Moonbility Multi-Modal Disruption Impact Platform
Moonbility is a national-scale iSaaS platform for disruption impact management. Trusted by TfGM, LNER, and National Express, it integrates real-time data to simulate intervention outcomes and streamline stakeholder communication, providing predictive analytics and control room interfaces to enhance resilience across multi-modal networks.
Features
- National-scale transport network operations and infrastructure monitoring.
- Real-time predictive simulation of multi-modal operational intervention scenarios.
- Automated disruption detection with quantifiable impact and ripple-effect analytics.
- Centralised command and control dashboard for unified situational awareness.
- Collaborative incident management workflows to streamline stakeholder communication.
- Scenario-based modelling to optimise transport network resilience and recovery.
- Cloud-native iSaaS architecture with enterprise-grade security and reliability.
- Automated data synchronisation for passenger information and communication channels.
- Comprehensive audit trails for post-incident performance and compliance reporting.
- Secure API gateway for seamless integration with legacy transport systems.
Benefits
- Increased transport network resilience through data-driven intervention planning.
- Reduced cost of operational delays by optimising real-time response times.
- Improved situational awareness for control room operators and stakeholders.
- Enhanced passenger experience through faster recovery and accurate communication.
- Streamlined cross-agency collaboration via a single source of operational truth.
- Evidence-based decision-making supported by predictive impact analytics.
- Reduced manual processing of disruption data, increasing operational efficiency.
- Scalable iSaaS deployment reducing total cost of ownership (TCO).
- Improved KPI performance and regulatory compliance reporting accuracy.
- Accelerated network recovery through pre-validated intervention strategies.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 5 9 8 5 8 5 8 9 7 0 5 5 8 7
Contact
Moonbility
Andre Wang
Telephone: 07596948400
Email: andre@moonbility.com
About the service
- Service categories
-
Systems Infrastructure Software
System and service management
- IT operations management
- IT service management
IT automation and configuration management
- Workload management
- Datacentre system and application control
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- To ensure maximum service resilience, routine maintenance is conducted during off-peak windows with 48-hour prior notification. As a secure iSaaS solution, access requires a modern HTML5-compliant web browser. The resolution of predictive analytics is synchronised with the granularity and refresh rates of third-party transport data feeds. While our core algorithms ensure high-performance modelling, the outcomes reflect the real-time availability of infrastructure data. Any specific regional configurations are established during the formal onboarding phase to ensure alignment with local authority operational protocols.
- System requirements
-
- HTML5-compliant web browser (latest Chrome, Edge, or Safari).
- Stable internet connection for real-time data synchronisation.
- Minimum 8GB RAM recommended for optimal dashboard performance.
- No specific proprietary hardware or local software installation required.
User support
- Email or online ticketing support
- Yes
- Support response times
- We provide a standard response time of within 4 hours for high-priority operational issues and within 1 working day for general enquiries. Support is accessible via our dedicated support email and online portal from 09:00 to 17:00 (UK time), Monday to Friday, excluding UK public holidays. During major planned transport events or critical disruptions, extended support windows can be pre-arranged to ensure continuous monitoring. All enquiries are formally logged and tracked to ensure transparent resolution. This dual-channel approach ensures that stakeholders can always reach our technical team during critical incidents.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We provide a unified, premium support tier included in the platform subscription to ensure all transport operations receive high-priority attention. This includes access to dedicated technical account managers and cloud support engineers who understand the specific operational requirements of the transport sector. General support enquiries are handled via email and our ticketing portal during standard United Kingdom business hours (09:00 - 17:00, Monday to Friday). For critical infrastructure incidents, we offer prioritised response protocols to ensure rapid resolution and continuous platform resilience. Bespoke 24/7 mission-critical support packages and onsite technical assistance are available as optional add-on services. These supplemental support modules are priced based on specific organisational resilience needs and can be tailored as part of the service agreement to ensure comprehensive operational coverage.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We facilitate a seamless transition through a structured three-phase onboarding programme. Initially, users are provided with a comprehensive library of tutorial videos and digital documentation for self-paced learning. This is followed by an intensive onsite onboarding workshop led by our specialists to align the platform’s predictive capabilities with local operational requirements. To ensure long-term success, we provide a dedicated two-week intensive support period immediately following the launch, offering real-time online assistance to resolve any queries during the critical initial adoption phase. This multi-layered approach ensures that both technical teams and operational staff can confidently manage network disruptions and enhance organisational resilience from day one.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At the end of the contract, buyers can export their historical data and analysis reports directly from the platform. Data can be downloaded in standard CSV and Microsoft Excel formats, ensuring it can be easily integrated into the buyer's internal systems or archived. This self-service approach ensures the buyer maintains full data sovereignty and can migrate their information at any time without any proprietary vendor lock-in.
