TAAP Forms

This is a cloud hosted service for the purpose of delivering Digital Forms. Its is a subset of the TAAP Enterprise Applications Platform.

You can create simple, or complex applications, for one or all your digital processes.


  • Digital Forms
  • Online and Offline Operation
  • Enterprise Workflow
  • Enterprise Integration
  • Electronic Signatures
  • Business Intelligence
  • Work Management
  • Audit and Compliance Applications
  • Standardisation of Digital Processes
  • Version Managed IP and Process Updates


  • Digital Data Quality
  • Paperless Operations / Removal of Excel
  • GDPR Compliance / Data Security
  • Audit and Compliance
  • Low cost of ownership
  • Digitalise all processes within your organisation on 1 app
  • Machine Learning and Actionable Insights mining data
  • Real time reducing efficiencies
  • Create Apps in Hours and Distribute Globally
  • Connected Workforce with structured data and KPI's


£260 to £100000 per licence per year

Service documents


G-Cloud 11

Service ID

2 8 1 9 2 3 5 2 1 5 5 0 9 6 9



Steve Higgon



Service scope

Service scope
Software add-on or extension No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints No constraints known to exist. Product created from Space and Defence sector and is being constantly extended. Services provided since 2004 and applications still running, and have more and more capabilities available to them, and at no extra cost, same for the same license fees - no change since 2004.
System requirements
  • Device agnostic - Phone, Tablet, Desktop or Browser
  • Operating System agnostic - iOS, Windows, Android, Browser
  • Playtform been designed to minimise operational impacts to change
  • Designed to provide long life cycle 10-20 years without change
  • By design simplified to own and run

User support

User support
Email or online ticketing support Email or online ticketing
Support response times Standard SLA 4 hrs to respond to initial questions
User can manage status and priority of support tickets Yes
Online ticketing support accessibility None or don’t know
Phone support No
Web chat support No
Onsite support Yes, at extra cost
Support levels We provide all levels of onsite support.

Solution scoping, workshops, integration planner, system training, whatever needs/consultancy is required.
Support available to third parties Yes

Onboarding and offboarding

Onboarding and offboarding
Getting started In most cases Users are directed to a URL or App Store and applications downloaded. They are provided with a Client ID, Username and then they login. At this point the TAAP Forms technology depending upon the way in which you have configured the solution is intuitive and typically mirrors and existing digital process that they are already familiar with. We perform a lot of migrations and this is a common approach. A recent NHS GDE Hospital had a complete hospital discharge system setup in 4 weeks from initial discussion. The hospital flipped from Paper to Digital, fully live, in all wards, in four hours. The staff then took the solution and made 40+ improvements over the next 4-6 weeks as there experience and understanding of mobility grew. We provided initially Train the Trainer sessions and supporting documentation for the solution. This is a typical deployment using TAAP.
Service documentation Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction TAAP hosts your data and it would be held in your own container for security and isolation. At contract end we would assign you ownership, remove ourselves, and then you would have access to the data assets held, including Databases, Blob/File Storage, Photos etc...
End-of-contract process This varies in terms of whether you would like TAAP to adapt or change the data to a format that can be used by the new provided. In that case a charge would be levied depending upon the work required.

Using the service

Using the service
Web browser interface Yes
Supported browsers
  • Internet Explorer 7
  • Internet Explorer 8
  • Internet Explorer 9
  • Internet Explorer 10
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari 9+
  • Opera
Application to install Yes
Compatible operating systems
  • Android
  • IOS
  • MacOS
  • Windows
  • Windows Phone
Designed for use on mobile devices Yes
Differences between the mobile and desktop service We have designed the platform to appear near identical between Online and Offline operation.

However the primary difference is if the mobile is working offline.

Where possible we try to keep the functionality consistent, and the
adaptation varies based upon your business and functional requirements.
Service interface Yes
Description of service interface •Collect, connect, report and manage your data in real-time
•Fully responsive and cross-platform native mobile app enabled
•Flexible workflow that can be built and enhanced upon
•Integrate via API to any endpoint, database, ERP or CRM
•Offline data capture ability
•Route information and optimised routing based on smart calculation
•Access control to get forms to the right people
•Data Analytics providing real-time data insight
Accessibility standards None or don’t know
Description of accessibility Web Browser and API interfaces exist, this can also be extended and adapted to suit your needs.
Accessibility testing We have created clear, clean and easy to user interfaces that are compliant to the needs of many global brands and organisations. In this respect our technology has been exposed to very many different types of users, capabilities and abilities, across very many industry sectors.
What users can and can't do using the API TAAP Connect allows organisations to securely connect Back Office systems to the TAAP platform. This allows for bi-directional flow of data to / from connected systems. The API's support message based data flows, with attachments. Integration with TAAP can be very quick, and does not require any Firewall rules to be added to your firewalls. Data is securely transmitted encrypted via an SSL HTTPS link.
API documentation Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment Yes
Customisation available Yes
Description of customisation The TAAP system is a platform that can be configured to deliver all digital processes. The extent to which you configure it and adapt it relevant to each department is a based upon the complexity of what it is you are trying to achieve. Tooling is provided that allows Business Analysts publish Process IP, potential for one or more processes, that can then be deployed in a version managed fully audit controlled manner. This flexibility allows non programmers, but Excel Power Users to create forms, generate reports, and digitally e-integrate with your systems. It is the TAAP flexibility and agility that allows organisations to embrace digital transformation, create apps in hours, deploy them globally, and then continue to update them as your insights and learnings evolve and are shaped by the data that you collect back into the system.


