Skip to main content

Help us improve the Digital Marketplace - send your feedback

CASCADE RISK MANAGEMENT LTD

Cascade Digital Safety Case and Gateway software

Cascade is a digital safety case software that enables organisations to develop and manage safety cases and Gateway applications across their lifecycle. It combines evidence management, accountability and auditability with AI-enabled safety-case checking, helping teams manage risk, demonstrate compliance and maintain confidence in safety decisions during change and ongoing operations.

Features

  • Web-based digital safety case for higher-risk residential buildings
  • Supports active safety case and gateway application management
  • Configurable dashboards showing status, risks and outstanding actions
  • Built-in report builder with version control and collaborative authoring
  • Custom safety case templates to drive organisational consistency and scale
  • Integrated golden thread evidence library for structured information management
  • Workflow and notifications for task allocation and accountability tracking
  • Full audit trail of changes, actions and user activity
  • Open APIs for integration with asset, compliance, golden thread systems
  • Supports creation and management of Building Safety Regulator gateway applications

Benefits

  • Supports compliance with Building Safety Act safety case requirements
  • Provides Accountable Persons clear visibility of building safety risks
  • Creates an auditable trail of accountability and safety decisions
  • Reduces risk through structured evidence and assurance
  • Improves efficiency managing multiple safety cases across portfolios
  • Ensures consistency in safety case content and approach
  • Reduces effort and risk when preparing gateway applications
  • Saves time through automated reporting linked to evidence
  • Supports creation and maintenance of the golden thread
  • Requires minimal training due to intuitive, user-friendly design

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at emily.harbottle@cascade-risk.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 9 9 2 0 0 0 8 5 5 5 2 9 4 7

Contact

CASCADE RISK MANAGEMENT LTD Emily Harbottle
Telephone: 07976729213
Email: emily.harbottle@cascade-risk.com

About your service

Service categories

Applications

Content workflow and management

  • Document

Content services

  • Content Sharing and Collaboration Applications

Persuasive content management

  • Digital Asset Management Applications

Enterprise portals and digital workspaces

  • Integrated Employee Workspaces
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Planned maintenance is scheduled outside normal UK working hours where possible.
Advance notice is provided for any planned service maintenance or updates.
Service access requires a modern web browser and internet connectivity.
Custom configuration or integrations are subject to agreement and availability.
Major feature changes or deprecations are communicated in advance.
System requirements
  • Access via a modern web browser
  • Optimised for laptop and desktop computers
  • Reliable internet connection required
  • No additional software or plugins required

User support

Email or online ticketing support
Yes
Support response times
Cascade has a dedicated team to assist and support users of the system on a day-to-day basis. Support covers all elements of the system from general support questions and guidance, training and providing user guides, to supporting users with technical issues
All issues are directed through our dedicated Cascade support mailbox, which is monitored hourly between 0900-1700 Mon to Fri.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
The provider has assured us of the following:
Keyboard Operability: Users can navigate and interact with the chat widget using only a keyboard.
Screen Reader Support: The interface is designed to be read by assistive technology like NVDA on Windows and VoiceOver on iOS.
ARIA Attributes & Focus Rings: Proper coding allows screen readers to interpret chat elements, while visible focus indicators help users track their location.
Color Contrast: Elements are designed to meet contrast standards for visual accessibility.
Onsite support
Yes, at extra cost
Support levels
Standard support hours: Monday to Friday, 09:00–17:00 (UK time), excluding public holidays
Out-of-hours support: Available for critical service outages only
Weekend support: Critical incidents only

Incident priority and response
Support requests are prioritised based on impact and urgency:

Critical
Complete loss of service or safety case access for all users
Initial response: within 4 hours
Target restoration: as soon as practicable, with regular updates

High
Major functionality unavailable, significantly impacting users
Initial response: within 1 working day
Resolution or workaround: targeted within agreed timescales

Medium
Partial loss of functionality with workaround available
Initial response: within 2 working days
Resolution: scheduled and prioritised accordingly

Low
Minor issues, usability queries or enhancement requests
Initial response: within 3 working days

Recovery objectives
Recovery Time Objective (RTO): 4 hours for critical incidents

Support levels and cost
Standard support is included as part of the service subscription
No additional charge for incident support within standard hours
Any enhanced support arrangements or bespoke support requirements are subject to agreement

Cascade does not provide a dedicated Technical Account Manager as standard

Customers have a single, clear point of contact for support coordination
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Cascade is designed to be straightforward to adopt, with onboarding and training scaled to the needs and size of each customer.

New customers are supported through an initial onboarding process that introduces the service, confirms requirements and supports early configuration. This typically includes one or more remote onboarding sessions, provided at no additional cost, with follow-up sessions available depending on the scale and complexity of the organisation, to be agreed during the contract negotiation.

Users are supported by a range of self-service learning resources, including freely available how-to videos and a comprehensive safety case user manual. These resources support both initial use and ongoing reference.

Authorised administrators receive guidance on setting up organisational templates, workflows and reporting to ensure consistent use across teams.

Ongoing support is available through standard service support channels, and additional training or advisory services can be provided where required, subject to agreement.

For customers who require deeper understanding of safety case concepts or the Building Safety Act 2022, Cascade also offers an optional e-learning module at additional cost. This module focuses on safety case principles and regulatory context rather than system operation.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
All data held within Cascade remains the property of the customer. At the end of the contract, customers can extract their data in commonly used, non-proprietary formats.

Safety case data and structured records can be exported in CSV format and safety case content can also be provided as PDF reports. Supporting documentation and evidence files can be provided as ZIP archives.

Data exports can be made available via secure download or transferred to a customer-nominated file-sharing location, such as Microsoft OneDrive or another agreed secure file storage system.

Customers may request assistance with data export as part of contract exit support, subject to agreement. No proprietary tools are required to gain access to the exported data.
End-of-contract process
At contract termination, customer access to the Cascade service is closed. Customers retain ownership of all data held within the service. Standard data export is included in the contract price and allows customers to extract their data in commonly used formats, including CSV and PDF, with supporting files provided as ZIP archives. Data can be made available via secure download or transferred to a customer-nominated file-sharing location, such as Microsoft OneDrive.

Following completion of the agreed data export, customer data is securely deleted in accordance with the supplier’s data retention and security policies.

The following is included in the contract price at termination:
-Standard data export in CSV, PDF and ZIP formats
-Secure delivery of exported data
-Secure deletion of customer data after export

What may incur additional cost:
-Bespoke or complex data exports beyond standard formats
-Additional support or consultancy during contract exit
-API-based data extraction or integration support at termination
-Extended data retention beyond standard deletion timelines
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Service documentation is provided in PDF format. The documentation has not yet been formally tested against a specific accessibility standard. Where possible, documentation is produced using clear structure, headings and readable formatting. Alternative formats or reasonable adjustments can be provided on request. Accessibility of documentation will be reviewed and improved as part of ongoing service development.
As an organisation we aim to achieve WCAG 2.2 AA standards and will make improvements where that is not the case. With this in mind, we always:
Ensure PDFs are text-based, not scanned images
Use proper headings
Ensure selectable text
Add document titles

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Cascade is accessed via a secure, web-based user interface using a standard web browser. The service also provides APIs to support integration with external systems where required.
Accessibility standards
None or don’t know
Description of accessibility
The service supports keyboard navigation with visible focus indicators and logical tab ordering across core workflows. Form fields and images include associated labels and alternative text where appropriate and pages use semantic HTML with language attributes to support screen readers. Some modal interactions are not yet fully operable using keyboard-only navigation and colour contrast improvements have been identified.
Accessibility testing
Accessibility testing has been undertaken using Google Lighthouse on authenticated pages within the service, achieving accessibility scores between 82 and 86. Manual keyboard navigation testing has also been completed. The service provides a visible focus indicator; however, some modal interactions are not yet fully operable using keyboard-only navigation. These issues have been identified and will be addressed as part of ongoing service improvements.

Accessibility is considered during ongoing development and improvements will be prioritised to further align with WCAG 2.2 AA guidance.

Planned improvements include enhanced keyboard operability for modal dialogs and further accessibility refinements informed by automated and manual testing with users of assistive technology.
API
Yes
What users can and can't do using the API
Cascade provides an API that enables advanced users to integrate the service with other applications. API access is available as an optional, chargeable feature and is intended for integration and data exchange rather than day-to-day user interaction.