- End-of-contract process
- Upon expiry or termination of the contract, the buyer can export their historical data and analysis reports from the platform as part of the standard service subscription. This self-service data retrieval in standard formats, such as CSV and Microsoft Excel, is included in the contract price. Should the buyer require bespoke technical consultancy, complex data migration services, or specialised decommissioning support beyond the standard export functionality, these additional services can be provided as supplemental professional service packages. These services will be scoped and priced based on the specific project requirements and must be agreed upon in a separate Statement of Work (SOW) to ensure a tailored and secure transition of assets.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The platform is accessed via a responsive web interface designed to work across desktop, tablet, and mobile browsers. This ensures that operational data and predictive insights are accessible to users in the field or control room without the need for a separate native application.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The platform is accessed via a highly responsive web-based interface, providing a seamless and intuitive user experience across desktop, tablet, and mobile browsers. This design ensures that transport operators and strategic planners can access real-time operational data and predictive insights from any location without the need for additional software installations. The interface is optimised for high-performance data visualisation, featuring centralised dashboards that consolidate multi-modal information into a single, clear operational view. This browser-based approach facilitates rapid deployment and ensures consistent situational awareness across diverse organisational hardware environments.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We are committed to digital inclusion and ensure our web-based interface aligns with Web Content Accessibility Guidelines 2.2 Level AA standards. The platform undergoes regular internal assessments to ensure compatibility with common assistive technologies, including screen readers, keyboard-only navigation, and high-contrast display modes. We prioritise logical heading structures, descriptive alternative text for interactive elements, and sufficient colour contrast ratios to support users with visual or motor impairments. Feedback from stakeholders is continuously integrated into our development lifecycle to refine the user experience and ensure the platform remains accessible to all authorised personnel within the transport authority.
- API
- Yes
- What users can and can't do using the API
- We provide a secure API to facilitate seamless data interoperability and integration with existing transport management systems. Users can programme the service to retrieve real-time predictive analytics, impact assessments, and historical disruption data for use in external dashboards or reporting tools. While the API supports comprehensive data retrieval and automated synchronisation, administrative system configurations and sensitive security settings are managed exclusively through the primary web-based management console. This ensures that core infrastructure parameters remain protected while allowing flexible data sharing across the buyer’s operational ecosystem. Comprehensive authentication protocols are enforced to maintain data integrity and prevent unauthorised access.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Our platform offers extensive configuration options to align with the buyer's specific operational environment and branding requirements. Users can customise data visualisation dashboards, set localised geographical boundaries for disruption monitoring, and configure automated alert parameters based on their unique key performance indicators. We also provide flexible data integration mapping to ensure the service reflects the specific multi-modal transport infrastructure of the region. These customisations are managed through a pre-agreed scope, allowing the platform to be tailored to local urban or regional requirements without altering the core software architecture.
Scaling
- Independence of resources
- Our platform utilises a highly scalable cloud infrastructure that employs automated resource scaling to handle fluctuations in demand without impacting service performance. Each client’s environment is logically isolated within a multi-tenant architecture, ensuring that the computational workload or data traffic from one user does not affect the availability or speed of the service for others. We continuously monitor resource utilisation and implement load balancing to distribute traffic effectively across our server clusters. This guarantees that all users receive a consistent and high-performing experience, even during periods of peak regional disruption when system demand may increase significantly.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide service usage metrics to help buyers monitor platform adoption and engagement levels. This includes tracking anonymised data such as total page views, frequency of user logins, and active session durations across the dashboard. These metrics offer insights into how operational teams are interacting with disruption data and predictive tools. By providing visibility into these usage patterns, we support the buyer in ensuring that the platform is being effectively utilised to enhance network resilience and that user training requirements are being met.
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- We ensure the buyer retains full data sovereignty. Historical operational data and analysis reports can be retrieved in standard formats, such as CSV and Microsoft Excel. We facilitate data extraction to ensure seamless integration with the buyer’s internal systems or for archiving purposes. This approach prevents proprietary vendor lock-in and ensures a smooth transition of assets at the end of the contract, aligned with the buyer’s data retention requirements.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Microsoft Excel
- Data import formats
-
- CSV
- Other
- Other data import formats
- API
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Moonbility provides a guaranteed level of service availability, supported by a resilient, multi-zone cloud architecture and continuous monitoring. Our platform is designed to maintain reliable service during core operational hours through enterprise-grade infrastructure and proactive incident management.
