendar month, excluding scheduled maintenance. The service is designed and operated to support 24x7 availability, with scheduled maintenance planned outside normal business hours and notified with at least 48 hours notice (emergency maintenance notified as early as practicable and will happen during normal business hours if it must).
SLA measurement and exclusions
Availability is measured monthly. Scheduled maintenance windows are excluded from the availability calculation, in line with the agreed SLA schedule.
Service credits if availability is not met
Where the guaranteed availability level is not achieved, the contract SLA can include a service credit/penalty regime linked to downtime (and also to any deviation from agreed response and resolution targets). The specific credit calculation and application method (e.g., credits applied to future invoices) are documented in the SLA schedule agreed with the buyer and used for KPI reporting and service credits. - Approach to resilience
-
Our service is designed for resilience through a layered approach across application, platform, and operational controls. The platform is hosted in resilient cloud datacentres, using redundant infrastructure and services designed to tolerate component failure without loss of service. We deploy services across multiple fault domains (for example, separate availability zones) with load balancing and health checks so traffic is automatically routed away from unhealthy instances. Data stores are configured with replication and automated failover to reduce the risk of single points of failure.
We implement continuous monitoring and alerting across availability, latency, error rates, capacity and key dependencies, backed by defined incident management and on-call escalation for critical issues. Capacity is managed proactively and the service is built to scale to meet demand, reducing performance-related outages. We maintain regular, encrypted backups and tested restore procedures, with retention aligned to contractual and regulatory requirements. Disaster recovery arrangements are documented and can include defined recovery objectives (RPO/RTO) agreed with the buyer.
Datacentre location, topology, and specific resilience architecture details (regions/availability zones) can be provided to buyers on request where disclosure is appropriate and aligned to security and contractual obligations. - Outage reporting
-
We report outages through direct customer communications and service integration options:
Public dashboard: We do not use a public status dashboard but could maybe one available if necessary. Outage notifications are currently provided directly to affected buyers to ensure relevance and security.
API: Where enabled, customers can use the service API to query service/transaction status signals relevant to their integration flows (for example, connectivity/health checks and processing outcomes), subject to authentication and role-based access controls.
Email alerts: We send email alerts to the buyer’s nominated contacts and distribution lists for service incidents, including incident start time, impact, affected components, workaround (if available), and estimated restoration updates.
In addition, we log incidents within our support/ticketing process, provide regular update cadence during major incidents, and issue a post-incident summary (including root cause and corrective/preventative actions) where appropriate.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
-
Users authenticate to the service using unique named accounts. By default,authentication is via username-password, enforced through strong password-policy, account lockout controls, and session-management. MFA can be enabled to provide an additional factor at login, and is mandated for privileged/administrative access.
Where required, we support identity federation (SSO) so buyers can authenticate users through their existing identity provider(e.g.Azure AD/Entra ID or other SAML/OIDC-capable providers), enabling centralised access control and alignment with buyer joiner/mover/leaver processes.
Other controls: role-based authorisation after login, least-privilege permissions, audit logging of authentication and administrative actions, and the ability to disable accounts or revoke access immediately where required. - Access restrictions in management interfaces and support channels
- We restrict access to management interfaces and support channels using layered controls. Management functions are protected by role-based access control (RBAC), unique named accounts, strong authentication (including MFA for privileged roles), least-privilege permissions and, where required, separation of duties. Administrative actions and authentication events are logged to provide a full audit trail, and accounts can be disabled immediately. Support is accessed via phone, email or ticketing portal, with requests accepted from authenticated users or nominated buyer contacts. Sensitive requests (e.g.,access-changes) require additional verification and approval. Tickets are restricted to authorised support staff and handled under data-minimisation and secure communication practices.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We follow documented IT and Data Security Policies for the mWorkerCIS service, covering data protection/GDPR, system security hardening, secure development (OWASP), access control, incident response, threat/vulnerability management, and business continuity/backup/restore.
