Internet of Things (IoT) Enabling Service
Solnet’s IoT Enabling Service provides cloud-based data collection, storage, and management for connected devices. It enables real-time monitoring, analytics, and remote control of assets, ensuring seamless integration, scalability, and security. Businesses gain actionable insights, operational efficiency, and simplified management of IoT ecosystems through a centralized cloud platform.
Features
- Real-time device monitoring
- Cloud-based data storage
- Secure data transmission
- Remote device management
- Scalable IoT integration
- Analytics and reporting
- Automated alerts
- API for third-party apps
- Dashboard visualisation
- Firmware updates
Benefits
- Improve operational efficiency
- Reduce downtime
- Enhance decision-making
- Centralized control
- Cost savings
- Faster response times
- Data-driven insights
- Simplified management
- Increased scalability
- Secure operations
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 6 6 5 6 3 8 5 0 3 3 0 0 9 5
Contact
SOLNET
Syed Kazmi
Telephone: 01438419889
Email: info@solnetiot.com
About the service
- Service categories
-
Systems Infrastructure Software
System and service management
- IT service management
IT automation and configuration management
- Datacentre system and application control
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Solnet’s IoT Enabling Service works standalone or as an add-on to existing software, seamlessly collecting, storing, and managing IoT device data. It integrates with dashboards and apps, enabling real-time monitoring, analytics, automation, and remote control, enhancing operational efficiency, decision-making, and scalability without replacing core systems.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
Solnet’s IoT Enabling Service has a few constraints buyers should be aware of:
Hardware compatibility: Works only with supported IoT devices and protocols.
Planned maintenance: Occasional cloud maintenance may cause brief service interruptions.
Connectivity dependency: Requires reliable internet connection for real-time monitoring and remote control.
Support scope: Technical support is optimized for certified devices and configurations. - System requirements
-
- Supported IoT devices and sensors only.
- Web dashboard accessible via modern browsers (Chrome, Edge, Firefox, Safari).
- Recommended TLS 1.3 support; up-to-date antivirus on client machines
- No special hardware required for cloud backend.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Olnet provides both email and online ticketing support for the IoT Enabling Service.
Email support: Users can submit queries directly via a dedicated support email address.
Online ticketing: A web-based portal allows logging, tracking, and prioritizing issues, ensuring timely responses and resolution. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Solnet has conducted web chat testing with assistive technology users, including screen readers and keyboard-only navigation. Feedback from users with visual and motor impairments was used to ensure chat interface accessibility, proper focus management, clear labeling, and compliance with WCAG guidelines, enabling an inclusive and usable support experience.
- Onsite support
- Yes
- Support levels
-
Support Levels:
Standard Support (Included):
Email and online ticketing access
Response within 48 hours
Covers general usage questions and minor issues
Cost: Included in subscription
Premium Support:
Priority response within 1–2 hours
Direct access to a Cloud Support Engineer for technical issues
Includes guidance for integrations and troubleshooting
Enterprise Support:
Dedicated Technical Account Manager (TAM)
24/7 support via email, ticketing, and phone
Onboarding assistance, regular system reviews, and proactive monitoring
Cost: Custom pricing based on account. size and requirements - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
User Documentation: Comprehensive online manuals and quick-start guides for web dashboard, mobile app, and API usage.
Online Training: Live webinars and recorded tutorials for onboarding and feature walkthroughs.
Onsite Training: Available for enterprise clients requiring hands-on guidance.
Support Access: Email and ticketing support during setup to assist with configuration, device registration, and initial customisation. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Users can export all historical device and transaction data via the web dashboard or mobile app in standard formats such as CSV, Excel, or JSON.
The API also allows bulk extraction of device logs, alerts, and analytics.
Solnet ensures secure data transfer and offers assistance through support channels to facilitate a smooth handover.
After extraction, cloud-stored data is securely deleted in accordance with privacy and data protection policies.
This ensures users retain full access to their data even after service termination. - End-of-contract process
-
End of Contract:
Users retain access to all exported data and historical device logs.
Cloud-stored data is securely deleted after contract termination, in line with privacy policies.
Device connections are deactivated; users may choose to renew, migrate, or terminate service.
What’s Included in the Price:
Access to web and mobile dashboards
Cloud data collection and storage
Standard support (email/ticketing)
Firmware updates and API access
Additional Costs:
Premium or enterprise support (TAM or 24/7 engineer access)
Onsite training
Integration with third-party enterprise systems beyond standard API capabilities - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Core Functionality: Both mobile app and desktop dashboard provide access to IoT device monitoring, data analytics, and scheduling.
User Interface: Desktop offers larger, more detailed dashboards and advanced analytics views; mobile app is streamlined for quick access, notifications, and on-the-go control.
Notifications: Mobile app supports push notifications for alerts and events; desktop relies on email or in-dashboard alerts.