Availability commitments are governed through service level agreements (SLAs), which are agreed with buyers at call-off stage to reflect the specific operational context and usage requirements.
In the event that guaranteed availability levels are not met, Moonbility operates a service credit mechanism. Any applicable credits are applied against future invoices, in line with the terms defined in the agreed SLA and Terms and Conditions. - Approach to resilience
- Detailed resilience and business continuity plans are available on request. For security reasons, we do not publicly disclose the specific architectural redundancies of our iSaaS platform. We can provide a comprehensive Resilience Statement directly to the buyer during the procurement process, covering our data backup procedures and service restoration protocols.
- Outage reporting
-
In the event of a service outage, we provide proactive notification to the buyer's designated technical contacts via automated email alerts. Our monitoring systems detect service disruptions in real-time, triggering these notifications to ensure the buyer is informed immediately of the situation.
We focus on direct communication to provide the buyer with the most accurate and up-to-date information regarding the nature of the incident and the estimated time for service restoration. Subsequent updates are issued periodically via email until the service is fully operational.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- In addition to username and password, we support API-based authentication for integrated systems. We use industry-standard protocols such as API Keys or OAuth 2.0 tokens to ensure secure programmatic access to our service. For human users, we also support Multi-Factor Authentication (MFA) to provide an additional layer of security beyond basic credentials.
- Access restrictions in management interfaces and support channels
-
Access to our management interfaces is strictly limited to authorised technical personnel using Multi-Factor Authentication (MFA). We follow the principle of least privilege, ensuring staff only have access to the specific resources required for their role.
All administrative actions are performed through secure, encrypted connections (HTTPS/TLS). We also use IP allowlisting for critical administrative tasks where applicable, providing an additional layer of perimeter security. Access logs are reviewed periodically to ensure ongoing compliance and security. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- Management access is secured through cloud identity management with mandatory Multi-Factor Authentication (MFA). Technical staff access administrative interfaces exclusively via encrypted TLS connections. We support identity federation for secure administrative login and use Service Accounts with scoped permissions for automated tasks. This ensures the principle of least privilege is maintained across all management activities.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Our security management follows ISO/IEC 27001 standards. We maintain clear internal policies for data access, classification, and incident response. Our Tech Lead oversees all security governance to ensure accountability. We perform regular internal audits and staff training to maintain high standards. By utilising the native compliance and security tools provided by our Tier 1 cloud infrastructure, we maintain technical guardrails across our platform to ensure buyer data remains secure and compliant.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We use a CI/CD pipeline to manage all software and infrastructure changes. All source code is version-controlled to track the entire lifecycle of every component.
Before any update reaches production, it is first deployed to a dedicated staging environment for rigorous testing. This ensures that changes are validated in a non-live environment after passing mandatory peer reviews and automated security scans. Only after successfully clearing these stages is the update authorised for deployment to the live environment. This multi-stage process prevents unverified changes from impacting our service stability or security. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We perform automated scans across both our infrastructure and application layers to identify potential weaknesses. This includes monitoring for insecure cloud configurations and checking our software dependencies for known vulnerabilities.
Identified threats are prioritised by severity. High-risk patches follow an expedited workflow: they are validated in our staging environment before being promoted to production via our CI/CD pipeline. This ensures we fix critical bugs fast without breaking the platform. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We use automated cloud logging and alerting to identify potential security compromises, such as unusual login patterns or unauthorised access attempts. Our system monitors traffic in real-time and triggers immediate notifications for any suspicious activity.
Once an anomaly is detected, our technical team performs an instant investigation to assess the risk. Critical security incidents are treated as top-priority, with an initial response aimed within 30 to 60 minutes. We use these insights to continuously refine our firewall rules and access policies to prevent future threats. - Incident management type
- Supplier-defined controls
- Incident management approach
- We have a defined incident response process where our Tech Lead initiates an immediate assessment upon identifying any security breach. Our priority is to isolate affected systems and contain the threat. Users report incidents via our support email, and we provide critical incident reports to the buyer via direct email alerts as soon as possible. Following resolution, we perform a root cause analysis to update our security policies, ensuring transparency and continuous improvement of our service.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 4%
- Between £1,000,001 and £2,500,000
- 6%
- Between £2,500,001 and £5,000,000
- 8%
- Over £5,000,001
- 10%
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for positive actions with community groups.
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce