
Kick-Off and Project Planning
Begin with a kick-off call to align on project goals, stakeholders, timelines, and key deliverables.
Assign an Evotix Customer Implementation Consultant and establish your internal project team (Project Lead, Key Decision Maker, System Expert).
Orientation and Requirements Gathering
Receive a high-level orientation of the Evotix platform and access to self-learning resources.
Conduct configuration workshops to review detailed requirements and map out your organization’s specific needs.
System Configuration and Customization
Collaborate with Evotix to configure the system, including forms, permissions, workflows, and reports.
Make iterative adjustments based on feedback, with hands-on training for your team to support ongoing configuration.
User Acceptance Testing (UAT)
Coordinate and execute UAT to validate that the system meets your requirements.
Address any final adjustments or refinements based on test outcomes.
Training and Knowledge Transfer
Deliver tailored training sessions for administrators and end users, often via webinars or interactive tutorials.
Provide recorded sessions and reusable resources for future reference.
Go-Live and Phased Rollout
Approve the system for rollout and begin phased deployment to users or business units.
Encourage early adoption and provide ongoing support during the initial launch period.
Post-Implementation Support
Transition to ongoing support with a dedicated Customer Success Manager and technical support team.
Evotix is designed with a high degree of configurability to meet the unique requirements of organizations across industries. Here are the primary ways Evotix can be customized to fit specific business needs:
Drag-and-Drop Form Builder: Create, edit, and deploy unlimited custom forms for incident reporting, audits, inspections, and more, using a drag-and-drop interface.
Custom Fields: Add, remove, or modify fields in forms to capture the exact data your business requires.
Workflow Customization: Design approval and review workflows, including escalations and automated notifications, tailored to your operational structure.
Custom Dashboards: Design, create, and share dashboards and visualizations that reflect your organization’s KPIs, compliance status, and risk profile.
Customizable Reports: Alter the layout, content, and structure of reports to match your reporting standards and regulatory requirements.
Quick Search Columns: Customize which fields appear in quick search results for faster access to relevant information.
System Email Templates: Edit and personalize system-generated emails (reminders, notifications, data imports) by language, region, or business unit. Add custom text, links, and branding elements.
Localization: Customize emails and forms for different regions or regulatory environments (e.g., OSHA compliance in the US).
Role-Based Permissions: Set granular access controls for users, teams, or departments, ensuring sensitive data is only accessible to authorized personnel.
GDPR and SSO Settings: Configure system and user permissions to align with privacy and security policies.
Configurable Homepage: Personalize the homepage layout and shortcuts for different user groups, making the most relevant modules and actions easily accessible.
Custom Navigation: Adjust menus and user journeys to align with your business processes.
Custom Document Templates: Create and manage templates for policies, procedures, and compliance documents, ensuring consistency and regulatory alignment.
Learning Content: Upload and organize custom training materials, including videos, articles, PDFs, and SCORM files, to support unique learning journeys.
Third-Party Integrations: Connect Evotix with other business systems (e.g., Microsoft Teams, SAP, Salesforce) via APIs and connectors for seamless data flow.
API Access: Use the API sandbox or test environment for advanced custom integrations.
Mobile App Customization: Configure mobile forms, notifications, and offline capabilities for field-based teams.
Multilingual Capabilities: Customize forms, emails, and system prompts in multiple languages to support global teams.
Tailored Solutions: Evotix can be configured for industry-specific needs, such as construction, healthcare, manufacturing, and more, adapting forms, workflows, and reporting to sector regulations and practices.
Scalability: The platform evolves with your business, supporting new processes, locations, or regulatory requirements as you grow.
Custom Shortcuts: Add shortcuts to frequently used modules or actions for each user or team.
Kick-Off and Orientation: New users begin with a project kick-off call and a high-level orientation of the Evotix platform, supported by a Customer Implementation Consultant and a dedicated project team.