Independence of resources Yes, you have an isolated version of the solution for your requirements and loading demands.


Service usage metrics Yes
Metrics types •CPU
•HTTP request and response status
•Number of active instances
•Application KPI's (Customisable)
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request


Supplier type Not a reseller

Staff security

Staff security
Staff security clearance Other security clearance
Government security clearance Up to Developed Vetting (DV)

Asset protection

Asset protection
Knowledge of data storage and processing locations Yes
Data storage and processing locations United Kingdom
User control over data storage and processing locations No
Datacentre security standards Managed by a third party
Penetration testing frequency At least every 6 months
Penetration testing approach Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v3.0
  • Physical access control, complying with SSAE-16 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process No
Equipment disposal approach A third-party destruction service

Data importing and exporting

Data importing and exporting
Data export approach Access to the data can be via Web Browser with Excel/CSV exports, or API's for querying and extracting data. This can be delivered to suit your requirements.
Data export formats
  • CSV
  • Other
Other data export formats
  • SQL Direct
  • JSON
  • XML
  • Flat File
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • XML

Data-in-transit protection

Data-in-transit protection
Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Bonded fibre optic connections
  • Legacy SSL and TLS (under version 1.2)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)

Availability and resilience

Availability and resilience
Guaranteed availability We host on the Microsoft Azure Platform, and they offer 99.999% resilience. We don't offer credits, this is something Microsoft does not provide.
Approach to resilience The TAAP platform is a stateless scalable platform. The application utilises as much of the device local processing capabilities as can be sensibly utilised, with degrade not crash modality. The Web Platform is scalable based upon load/throughput to provide responsiveness, with middle tier functions, and database worker roles and queuing to be elastic.
Outage reporting Public Dashboard, the Azure Service Status Dashboard

Identity and authentication

Identity and authentication
User authentication needed Yes
User authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels Role and Function based security access User based data and functional access
Access restriction testing frequency At least every 6 months
Management access authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Audit information for users
Access to user activity audit information Users have access to real-time audit information
How long user audit data is stored for At least 12 months
Access to supplier activity audit information Users have access to real-time audit information
How long supplier audit data is stored for At least 12 months
How long system logs are stored for At least 12 months

Standards and certifications

Standards and certifications
ISO/IEC 27001 certification No
ISO 28000:2007 certification No
CSA STAR certification No
PCI certification No
Other security certifications No

Security governance

Security governance
Named board-level person responsible for service security Yes
Security governance certified Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards We are working towards ISO/IEC 27001 internally at TAAP Microsoft is ISO/IEC 27001 - and they manage the data, security, DR, physical access security and alike
Information security policies and processes We are working towards ISO/IEC 27001 internally at TAAP

Operational security

Operational security
Configuration and change management standard Supplier-defined controls
Configuration and change management approach We operate a full Lifecycle Change Control Review Board. The product CR's or Client CR's are reviewed, agreed, scheduled, tested and then made available for release. Customers then optin for the upgrade.
Vulnerability management type Supplier-defined controls
Vulnerability management approach Microsoft provides this capability as part of the service They also provide patches to close vulnerabilities We are often advised of threats post fix to avoid Zero day vulnerabilities This is why we use the Azure platform for that level of resilience
Protective monitoring type Supplier-defined controls
Protective monitoring approach We run external monitoring functions for our clients This highlights any vulnerabilities to the OS and Application Stack If we identify any issues then we react to resolve based upon the recommendations provided by the supporting tools Depending upon the criticality of the issue we take appropriate action to ensure the issue is resolved in a timely manner and not make matters worse
Incident management type Supplier-defined controls
Incident management approach We have an internal policy and governance approach to classification, impact and reporting.

Secure development

Secure development
Approach to secure software development best practice Conforms to a recognised standard, but self-assessed

Public sector networks

Public sector networks
Connection to public sector networks No


Price £260 to £100000 per licence per year
Discount for educational organisations No
Free trial available No

Service documents

Return to top ↑