Stroma Certification Ltd

Formation Software

Formation Software is a self-serve digital form generator which adapts to your business and individual processes. Link your organisation's field and office based operations. You can collect data efficiently and securely on an iPad or Android tablet and Android phone. Suitable for use in any industry.

Features

  • Mobile Data Capture
  • Dynamic Form Design
  • Real-time Reporting
  • Multi Language Support
  • Automated Data Processing
  • Work Management System
  • Secure Audit and Evidence Capture
  • Full Off-Line Functionality
  • Store Local Data Sets
  • Conditional Logic

Benefits

  • Capture all data on any device
  • Update data capture forms quickly and instantly publish changes
  • Streamlined data capture
  • Send information and data in real time to field staff
  • Third party integration
  • Capture on site data quickly
  • Reduce paperwork with digital forms
  • Improve departmental efficiency
  • Improved data quality and data security
  • Improved communication between the field and main office

Pricing

£7500 per licence

  • Free trial available

Service documents

G-Cloud 9

951164030684192

Stroma Certification Ltd

Stuart Oakes

08456211111

s.oakes@stroma.com

Service scope

Service scope
Software add-on or extension Yes, but can also be used as a standalone service
What software services is the service an extension to DocuWare
Cloud deployment model Private cloud
Service constraints There is substantial flexibility, capacity and scalability in both the Formation Management Studio back office platform and the Formation mobile application. Upgrades will be made as required to support device OS upgrades and our track record is excellent for delivery software upgrades in accordance with Apple and Android developments. Maintenance arrangements can be discussed with individual clients and any software updates will be conducted to minimise disruption.
System requirements None

User support

User support
Email or online ticketing support Yes, at extra cost
Support response times All support requests are logged and given a designation according to the severity of the issue. Specific response times and SLAs can be determined and agreed during discussions with the client.
User can manage status and priority of support tickets No
Phone support Yes
Phone support availability 9 to 5 (UK time), Monday to Friday
Web chat support No
Onsite support Yes, at extra cost
Support levels Support and Development resources are based in Castleford, including CRM and back office systems. Phone and helpdesk support is available during normal business hours. Mobile application and Field based operative development and support is based in Castleford, West Yorkshire and is available via Phone and Helpdesk (08:00-19:00 Monday-Friday). Second and third line support services are also available via the same location, with a dedicated Account Manager based at Castleford.
Support available to third parties Yes

Onboarding and offboarding

Onboarding and offboarding
Getting started During the initial System set-up, training will be provided to Authorised Users as instruction in the use of the software. Subsequently, we will tailor training courses appropriately to identified requirements.

Formation Software is extremely user-friendly in both the back office and mobile applications. Stroma Software will provide full training for all office and field based users to ensure full understanding prior to system implementation.
Service documentation Yes
Documentation formats PDF
End-of-contract data extraction All data will be made available to the client in a format requested by them. Back-up and destruction processes will be adhered to in line with the requirements of our ISO 27001 management policy.
End-of-contract process This can be determined during discussions with the individual client. Data transfer and handover will be carried out securely according to the client's requirements.

Using the service

Using the service
Web browser interface Yes
Supported browsers
  • Internet Explorer 7
  • Internet Explorer 8
  • Internet Explorer 9
  • Internet Explorer 10+
  • Firefox
  • Chrome
  • Safari 9+
Application to install Yes
Compatible operating systems
  • Android
  • IOS
  • Windows
Designed for use on mobile devices Yes
Differences between the mobile and desktop service Formation Management Studio is used to store all form data and create bespoke forms. Formation Mobile is used for on site data collection.
Accessibility standards None or don’t know
Description of accessibility Formation Management studio, the back office application used to manage users and data runs on Windows .Net framework so is accessible to any Windows user. FMS is not access by field users, administrators use the platform to configure the data capture, manage submitted data and any integration connections for the subsequently submitted data.
Accessibility testing All applications run nativity on each device leading to functionality being as expected on each platform. UX and UI focus groups and workshops have been held continually through the product life cycle ensuring a consistent and intuitive design
API Yes
What users can and can't do using the API Accredited Partners and customers can take advantage of the Formation API to build an integrated solution that meets their requirements and incorporates existing IT systems. The Formation API uses a REST web service to provide a range of functions for integration.

Proprietary integrations into Database technology (SQL and MySQL), Document Management solutions and CRM/ERP also exist.
API documentation Yes
API documentation formats PDF
API sandbox or test environment Yes
Customisation available Yes
Description of customisation Super users have the ability to create bespoke forms within the software. Forms can be created which are digital replicas of traditional paper based documents to enable digital data collection.