Configuration Workshops: A series of collaborative workshops are held to tailor the system to your organization’s needs. During these sessions, users receive hands-on training in configuration tools and system setup.
User Acceptance Testing (UAT): Evotix guides your team through UAT to ensure the solution meets your requirements before going live. Training continues as adjustments are made based on feedback.
Phased Rollout: Implementation is typically phased, allowing organizations to realize value quickly and expand usage over time. The process can be as fast as 4 weeks for focused deployments, with most projects completed in 12–36 weeks, depending on complexity and engagement.
Administrator and User Training: Evotix recommends 4 hours of administrator training and 4 hours of user training, customizable to your organization’s needs. Training is delivered via live webinars, which can be recorded for future reference, and interactive video tutorials.
Self-Learning Resources: All licensed users have access to an extensive knowledge base with help videos, articles, and documentation for ongoing self-service learning.
E-Learning and Microlearning: The platform includes a scalable e-learning solution with video-based training, multilingual content, quizzes, and gamification features. Organizations can upload their own content or use Evotix’s library of accredited courses.
Evotix EHS Academy: New users can access the Evotix EHS Academy, which offers practical, micro-learning courses and toolkits for EHS professionals, leaders, and change-makers, focusing on both technical skills and leadership development.
Customer Success Squad: Each customer is supported by a dedicated “squad” of Evotix experts, including a Customer Success Manager, who guides implementation through ongoing optimization.
Help Desk and Ticketing: Support is available via online ticketing, with standard response times of 4 hours (or 3 hours for premium support). Phone and web chat support are available during UK business hours, with onsite support offered at extra cost.
Case Management: All support requests are tracked through a structured case management system, with escalation from first-line to specialist support as needed.
Knowledge Base and Documentation: Users have access to a comprehensive library of service documentation, FAQs, and recorded training sessions.
Evotix employs a multi-layered approach to data security, ensuring the confidentiality, integrity, and availability of customer and user information. Below are the key security measures implemented by Evotix:
Encryption in Transit: All data transmitted between users and the Evotix platform is encrypted using SSL/TLS protocols (TLS 1.2 or above), ensuring secure communication and preventing interception by unauthorized parties.
Encryption at Rest: All data stored within the Evotix platform, including databases, backups, and attachments, is encrypted at rest using industry-standard AES-256 encryption.
AWS Data Centers: Data is hosted in highly secure Amazon Web Services (AWS) data centers, which are ISO 27001 certified, providing robust physical and environmental security controls.
High Availability: Database servers operate in high availability mode, with real-time replication to prevent data loss and ensure business continuity.
Principle of Least Privilege: Access to customer data is strictly limited to authorized personnel based on their roles and responsibilities. Permissions are managed to ensure only those who need access for support or development have it, and all access is logged and monitored.
Role-Based Permissions: User access within the platform is governed by role-based access controls, ensuring sensitive data is only accessible to those with appropriate permissions.
Authentication: Forms-based authentication is enforced, with support for strong password policies and secure key exchange mechanisms (ECDHE with RSA keys).
ISO 27001 Certification: Evotix is certified to the ISO 27001 standard for information security management, demonstrating a rigorous approach to data protection and risk management.
Cyber Essentials Certified: The platform is also Cyber Essentials certified, further validating its security posture.
GDPR Compliance: Evotix complies with the General Data Protection Regulation (GDPR), including support for data subject access requests, data export, and deletion. A Data Protection Officer (DPO) oversees compliance and reports to senior management.
HTTPS-Only Access: All application service requests are restricted to HTTPS, ensuring secure access to the platform.
DDoS and Intrusion Prevention: The platform employs Distributed Denial of Service (DDoS) prevention and Intrusion Detection Systems (IDS) to protect against external threats and unauthorized access attempts.
Vulnerability Management: Continuous monitoring and vulnerability testing are conducted, with prompt patching and remediation based on risk assessment.
Data Controller/Processor Roles: Customers retain ownership of their data (as Data Controllers), while Evotix acts as a Data Processor, handling data only as required for service delivery and support.
