StarGo
End to end solution for the application and management of highways licenses and permits.
Features
- Online account to apply, renew and pay for permits
- Back office solution to process and manage applications
- Process Skips, Scaffold, Hoarding, TTRO, Crane, Section 50 and more
- Upload documentation to support permit applications
- Integration with payment providers e.g. World Pay
- View expired permits on smartphone map for targeted enforcement
- Reminder for renewal of relevant permits and licenses
- Report builder for detailed management information
- Automated customisable emails for back office staff
- View the status of ongoing permit applications
Benefits
- One solution for license and permit processing
- Minimal setup time and deployment costs
- Reduce staff processing time and costs
- Monitor and maximise staff performance
- Capture revenue upfront, reduce invoicing effort, and prevent missed revenue
- Integration with online payment gateways
- Eliminate manual data re-keying
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 5 3 1 4 6 8 9 8 1 7 7 5 0 5
Contact
POLARIS SOFTWARE SOLUTIONS LIMITED
Richard Gorringe
Telephone: 441295273000
Email: tenders@polarissoftware.com
About your service
- Service categories
-
Application Development and Deployment
Data management
Data integration and intelligence
- Data Ingestion and Transformation Software
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- None
- System requirements
-
- Up to date versions of Microsoft Edge
- Up to date versions of Google Chrome
- Up to date versions of Mozilla Firefox
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support response times are based on priority. For Example:
High Priority - 60 minutes
Medium Priority - 120 minutes
Low Priority - 240 minutes" - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We offer a fully comprehensive support and maintenance package which includes:
• All upgrades and updates during the contract period
• Unlimited telephone and email support between the hours of 08:30 and 17:00 UK time
• Monday to Friday, excluding bank holidays. These hours can be extended at an additional
cost.
• Access to a self-help web portal for online support case logging and tracking of open support
cases
Our Support process includes:
• Answering questions related to the use of the software
• Logging calls, incidents and faults
• Identifying and verifying the causes of suspected errors
• Providing workarounds, when available, for verified errors
• Escalating issues which are not resolved to meet agreed response targets
Customer accounts will be managed by a customer success manager who will ultimately be the point of contact for the customer to raise issues outside of the service desk. Any professional service work will be costed separately. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We can provide either on site or online training, subject to the customers needs. We also provide a resource of user guides and FAQs.
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- MP4 Video
- DOCX
- End-of-contract data extraction
- Data will be exported at the end of the contract and sent via a secure method to the customer
- End-of-contract process
- All data held will be returned to the customer. Once the contract ends and there is no extension required, our software licence will expire and our services will not be available. Once data has been returned to the customer it will be permanently deleted from any Polaris systems.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
The on-boarding process involves the end user subscribing via the call off contract. Following this a
detailed implementation plan will be agreed which includes details and timescales for implementing
the software, carrying out any appropriate testing and training all users. Any implementation time
will be quoted and charged in accordance with our published rates.
Off-boarding is simply a case of the customer providing enough notice, followed by both parties
jointly agreeing the retirement schedule of their service and associated data. All data will be
returned to the customer after which it will be permanently deleted.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The Customer portal and Traqer applications are fully functional on mobile devices, and whilst mobile responsive the back office solution works best on a desktop.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
Customer Portal – An online self-service site where customers can log in to manage their accounts, applications, and permits. Back Office – An internal interface for authority officers to review, assess, approve or refuse applications, and maintain audit and reporting.
Traqer – A mobile site that allows enforcement officers to capture details in the field, which are then uploaded to the Back Office. - Accessibility standards
- None or don’t know
- Description of accessibility
- N/A
- Accessibility testing
- N/A
- API
- No
- Customisation available
- Yes
- Description of customisation
- Each customer can customise their license types and the workflow of the customer application forms including payment set ups. This can be done in conjunction with the onboarding team.
Scaling
- Independence of resources
- We do not guarantee this.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Custom reporting tools on licence and permit data.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Other
- Other data at rest protection approach
- AES 256 Azure Encryption at Rest using Azure keys (DEK/KEK)
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Data will be exported at the end of the contract and sent via a secure method to the customer.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- Traffic will enter our hosted environment through our Web Application Firewall. Traffic will be transmitted using HTTPS for all traffic entering/leaving our environment secured by SSL certificates. Data stored in our environment will be encrypted at rest.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Traffic will enter our hosted environment through our Web Application Firewall. Traffic will be transmitted using HTTPS for all traffic entering/leaving our environment secured by SSL certificates. Data stored in our environment will be encrypted at rest.
