RoadAI
The PAS2161 accredited technology uses a smartphone app to collect video data which is then processed using Computer Vision; this process automatically analyses the video data and RoadAI applies a methodology to categorize and report pavement condition, road signs, road markings, surface markings, connected vehicles data and other assets.
Features
- Video capture using smartphone app from any vehicle
- Automated data analysis using computer vision technology
- Results within a few hours of upload
- Survey at normal driven speed
- Data collection multiple times per annum
- Unlimited devices and users
- Data easily integrated into asset management systems
- Reports in HMDIF (UKPMS), Excel, Shapefile, GeoJSON and other
- Accessible through web based user interface
- PAS 2161 accredited
Benefits
- Easy to use without any specialized equipment
- Flexible deployment with any vehicle or team
- No complicated manual analysis required
- Quick access to the data via cloud user interface
- Continuous survey of the network enables early intervention maintenance plans
- Reduced ad hoc site visits
- Network deterioration modelling
- Safety and environmental benefits
- Risk based management of assets
- Cost savings
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 6 9 3 7 2 4 8 4 1 5 4 7 4 6
Contact
VAISALA LIMITED
Marina Chambers
Telephone: +447887537562
Email: marina.chambers@vaisala.com
About the service
- Service categories
-
Application Development and Deployment
AI platforms
AI software services
- Computer Vision AI Software Services
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- None
- System requirements
- Access to web browser interface
User support
- Email or online ticketing support
- Yes
- Support response times
-
First line technical support helpdesk 24/7/365
Second line technical support Mon-Fri 7am-3pm UK time
Business support Mon-Fri 9am-5pm UK time - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
First line technical support helpdesk 24/7/365
Second line technical support Mon-Fri 7am-3pm UK time
Business support Mon-Fri 9am-5pm UK time - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
A series of project review meetings will be put in place for the purpose of reviewing progress against project objectives. It is critical that Strategic Managers and Operational Teams responsible for managing and delivering the project on behalf of the customer attend these meetings.
A project manager will be assigned to the project on day 1, project management meetings will be booked with the agreed project team, and at the first project meeting the project goals will be outlined, and in consultation with the team, goals will be prioritized and built into the project plan that will be used as a working document to manage the project. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- All data can be exported from the UI
- End-of-contract process
- Export of all data can be done from the user interface and is FOC
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Available in PDF and also in the Help section of the UI
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The videos are collected with the mobile app and then are viewed in the web browser.
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
-
Purpose of this API is to enable easy access to mobile observation data provided by Computer Vision team. Most of the Mobile observations are video data analyzed by computer vision. API key OR credentials for Vaisala RoadAI are needed for using this API. With credentials temporary API token can be fetched from login/ resource. API key OR API token should be delivered with every request to resource endpoint.Limitations
Currently 100 is maximum amount of records returned with limit parameter. To fetch more use offset parameter or next parameter (cursor). Cursor is faster to loop through big set of records. Valid next cursor can be found from Links-header. Default size of collection is 30 records. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users can create different shares (folders) for their data, the user with administrative rights can add/delete users and provide access to specific data
Scaling
- Independence of resources
- RoadAI uses a highly scalable, container based cloud platform architecture. The computing and storage capacity can be easily scaled by adding more servers and even data centers to the cluster.
Analytics
- Service usage metrics
- Yes
- Metrics types
- User engagement statistic, network coverage, hours of videos collected, phones usage
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Through the reports or with the API
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Shapefile
- GeoJSON
- HMDIF
- PAS2161
- Data import formats
- Other
- Other data import formats
-
- Shapefile for network layer
- GeoJSON for network layer
- MPEG4 video footage
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- Other
- Other protection within supplier network
- No special data-in-transit security measures within the protected, RoadAI secure network used in service internal traffic.
Availability and resilience
- Guaranteed availability
- We provide 99.5% 24/7/365 availability. A typical refund policy would be to extend the contract duration with the number of downtime hours exceeding the SLA limit.
- Approach to resilience
- Available on request
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Most management interfaces are integrated into the web-based RoadAI UI and API which have a fine-grained username/password or access token -based permissions system. Support channels and management interfaces are only accessible by authorized persons, e.g. RoadAI developers and service managers, customers' admin users.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Vaisala has an Information Security Management system as stated on the "Vaisala Policies" page: https://www.vaisala.com/en/vaisala-policies. A more thorough description of all policies are available on request.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Changes to the system are done by using a version control system. The changes are reviewed internally by using a pull request process. Changes are released by an automated continuous delivery pipeline once a pull request has been, reviewed, tested and merged into the production branch. For significant changes, a change log notification is sent to RoadAI users.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- The systems are regularly scanned for malware. RoadAI is also in the process on adopting automated open source package vulnerability scans for all its services.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Potential compromises are identified by monitoring anomalies in the number of connection attempts, resource usage, and events like unexpected restarts, liveness probes, etc. in all RoadAI services, and by running security scans on the Vaisala network. Our IAAS provider, Hetzner, also scans for certain types of attacks in their network like DDOS.
We respond to potential compromises within the same business day by identifying what is compromised and imposing further usage restrictions if needed. Within 2 business days we assess the full impact, notify affected customers and plan on how to prevent similar compromises in the future. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Users can report incidents via RoadAI support service channels 24/7/365.
We have a developer on active support duty at business hours to handle minor incidents like bugs, problems in the processing pipeline, service degradation etc.
Incident reports outside the European business hours are received by Vaisala centralized support center.
Serious incidents like severe or complete service unavailability are escalated to the entire dev team to fix the issue and to the service managers to contact our customers.
Incident reports are created for each severe incident. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
Give customer the ability to try RoadAI, collect some data and view on user interface.
Including:
4 weeks or free data collection and access to data via the online user interface
Introductory meeting
Basic training
Review meeting to support customer activity
Final review to evaluate customer progress
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- DNV Business Assurance UK Limited
- ISO/IEC 27001 accreditation date
- Monday 9 June 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- DNV Business Assurance UK Limited
- ISO 9001 accreditation date
- Wednesday 27 November 2013
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 7be3cc4a-2abb-4362-a821-66912a79086a
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies