Skip to main content

Help us improve the Digital Marketplace - send your feedback

VAISALA LIMITED

RoadAI

The PAS2161 accredited technology uses a smartphone app to collect video data which is then processed using Computer Vision; this process automatically analyses the video data and RoadAI applies a methodology to categorize and report pavement condition, road signs, road markings, surface markings, connected vehicles data and other assets.

Features

  • Video capture using smartphone app from any vehicle
  • Automated data analysis using computer vision technology
  • Results within a few hours of upload
  • Survey at normal driven speed
  • Data collection multiple times per annum
  • Unlimited devices and users
  • Data easily integrated into asset management systems
  • Reports in HMDIF (UKPMS), Excel, Shapefile, GeoJSON and other
  • Accessible through web based user interface
  • PAS 2161 accredited

Benefits

  • Easy to use without any specialized equipment
  • Flexible deployment with any vehicle or team
  • No complicated manual analysis required
  • Quick access to the data via cloud user interface
  • Continuous survey of the network enables early intervention maintenance plans
  • Reduced ad hoc site visits
  • Network deterioration modelling
  • Safety and environmental benefits
  • Risk based management of assets
  • Cost savings

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at marina.chambers@vaisala.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 6 9 3 7 2 4 8 4 1 5 4 7 4 6

Contact

VAISALA LIMITED Marina Chambers
Telephone: +447887537562
Email: marina.chambers@vaisala.com

About the service

Service categories

Application Development and Deployment

AI platforms

AI software services

  • Computer Vision AI Software Services
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
None
System requirements
Access to web browser interface

User support

Email or online ticketing support
Yes
Support response times
First line technical support helpdesk 24/7/365
Second line technical support Mon-Fri 7am-3pm UK time
Business support Mon-Fri 9am-5pm UK time
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes
Support levels
First line technical support helpdesk 24/7/365
Second line technical support Mon-Fri 7am-3pm UK time
Business support Mon-Fri 9am-5pm UK time
Support available to third parties
Yes

Onboarding and offboarding

Getting started
A series of project review meetings will be put in place for the purpose of reviewing progress against project objectives. It is critical that Strategic Managers and Operational Teams responsible for managing and delivering the project on behalf of the customer attend these meetings.
A project manager will be assigned to the project on day 1, project management meetings will be booked with the agreed project team, and at the first project meeting the project goals will be outlined, and in consultation with the team, goals will be prioritized and built into the project plan that will be used as a working document to manage the project.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
All data can be exported from the UI
End-of-contract process
Export of all data can be done from the user interface and is FOC
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Available in PDF and also in the Help section of the UI

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The videos are collected with the mobile app and then are viewed in the web browser.
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
Purpose of this API is to enable easy access to mobile observation data provided by Computer Vision team. Most of the Mobile observations are video data analyzed by computer vision. API key OR credentials for Vaisala RoadAI are needed for using this API. With credentials temporary API token can be fetched from login/ resource. API key OR API token should be delivered with every request to resource endpoint.Limitations
Currently 100 is maximum amount of records returned with limit parameter. To fetch more use offset parameter or next parameter (cursor). Cursor is faster to loop through big set of records. Valid next cursor can be found from Links-header. Default size of collection is 30 records.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can create different shares (folders) for their data, the user with administrative rights can add/delete users and provide access to specific data

Scaling

Independence of resources
RoadAI uses a highly scalable, container based cloud platform architecture. The computing and storage capacity can be easily scaled by adding more servers and even data centers to the cluster.

Analytics

Service usage metrics
Yes
Metrics types
User engagement statistic, network coverage, hours of videos collected, phones usage
Reporting types
Reports on request
Resource tagging
No
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Through the reports or with the API
Data export formats
  • CSV
  • Other
Other data export formats
  • Shapefile
  • GeoJSON
  • HMDIF
  • PAS2161
Data import formats
Other
Other data import formats
  • Shapefile for network layer
  • GeoJSON for network layer
  • MPEG4 video footage

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
Other
Other protection within supplier network
No special data-in-transit security measures within the protected, RoadAI secure network used in service internal traffic.

Availability and resilience

Guaranteed availability
We provide 99.5% 24/7/365 availability. A typical refund policy would be to extend the contract duration with the number of downtime hours exceeding the SLA limit.
Approach to resilience
Available on request
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Most management interfaces are integrated into the web-based RoadAI UI and API which have a fine-grained username/password or access token -based permissions system. Support channels and management interfaces are only accessible by authorized persons, e.g. RoadAI developers and service managers, customers' admin users.
Access restriction testing frequency
At least once a year
Management access authentication
  • Public key authentication (including by TLS client certificate)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Vaisala has an Information Security Management system as stated on the "Vaisala Policies" page: https://www.vaisala.com/en/vaisala-policies. A more thorough description of all policies are available on request.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Changes to the system are done by using a version control system. The changes are reviewed internally by using a pull request process. Changes are released by an automated continuous delivery pipeline once a pull request has been, reviewed, tested and merged into the production branch. For significant changes, a change log notification is sent to RoadAI users.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
The systems are regularly scanned for malware. RoadAI is also in the process on adopting automated open source package vulnerability scans for all its services.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Potential compromises are identified by monitoring anomalies in the number of connection attempts, resource usage, and events like unexpected restarts, liveness probes, etc. in all RoadAI services, and by running security scans on the Vaisala network. Our IAAS provider, Hetzner, also scans for certain types of attacks in their network like DDOS.

We respond to potential compromises within the same business day by identifying what is compromised and imposing further usage restrictions if needed. Within 2 business days we assess the full impact, notify affected customers and plan on how to prevent similar compromises in the future.
Incident management type
Supplier-defined controls
Incident management approach
Users can report incidents via RoadAI support service channels 24/7/365.
We have a developer on active support duty at business hours to handle minor incidents like bugs, problems in the processing pipeline, service degradation etc.

Incident reports outside the European business hours are received by Vaisala centralized support center.

Serious incidents like severe or complete service unavailability are escalated to the entire dev team to fix the issue and to the service managers to contact our customers.

Incident reports are created for each severe incident.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Give customer the ability to try RoadAI, collect some data and view on user interface.
Including:
4 weeks or free data collection and access to data via the online user interface
Introductory meeting
Basic training
Review meeting to support customer activity
Final review to evaluate customer progress

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
DNV Business Assurance UK Limited
ISO/IEC 27001 accreditation date
Monday 9 June 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
ISO 9001 certification accredited by
DNV Business Assurance UK Limited
ISO 9001 accreditation date
Wednesday 27 November 2013
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
7be3cc4a-2abb-4362-a821-66912a79086a
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Mission: Make Britain a clean energy superpower

To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

  • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at marina.chambers@vaisala.com. Tell them what format you need. It will help if you say what assistive technology you use.