Skip to main content

Help us improve the Digital Marketplace - send your feedback

Moonbility

Moonbility Multi-Modal Disruption Impact Platform

Moonbility is a national-scale iSaaS platform for disruption impact management. Trusted by TfGM, LNER, and National Express, it integrates real-time data to simulate intervention outcomes and streamline stakeholder communication, providing predictive analytics and control room interfaces to enhance resilience across multi-modal networks.

Features

  • National-scale transport network operations and infrastructure monitoring.
  • Real-time predictive simulation of multi-modal operational intervention scenarios.
  • Automated disruption detection with quantifiable impact and ripple-effect analytics.
  • Centralised command and control dashboard for unified situational awareness.
  • Collaborative incident management workflows to streamline stakeholder communication.
  • Scenario-based modelling to optimise transport network resilience and recovery.
  • Cloud-native iSaaS architecture with enterprise-grade security and reliability.
  • Automated data synchronisation for passenger information and communication channels.
  • Comprehensive audit trails for post-incident performance and compliance reporting.
  • Secure API gateway for seamless integration with legacy transport systems.

Benefits

  • Increased transport network resilience through data-driven intervention planning.
  • Reduced cost of operational delays by optimising real-time response times.
  • Improved situational awareness for control room operators and stakeholders.
  • Enhanced passenger experience through faster recovery and accurate communication.
  • Streamlined cross-agency collaboration via a single source of operational truth.
  • Evidence-based decision-making supported by predictive impact analytics.
  • Reduced manual processing of disruption data, increasing operational efficiency.
  • Scalable iSaaS deployment reducing total cost of ownership (TCO).
  • Improved KPI performance and regulatory compliance reporting accuracy.
  • Accelerated network recovery through pre-validated intervention strategies.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andre@moonbility.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 5 9 8 5 8 5 8 9 7 0 5 5 8 7

Contact

Moonbility Andre Wang
Telephone: 07596948400
Email: andre@moonbility.com

About the service

Service categories

Systems Infrastructure Software

System and service management

  • IT operations management
  • IT service management

IT automation and configuration management

  • Workload management
  • Datacentre system and application control
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
To ensure maximum service resilience, routine maintenance is conducted during off-peak windows with 48-hour prior notification. As a secure iSaaS solution, access requires a modern HTML5-compliant web browser. The resolution of predictive analytics is synchronised with the granularity and refresh rates of third-party transport data feeds. While our core algorithms ensure high-performance modelling, the outcomes reflect the real-time availability of infrastructure data. Any specific regional configurations are established during the formal onboarding phase to ensure alignment with local authority operational protocols.
System requirements
  • HTML5-compliant web browser (latest Chrome, Edge, or Safari).
  • Stable internet connection for real-time data synchronisation.
  • Minimum 8GB RAM recommended for optimal dashboard performance.
  • No specific proprietary hardware or local software installation required.

