Flood Platform
Flood Platform is a cloud-based solution designed to unify and streamline flood modelling workflows. It provides a centralised hub for model management, enabling secure storage and collaboration among modelling teams and stakeholders. Includes advanced visualisation tools for modelling data and results, simulation and analysis capabilities, and integrated reporting features.
Features
- Secure centralised model storage and version control
- Cloud-based storage, simulation and analysis of flood data
- Visulationsation tools, clear, actionable insights
- Automated generation of compliance-ready reports
- Granular role-based access controls
- Real-time sharing across teams and organisations
- Automated workflows. Standardised processes to streamline operations
- External data integration capability
- QA review and validation tools
- Future-ready AI enhancements
Benefits
- Centralised model storage and management - ensures access and sharing
- Cloud-Based Simulation – Run simulations quickly with scalable resources
- Visualisation Intuitive visual tools for clear insights
- Automate report generation to reduce errors and improve compliance
- Collaboration Tools – realtime feedback across teams and organisation
- Enterprise-grade security with two-factor authentication protects data.
- Standardise processes to boost efficiency and reduce operational costs.
- Seamlessly connect with external sources for richer analysis.
- QA – Perform collaborative QA checks to accelerate delivery.
- AI - Future ready enhancements driven by AI
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 9 5 0 9 0 7 3 0 0 2 0 9 6 9
Contact
JACOBS U.K. LIMITED
Hugh McMichael
Telephone: 0131 659 1500
Email: gcloudframework@jacobs.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Location and geospatial data management and analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
-
- Compliant web browser
- Internet connection
- 3rd party software licences where applicable (extended functionality) e.g. TUFLOW
User support
- Email or online ticketing support
- Yes
- Support response times
-
Response within 1 working day.
Standard support not provided during weekends or UK Public Holidays.
Enterprise support available 7 days a week. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
User support is provided via a dedicated knowledge base and a technical support team, with tickets created online, via email or phone call.
Our support SLA is detailed here https://app.floodplatform.com/page/support-policy
Cost of support is included in service subscription fee
Enhanced support available on request at additional cost
Support engineers accessed via front line support - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
An onboarding session is available at start of all new contracts - delivered online.
In-built step-through guides assist new users.
Knowledge base includes quick start guides - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
Customers (users) are able to self download the data at any point to their desktop.
We provide a grace period at the end of the contract to enable download.
If a customer requires data transferring to another cloud location or service provider (e.g. Azure Blob Storage) this can be arranged (may attract an additional cost). - End-of-contract process
-
Access to the operational features of the platform and support ceases.
Users ability to store additional data, undertake data processing or simulations also ceases.
Users have a grace period to download their data.
If a customer requires data transferring to another cloud location or service provider (e.g. Azure Blob Storage) this can be arranged (may attract an additional cost). - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- WCAG 2.2 A
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- We are able to auto-scale workloads, specifically core functionality, data processing and simulations. However, compute resources (quota) for simulations (CPU and GPU) are constrained by the limits (quota) placed upon us by Microsoft. On request we can arrange with Microsoft for additional quota.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Data Storage used, Data Processing Compute Credits used, Simulation Credits used. These are provided at Organisational, Teamspace, and Project level.
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
There is a "Export" function that enables users to to download partial or full flood model data files (input and output).
There is also the ability to "Transfer" data to another organisation. - Data export formats
- Other
- Other data export formats
- Native model data file formats
- Data import formats
- Other
- Other data import formats
-
- Native model data file formats.
- Non-model data - PDF, Microsoft office, etc
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Kubernetes Ingress controller
Availability and resilience
- Guaranteed availability
-
Jacobs shall, subject to paragraph 2.6 of our support policy (https://app.floodplatform.com/page/support-policy), use Commercially Reasonable Efforts to make Flood Platform available twenty-four hours a day, seven days a week, except for when planned and unscheduled maintenance need to be carried out. Both planned and unscheduled maintenance will be undertaken at times to cause the least disruption and with as much advance notice as possible.
DATA RESILIANCE
Data resilience is based on Microsoft Azure Locally Redundant Storage (LRS): LRS stores three copies of your data that all reside within a single data centre. The data is written across all three copies synchronously.
LRS storage provides a resiliency of 11 nines (99.999999999 %) over a given year. While LRS storage protects your data from drive or server rack failures, the availability of data would be impacted if an outage ever affects the data centre used to host Flood Platform. - Approach to resilience
- It’s available on request.
- Outage reporting
- Users will be notified of planned outages in advance via email. Users are notified of outages in progress (both planned and unplanned) via the service login page.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Users permissions are assigned and managed by organisations. Only organisation "owners" and "admins" can access restricted interfaces. There are no restrictions on access to support channels.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
ISO9001, ISO14001, ISO45001 and SSIP LRQA Registration Certificate
NIST CSF
ISO27001
Cyber Essentials Plus - Information security policies and processes
-
Information Security Policies & Processes
We operate under a Global Security Policy, UK Information Security Policy, and Global Data Protection Policy, all supported by ISO 27001 and Cyber Essentials Plus accreditation. Our Security Operations Centre provides 24/7 monitoring of networks, servers, and endpoints. Access to information is governed by “need-to-know” principles, with controls such as classified document registers, secure transfer protocols, clear-desk policies, and documented backup/recovery procedures. All staff undergo annual security awareness training, sign acceptable-use policies, and complete BPSS vetting with controlled office access.
