Skip to main content

Help us improve the Digital Marketplace - send your feedback

BRX Technology

Service Charge Pro

Service Charge Pro is a cloud-hosted service charge management system for housing providers. It supports service charge budgeting, actualisation, apportionment, reconciliation, audit support and resident statements. The service provides real-time visibility of service charge positions, detailed deficit analysis, and automated production of statutory information, including Section 22 documentation.

Features

  • Cloud-hosted, browser-based service charge management application
  • Real-time service charge actualisation and apportionment
  • Flexible apportionment rules configurable to leases and tenancies
  • End-to-end service charge budgeting and reconciliation
  • Real-time deficit and surplus analysis by scheme and cost type
  • Automated production of resident statements and statutory reports
  • Audit trail and controls supporting service charge assurance
  • Integration with finance and housing management systems via interfaces
  • Single-tenant deployment with logical data segregation

Benefits

  • Reduce reliance on spreadsheets through automated service charge processing
  • Maintain up-to-date service charge positions throughout the year
  • Support fair and consistent recharging across complex property portfolios
  • Improve visibility of service charge deficits and recovery risks
  • Simplify preparation of audit evidence and statutory documentation
  • Enable clearer explanations of charges to residents
  • Reduce manual effort in service charge calculations and adjustments
  • Support timely identification of data issues and anomalies
  • Provide a single system for service charge management processes

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@brx-technology.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 6 0 7 3 2 3 2 7 2 8 4 3 2 5

Contact

BRX Technology Raj Rajendram
Telephone: 07491514848
Email: info@brx-technology.co.uk

About your service

Service categories

Applications

Enterprise resource management

Financial

  • Financial and Accounting Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
No material service constraints beyond standard SaaS operational requirements.
System requirements
  • Modern web browser
  • Internet connection

User support

Email or online ticketing support
Yes
Support response times
Support is provided via email and an online ticketing system during core business hours (09:00–18:00, Monday to Friday).

Issues are triaged by severity on receipt. Critical incidents are responded to as a priority, with rapid acknowledgement and active investigation. Lower-severity queries are responded to as part of normal support operations.

Weekend support is not provided as standard but can be agreed for specific operational periods.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
A single standard support level is provided and included within the service subscription.

Support is delivered via email, phone and an online ticketing system during core business hours. Queries and incidents are triaged and handled by the supplier, with issues escalated internally as required.

A named account contact is provided for each customer and is responsible for overall service relationship management and coordination of support.

Enhanced or out-of-hours support, including onsite support, can be provided by agreement and is chargeable depending on requirements.
Support available to third parties
No

Onboarding and offboarding

Getting started
Users are supported through a structured onboarding process to enable effective use of the service as a standard, configurable product.

Onboarding typically includes initial setup and configuration aligned to the organisation’s service charge structures, supported data migration where required, and testing and validation of outputs to ensure accuracy. Where organisations require support to clarify or confirm service charge structures prior to configuration, this can be supported as part of the onboarding process.

Training is delivered using a train-the-trainer approach, supported by guided walkthroughs and training sessions tailored to user roles. This enables organisations to build internal capability to use and maintain the service effectively.

User documentation is provided to support ongoing use of the service, including guidance on configuration and use of core functionality.

Training and support can be delivered remotely or onsite, depending on the scope and nature of the training required.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
At the end of the contract, users can extract their data in full. Data is provided as structured database exports, including SQL exports of the customer’s data, covering configuration, transactional and reference data held within the service.

Data extraction is supported by the supplier as part of contract exit to ensure data is complete and transferred securely. Where required, additional guidance can be provided by agreement to assist customers or their appointed third parties in understanding the exported data structure.
End-of-contract process
At the end of the contract, access to the service is withdrawn in line with the agreed contract end date. The supplier supports contract exit by providing the customer with a complete export of their data, including configuration and transactional data, to enable transition to another system or internal archiving.

Data extraction in the standard export format is included as part of the contract. Data is transferred securely and in accordance with agreed information security arrangements.

Additional exit support, such as assistance with data interpretation, extended access periods, bespoke export formats or support for migration to a replacement system, can be provided by agreement and may incur additional costs depending on scope and requirements.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and offboarding documentation is provided in PDF format and is accessible using standard accessibility features available in modern browsers and operating systems, such as screen magnification, zoom controls and text resizing.

Documentation is written using clear language and structured content to support readability and ease of navigation. Content is organised into sections to help users locate relevant information efficiently.

The documentation has not been formally audited against specific accessibility standards and may not be fully compatible with all assistive technologies. Alternative formats or additional support can be discussed where required as part of onboarding or service transition activities.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service is accessed via a secure, browser-based web application. The interface provides role-based access to service charge data, including budgets, actuals, apportionment rules, reporting and resident outputs. Users interact with the service through standard web forms, tables and reports, with navigation designed for use on desktop devices.
Accessibility standards
None or don’t know
Description of accessibility
The service is accessed through a browser-based web interface and supports standard accessibility features provided by modern browsers and operating systems, such as keyboard navigation and screen magnification. The interface is designed for use on desktop devices and uses standard web components. The service has not been formally audited against accessibility standards and may not be fully usable with all assistive technologies.
Accessibility testing
Formal testing with users of assistive technology has not yet been conducted. Accessibility considerations are taken into account during design and development, and feedback from users is incorporated where accessibility issues are identified.
API
No
Customisation available
Yes
Description of customisation
The service is provided as a standard product and can be configured to align with an organisation’s service charge rules, property structures and resident requirements.