Users can:
Integrate Cascade with external systems, such as asset, compliance or golden thread platforms
Extract safety case data for reporting or analysis
Synchronise selected data between Cascade and third-party systems
Support automated data exchange where appropriate

API access is enabled by agreement and configuration by the supplier
Setup and configuration are undertaken as part of a bespoke integration service
Integration requirements are agreed in advance based on customer needs

Subject to configuration, users can create, update or retrieve agreed data objects
Changes via the API are limited to defined integration use cases
Core service configuration and user management remain via the web interface

Limitations of the API
The API is not self-service and requires supplier involvement to configure
Not all service functionality is exposed via the API

Bespoke integrations require developer time and are charged separately

API availability and scope are defined on a case-by-case basis
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Cascade provides configurable, admin-led customisation to support organisational consistency while maintaining a standard, supported service.

What can be customised
-Organisational safety case templates, including claims and arguments
-Report layouts, content structure and organisational branding
-Application branding elements (for example logos and colour accents), presented as “powered by Cascade”
-Dashboard views and configuration options

How users can customise
-Customisation is performed through the web-based administration interface
-Templates and branding options can be configured without development work
-Changes take effect across the organisation to ensure consistent use

Who can customise
-Customisation is available to authorised administrator users
-Standard users apply approved templates but cannot modify organisational settings

Scaling

Independence of resources
Cascade is delivered as a cloud-hosted, multi-tenant service designed to scale with demand. Each customer organisation is logically separated within the platform, including use of separate organisational domains and access controls.

The service is hosted on Amazon Web Services (AWS) and benefits from flexible infrastructure that can scale to accommodate variations in demand. Core services are designed to handle concurrent usage without degradation of performance for individual customers.

Usage is monitored to identify abnormal load or performance issues and operational controls are in place to ensure that excessive demand from one customer does not adversely affect others.

Analytics

Service usage metrics
Yes
Metrics types
The service records usage and activity data to support operational monitoring and assurance. At present, service usage metrics are retrieved by the supplier from the backend and can be provided to customers on request. These metrics typically relate to service activity, such as safety case status, usage levels and recent activity.

Self-service access to usage metrics via the application interface is not currently available. Enhancements to make service usage metrics more directly visible to administrators are planned as part of ongoing software development.
Reporting types
Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
During the contract term, users can export data directly from the Cascade service using built-in functionality. Safety case content can be exported as PDF safety case reports via the web interface.

Where the AI safety case checker is used, outputs can also be exported in editable formats, including Microsoft Word and CSV, to support review, amendment and further analysis.

Where required, data can additionally be exported via API integrations to support use in external reporting and analytics tools, such as Microsoft Power BI, for bespoke reports or dashboards. API-based integrations are optional and provided subject to agreement.
Data export formats
  • CSV
  • Other
Other data export formats
  • .PDF
  • MS Word
Data import formats
  • CSV
  • Other
Other data import formats
  • .pdf
  • MS Word

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Cascade is designed to be a highly available, cloud-hosted service. The supplier uses reasonable endeavours to ensure service availability of at least 99.9% uptime per calendar month, excluding scheduled maintenance and events outside the supplier’s reasonable control.

Scheduled maintenance is normally carried out during off-peak hours and is communicated to customers at least 48 hours in advance.

The service is hosted on Amazon Web Services (AWS) and core components are deployed across multiple AWS Availability Zones to support resilience and automated failover. Continuity and recovery processes are in place to minimise disruption in the event of service incidents.

If the availability target is not met, customers may be eligible for service credits in accordance with the supplier’s Service Level Agreement (SLA). Service credits are the sole remedy for failure to meet availability targets, as set out in the SLA.
Approach to resilience
Core service components are deployed across multiple Amazon Web Services (AWS) Availability Zones, enabling automated failover and reducing single points of failure.

The service includes regular backup processes to support data recovery. Uploaded files are stored in Amazon S3 and mirrored to a secondary bucket for resilience. Application databases are backed up on a rolling 35-day window to support recovery from data loss or corruption.

The architecture supports continuity of access during partial outages and where appropriate, read-only or fallback modes may be enabled. The service has a Recovery Time Objective (RTO) of less than 4 hours and a Recovery Point Objective (RPO) of less than 24 hours.

