Cascade Digital Safety Case and Gateway software
Cascade is a digital safety case software that enables organisations to develop and manage safety cases and Gateway applications across their lifecycle. It combines evidence management, accountability and auditability with AI-enabled safety-case checking, helping teams manage risk, demonstrate compliance and maintain confidence in safety decisions during change and ongoing operations.
Features
- Web-based digital safety case for higher-risk residential buildings
- Supports active safety case and gateway application management
- Configurable dashboards showing status, risks and outstanding actions
- Built-in report builder with version control and collaborative authoring
- Custom safety case templates to drive organisational consistency and scale
- Integrated golden thread evidence library for structured information management
- Workflow and notifications for task allocation and accountability tracking
- Full audit trail of changes, actions and user activity
- Open APIs for integration with asset, compliance, golden thread systems
- Supports creation and management of Building Safety Regulator gateway applications
Benefits
- Supports compliance with Building Safety Act safety case requirements
- Provides Accountable Persons clear visibility of building safety risks
- Creates an auditable trail of accountability and safety decisions
- Reduces risk through structured evidence and assurance
- Improves efficiency managing multiple safety cases across portfolios
- Ensures consistency in safety case content and approach
- Reduces effort and risk when preparing gateway applications
- Saves time through automated reporting linked to evidence
- Supports creation and maintenance of the golden thread
- Requires minimal training due to intuitive, user-friendly design
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 9 9 2 0 0 0 8 5 5 5 2 9 4 7
Contact
CASCADE RISK MANAGEMENT LTD
Emily Harbottle
Telephone: 07976729213
Email: emily.harbottle@cascade-risk.com
About your service
- Service categories
-
Applications
Content workflow and management
- Document
Content services
- Content Sharing and Collaboration Applications
Persuasive content management
- Digital Asset Management Applications
Enterprise portals and digital workspaces
- Integrated Employee Workspaces
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
Planned maintenance is scheduled outside normal UK working hours where possible.
Advance notice is provided for any planned service maintenance or updates.
Service access requires a modern web browser and internet connectivity.
Custom configuration or integrations are subject to agreement and availability.
Major feature changes or deprecations are communicated in advance. - System requirements
-
- Access via a modern web browser
- Optimised for laptop and desktop computers
- Reliable internet connection required
- No additional software or plugins required
User support
- Email or online ticketing support
- Yes
- Support response times
-
Cascade has a dedicated team to assist and support users of the system on a day-to-day basis. Support covers all elements of the system from general support questions and guidance, training and providing user guides, to supporting users with technical issues
All issues are directed through our dedicated Cascade support mailbox, which is monitored hourly between 0900-1700 Mon to Fri. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
The provider has assured us of the following:
Keyboard Operability: Users can navigate and interact with the chat widget using only a keyboard.
Screen Reader Support: The interface is designed to be read by assistive technology like NVDA on Windows and VoiceOver on iOS.
ARIA Attributes & Focus Rings: Proper coding allows screen readers to interpret chat elements, while visible focus indicators help users track their location.
Color Contrast: Elements are designed to meet contrast standards for visual accessibility. - Onsite support
- Yes, at extra cost
- Support levels
-
Standard support hours: Monday to Friday, 09:00–17:00 (UK time), excluding public holidays
Out-of-hours support: Available for critical service outages only
Weekend support: Critical incidents only
Incident priority and response
Support requests are prioritised based on impact and urgency:
Critical
Complete loss of service or safety case access for all users
Initial response: within 4 hours
Target restoration: as soon as practicable, with regular updates
High
Major functionality unavailable, significantly impacting users
Initial response: within 1 working day
Resolution or workaround: targeted within agreed timescales
Medium
Partial loss of functionality with workaround available
Initial response: within 2 working days
Resolution: scheduled and prioritised accordingly
Low
Minor issues, usability queries or enhancement requests
Initial response: within 3 working days
Recovery objectives
Recovery Time Objective (RTO): 4 hours for critical incidents
Support levels and cost
Standard support is included as part of the service subscription
No additional charge for incident support within standard hours
Any enhanced support arrangements or bespoke support requirements are subject to agreement
Cascade does not provide a dedicated Technical Account Manager as standard
Customers have a single, clear point of contact for support coordination - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Cascade is designed to be straightforward to adopt, with onboarding and training scaled to the needs and size of each customer.