Availability and resilience
- Guaranteed availability
-
Service Levels and Availability
The service is designed and operated to support high availability using industry-standard cloud infrastructure and operational practices. Service availability targets, where applicable, are defined in the service documentation or agreed contractually.
Availability is monitored continuously, and incidents are managed in accordance with agreed support and incident management processes.
Service Credits and Refunds
We do not provide service credits, refunds, or financial compensation linked to service availability or uptime.
If availability targets are not met, we will investigate the issue, restore service as quickly as possible, and take appropriate corrective actions to prevent recurrence. Any customer remedies are governed by the applicable contract terms. - Approach to resilience
- Information available upon request
- Outage reporting
- Email alerts to key stakeholders.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is tightly controlled using role-based access control (RBAC), multi-factor authentication (MFA), and the principle of least privilege. Only authorised personnel with a valid business need can access these systems. All access is logged, monitored, and regularly reviewed to ensure compliance, and sensitive operations require elevated permissions or additional approvals.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
- ISO 9001, Cyber Essentials Plus
- Information security policies and processes
-
Our security governance and controls are aligned to our ISO 27001 policies including access control, physical security and best practise. We have also been certified to Cyber Essentials Plus and ISO 9001. We align to the NCSC cloud security principles including data in transit, audit and monitoring and supply chain security.
We have established clear roles and responsibilities for security and also build security into our service design through configuration, design and data flows.
Our solution integrates with a SIEM solution which reviews logs for anomalies and process are regularly reviewed. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Changes conform to our ISO 27001 procedures. Each change is scored against our risk criteria and changes that are classified as high risk are added to our risk register as required.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We continuously monitor our systems using automated vulnerability scanners, review threat intelligence, and conduct regular security testing. Identified vulnerabilities are evaluated based on severity, exploitability, and impact to prioritise remediation.
We follow a severity-based SLA:
Critical vulnerabilities: patched as quickly as possible (often within 24–72 hours).
High severity: typically within 1 week.
Lower severity: scheduled in routine maintenance cycles.
We use multiple sources to gather information about potential threats through vendor advisories, CVE recommendations, threat intelligence services and internal monitoring tools to stay informed about emerging risks. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We use continuous monitoring, log analysis, intrusion detection, and threat intelligence to detect suspicious or abnormal activity.
We follow a structured incident response process: investigate, contain, eradicate the threat, recover systems, and document the incident.
Critical incidents are addressed immediately (24/7), with all other incidents handled according to defined severity-based response times. - Incident management type
- Supplier-defined controls
- Incident management approach
- Our Information Security Incident Management policy defines processes for reporting, responding to, and managing security events that compromise confidentiality, integrity, or availability. It mandates prompt reporting via our ticketing systems, communication channels, local processes, or email. Our processes outline personal data breach handling, evidence maintenance, awareness training, and root cause analysis for continuous improvement. We can share our incident handling policy upon request.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Police National Network (PNN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 30%
- Between £250,000 and £500,000
- 32.5%
- Between £500,001 and £1,000,000
- 35%
- Between £1,000,001 and £2,500,000
- 37.5%
- Between £2,500,001 and £5,000,000
- 40%
- Over £5,000,001
- 42.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA
- ISO/IEC 27001 accreditation date
- Monday 2 September 2024
- What the ISO/IEC 27001 doesn’t cover
- Our ISO certifications cover all operational, technical and organisational processes.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA
- ISO 9001 accreditation date
- Saturday 11 March 2023
- What the ISO 9001 doesn’t cover
- Our ISO certifications cover all operational, technical and organisational processes.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Securious Limited
- PCI DSS accreditation date
- Wednesday 2 April 2025
- What the PCI DSS doesn’t cover
-
Polaris Software has demonstrated compliance with all PCI DSS
requirements. - Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Db8897c3-145d-4e0d-8989-c6ab205acb84
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 96a86d54-db53-4ee5-8245-0d6fe29b7579
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-