Tillr
Tillr is a UK-hosted online platform for Facilities Management, Health & Safety audits, and compliance reporting. It is highly configurable, enabling public sector organisations to align workflows and reporting with existing maintenance contracts, simplifying communication, oversight, and compliance management.
Features
- Inspection forms tailored to individual premises
- Health and safety audit workflows with configurable checklists
- Create maintenance tasks during inspections, instantly notifying your maintenance team
- Track task progress collaboratively until completion
- Monitor overdue tasks and agreed response times
- Management dashboards for real-time operational oversight
- Customisable compliance reports for audits and governance
- Central document management for certifications and compliance evidence
- Mobile-friendly access for on-site inspections and reporting
- Offline capabilities for locations with poor internet connectivity
Benefits
- Improves visibility of facilities and compliance risks
- Supports consistent statutory inspections across all premises
- Reduces delays in reporting and maintenance response
- Improves collaboration with contractors and maintenance providers
- Helps demonstrate compliance with statutory requirements
- Reduces risk of overdue or missed remedial actions
- Enables faster management oversight and decision-making
- Simplifies audit preparation and governance reporting
- Centralises compliance evidence for easier access and review
- Supports efficient on-site working without returning to the office
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 0 9 1 6 1 1 3 0 2 5 8 3 9 3
Contact
Tillr
Tim Iles
Telephone: 07915 617276
Email: g-cloud@tillr.io
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
-
- Modern web browser
- Android 6.0 or above
- IOS 15 or above
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support hours are Monday–Friday, 09:00–17:00 UK time, excluding public holidays, and weekends for critical or high issues.
● Critical (system down): Initial response within 2 business hours
● High (major function impacted): Within 4 business hours
● Medium (partial impact): Within 1 business day
● Low (minor or cosmetic): Within 3 business days - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- All customers have top-level support on the core platform. For customers with bespoke functionality, prioritised support is provided within SLAs as agreed at the point of development.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide user documentation, and can provide onsite or online training at an extra cost.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- All Forms and Tasks data can be exported in flat CSV files, compatible with Excel and other spreadsheet software. Attachments and Library files can be exported as zip files and uploaded to cloud storage, or if too large, copied to a hard drive provided by the customer and sent via recorded delivery.
- End-of-contract process
- All data export mentioned above is included in the price of the contract. Any further data exports can be arranged using purchased professional service hours. Data is then permanently erased once customer has received exports.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- All functionality is available in both mobile and desktop. Some advanced reporting features might work better in desktop browsers, due to smaller mobile screen size.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- No
- Customisation available
- Yes
- Description of customisation
- The Tillr Platform can be white-labelled and hosted on any domain owned by the customer, or a subdomain of tillr.io. Tillr is highly configurable to match your form data collection, third-party contract agreements, user access levels, report views and automated data exports. Our professional services team will configure the solution according to the customer's needs.
Scaling
- Independence of resources
- All customers have their own dedicated database in the cloud. The performance of these databases can be scaled independently. Web app is hosted on high availability CDN servers. API servers are automatically scaled up and down as per user demand.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- On the web interface, all reports can be downloaded as CSV format. Forms and Tasks data can be scheduled as a periodic data export (eg monthly).
- Data export formats
- CSV
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.5% uptime target (excluding planned maintenance and emergency fixes). If uptime drops below SLA, customer receives 0.5 days of professional services credit per affected business day, capped at 5 days per contract year.
- Approach to resilience
- Database backups are stored for 7 days, or longer by request, enabling point-in-time recovery. Backups use geo-redundant storage, to protect from datacentre failure. Further information is available on request.
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Role-based access control dictates whether a user has Admin privileges sufficient for management interfaces.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We keep server operating systems up to date, as well as third party libraries used in our software, to ensure we are patched from known vulnerabilities. We have Cyber Essentials accreditation and follow security best practices as per the Software Security Code of Practice guidance and self-assessment.
- Information security policies and processes
- Regular internal audits and annual Cyber Essentials accreditation.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All service configuration is defined as code or documented configuration and version controlled using a private source control repository. Changes are developed and tested in a non-production environment before being deployed to production.
Changes are reviewed prior to deployment to ensure they are necessary, low risk, and aligned with service requirements. Where feasible, changes are deployed using automated deployment processes to reduce the risk of human error.
Backups and rollback mechanisms are in place so that services can be restored quickly in the event of an unsuccessful change. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
The service uses supported versions of the .NET runtime and npm packages. Operating systems, frameworks, libraries and dependencies are kept up to date, with security patches applied in a timely manner based on severity and risk.
Automated dependency scanning tools (such as npm audit and .NET dependency vulnerability checks) are used to identify known vulnerabilities in third-party libraries. Security advisories from Microsoft, npm and other relevant vendors are monitored to assess potential impact on the service.
Identified vulnerabilities are prioritised, remediated or mitigated as soon as reasonably practicable, with fixes tested prior to deployment to production. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Internal data changes are tracked via audit logs; user access is logged and can be revoked if suspicious behaviour is detected.
Automated alerts are configured to notify of abnormal behaviour, availability issues, or potential security events, enabling timely investigation and response.
Logs and alerts are reviewed on a regular basis to identify unusual patterns or indicators of compromise, with escalation and investigation carried out where required. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Security incidents or service disruptions are identified through monitoring alerts, user reports (by emailing support), or routine checks. Incidents are assessed to determine severity, impact, and required response.
Appropriate actions are taken to contain, mitigate, and resolve incidents as quickly as possible, including restoring services from backup if required.
Where an incident affects customers or involves personal data, relevant stakeholders are informed in a timely manner, and any regulatory reporting obligations are met.
Following resolution, incidents are reviewed to identify root causes and lessons learned, with improvements implemented to reduce the likelihood of recurrence. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Facilities Management, Health & Safety modules: example form templates, task management, and reporting - purely for demonstration purposes only, not tailored to the customer's assets.
- Link to free trial
- https://demo.tillr.io
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Bcdab191-3787-4cb8-8175-59f939a37135
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-