Reporting Structure
Security oversight is led by a Board-level Senior Information Risk Owner (SIRO), supported by a Group Security Controller (GSC) and a Corporate Security Team. The named Security Controller for UK/B&I Europe is Steve Colwill.
Ensuring Adherence
We ensure compliance through regular risk-register reviews, incident reporting and updates, IT governance and internal audit, and by aligning suppliers with our security procedures. These measures collectively maintain robust information security and policy adherence across the organization. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All service components, including application code, configuration, and infrastructure, are version-controlled and tracked using Azure DevOps. Each change is linked to a work item, providing traceability through to deployment.
changes are reviewed and approved before development. Changes are assessed for security impact, including effects on data handling, access control, integrations, system exposure.
Changes are developed in controlled environments and subject to peer review and automated checks. The service is penetration tested by internal IT prior to deployment to production. Any identified issues must be resolved before release.
Only approved are deployed using auditable release processes. Only approved individuals can deploy. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Potential threats are assessed through a combination of automated tooling and internal security review. This includes static code analysis, automated dependency scanning, and regular security scans. The service is hosted on Azure, benefiting from platform monitoring Via Defender.
Remediation actions are prioritised based on severity and potential impact. Patches and fixes are normally deployed as part of the regular development cycle, with releases occurring at least once per sprint (typically every two weeks). Where critical or high-risk vulnerabilities are identified, urgent hotfixes can be developed.
All remediation activity is tracked and auditable. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Azure hosting provides platform monitoring and threat detection, including security alerts from Defender. Application and infrastructure logs are captured and reviewed as part of operational support and incident investigation.
Security alerts and findings from automated tools or internal IT security scans are reviewed and acted upon as required, with remediation tracked through established change and vulnerability management processes.
Remediation actions are prioritised based on severity and potential impact. Patches are deployed as part of the regular development cycle, with releases occurring at least once per sprint. Where critical or high-risk vulnerabilities are identified, hotfixes can be developed. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Pre-defined processes are in place for common event types, including service outages, security issues, and platform-related incidents. These processes define assessment, response, escalation, and resolution activities.
Users report incidents by submitting a support ticket or by emailing the Flood Platform support team. All incidents are logged, assessed for severity and impact, and tracked through to resolution.
Where relevant, incidents are communicated to users via email. Communications are proportionate to the nature and impact of the incident and may include status updates and resolution information.
Incident outcomes are recorded and used to inform service improvements and preventative actions. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
14 Day Free access
Basic onboarding
No support via telephone
Support via email
Limited free credit for data analysis and simulation - Link to free trial
- Www.floodplatform.com
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA Limited
- ISO/IEC 27001 accreditation date
- Monday 2 September 2024
- What the ISO/IEC 27001 doesn’t cover
-
The scope of this approval is applicable to:
The scope of the ISMS includes the protection of all information and data assets for the delivery of services by Jacobs to its clients. The assets protected are physical locations, information assets, and applicable information technology assets to support the organization’s lines of business and in-scope services in accordance with the Statement of Applicability (SoA) v1.n.
This Certification covers the following Lines of Business and named projects.
Critical Missions Solutions
People & Places Solutions
Divergent Solutions
Bonneville Power Administration Project
Operating from permanent, temporary office and hybrid locations as defined within scope, for Jacobs Solutions Inc. and following subsidiaries which contain additional legal entities: Jacobs Australia Pty Limited, Jacobs Engineering Ireland Ltd, Jacobs Germany GmbH, Jacobs Group (Australia) Pty Limited, Jacobs New Zealand Ltd, Jacobs Project Management Company, Jacobs Technology Inc, Jacobs UK Ltd, Jacobs Field Services Limited, CH2M HILL POLSKA Limited SP. Z O.O. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA Limited
- ISO 9001 accreditation date
- Friday 10 January 2025
- What the ISO 9001 doesn’t cover
-
The scope of this approval is applicable to:
The provision of full life cycle services comprising multi-disciplinary consulting, programme and project management, advisory, planning, research, software development, design, engineering, project controls, procurement, construction, construction management, installation and maintenance of electrical instrumentation, management of sub-contractors and provision of site contract labour and training, commissioning, qualification & validation and decommissioning, independent certification of regulatory information, management of information and operational support teams in connection with the built environment and the protection, enhancement and maintenance of the natural environment.
Operating from permanent and temporary office and site locations across the UK, Ireland, The Netherlands, Poland, France, Germany - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Cfb49fe7-e1a3-4ca5-a6c7-d23b2a899579
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Plans for positive actions with community groups.
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-