Continuity and recovery plans are maintained and tested at least annually to ensure the service can be restored within defined objectives.
Outage reporting
Service outages and significant incidents are communicated to customers via email notifications. Where appropriate, updates are provided until the issue is resolved.

The service does not currently provide a public status dashboard or outage reporting API. As part of ongoing service improvements, the ability to display service status information within the application (for example, via an in-application notification banner) is planned.

Identity and authentication

User authentication needed
Yes
User authentication
Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted to authorised users only and secured using strong authentication over HTTPS with TLS encryption. Role-based access controls ensure users can only gain access to functions and data appropriate to their role, with administrative privileges limited to authorised administrators.

Support access is restricted to authorised personnel and granted on a least-privilege basis when required. Support activities are logged and subject to oversight. Secure access controls and authentication requirements apply equally to internal management and support channels.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
The organisation operates a set of information security policies and processes designed to protect customer data and support the secure operation of the Cascade service. These policies are informed by Cyber Essentials Plus certification requirements and recognised UK guidance, including the NCSC Software Security Code of Practice.

Information security governance is the responsibility of senior management, who retain overall accountability for security. Day-to-day secure development practices are delivered through a UK-based development partner, with security requirements, oversight and assurance retained by the supplier.

Key policies and processes include access control, secure handling of data, incident management, backup and recovery, supplier management and secure change management. Security considerations are embedded into service design, development and operational processes.

Compliance with information security policies is supported through defined roles and responsibilities, restricted access based on least privilege, regular review of controls and independent assurance. Security incidents are reported, managed and reviewed in line with documented incident management processes.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and change management are controlled through supplier-defined processes. Service components, including application code and infrastructure, are managed using version-controlled Infrastructure as Code, allowing changes to be tracked throughout their lifecycle. Changes are developed and tested in a staging environment before deployment to production during defined release windows. All changes are assessed for potential security impact, with explicit approval required for changes affecting security or access controls. Automated checks, including static code analysis and container vulnerability scanning, are completed prior to deployment.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Potential threats to the service are assessed through automated vulnerability scanning of containerised application components during deployment and through continuous monitoring of the hosting environment. AWS-native security monitoring and alerting are used to identify suspicious activity and potential threats.

Security patches and updates are deployed as part of controlled release processes once assessed and tested, with critical vulnerabilities prioritised for prompt remediation.

Information about potential threats is obtained from automated scanning tools, AWS security services and supplier and platform security advisories. Alerts and security-relevant events are monitored by authorised personnel to enable timely response.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring uses AWS-native monitoring and alerting alongside external service monitoring tools to identify potential compromises, including abnormal behaviour, suspicious login patterns and security-relevant actions. Alerts and logs are reviewed by authorised personnel to assess legitimacy. When a potential compromise is identified, incidents are investigated and managed through defined incident response processes, which may include access restriction, configuration changes or security updates. Critical incidents are acknowledged within 30 minutes during support hours. Major incidents are communicated to users within 1 hour of identification, with resolution targeted within a 4-hour Recovery Time Objective.
Incident management type
Supplier-defined controls
Incident management approach
The organisation operates documented incident management processes for identifying, handling and resolving service incidents. Pre-defined processes are in place for common events, including service outages, security incidents and access issues.

Users can report incidents via email to the support team during support hours. Incidents may also be identified proactively through monitoring and alerting.

Incidents are logged and prioritised. Critical incidents are acknowledged within 30 minutes during support hours. For major incidents, users are notified within 1 hour of identification and provided with updates until resolution.

Incident reports summarising impact and actions taken can be provided to customers on request.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Cascade is available via a free trial, typically for 14 days.

The trial provides access to the core functionality, allowing users to explore safety case creation, management, reporting and workflows.

It excludes bespoke configuration, integrations, API access, data migration or training. Support is provided on a best-endeavours basis.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Aefcf51d-fa90-48f6-8ca7-d0e3c019fbe6
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
50f2169e-172b-4f68-ba2c-1cc442c788e6
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Understanding of issues relating to entering the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at emily.harbottle@cascade-risk.com. Tell them what format you need. It will help if you say what assistive technology you use.