Offline Access: Desktop dashboards provide more robust reporting options; mobile app requires internet for most features.
Ease of Use: Mobile optimized for convenience and mobility; desktop optimized for in-depth management and multi-device oversight. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Solnet provides a web-based dashboard and mobile app that enable users to monitor, manage, and control connected IoT devices in real time. The interface features intuitive navigation, interactive charts, device status indicators, scheduling tools, alerts, and downloadable reports, all secured via TLS 1.3.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Solnet has conducted extensive testing of its web and mobile interfaces with users of screen readers, keyboard-only navigation, and voice-control tools. Feedback focused on accessibility, focus management, labeling, color contrast, and navigational clarity. Adjustments were made to ensure compliance with WCAG guidelines, providing an inclusive, usable experience for users with visual, motor, or cognitive impairments.
- API
- Yes
- What users can and can't do using the API
-
What Users Can Do:
Setup: Users can register devices, configure device parameters, and link devices to their cloud account using API calls.
Management: Users can schedule device operations, update firmware, retrieve real-time and historical data, and manage alerts programmatically.
Integration: API allows integration with third-party dashboards, analytics tools, or enterprise software.
Limitations:
Only supported IoT devices and protocols can be registered via the API.
Certain advanced configurations (e.g., network-level settings, security certificates) must be performed via the web or mobile dashboard.
API requests are rate-limited to ensure service stability.
Some administrative actions (e.g., creating new accounts or billing changes) cannot be performed through the API. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
What Can Be Customised:
Device schedules and charging limits
Alert notifications and thresholds
Dashboard layout and reporting views
API integrations and data export formats
How Users Can Customise:
Through the web dashboard or mobile app using intuitive settings panels
Programmatically via the API for automation or third-party integration
Who Can Customise:
Account administrators or users with appropriate permissions can adjust settings
End-users can modify personal preferences such as notifications and schedules
Scaling
- Independence of resources
- We guarantee users aren’t affected by others’ demand through rigorous stress testing. Our platform has been tested in multi-million user environments and under high-demand scenarios to ensure consistent performance, reliable uptime, and fast response times, even when multiple users are accessing or managing charge points simultaneously.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Service usage metrics
Yes
Metrics types
Users can export performance metrics as part of their data, including KPIs for charger uptime, connectivity, service performance, and overall reliability. Metrics are accessible via the web interface or API, downloadable in standard formats (CSV/JSON) for reporting, analysis, or integration with other systems. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export their data using the web interface or the API. Data can be downloaded in standard formats such as CSV or JSON, allowing easy integration with other systems, reporting, or backup. Exports can include usage logs, transaction history, and configuration settings, with filters for date ranges or specific charge points.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- XML
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We guarantee 99.9% platform availability under normal operating conditions, backed by our Service Level Agreement (SLA). If availability falls below this threshold, users are eligible for service credits or refunds, calculated proportionally to the downtime experienced, ensuring accountability and maintaining trust in our service reliability.
- Approach to resilience
- Our service’s resilience strategy is built around industry best practices and proven architecture principles: • Redundancy & Diversity Critical components (compute, storage, network) exist in multiple independent instances to ensure failures in one do not impact overall service. We architect for failure — components can fail without impacting live service availability. • Isolation & Separation Production, staging, and disaster recovery environments are logically and physically separated to reduce cross-environment impact and risk. • Scalability & Elasticity Services automatically scale to handle load spikes, helping maintain performance during traffic surges or degraded conditions. • Data Protection Data is replicated securely across locations; backups are maintained and regularly validated to ensure periodic restores are possible.
- Outage reporting
- Outage Reporting Our service provides clear and timely outage reporting through automated monitoring and customer communication channels, ensuring transparency and rapid awareness of any service disruption. The platform is continuously monitored using automated health checks across core services, APIs, and infrastructure components. When an issue is detected, alerts are generated in real time, incidents are logged, and severity levels are assigned to support prompt investigation and resolution. A public service status dashboard is available to provide real-time visibility of overall platform availability, active incidents, and planned maintenance. Historical incident information is also retained to support transparency and service assurance. Where required, more detailed technical information can be made available on request. Service status information can also be accessed via an API, allowing customers or partners to integrate outage and availability data into their own monitoring or reporting systems. The API is secured and rate-limited to ensure reliability and data protection. In addition, email alerts are sent to nominated contacts for confirmed outages, significant service degradation, planned maintenance, and incident resolution updates. Communication is maintained throughout an incident, and post-incident summaries can be provided following major outages.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Other
- Other user authentication
- Access to the service is secured using OpenID Connect (OIDC) integrated with Microsoft Entra ID (Azure AD). Users authenticate via their Entra credentials, supporting single sign-on (SSO) and strong identity verification. Authentication tokens are issued by Entra and validated by the service before granting access. Role-based access controls ensure users can only access appropriate functionality and data. All authentication processes follow industry best practices, including token expiration, revocation, and encrypted transmission over TLS 1.3 to protect credentials and session integrity.