The solution is designed as a 'Zero Code' product allowing superusers access to customise and configure all elements inside the solution

Scaling

Scaling
Independence of resources There are no usage restrictions in Formation Software

Analytics

Analytics
Service usage metrics Yes
Metrics types Management reporting and analysis is provided by SQL Reporting Services (SSRS). SSRS is a leading reporting platform provided by Microsoft, delivering a range of reporting functionality. This includes automated reports, subscription reporting, web portal and embedded application reporting.
Reporting types
  • Regular reports
  • Reports on request

Resellers

Resellers
Supplier type Not a reseller

Staff security

Staff security
Staff security clearance Staff screening not performed
Government security clearance Up to Developed Vetting (DV)

Asset protection

Asset protection
Knowledge of data storage and processing locations Yes
Data storage and processing locations United Kingdom
User control over data storage and processing locations Yes
Datacentre security standards Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency At least once a year
Penetration testing approach Another external penetration testing organisation
Protecting data at rest Physical access control, complying with CSA CCM v3.0
Data sanitisation process Yes
Data sanitisation type Deleted data can’t be directly accessed
Equipment disposal approach Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data importing and exporting
Data export approach Data can be imported/exported into the solution using the API, facilities are also given for scripting import/Export facilities. Simple import/export can be achieved via csv/xml format.
Data export formats
  • CSV
  • Other
Other data export formats API - XML/Json
Data import formats CSV

Data-in-transit protection

Data-in-transit protection
Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network TLS (version 1.2 or above)

Availability and resilience

Availability and resilience
Guaranteed availability Formation is designed to be operational 24 hours a day, 7 days a week. Specific SLAs can be discussed and determined by the client. This would include arrangements for refunds in the event of any part of the service being unavailable for a given period of time which contravened one or more of the SLAs.
Approach to resilience This is available on request.
Outage reporting Any outages or service disruptions will be communicated to clients via email.

Identity and authentication

Identity and authentication
User authentication needed Yes
User authentication Username or password
Access restrictions in management interfaces and support channels Managers can be assigned administrative privileges in the Formation Management Studio. They would be determined as Super Users with the ability to create forms, assign forms and create additional users. Additional privileges can also be determined to restrict access to individual forms and functions on the Formation mobile application.
Access restriction testing frequency At least once a year
Management access authentication Username or password

Audit information for users

Audit information for users
Access to user activity audit information Users receive audit information on a regular basis
How long user audit data is stored for User-defined
Access to supplier activity audit information Users receive audit information on a regular basis
How long supplier audit data is stored for User-defined
How long system logs are stored for User-defined

Standards and certifications

Standards and certifications
ISO/IEC 27001 certification Yes
Who accredited the ISO/IEC 27001 QMS International
ISO/IEC 27001 accreditation date 17/01/2013
What the ISO/IEC 27001 doesn’t cover N/A
ISO 28000:2007 certification No
CSA STAR certification No
PCI certification No
Other security accreditations No

Security governance

Security governance
Named board-level person responsible for service security Yes
Security governance accreditation Yes
Security governance standards ISO/IEC 27001
Information security policies and processes Stroma complies with the requirements of ISO 27001. Our objectives and reporting structure is enshrined within our information security policy. This policy applies to all business functions within Stroma to include information systems, networks, the physical environment and people. A copy of our information security policy can be provided on request. Overall responsibility for information security rests with the Managing Director.

Operational security

Operational security
Configuration and change management standard Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach Any changes to the software are fully documented in release notes which communicated to all clients prior to any software updates. These are issued in line with the contract management and document control procedures set out in our ISO 9001-accredited Quality Management System.

An established review process ensures that the client’s needs and requirements are adequately understood, defined, and documented; that we have the capability and resources to meet the requirements and that they are met throughout the term of the contract. Records of the review are maintained. Changes and amendments are documented and communicated to all relevant staff.
Vulnerability management type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach Our Incident Management Plan addresses disruptions to premises, ICT systems, data, staff and equipment, which is enshrined within our Quality Management System. This includes responsibilities and procedures when an incident poses a risk to continuous service delivery (based on comprehensive risk assessment). It helps the company recover quickly and effectively from an unforeseen disaster or emergency. It is reviewed on an annual basis.

Data is continuously replicated across multiple geographically dispersed data centres, resulting in a minimum recovery point objective of 10 seconds. Full backups are completed according to client requirements.
Protective monitoring type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach PMA processes are conducted in line with industry best practice along with physical threat protection on all servers and external services where tracking and logging of all connections and interactions takes place.

The data is held in a format that can be used to analyse access in an audit situation – users have access to this via the User Interface.
Incident management type Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach Our Incident Management Plan addresses disruptions to premises, ICT systems, data, staff and equipment, which is enshrined within our Quality Management System. This includes responsibilities and procedures when an incident poses a risk to continuous service delivery (based on comprehensive risk assessment). It helps the company recover quickly and effectively from an unforeseen disaster or emergency. It is reviewed on an annual basis. Data is continuously replicated across multiple geographically dispersed data centres, resulting in a minimum recovery point objective of 10 seconds. Full backups are completed according to client requirements.

Secure development

Secure development
Approach to secure software development best practice Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Public sector networks

Public sector networks
Connection to public sector networks No

Pricing

Pricing
Price £7500 per licence
Discount for educational organisations No
Free trial available Yes
Description of free trial Formation is available to trial for 60 days, with use of the standard package for up to 10 users. It allows users to build up to 3 forms on Android, iOS or Desktop. A minor fee of £550 covers training and configuration.

Documents

Documents
Pricing document View uploaded document
Terms and conditions document View uploaded document
Return to top ↑