New customers are supported through an initial onboarding process that introduces the service, confirms requirements and supports early configuration. This typically includes one or more remote onboarding sessions, provided at no additional cost, with follow-up sessions available depending on the scale and complexity of the organisation, to be agreed during the contract negotiation.
Users are supported by a range of self-service learning resources, including freely available how-to videos and a comprehensive safety case user manual. These resources support both initial use and ongoing reference.
Authorised administrators receive guidance on setting up organisational templates, workflows and reporting to ensure consistent use across teams.
Ongoing support is available through standard service support channels, and additional training or advisory services can be provided where required, subject to agreement.
For customers who require deeper understanding of safety case concepts or the Building Safety Act 2022, Cascade also offers an optional e-learning module at additional cost. This module focuses on safety case principles and regulatory context rather than system operation. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
All data held within Cascade remains the property of the customer. At the end of the contract, customers can extract their data in commonly used, non-proprietary formats.
Safety case data and structured records can be exported in CSV format and safety case content can also be provided as PDF reports. Supporting documentation and evidence files can be provided as ZIP archives.
Data exports can be made available via secure download or transferred to a customer-nominated file-sharing location, such as Microsoft OneDrive or another agreed secure file storage system.
Customers may request assistance with data export as part of contract exit support, subject to agreement. No proprietary tools are required to gain access to the exported data. - End-of-contract process
-
At contract termination, customer access to the Cascade service is closed. Customers retain ownership of all data held within the service. Standard data export is included in the contract price and allows customers to extract their data in commonly used formats, including CSV and PDF, with supporting files provided as ZIP archives. Data can be made available via secure download or transferred to a customer-nominated file-sharing location, such as Microsoft OneDrive.
Following completion of the agreed data export, customer data is securely deleted in accordance with the supplier’s data retention and security policies.
The following is included in the contract price at termination:
-Standard data export in CSV, PDF and ZIP formats
-Secure delivery of exported data
-Secure deletion of customer data after export
What may incur additional cost:
-Bespoke or complex data exports beyond standard formats
-Additional support or consultancy during contract exit
-API-based data extraction or integration support at termination
-Extended data retention beyond standard deletion timelines - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Service documentation is provided in PDF format. The documentation has not yet been formally tested against a specific accessibility standard. Where possible, documentation is produced using clear structure, headings and readable formatting. Alternative formats or reasonable adjustments can be provided on request. Accessibility of documentation will be reviewed and improved as part of ongoing service development.
As an organisation we aim to achieve WCAG 2.2 AA standards and will make improvements where that is not the case. With this in mind, we always:
Ensure PDFs are text-based, not scanned images
Use proper headings
Ensure selectable text
Add document titles
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Cascade is accessed via a secure, web-based user interface using a standard web browser. The service also provides APIs to support integration with external systems where required.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service supports keyboard navigation with visible focus indicators and logical tab ordering across core workflows. Form fields and images include associated labels and alternative text where appropriate and pages use semantic HTML with language attributes to support screen readers. Some modal interactions are not yet fully operable using keyboard-only navigation and colour contrast improvements have been identified.
- Accessibility testing
-
Accessibility testing has been undertaken using Google Lighthouse on authenticated pages within the service, achieving accessibility scores between 82 and 86. Manual keyboard navigation testing has also been completed. The service provides a visible focus indicator; however, some modal interactions are not yet fully operable using keyboard-only navigation. These issues have been identified and will be addressed as part of ongoing service improvements.
Accessibility is considered during ongoing development and improvements will be prioritised to further align with WCAG 2.2 AA guidance.
Planned improvements include enhanced keyboard operability for modal dialogs and further accessibility refinements informed by automated and manual testing with users of assistive technology. - API
- Yes
- What users can and can't do using the API
-
Cascade provides an API that enables advanced users to integrate the service with other applications. API access is available as an optional, chargeable feature and is intended for integration and data exchange rather than day-to-day user interaction.
