RTPI iConnex
iConnex is a comprehensive, secure, easy‑to‑use Real‑Time Information (RTI) System that helps councils and bus operators give passengers accurate, real‑time bus arrival information. It shows where buses are, when they will actually arrive, and helps keep services running smoothly.
Features
- Map View and Dashboards
- Reporting
- Scrolling Messaging
- Audio Announcements
- Live and/or Scheduling detail
- On vehicle passenger information
- On-street passenger information
- Timtetable, NaPTAN/location data import and management
- Disruption Information
- Content Management System
Benefits
- Real Time tracking for urban buses
- Publishing relliable information for passengers
- Easily accessible journey information across various platforms
- Allows passengers to make informed choices
- Allows operators to control available data to passengers
- Increases public transport opportunities for impared passengers
- Integration of on-street, on-bus and digital information
- Multiple platforms for passengers to access real time information
- Live System View and status monitoring
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 7 0 0 3 4 8 7 0 1 1 2 9 9 4
Contact
R2P UK SYSTEMS LIMITED
Steve Holloway
Telephone: 01293 665398
Email: ukroad@r2p.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Location and geospatial data management and analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- No constraints
- System requirements
- Software licences
User support
- Email or online ticketing support
- Yes
- Support response times
- Hdepends on the fault category, minimum time is 8 h for the highset priority
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
Business hours support (Monday to Friday, 09:00–17:00 UK, excluding public holidays)
Access to the service desk via email and ticketing system
Incident logging, triage, and resolution for software and platform issues
Monitoring of core system availability
Access to documentation and standard release notes - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- We provide online training and user documentation to complement the training
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- All the information can be downloaded from the website before the contract ends
- End-of-contract process
- We proceed to decomission all the data incoming from third parties and to take off the site for the customer
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There are not many differences, it is the same desktop version which is mobile friendly
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure web-based service interface, providing role-based access to system configuration, operational dashboards, and reporting. The service also exposes documented APIs to support integration with third-party systems.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- User interfaces have been tested for accessibility in line with WCAG 2.1 AA. Testing includes keyboard-only navigation, screen reader compatibility (e.g. NVDA and VoiceOver), colour contrast, text scaling, and accessible form controls. Issues identified are logged and remediated, with re-testing performed after significant interface changes.
- API
- Yes
- What users can and can't do using the API
- Users can register on the webiste to use API for bus stop predictions, all the users must be approved by the Support Team
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
- Capacity is planned and monitored so that increases in load trigger the allocation of additional resources rather than performance degradation for existing users. Independent firewalls on every server strictly control traffic flows between services and users, and all connections use TLS 1.2, aligning with NCSC cloud security principles to ensure that traffic from one tenant cannot interfere with others. Regular independent and internal vulnerability scanning, alongside pre‑go‑live testing for each new customer, validates that these controls remain effective as usage grows, maintaining consistent performance for all users.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Depending on the data, like reporting information that can be exported as a CSV format
- Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
R2p offers support via our help desk with our standard operating hours being Monday–Friday, 8am-6pm.
Our Fault management system offers different levels of priority (P1 to P5) based on the nature of the fault; each fault categorisation has a different resolution time which need to be agreed with the specific customer.
Typically, we offer anything from a 4-hr response time to P1 calls through to a 14-day response time for P5 faults.
Our standard KPIs for all our solutions are as follows:
System Security – 100% (Per Month)
System Availability – 98% (Per Month)
SIRI Connectivity – 98% (Per Month)
API Connectivity – 98% (Per Month)
Display accuracy – 90% (Per Month)
These are our standard offerings, any additional SLAs or KPIs that are needed by specific customers would be subject to additional costs. Likewise any requirements for Low Performance Damages (LPDs) to be applicable to our systems will also be subject to increased costs.
In our experience, the best way to handle any LPDs that may be applicable to a system, would be to have them applied as service credits against monthly maintenance fees. All service credits would also be capped to an agreed level. - Approach to resilience
- Available on request
- Outage reporting
-
- Automatic Email Alerts, as well as email correspondence to customers
- A Service Monitoring Dashboard that is private to the customer
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
-
Include:
whether you have pre-defined processes for common events
how users report incidents
how you provide incident reports - Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- CYBER ESSENTIALS PLUS
- Information security policies and processes
- CYBER ESSENTIALS PLUS
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
The Company recognises the importance of change management and the risks associated with ineffective change management. By implementing this policy we aim to mitigate risks such as:
• Information being corrupted and/or destroyed
• Systems performance being disrupted and/or degraded
• Productivity losses being incurred
• Exposure to reputational risk. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
All systems must permit central vulnerability scanning and periodic penetration testing. Internal and external vulnerability scans must be performed at least annually and after any significant network change.
A risk-based remediation plan will prioritise patching by asset criticality:
CVSS ≥ 8.9: remediate within 7 days
CVSS 7.0–8.9: remediate within 14 days
CVSS 4.0–6.9: remediate within 90 days
CVSS < 4.0: remediate within 180 days as part of normal maintenance
Remediation will be validated through rescanning.
Penetration testing of internal systems, external interfaces, and hosted applications will be conducted at least annually and after significant changes. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Our ISP runs attack detection processes on their primary routers and firewalls.
We run log and firewall monitoring.
We run Heimdal security NextGen antivirus and anti-ransomware encyption solution.
Our security incident process covers all forms of security, not just IT.
It follows a five-step process:
• Prepare for handling incidents.
• Identify potential incidents through monitoring and reporting.
• Assess identified incidents for mitigation & onward alerting
• Responding and resolve
• Post-incident review
The system architecture provides for a high availability solution which is capable of supporting operations to meet the 1-hour RTO - Incident management type
- Supplier-defined controls
- Incident management approach
-
1. Detection: Staff and Vendors must monitor systems and alert the Delivery and Support Director within 1 hour of suspected incidents.
2. Reporting: Incidents are logged in the Incident Register with timestamp, source, and initial classification.
3. Containment: Vendors must isolate affected systems and prevent further spread.
4. Investigation: Root cause analysis and evidence collection led by the Vendor with Company oversight.
5. Communication: Stakeholders, customers, and regulators are notified when necessary.
6. Recovery: Systems restored as required following backup/restore or disaster recovery plans.
7. Closure: Incident formally closed with lessons learned and corrective actions. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Other
- Other public sector networks
- BODS
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Time limited trial, using BODS data to demonstrate the capabilities of the iConnex System.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 7.5%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Nqa
- ISO 9001 accreditation date
- Friday 8 November 2024
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 6df0f212-3c93-4f20-880e-269d25828ceb
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 1b5e540e-78b2-4ee2-8776-2fba9c0ce13f
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Ensuring new workers are informed of their right to join a trade union
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-