Service Charge Pro
Service Charge Pro is a cloud-hosted service charge management system for housing providers. It supports service charge budgeting, actualisation, apportionment, reconciliation, audit support and resident statements. The service provides real-time visibility of service charge positions, detailed deficit analysis, and automated production of statutory information, including Section 22 documentation.
Features
- Cloud-hosted, browser-based service charge management application
- Real-time service charge actualisation and apportionment
- Flexible apportionment rules configurable to leases and tenancies
- End-to-end service charge budgeting and reconciliation
- Real-time deficit and surplus analysis by scheme and cost type
- Automated production of resident statements and statutory reports
- Audit trail and controls supporting service charge assurance
- Integration with finance and housing management systems via interfaces
- Single-tenant deployment with logical data segregation
Benefits
- Reduce reliance on spreadsheets through automated service charge processing
- Maintain up-to-date service charge positions throughout the year
- Support fair and consistent recharging across complex property portfolios
- Improve visibility of service charge deficits and recovery risks
- Simplify preparation of audit evidence and statutory documentation
- Enable clearer explanations of charges to residents
- Reduce manual effort in service charge calculations and adjustments
- Support timely identification of data issues and anomalies
- Provide a single system for service charge management processes
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 6 0 7 3 2 3 2 7 2 8 4 3 2 5
Contact
BRX Technology
Raj Rajendram
Telephone: 07491514848
Email: info@brx-technology.co.uk
About your service
- Service categories
-
Applications
Enterprise resource management
Financial
- Financial and Accounting Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No material service constraints beyond standard SaaS operational requirements.
- System requirements
-
- Modern web browser
- Internet connection
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support is provided via email and an online ticketing system during core business hours (09:00–18:00, Monday to Friday).
Issues are triaged by severity on receipt. Critical incidents are responded to as a priority, with rapid acknowledgement and active investigation. Lower-severity queries are responded to as part of normal support operations.
Weekend support is not provided as standard but can be agreed for specific operational periods. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
A single standard support level is provided and included within the service subscription.
Support is delivered via email, phone and an online ticketing system during core business hours. Queries and incidents are triaged and handled by the supplier, with issues escalated internally as required.
A named account contact is provided for each customer and is responsible for overall service relationship management and coordination of support.
Enhanced or out-of-hours support, including onsite support, can be provided by agreement and is chargeable depending on requirements. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Users are supported through a structured onboarding process to enable effective use of the service as a standard, configurable product.
Onboarding typically includes initial setup and configuration aligned to the organisation’s service charge structures, supported data migration where required, and testing and validation of outputs to ensure accuracy. Where organisations require support to clarify or confirm service charge structures prior to configuration, this can be supported as part of the onboarding process.
Training is delivered using a train-the-trainer approach, supported by guided walkthroughs and training sessions tailored to user roles. This enables organisations to build internal capability to use and maintain the service effectively.
User documentation is provided to support ongoing use of the service, including guidance on configuration and use of core functionality.
Training and support can be delivered remotely or onsite, depending on the scope and nature of the training required. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
At the end of the contract, users can extract their data in full. Data is provided as structured database exports, including SQL exports of the customer’s data, covering configuration, transactional and reference data held within the service.
Data extraction is supported by the supplier as part of contract exit to ensure data is complete and transferred securely. Where required, additional guidance can be provided by agreement to assist customers or their appointed third parties in understanding the exported data structure. - End-of-contract process
-
At the end of the contract, access to the service is withdrawn in line with the agreed contract end date. The supplier supports contract exit by providing the customer with a complete export of their data, including configuration and transactional data, to enable transition to another system or internal archiving.
Data extraction in the standard export format is included as part of the contract. Data is transferred securely and in accordance with agreed information security arrangements.
Additional exit support, such as assistance with data interpretation, extended access periods, bespoke export formats or support for migration to a replacement system, can be provided by agreement and may incur additional costs depending on scope and requirements. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Onboarding and offboarding documentation is provided in PDF format and is accessible using standard accessibility features available in modern browsers and operating systems, such as screen magnification, zoom controls and text resizing.
Documentation is written using clear language and structured content to support readability and ease of navigation. Content is organised into sections to help users locate relevant information efficiently.
The documentation has not been formally audited against specific accessibility standards and may not be fully compatible with all assistive technologies. Alternative formats or additional support can be discussed where required as part of onboarding or service transition activities.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is accessed via a secure, browser-based web application. The interface provides role-based access to service charge data, including budgets, actuals, apportionment rules, reporting and resident outputs. Users interact with the service through standard web forms, tables and reports, with navigation designed for use on desktop devices.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service is accessed through a browser-based web interface and supports standard accessibility features provided by modern browsers and operating systems, such as keyboard navigation and screen magnification. The interface is designed for use on desktop devices and uses standard web components. The service has not been formally audited against accessibility standards and may not be fully usable with all assistive technologies.
- Accessibility testing
- Formal testing with users of assistive technology has not yet been conducted. Accessibility considerations are taken into account during design and development, and feedback from users is incorporated where accessibility issues are identified.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
The service is provided as a standard product and can be configured to align with an organisation’s service charge rules, property structures and resident requirements.
Configurable elements include apportionment rules, property recharging hierarchies, cost groupings, service charge exclusions and drop-down list values. Configuration is performed through the service interface by authorised users and may also be supported by the supplier during implementation and ongoing service use.
Customisation is delivered through configuration and data setup, rather than changes to the underlying product.
Scaling
- Independence of resources
- Each customer is deployed into a dedicated service environment, ensuring isolation of application resources and data. This architecture prevents demand from one customer impacting the performance or availability experienced by others. Underlying cloud infrastructure is provisioned and managed to support the expected workload for each environment, with monitoring in place to identify and address capacity-related issues.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service includes standard in-application dashboards providing real-time visibility of processing activity and team progress within the system. These dashboards support operational management by showing workload status and activity levels. In addition, service usage metrics can be provided on request to support service management and review, including user activity and volume-based metrics. Metrics are not exposed through external analytics platforms or APIs.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export their data directly from the service using structured data extracts. Exports include service charge configuration, transactional data and reference data, and are provided in standard formats suitable for analysis and reporting in external tools.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Xlsx
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- Other
- Other protection within supplier network
- Data stored within the service is encrypted at rest using AES-256 encryption.
Availability and resilience
- Guaranteed availability
- The service is hosted on resilient cloud infrastructure and is operated to support high levels of availability. Planned maintenance is scheduled to minimise disruption, and unplanned incidents are managed in line with established incident management processes. Availability may be affected by maintenance activities or events outside the supplier’s reasonable control. Availability commitments, where required, can be agreed as part of a specific call-off contract.
- Approach to resilience
-
The service is hosted on resilient cloud infrastructure within Microsoft Azure and is designed to minimise single points of failure. The platform uses managed cloud services and redundant components appropriate to the service’s operating model to support continuity of service.
Customer environments are deployed independently, which limits the impact of faults and reduces the risk of cross-customer impact.
The underlying datacentre infrastructure is operated by a third-party cloud provider and benefits from built-in physical security, redundancy and resilience measures in line with industry standards.
Further details of the service architecture and resilience approach can be made available on request. - Outage reporting
-
Service availability is monitored to identify and respond to incidents that impact users. Where an outage affects users, communication is provided directly to impacted customers by email within a reasonable timeframe, with updates provided as appropriate until service is restored.
The service does not provide a public status dashboard or API for outage reporting. Outage information and updates are managed through direct communication to ensure information is accurate and relevant to the affected customer environment.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted using role-based access controls, ensuring users only have access to functions and data appropriate to their role. Administrative permissions are limited to authorised users and reviewed periodically. Access to support channels is restricted to named contacts within the customer organisation, with identity verified before actions affecting customer data or configuration are undertaken. Support access is logged and controlled to maintain auditability and prevent unauthorised changes.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security governance is overseen at a senior level within the organisation, with responsibility for security and risk management held by the CEO. The organisation follows a risk-based approach to security, informed by recognised best practice, including regular independent penetration testing, secure cloud hosting and defined processes for access control, data protection and incident management. Security practices are reviewed periodically and updated as the service evolves. The organisation is progressing towards Cyber Essentials certification, with certification planned for Q1.
- Information security policies and processes
-
The organisation operates a set of information security policies covering key areas including access control, data protection, incident management and acceptable use. Responsibility for information security sits at senior management level, with overall accountability held by the CEO.
Policies are communicated to staff and contractors and are supported by defined processes, including role-based access controls, secure handling of customer data, and regular review of user access. Compliance with security policies is reinforced through onboarding, contractual obligations with suppliers and contractors, and periodic review of controls.
Security incidents or concerns are escalated through a defined reporting structure and investigated promptly. Independent penetration testing is carried out annually to provide assurance that controls remain effective, and automated vulnerability scanning is used to identify potential security issues between formal testing cycles. Policies and processes are reviewed and updated as the service and organisation evolve. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Service configuration and changes are managed through defined internal processes. Service components and configuration are version-controlled and tracked through their lifecycle. Changes are assessed prior to implementation to identify potential security or operational impacts, with higher-risk changes reviewed and approved at senior level. Changes are tested before deployment and deployed in a controlled manner to minimise risk and disruption. Configuration and change activities are logged to support traceability and review.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management follows a risk-based approach. Potential threats are identified through ongoing automated vulnerability scanning, independent penetration testing and monitoring of relevant security advisories from suppliers and trusted sources. Identified vulnerabilities are assessed based on severity and potential impact to the service. Patches and mitigations are prioritised accordingly and deployed in a controlled manner, with higher-risk issues addressed promptly and validated following deployment.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is implemented through service and security monitoring to identify abnormal behaviour, errors and potential security issues. Alerts from monitoring, vulnerability scanning and operational checks are reviewed to identify potential compromises. Where a potential security incident is identified, it is investigated promptly, appropriate containment actions are taken, and escalation occurs in line with the incident management process. Response actions are prioritised based on severity and potential impact, with higher-risk incidents addressed urgently and customers informed where required.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The organisation operates defined incident management processes for common operational and security events. Users can report incidents via the support desk, with incidents logged, triaged and managed according to severity. Incidents are investigated and resolved using established procedures, with escalation where required. Where incidents impact customers, updates and summary information are provided directly, including incident reports where appropriate, to support transparency and post-incident review.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-