Users can:
Integrate Cascade with external systems, such as asset, compliance or golden thread platforms
Extract safety case data for reporting or analysis
Synchronise selected data between Cascade and third-party systems
Support automated data exchange where appropriate
API access is enabled by agreement and configuration by the supplier
Setup and configuration are undertaken as part of a bespoke integration service
Integration requirements are agreed in advance based on customer needs
Subject to configuration, users can create, update or retrieve agreed data objects
Changes via the API are limited to defined integration use cases
Core service configuration and user management remain via the web interface
Limitations of the API
The API is not self-service and requires supplier involvement to configure
Not all service functionality is exposed via the API
Bespoke integrations require developer time and are charged separately
API availability and scope are defined on a case-by-case basis - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Cascade provides configurable, admin-led customisation to support organisational consistency while maintaining a standard, supported service.
What can be customised
-Organisational safety case templates, including claims and arguments
-Report layouts, content structure and organisational branding
-Application branding elements (for example logos and colour accents), presented as “powered by Cascade”
-Dashboard views and configuration options
How users can customise
-Customisation is performed through the web-based administration interface
-Templates and branding options can be configured without development work
-Changes take effect across the organisation to ensure consistent use
Who can customise
-Customisation is available to authorised administrator users
-Standard users apply approved templates but cannot modify organisational settings
Scaling
- Independence of resources
-
Cascade is delivered as a cloud-hosted, multi-tenant service designed to scale with demand. Each customer organisation is logically separated within the platform, including use of separate organisational domains and access controls.
The service is hosted on Amazon Web Services (AWS) and benefits from flexible infrastructure that can scale to accommodate variations in demand. Core services are designed to handle concurrent usage without degradation of performance for individual customers.
Usage is monitored to identify abnormal load or performance issues and operational controls are in place to ensure that excessive demand from one customer does not adversely affect others.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The service records usage and activity data to support operational monitoring and assurance. At present, service usage metrics are retrieved by the supplier from the backend and can be provided to customers on request. These metrics typically relate to service activity, such as safety case status, usage levels and recent activity.
Self-service access to usage metrics via the application interface is not currently available. Enhancements to make service usage metrics more directly visible to administrators are planned as part of ongoing software development. - Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
During the contract term, users can export data directly from the Cascade service using built-in functionality. Safety case content can be exported as PDF safety case reports via the web interface.
Where the AI safety case checker is used, outputs can also be exported in editable formats, including Microsoft Word and CSV, to support review, amendment and further analysis.
Where required, data can additionally be exported via API integrations to support use in external reporting and analytics tools, such as Microsoft Power BI, for bespoke reports or dashboards. API-based integrations are optional and provided subject to agreement. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- MS Word
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- MS Word
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Cascade is designed to be a highly available, cloud-hosted service. The supplier uses reasonable endeavours to ensure service availability of at least 99.9% uptime per calendar month, excluding scheduled maintenance and events outside the supplier’s reasonable control.
Scheduled maintenance is normally carried out during off-peak hours and is communicated to customers at least 48 hours in advance.
The service is hosted on Amazon Web Services (AWS) and core components are deployed across multiple AWS Availability Zones to support resilience and automated failover. Continuity and recovery processes are in place to minimise disruption in the event of service incidents.
If the availability target is not met, customers may be eligible for service credits in accordance with the supplier’s Service Level Agreement (SLA). Service credits are the sole remedy for failure to meet availability targets, as set out in the SLA. - Approach to resilience
-
Core service components are deployed across multiple Amazon Web Services (AWS) Availability Zones, enabling automated failover and reducing single points of failure.
The service includes regular backup processes to support data recovery. Uploaded files are stored in Amazon S3 and mirrored to a secondary bucket for resilience. Application databases are backed up on a rolling 35-day window to support recovery from data loss or corruption.