User support

Email or online ticketing support
Yes
Support response times
We provide a standard response time of within 4 hours for high-priority operational issues and within 1 working day for general enquiries. Support is accessible via our dedicated support email and online portal from 09:00 to 17:00 (UK time), Monday to Friday, excluding UK public holidays. During major planned transport events or critical disruptions, extended support windows can be pre-arranged to ensure continuous monitoring. All enquiries are formally logged and tracked to ensure transparent resolution. This dual-channel approach ensures that stakeholders can always reach our technical team during critical incidents.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We provide a unified, premium support tier included in the platform subscription to ensure all transport operations receive high-priority attention. This includes access to dedicated technical account managers and cloud support engineers who understand the specific operational requirements of the transport sector. General support enquiries are handled via email and our ticketing portal during standard United Kingdom business hours (09:00 - 17:00, Monday to Friday). For critical infrastructure incidents, we offer prioritised response protocols to ensure rapid resolution and continuous platform resilience. Bespoke 24/7 mission-critical support packages and onsite technical assistance are available as optional add-on services. These supplemental support modules are priced based on specific organisational resilience needs and can be tailored as part of the service agreement to ensure comprehensive operational coverage.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We facilitate a seamless transition through a structured three-phase onboarding programme. Initially, users are provided with a comprehensive library of tutorial videos and digital documentation for self-paced learning. This is followed by an intensive onsite onboarding workshop led by our specialists to align the platform’s predictive capabilities with local operational requirements. To ensure long-term success, we provide a dedicated two-week intensive support period immediately following the launch, offering real-time online assistance to resolve any queries during the critical initial adoption phase. This multi-layered approach ensures that both technical teams and operational staff can confidently manage network disruptions and enhance organisational resilience from day one.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, buyers can export their historical data and analysis reports directly from the platform. Data can be downloaded in standard CSV and Microsoft Excel formats, ensuring it can be easily integrated into the buyer's internal systems or archived. This self-service approach ensures the buyer maintains full data sovereignty and can migrate their information at any time without any proprietary vendor lock-in.
End-of-contract process
Upon expiry or termination of the contract, the buyer can export their historical data and analysis reports from the platform as part of the standard service subscription. This self-service data retrieval in standard formats, such as CSV and Microsoft Excel, is included in the contract price. Should the buyer require bespoke technical consultancy, complex data migration services, or specialised decommissioning support beyond the standard export functionality, these additional services can be provided as supplemental professional service packages. These services will be scoped and priced based on the specific project requirements and must be agreed upon in a separate Statement of Work (SOW) to ensure a tailored and secure transition of assets.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The platform is accessed via a responsive web interface designed to work across desktop, tablet, and mobile browsers. This ensures that operational data and predictive insights are accessible to users in the field or control room without the need for a separate native application.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The platform is accessed via a highly responsive web-based interface, providing a seamless and intuitive user experience across desktop, tablet, and mobile browsers. This design ensures that transport operators and strategic planners can access real-time operational data and predictive insights from any location without the need for additional software installations. The interface is optimised for high-performance data visualisation, featuring centralised dashboards that consolidate multi-modal information into a single, clear operational view. This browser-based approach facilitates rapid deployment and ensures consistent situational awareness across diverse organisational hardware environments.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We are committed to digital inclusion and ensure our web-based interface aligns with Web Content Accessibility Guidelines 2.2 Level AA standards. The platform undergoes regular internal assessments to ensure compatibility with common assistive technologies, including screen readers, keyboard-only navigation, and high-contrast display modes. We prioritise logical heading structures, descriptive alternative text for interactive elements, and sufficient colour contrast ratios to support users with visual or motor impairments. Feedback from stakeholders is continuously integrated into our development lifecycle to refine the user experience and ensure the platform remains accessible to all authorised personnel within the transport authority.
API
Yes
What users can and can't do using the API
We provide a secure API to facilitate seamless data interoperability and integration with existing transport management systems. Users can programme the service to retrieve real-time predictive analytics, impact assessments, and historical disruption data for use in external dashboards or reporting tools. While the API supports comprehensive data retrieval and automated synchronisation, administrative system configurations and sensitive security settings are managed exclusively through the primary web-based management console. This ensures that core infrastructure parameters remain protected while allowing flexible data sharing across the buyer’s operational ecosystem. Comprehensive authentication protocols are enforced to maintain data integrity and prevent unauthorised access.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Our platform offers extensive configuration options to align with the buyer's specific operational environment and branding requirements. Users can customise data visualisation dashboards, set localised geographical boundaries for disruption monitoring, and configure automated alert parameters based on their unique key performance indicators. We also provide flexible data integration mapping to ensure the service reflects the specific multi-modal transport infrastructure of the region. These customisations are managed through a pre-agreed scope, allowing the platform to be tailored to local urban or regional requirements without altering the core software architecture.

Scaling

Independence of resources
Our platform utilises a highly scalable cloud infrastructure that employs automated resource scaling to handle fluctuations in demand without impacting service performance. Each client’s environment is logically isolated within a multi-tenant architecture, ensuring that the computational workload or data traffic from one user does not affect the availability or speed of the service for others. We continuously monitor resource utilisation and implement load balancing to distribute traffic effectively across our server clusters. This guarantees that all users receive a consistent and high-performing experience, even during periods of peak regional disruption when system demand may increase significantly.

Analytics

Service usage metrics
Yes
Metrics types
We provide service usage metrics to help buyers monitor platform adoption and engagement levels. This includes tracking anonymised data such as total page views, frequency of user logins, and active session durations across the dashboard. These metrics offer insights into how operational teams are interacting with disruption data and predictive tools. By providing visibility into these usage patterns, we support the buyer in ensuring that the platform is being effectively utilised to enhance network resilience and that user training requirements are being met.
Reporting types
Reports on request
Resource tagging
No
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
We ensure the buyer retains full data sovereignty. Historical operational data and analysis reports can be retrieved in standard formats, such as CSV and Microsoft Excel. We facilitate data extraction to ensure seamless integration with the buyer’s internal systems or for archiving purposes. This approach prevents proprietary vendor lock-in and ensures a smooth transition of assets at the end of the contract, aligned with the buyer’s data retention requirements.
Data export formats
  • CSV
  • Other
Other data export formats
Microsoft Excel
Data import formats
  • CSV
  • Other
Other data import formats
API

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Moonbility provides a guaranteed level of service availability, supported by a resilient, multi-zone cloud architecture and continuous monitoring. Our platform is designed to maintain reliable service during core operational hours through enterprise-grade infrastructure and proactive incident management.