Configurable elements include apportionment rules, property recharging hierarchies, cost groupings, service charge exclusions and drop-down list values. Configuration is performed through the service interface by authorised users and may also be supported by the supplier during implementation and ongoing service use.

Customisation is delivered through configuration and data setup, rather than changes to the underlying product.

Scaling

Independence of resources
Each customer is deployed into a dedicated service environment, ensuring isolation of application resources and data. This architecture prevents demand from one customer impacting the performance or availability experienced by others. Underlying cloud infrastructure is provisioned and managed to support the expected workload for each environment, with monitoring in place to identify and address capacity-related issues.

Analytics

Service usage metrics
Yes
Metrics types
The service includes standard in-application dashboards providing real-time visibility of processing activity and team progress within the system. These dashboards support operational management by showing workload status and activity levels. In addition, service usage metrics can be provided on request to support service management and review, including user activity and volume-based metrics. Metrics are not exposed through external analytics platforms or APIs.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data directly from the service using structured data extracts. Exports include service charge configuration, transactional data and reference data, and are provided in standard formats suitable for analysis and reporting in external tools.
Data export formats
  • CSV
  • Other
Other data export formats
Xlsx
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
Other
Other protection within supplier network
Data stored within the service is encrypted at rest using AES-256 encryption.

Availability and resilience

Guaranteed availability
The service is hosted on resilient cloud infrastructure and is operated to support high levels of availability. Planned maintenance is scheduled to minimise disruption, and unplanned incidents are managed in line with established incident management processes. Availability may be affected by maintenance activities or events outside the supplier’s reasonable control. Availability commitments, where required, can be agreed as part of a specific call-off contract.
Approach to resilience
The service is hosted on resilient cloud infrastructure within Microsoft Azure and is designed to minimise single points of failure. The platform uses managed cloud services and redundant components appropriate to the service’s operating model to support continuity of service.

Customer environments are deployed independently, which limits the impact of faults and reduces the risk of cross-customer impact.

The underlying datacentre infrastructure is operated by a third-party cloud provider and benefits from built-in physical security, redundancy and resilience measures in line with industry standards.

Further details of the service architecture and resilience approach can be made available on request.
Outage reporting
Service availability is monitored to identify and respond to incidents that impact users. Where an outage affects users, communication is provided directly to impacted customers by email within a reasonable timeframe, with updates provided as appropriate until service is restored.

The service does not provide a public status dashboard or API for outage reporting. Outage information and updates are managed through direct communication to ensure information is accurate and relevant to the affected customer environment.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted using role-based access controls, ensuring users only have access to functions and data appropriate to their role. Administrative permissions are limited to authorised users and reviewed periodically. Access to support channels is restricted to named contacts within the customer organisation, with identity verified before actions affecting customer data or configuration are undertaken. Support access is logged and controlled to maintain auditability and prevent unauthorised changes.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Security governance is overseen at a senior level within the organisation, with responsibility for security and risk management held by the CEO. The organisation follows a risk-based approach to security, informed by recognised best practice, including regular independent penetration testing, secure cloud hosting and defined processes for access control, data protection and incident management. Security practices are reviewed periodically and updated as the service evolves. The organisation is progressing towards Cyber Essentials certification, with certification planned for Q1.
Information security policies and processes
The organisation operates a set of information security policies covering key areas including access control, data protection, incident management and acceptable use. Responsibility for information security sits at senior management level, with overall accountability held by the CEO.

Policies are communicated to staff and contractors and are supported by defined processes, including role-based access controls, secure handling of customer data, and regular review of user access. Compliance with security policies is reinforced through onboarding, contractual obligations with suppliers and contractors, and periodic review of controls.

Security incidents or concerns are escalated through a defined reporting structure and investigated promptly. Independent penetration testing is carried out annually to provide assurance that controls remain effective, and automated vulnerability scanning is used to identify potential security issues between formal testing cycles. Policies and processes are reviewed and updated as the service and organisation evolve.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Service configuration and changes are managed through defined internal processes. Service components and configuration are version-controlled and tracked through their lifecycle. Changes are assessed prior to implementation to identify potential security or operational impacts, with higher-risk changes reviewed and approved at senior level. Changes are tested before deployment and deployed in a controlled manner to minimise risk and disruption. Configuration and change activities are logged to support traceability and review.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerability management follows a risk-based approach. Potential threats are identified through ongoing automated vulnerability scanning, independent penetration testing and monitoring of relevant security advisories from suppliers and trusted sources. Identified vulnerabilities are assessed based on severity and potential impact to the service. Patches and mitigations are prioritised accordingly and deployed in a controlled manner, with higher-risk issues addressed promptly and validated following deployment.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is implemented through service and security monitoring to identify abnormal behaviour, errors and potential security issues. Alerts from monitoring, vulnerability scanning and operational checks are reviewed to identify potential compromises. Where a potential security incident is identified, it is investigated promptly, appropriate containment actions are taken, and escalation occurs in line with the incident management process. Response actions are prioritised based on severity and potential impact, with higher-risk incidents addressed urgently and customers informed where required.
Incident management type
Supplier-defined controls
Incident management approach
The organisation operates defined incident management processes for common operational and security events. Users can report incidents via the support desk, with incidents logged, triaged and managed according to severity. Incidents are investigated and resolved using established procedures, with escalation where required. Where incidents impact customers, updates and summary information are provided directly, including incident reports where appropriate, to support transparency and post-incident review.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@brx-technology.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.