The architecture supports continuity of access during partial outages and where appropriate, read-only or fallback modes may be enabled. The service has a Recovery Time Objective (RTO) of less than 4 hours and a Recovery Point Objective (RPO) of less than 24 hours.
Continuity and recovery plans are maintained and tested at least annually to ensure the service can be restored within defined objectives. - Outage reporting
-
Service outages and significant incidents are communicated to customers via email notifications. Where appropriate, updates are provided until the issue is resolved.
The service does not currently provide a public status dashboard or outage reporting API. As part of ongoing service improvements, the ability to display service status information within the application (for example, via an in-application notification banner) is planned.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is restricted to authorised users only and secured using strong authentication over HTTPS with TLS encryption. Role-based access controls ensure users can only gain access to functions and data appropriate to their role, with administrative privileges limited to authorised administrators.
Support access is restricted to authorised personnel and granted on a least-privilege basis when required. Support activities are logged and subject to oversight. Secure access controls and authentication requirements apply equally to internal management and support channels. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
The organisation operates a set of information security policies and processes designed to protect customer data and support the secure operation of the Cascade service. These policies are informed by Cyber Essentials Plus certification requirements and recognised UK guidance, including the NCSC Software Security Code of Practice.
Information security governance is the responsibility of senior management, who retain overall accountability for security. Day-to-day secure development practices are delivered through a UK-based development partner, with security requirements, oversight and assurance retained by the supplier.
Key policies and processes include access control, secure handling of data, incident management, backup and recovery, supplier management and secure change management. Security considerations are embedded into service design, development and operational processes.
Compliance with information security policies is supported through defined roles and responsibilities, restricted access based on least privilege, regular review of controls and independent assurance. Security incidents are reported, managed and reviewed in line with documented incident management processes. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management are controlled through supplier-defined processes. Service components, including application code and infrastructure, are managed using version-controlled Infrastructure as Code, allowing changes to be tracked throughout their lifecycle. Changes are developed and tested in a staging environment before deployment to production during defined release windows. All changes are assessed for potential security impact, with explicit approval required for changes affecting security or access controls. Automated checks, including static code analysis and container vulnerability scanning, are completed prior to deployment.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Potential threats to the service are assessed through automated vulnerability scanning of containerised application components during deployment and through continuous monitoring of the hosting environment. AWS-native security monitoring and alerting are used to identify suspicious activity and potential threats.
Security patches and updates are deployed as part of controlled release processes once assessed and tested, with critical vulnerabilities prioritised for prompt remediation.
Information about potential threats is obtained from automated scanning tools, AWS security services and supplier and platform security advisories. Alerts and security-relevant events are monitored by authorised personnel to enable timely response. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring uses AWS-native monitoring and alerting alongside external service monitoring tools to identify potential compromises, including abnormal behaviour, suspicious login patterns and security-relevant actions. Alerts and logs are reviewed by authorised personnel to assess legitimacy. When a potential compromise is identified, incidents are investigated and managed through defined incident response processes, which may include access restriction, configuration changes or security updates. Critical incidents are acknowledged within 30 minutes during support hours. Major incidents are communicated to users within 1 hour of identification, with resolution targeted within a 4-hour Recovery Time Objective.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
The organisation operates documented incident management processes for identifying, handling and resolving service incidents. Pre-defined processes are in place for common events, including service outages, security incidents and access issues.
Users can report incidents via email to the support team during support hours. Incidents may also be identified proactively through monitoring and alerting.
Incidents are logged and prioritised. Critical incidents are acknowledged within 30 minutes during support hours. For major incidents, users are notified within 1 hour of identification and provided with updates until resolution.
Incident reports summarising impact and actions taken can be provided to customers on request. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
Cascade is available via a free trial, typically for 14 days.
The trial provides access to the core functionality, allowing users to explore safety case creation, management, reporting and workflows.
It excludes bespoke configuration, integrations, API access, data migration or training. Support is provided on a best-endeavours basis.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 20%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Aefcf51d-fa90-48f6-8ca7-d0e3c019fbe6
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 50f2169e-172b-4f68-ba2c-1cc442c788e6
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-