Reporting structure and governance:Ultimate accountability sits with the Board, with executive responsibility delegated to Executive Directors. A Security Committee (SC) provides oversight of physical and logical security and is chaired by the Information Security Manager (ISM), who leads information governance, standards, compliance monitoring, metrics, and incident management, and reports to executives. Information Asset Owners (IAOs) and managers are accountable for protecting assets and day-to-day policy implementation within their areas.
How we ensure policies are followed: Compliance is a condition of employment; staff complete induction covering the security policy, reinforced through ongoing awareness and operational meetings. Policy currency is maintained via regular reviews led by the Support Manager, with changes agreed by the security committee (including CTO and Data Protection Officer roles). We use least-privilege access, MFA for administrative consoles, IP-restricted admin access, and comprehensive audit logging. Hosting security is underpinned by AWS audited assurance and compliance programmes (e.g., ISO/SOC). - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We operate ITIL-aligned configuration and change management. Service components (code, infrastructure-as-code, configuration, and documentation) are version-controlled and linked to releases, tickets and approvals, providing a full audit trail from build to retirement. Environments are separated (dev/test/UAT/production) and changes are promoted through controlled pipelines with rollback plans and release notes. Every change is assessed for security impact using risk-based review: data/access impact, dependency changes, vulnerability/patch relevance, and compliance considerations. Security testing and peer review are performed before deployment; urgent vulnerabilities follow an emergency change process with accelerated approval and post-implementation review. Configuration baselines are periodically reviewed, and unauthorised change is investigated.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We run a documented, risk-based vulnerability management process combining monitoring, assurance and patching. Threats are assessed through continuous platform monitoring and alerting, secure development practices, periodic risk reviews, and independent testing (including annual penetration testing and OWASP-aligned peer review). We prioritise remediation by severity and business impact. Critical vulnerabilities follow emergency change control and are patched as soon as practicable; urgent fixes are applied at the next scheduled maintenance window, with other patches delivered on a planned cadence after testing in production-like environments. Threat intelligence sources include vendor advisories (e.g.Microsoft) and third-party component mailing lists, plus AWS security monitoring signals.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use 24/7 protective monitoring across infrastructure and application. AWS metrics and a third-party APM track CPU, memory, I/O, latency, errors and anomalous behaviour, with threshold alarms automatically raising Zendesk tickets. AWS IDS/IPS capabilities alert us to malicious activity and policy violations. Support staff triage alerts immediately, validate scope/impact, contain risk (e.g., block traffic, disable credentials), and escalate to senior engineers/management as required, while notifying buyer contacts per SLA. Response times follow priority SLAs (e.g., P1 within 15 minutes), with an on-call rota providing out-of-hours coverage for P1/P2 incidents where necessary.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate an ITIL-aligned incident management process with predefined runbooks for common events (e.g., service degradation, authentication failures, integration/email delivery issues, and capacity alerts). Users report incidents via telephone, email, or our web ticketing portal; tickets are categorised and prioritised (P1–P4) and tracked end-to-end with an auditable history. For major incidents, we invoke an escalation/on-call rota, provide regular update cadence to nominated buyer contacts, and coordinate restoration actions and workarounds. We provide incident reports via the ticketing system and email, including timeline, impact, root cause (where known), corrective/preventative actions, and SLA performance; post-incident reviews are produced for P1/P2 events.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We do not offer a permanent free version. Where agreed, we can provide a time-limited trial for a specific module for a single user. The trial includes access to the module’s standard features in a trial environment and a userguide for selfservice-support. It excludes ongoing-access,multi-user-rollout,bespoke-configuration,integrations,and onsite/remote training beyond the userguide.
- Link to free trial
- http://ultantechnologies.com/book-a-demo/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- CDL Group Ltd
- ISO/IEC 27001 accreditation date
- Wednesday 4 June 2025
- What the ISO/IEC 27001 doesn’t cover
- NA
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- CDL Group Ltd
- ISO 9001 accreditation date
- Wednesday 4 June 2025
- What the ISO 9001 doesn’t cover
- NA
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-