Cataphract

Pre Employment and Security Vetting Cloud Platform

Pre Employment Screening and Security Vetting services (BS7858, BPSS and CTC/SC) online platform to accept, run, manage and store your vetting checks.

Built for companies managing a large number of Security Clearances, looking to build in efficincies to their business.

Features

  • Customizable applicant data capture session by admin user.
  • Easily track and manage screening and vetting, up to SC
  • Dashboard reminders for all clearance renewals
  • Auto populate emails and letters to speed vetting
  • Send auto emails based on renewal
  • Various login levels to specific user groups and roles
  • In-built DBS E-Bulk function to prevent multiple data entry
  • Powerful search and data export function across system
  • Automatic reference manager from data entered by applicant
  • Built by a company specialising in security vetting.

Benefits

  • Start an applicants vetting for CTC/SC in 4 minutes.
  • New User Interface and excellent experince
  • Never lose an applicants screening with our unique dashboard
  • Automated form completion to speed up vetting
  • Self Auditing email communication log.
  • Self creating applicant interview sessions and application forms.
  • User friendly 'Content Management' section to customise
  • Extensive Employee search fuction by various filters and features
  • Export to excel for further analysis
  • Quickly review a locations clearance requirement throug Dash

Pricing

£1 to £500 per person per month

Service documents

Framework

G-Cloud 11

Service ID

7 5 9 4 8 4 8 6 9 8 7 4 9 9 4

Contact

Cataphract

David Clark

02080690505

david@cataphract.co.uk

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
No
System requirements
  • Up to date, modern web browser
  • Laptop, iPad and Iphone friendly.

User support

Email or online ticketing support
Email or online ticketing
Support response times
Within 24 hours for a query on the software and 48 hours if you report a bug or error about the platform
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support comes in the form of a project setup cost, often on site customising the platform to the users requirement.

There will be a small quarterly support fee post project setup.
Support available to third parties
No

Onboarding and offboarding

Getting started
We understand each new client has a different requirement from the platform, so Cataphract will guide you through your onboarding, through off site platform content creation defined through the induction process. Then onsite training if possible to enable staff to get the most from the platform.

We have build the platform for the user to be able to change nearly all of the key vetting data aligned to their company. Once you are through the system setup phase, Cataphract will happily assist refine and develop the platform to make it work for you.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
The key administorator has the ability, with Cataphract to download in csv format the key data thats included on the platform. We understand this data is your and will do everything to hand over when the contract ends.
End-of-contract process
There is not additional cost to extract the data held on the platform and system. We will assist as much as possible to ensure you are able to retrieve the data you require.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari 9+
Application to install
No
Designed for use on mobile devices
No
Service interface
No
API
No
Customisation available
Yes
Description of customisation
Customers purchase access to a blank service within the platform and can customise the following

Email content
Downloadsble, pre filled form content
Employees Cost Centres
Employee Location
Statuses like absenses and reasons
Special Flags and Codes
Creat various and different applicant interview application forms
Make their own fees if chargeing for vetting
Log timesheets from users for work delivered through the platform.

Scaling

Independence of resources
We have enough bandwidth and dedicated server space to manage scale if the platform develops and grows in the coming years. We have a dedicated Data Centre with pre purchased space to grow.

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2012
Government security clearance
Up to Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
Yes
Data sanitisation type
Deleted data can’t be directly accessed
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
Only certain users can export volume amounts od data, restricing the opportunity to donwload volumes of data. You can extract all or as much data as possible onto a CVS file with the right access control.
Data export formats
CSV
Data import formats
  • CSV
  • Other
Other data import formats
Upload is with assistance with our developer at cost.

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We have a dedicated server with local backups to ensure uptime. We commit to clients planned downtime will be well informed before and if there is unforeseen downtime, this is restricted to resolution in 2 hours.
Approach to resilience
Available on Request
Outage reporting
Email alerts and immediate communication with our clients.

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Username or password
Access restrictions in management interfaces and support channels
Only requested, proven emplioyees of Cataphract and our clients are able to receive user logins. Read only is encouraged across all levels, as the vetting managers should be the only ones making ammendments to the platform
Access restriction testing frequency
At least once a year
Management access authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
QMS
ISO/IEC 27001 accreditation date
10/8/2017
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Other security certifications
Yes
Any other security certifications
  • ISO 9001
  • Cyber Essentials

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
All key staff at Cataphract are security cleared to SC level and have extensive experience implementing and following security policies. Only staff with correct access can see relevant data. We have a flat security Hierarchy with a defined reporting line if there were to be an issue.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We have a cautious approach to changing the platform and ensure that we plan, test and re test any changes to the system. Our IT Team and Directors will agree the changes to be made outside of work hours to ensure uptime.
Vulnerability management type
Undisclosed
Vulnerability management approach
We have a dedicated IT function that liaise with out penetration test company tio ensure we have the most secure system possible. Because of the type of business we operate in, we do not publiclly want to discuslose further.
Protective monitoring type
Undisclosed
Protective monitoring approach
We will liaise with our dedicated IT function and Penetration test company to ensure we have had the forethought to predict any compromises. If we do find a compromise, we will follow the GDPR rules and follow all correct steps set out in our policy.
Incident management type
Undisclosed
Incident management approach
We have pre defined policy and procedure in relation to incident managment that clients agree to and will follow if there is a major incident focused to the platform.

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Public sector networks

Connection to public sector networks
No

Pricing

Price
£1 to £500 per person per month
Discount for educational organisations
No
Free trial available
No

Service documents

Return to top ↑