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is strictly controlled using role-based access controls (RBAC). Users are assigned roles with the minimum privileges required for their responsibilities. Administrative interfaces require multi-factor authentication (MFA) and are accessible only from approved devices or networks. Support channels are authenticated and monitored, with access limited to authorised personnel. All access attempts are logged and reviewed regularly. Changes to roles, privileges, or support access are subject to formal approval and periodic audit to ensure compliance with security policies and ISO/IEC 27001 standards.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Other
- Description of management access authentication
- Access to the service is secured using OpenID Connect (OIDC) integrated with Microsoft Entra ID (Azure AD). Users authenticate via their Entra credentials, supporting single sign-on (SSO) and strong identity verification. Authentication tokens are issued by Entra and validated by the service before granting access. Role-based access controls ensure users can only access appropriate functionality and data. All authentication processes follow industry best practices, including token expiration, revocation, and encrypted transmission over TLS 1.3 to protect credentials and session integrity.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Our organisation fully complies with ISO/IEC 27001 and operates a formal Information Security Management System (ISMS) covering people, processes, and technology. The ISMS is approved by senior management and is designed to protect the confidentiality, integrity, and availability of information assets. We maintain a comprehensive suite of documented information security policies aligned with ISO 27001 Annex A controls. These include policies for risk management, access control, asset management, cryptography, secure development, incident management, business continuity, supplier security, and data protection. Policies are version-controlled, communicated to relevant staff, and reviewed regularly or following significant change. Responsibility for information security sits with senior management and is supported by a designated Information Security Officer. Security risks, incidents, audit results, and compliance metrics are reported through defined management reporting lines and reviewed as part of formal management reviews. Compliance with policies is ensured through mandatory staff security awareness and role-based training, least-privilege access controls, continuous monitoring and logging, and regular risk assessments. Internal audits are conducted to verify adherence to ISO 27001 requirements, and corrective actions are tracked to completion. Security incidents are formally recorded, investigated, and used to drive continual improvement of the ISMS.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We operate formal configuration and change management processes aligned with ISO/IEC 27001. All service components are recorded in a central configuration management repository and tracked throughout their lifecycle, from deployment through change and retirement. Changes are requested, assessed, approved, implemented, and reviewed using a controlled change process. Each change is evaluated for potential security impact, including risks to confidentiality, integrity, and availability. Security reviews, testing, and rollback plans are required for material changes, ensuring service stability and ongoing compliance.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We operate a formal vulnerability management process aligned with ISO/IEC 27001. Potential threats are identified through vulnerability scanning, risk assessments, penetration testing, and code reviews. Vulnerabilities are assessed based on severity, exploitability, and impact, with remediation prioritised accordingly. Critical vulnerabilities are patched as a priority, typically within hours or days, while other issues follow defined timelines. Threat intelligence is sourced from vendor advisories, CVE databases, security bulletins, and automated security monitoring tools.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We operate continuous protective monitoring aligned with ISO/IEC 27001 to detect and respond to potential security compromises. Logs and system events are collected from all critical services and analysed for anomalies, suspicious activity, and policy violations. Potential compromises trigger automated alerts and are escalated to the security team for immediate investigation. Incidents are assessed, contained, and remediated according to severity, with critical events responded to within hours. Lessons learned are documented and fed back into our monitoring and incident response processes to strengthen ongoing security.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate a formal incident management process aligned with ISO/IEC 27001. Pre-defined procedures exist for common incidents, including system outages, security events, and data breaches. Users can report incidents via a dedicated support portal, email, or telephone, which are logged and tracked in our incident management system. Each incident is assessed, prioritised, and investigated promptly. Incident reports, including cause, impact, resolution, and lessons learned, are provided to affected users and stakeholders. Post-incident reviews inform continuous improvement of processes and controls.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- The free version provides basic EV charger management, mobile and web access, and charging history. Advanced features, analytics, automated scheduling, and priority support are not included. The service is available indefinitely.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0.5%
- Between £500,001 and £1,000,000
- 0.75%
- Between £1,000,001 and £2,500,000
- 1%
- Between £2,500,001 and £5,000,000
- 1.25%
- Over £5,000,001
- 1.5%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- Alcumus ISOQAR Limited
- ISO/IEC 27001 accreditation date
- Friday 7 November 2025
- What the ISO/IEC 27001 doesn’t cover
- The ISMS covers all operational, technical, and support processes related to the delivery of our services
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- Alcumus ISOQAR Limited
- ISO 9001 accreditation date
- Friday 7 November 2025
- What the ISO 9001 doesn’t cover
- The ISMS covers all operational, technical, and support processes related to the delivery of our services
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- B6010d24-d0f6-45a4-9a3c-7898d0c60133
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Creation of outreach activities to create a pipeline of employees for the future contract delivery