Availability commitments are governed through service level agreements (SLAs), which are agreed with buyers at call-off stage to reflect the specific operational context and usage requirements.

In the event that guaranteed availability levels are not met, Moonbility operates a service credit mechanism. Any applicable credits are applied against future invoices, in line with the terms defined in the agreed SLA and Terms and Conditions.
Approach to resilience
Detailed resilience and business continuity plans are available on request. For security reasons, we do not publicly disclose the specific architectural redundancies of our iSaaS platform. We can provide a comprehensive Resilience Statement directly to the buyer during the procurement process, covering our data backup procedures and service restoration protocols.
Outage reporting
In the event of a service outage, we provide proactive notification to the buyer's designated technical contacts via automated email alerts. Our monitoring systems detect service disruptions in real-time, triggering these notifications to ensure the buyer is informed immediately of the situation.

We focus on direct communication to provide the buyer with the most accurate and up-to-date information regarding the nature of the incident and the estimated time for service restoration. Subsequent updates are issued periodically via email until the service is fully operational.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Other user authentication
In addition to username and password, we support API-based authentication for integrated systems. We use industry-standard protocols such as API Keys or OAuth 2.0 tokens to ensure secure programmatic access to our service. For human users, we also support Multi-Factor Authentication (MFA) to provide an additional layer of security beyond basic credentials.
Access restrictions in management interfaces and support channels
Access to our management interfaces is strictly limited to authorised technical personnel using Multi-Factor Authentication (MFA). We follow the principle of least privilege, ensuring staff only have access to the specific resources required for their role.

All administrative actions are performed through secure, encrypted connections (HTTPS/TLS). We also use IP allowlisting for critical administrative tasks where applicable, providing an additional layer of perimeter security. Access logs are reviewed periodically to ensure ongoing compliance and security.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
  • Other
Description of management access authentication
Management access is secured through cloud identity management with mandatory Multi-Factor Authentication (MFA). Technical staff access administrative interfaces exclusively via encrypted TLS connections. We support identity federation for secure administrative login and use Service Accounts with scoped permissions for automated tasks. This ensures the principle of least privilege is maintained across all management activities.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Our security management follows ISO/IEC 27001 standards. We maintain clear internal policies for data access, classification, and incident response. Our Tech Lead oversees all security governance to ensure accountability. We perform regular internal audits and staff training to maintain high standards. By utilising the native compliance and security tools provided by our Tier 1 cloud infrastructure, we maintain technical guardrails across our platform to ensure buyer data remains secure and compliant.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We use a CI/CD pipeline to manage all software and infrastructure changes. All source code is version-controlled to track the entire lifecycle of every component.

Before any update reaches production, it is first deployed to a dedicated staging environment for rigorous testing. This ensures that changes are validated in a non-live environment after passing mandatory peer reviews and automated security scans. Only after successfully clearing these stages is the update authorised for deployment to the live environment. This multi-stage process prevents unverified changes from impacting our service stability or security.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We perform automated scans across both our infrastructure and application layers to identify potential weaknesses. This includes monitoring for insecure cloud configurations and checking our software dependencies for known vulnerabilities.

Identified threats are prioritised by severity. High-risk patches follow an expedited workflow: they are validated in our staging environment before being promoted to production via our CI/CD pipeline. This ensures we fix critical bugs fast without breaking the platform.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use automated cloud logging and alerting to identify potential security compromises, such as unusual login patterns or unauthorised access attempts. Our system monitors traffic in real-time and triggers immediate notifications for any suspicious activity.

Once an anomaly is detected, our technical team performs an instant investigation to assess the risk. Critical security incidents are treated as top-priority, with an initial response aimed within 30 to 60 minutes. We use these insights to continuously refine our firewall rules and access policies to prevent future threats.
Incident management type
Supplier-defined controls
Incident management approach
We have a defined incident response process where our Tech Lead initiates an immediate assessment upon identifying any security breach. Our priority is to isolate affected systems and contain the threat. Users report incidents via our support email, and we provide critical incident reports to the buyer via direct email alerts as soon as possible. Following resolution, we perform a root cause analysis to update our security policies, ensuring transparency and continuous improvement of our service.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
4%
Between £1,000,001 and £2,500,000
6%
Between £2,500,001 and £5,000,000
8%
Over £5,000,001
10%

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
  • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible

Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

  • Plans for positive actions with community groups.
Mission: Break down barriers to opportunity

By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

  • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at andre@moonbility.com. Tell them what format you need. It will help if you say what assistive technology you use.