Geographic Data Restrictions: Customers can restrict the geographies in which their data is processed to meet regulatory or organizational requirements.
Data Destruction Policy: Upon contract termination, data is securely destroyed by documented policies, ensuring no unauthorized retention.
Continuous Monitoring: Systems are automatically monitored for abnormal behavior, with alerts sent to the security operations team for investigation.
Incident Management: A formal incident management process, assessed annually as part of ISO 27001 certification, ensures rapid response and notification in case of security events.
Audit Trails: All access to data and critical actions are logged for accountability and traceability.
Best Practice Development: Secure software development practices are followed, with independent reviews and adherence to standards such as ISO/IEC 27034 and ISO/IEC 27001.
Biweekly Releases: Evotix releases updates to its platform every two weeks. These updates include bug fixes, new features, and other enhancements to improve system performance and functionality.
Continuous Improvements: The platform is under active development, with ongoing improvements based on customer feedback and evolving EHS and ESG requirements.
Planned Maintenance: Scheduled maintenance and updates are performed outside of standard working hours to minimize disruption to users. Planned maintenance events are communicated in advance, and do not count against the platform’s uptime guarantees.
Change Management: Evotix follows an ISO 27001-compliant change management process. All configuration and system changes are independently reviewed and risk-assessed before deployment, ensuring updates are secure and reliable.
Vulnerability Management: The platform employs continuous monitoring tools to identify vulnerabilities, with a risk-based approach to patching and remediation. This ensures the software remains current and protected against emerging threats.
Customer Support Integration: All update-related issues, questions, or requests for change are managed through a centralized Help Desk and case management system. Support tickets are tracked, investigated, and escalated as needed to ensure timely resolution.
Transparent Communication: Users are notified of upcoming updates, maintenance windows, and new features through release notes and direct communications, ensuring transparency and preparedness for any changes.
High Availability: Evotix operates with a 99.9% uptime service level agreement (SLA), with exceptions only for planned maintenance or force majeure events.
Customer as Data Owner: When using Evotix software (including the Assure platform), all data entered or uploaded by the customer remains the property of the customer. Evotix acts as a Data Processor, while the customer is the Data Controller.
No Unauthorized Use: Evotix does not sell or use customer data for its own purposes. Access to customer information is strictly limited to authorized personnel for defined support or technical processes, and is managed under the Principle of Least Privilege (PoLP).
Compliance and Security: Evotix is registered as a data controller with the UK Information Commissioner's Office and is certified to ISO 27001. The company has a dedicated Data Protection Officer and employs technical and organizational measures to prevent unauthorized access, maintain data accuracy, and secure all personal data.
Right to Data Access and Export: Customers can request access to their data at any time. Evotix supports the ability to export personal data in structured, machine-readable formats, in line with GDPR requirements.
Support for Data Subject Requests: The Evotix platform and support team assist customers in fulfilling Data Subject Access Requests (DSARs), including data export and deletion, to ensure compliance with privacy regulations.
Geographic Restrictions: Customers may restrict the geographies within which their data is processed, supporting compliance with regional data protection laws.
Evotix is designed to support organizations as their needs evolve, offering flexibility to scale the platform up or down in line with changes in size, complexity, or operational requirements. Here’s how scaling is managed:
Tiered Licensing: Evotix solutions (such as Assure and Learn) are typically priced based on the number of users or licenses. Organizations can increase or decrease user counts to match workforce changes. For example, pricing packages may start at a set number of user licenses (e.g., 500 users), with the ability to add more as needed.
User Management: Admins can manually add, deactivate, or delete user accounts at any time, allowing for quick adaptation to organizational changes such as onboarding new teams or downsizing.
API Automation: For larger organizations, user management can be automated via the Customer API, enabling bulk updates, onboarding, and deactivation of users as business needs shift.
Annual Subscription Model: Most Evotix solutions operate on an annual subscription basis, with clear terms for increasing or reducing user licenses at renewal or during the contract period.
Scaling Up: If your organization grows, you can contact Evotix to increase your license count or upgrade your package. Pricing is adjusted accordingly, and additional implementation or training support is available for larger deployments.
Scaling Down: If your needs decrease, you may reduce the number of licenses at contract renewal. It is recommended to notify Evotix in advance of your renewal date to ensure adjustments are reflected in your next billing cycle.
No Long-Term Lock-In: Contracts are typically annual, allowing organizations to reassess and adjust their subscription each year without long-term commitment.
Inclusive Change Management: Ongoing change management support is included, covering user onboarding, configuration adjustments, and bulk updates as your organization scales up or down.
Customer Success Planning: Each client receives a customer success plan to guide scaling, adoption, and ROI measurement, ensuring the platform continues to meet changing business needs.
Automatic Updates: Maintenance and system updates are included, ensuring that scaling up or down does not disrupt service or require downtime.
Automatic Renewal: Evotix subscriptions typically renew automatically for additional periods equal to the original term (commonly one year) unless either party provides written notice of non-renewal before the end of the current term.
Notice Period: To prevent automatic renewal, written notice must be given by either party within the timeframe specified in the contract (often 30 days before the renewal date, but this can vary by agreement).
Renewal Terms: Renewals are generally at the same terms and pricing as the original contract unless Evotix notifies the customer in advance of any changes. Any updated terms or price increases are communicated prior to the renewal period.
Review and Renegotiation: Both parties may review and renegotiate contract terms at renewal, including service levels, pricing, and scope. This allows for adjustments based on evolving business needs, performance, or regulatory changes.
Contract Amendment: If changes are agreed upon during renewal discussions, an amendment or new contract is signed to reflect the updated terms.
Termination for Non-Renewal: If either party decides not to renew, the contract will expire at the end of the current term, and services will cease unless otherwise agreed.
Cancellation by Customer: Customers may cancel their subscription by providing written notice, typically within the notice period defined in the contract (commonly 30 days before the end of the term).
No Refunds for Early Termination: Fees already paid for the current subscription period are generally non-refundable, even if the contract is cancelled before the term ends. Customers retain access to the service until the end of the paid period.
Termination for Breach: Either party may terminate the agreement immediately (or after a specified cure period) if the other party materially breaches the contract and fails to remedy the breach within the allowed time.
Termination for Convenience: Some contracts may allow termination for convenience by providing advance written notice (notice period specified in the agreement), though specific terms should be reviewed in the contract.
Data Access and Migration: Upon cancellation or contract end, customers should request data export or migration within a specified period (often 10 days after contract end), after which data may be deleted from Evotix systems.
Evotix software is designed to meet a set of international compliance standards, ensuring robust data security, privacy, and operational integrity for organizations managing EHS (Environmental, Health, and Safety) and ESG (Environmental, Social, and Governance) processes.
ISO/IEC 27001 Certified: Evotix is certified to the ISO/IEC 27001 standard for information security management systems (ISMS), demonstrating strong controls over the confidentiality, integrity, and availability of customer data.
Cyber Essentials Certified: The platform holds the UK Cyber Essentials certification, which validates its protection against common cyber threats and adherence to security best practices.
ISO 9001 Certified: Evotix is also certified to ISO 9001, the international standard for quality management systems, ensuring consistent service delivery and continuous improvement.
GDPR Compliance: Evotix is fully compliant with the General Data Protection Regulation (GDPR), supporting data subject access requests, data export and deletion, and providing tools for customers to manage their data processing obligations.
Data Controller Registration: The company is registered as a data controller with the UK Information Commissioner’s Office (ICO), ensuring accountability and transparency in data handling practices.
AWS Secure Hosting: All data is hosted in highly secure Amazon Web Services (AWS) data centers, which themselves are ISO 27001 certified, providing robust physical and environmental security controls.