Azzido Customer Information - (CIS)
Azzido Cloud is a secure, scalable passenger information platform for transport networks. It centralises real-time data ingestion, orchestration and distribution across cloud, edge and display devices. Operators manage content, disruption messaging and analytics through a single interface, ensuring compliant, resilient, high-quality customer information at scale for modern multimodal transport systems.
Features
- Real-time passenger information platform
- Automates passenger information decisions through configurable business rules.
- Rapid, controlled response to incidents across all information channels
- Multi-channel distribution framework
- Improves control room coordination and decision-making during disruption events
- Multi-language visual and audio passenger information delivery
- Simplifies deployment and support through centrally managed SaaS delivery
- Secure, resilient cloud architecture
- Darwin-compatible real-time integration and validation layer
- Scalable, SaaS-based cloud delivery model
Benefits
- Always connected to Darwin for real-time national rail updates.
- Improves speed and consistency during disruption scenarios
- Improves information accuracy across individual edge assets and entire estates
- Ensures consistent passenger information across visual, audio and digital channels
- Reduces downtime through remote monitoring and faster fault resolution
- Enhances inclusive passenger experience using innovative, accessible communication methods
- Improves passenger understanding for diverse audiences, including non-native speakers
- SO/IEC ISO 27001 compliant for public sector assurance.
- Supports connected passenger information ecosystem across multiple vendors and systems
- Enables cost-effective scaling across estates without additional infrastructure
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 5 3 7 9 9 4 0 2 6 7 7 3 6 4
Contact
BLACKBOX COMPANY (UK) LIMITED
David Marlow
Telephone: 07738907020
Email: david.marlow@blackbox-co.com
About your service
- Service categories
-
Applications
Content workflow and management
Content services
- Enterprise Content Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- None
- System requirements
-
- Evergreen Browser for all Azzido users kept secure and patched.
- SSO integration for user management.
- Provision of tokens for national transit data
User support
- Email or online ticketing support
- Yes
- Support response times
-
ITIL base Service offering. Implement SLA and responses responsive to the KPI regime our customers require. - Our Standard Typical SLA is Hours of Coverage: 7am to 7pm
Critical Incident: respond within 2 hrs / fix in 6 hrs
High Incident: 2 hrs / 10 hrs
Medium Incident: 2hrs / 14 hours
Low Incident: 2 hrs / 2 weeks
A faster response model is possible and available for agreement at contract award. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
In addition to the standard support we operate a 24/7 Major Incident line documented under our communication plan for incidents with each customer.
we offer also:
Extended support hours, including evenings and weekends
Priority incident response and escalation
Proactive service monitoring and health checks
Support for configuration changes and platform updates
Named Technical Account Manager (TAM)
Telephone support for BAU Maintenance teams
Chargeable commissioning support for install teams. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Blackbox helps customers get started through a Train the Trainer approach, enabling nominated users to build internal capability quickly. This is supported by structured onboarding, user documentation and guided familiarisation with the service.
We also offer optional training services, including face-to-face and online sessions, delivered to groups or one-to-one as required. Familiarisation training is available for maintainers, installers and third-party suppliers who interface with our services, ensuring effective adoption across operational, technical and support teams.
A documented training resource is also provided. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Online Video Tutorials
- PowerPoint
- End-of-contract data extraction
- At the end of the contract, agreed data sets, including reference data created or held for the operation of the service, are made available for extraction in an agreed format. As a minimum, data can be provided in CSV or JSON format. Data is clearly labelled and transferred securely to a named customer representative or an agreed secure location.
- End-of-contract process
- At the end of the contract, service feeds are decommissioned and access credentials, tokens and authentication methods are revoked. Relevant customer reference data is securely provided as part of the standard service. A final snapshot of audit data is retained for the required industry-standard period, after which all remaining customer data, including backups, is securely deleted. Intellectual property rights in the cloud service remain the property of Blackbox Company. Any additional support required to assist transition or migration is available as an optional, chargeable service.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Documentation is provided in PDF formats and provisioned through a browser which supports accessibility standards.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The Azzido Service Portal (QuAD) provides a unified interface for monitoring, managing and supporting Azzido Cloud services. It offers real-time visibility of system health, edge device status and service performance, alongside incident tracking, audit information and operational insights. QuAD supports proactive service management, informed decision-making and transparent collaboration between operators, support teams and suppliers.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Users access the Azzido Service Portal (QuAD) through a secure, standards-compliant web browser, designed in line with WCAG 2.2 AA accessibility principles. The interface supports browser-native accessibility features such as screen readers, keyboard navigation, text resizing, contrast controls and language settings. Secure single sign-on (SSO) with role-based access ensures controlled, auditable access for all users.
- Accessibility testing
- None as yet.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Azzido offers a configuration-led approach that avoids bespoke development while enabling flexibility and future change. Customers can customise through modules—optional components like passenger information, campaigns, public address integration, analytics—and features, which allow fine-grained control over templates, workflows, languages, distribution channels, and disruption responses. Role-based access and approval workflows ensure governance and auditability. Managed updates introduce new features without service disruption, maintaining security and resilience.
Business Rules
Azzido includes a Business Rule Engine for further customisation and automation of processes. Rules can govern decisions, trigger workflows, and enforce compliance, enabling organisations to adapt logic dynamically and streamline operations.
Scaling
- Independence of resources
- The platform scales dynamically to meet demand, with continuous monitoring to ensure consistent performance, allowing control rooms and passenger information services to operate independently and reliably at all times.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Service usage metrics are available to authorised users through the Azzido QuAD service portal. QuAD provides dashboards and reports showing service availability, message and campaign activity, API usage, edge device status and user activity. Metrics support operational oversight, service management and continuous improvement. Access is role-based, secure and auditable.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Limited data export capabilities are available to logged-in users in parts of the system. Bespoke data extracts can be provided as a support function upon request.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- Excel
- XML
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Excel
- JSON
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Blackbox designs and operates the Azzido Cloud platform to deliver high availability suitable for operational passenger information services. A formal Service Level Agreement (SLA) is provided, with a target availability of 99% measured monthly, aligned to industry best practice for cloud-hosted services. If availability falls below the agreed threshold, eligible customers may receive service credits or refunds in accordance with the SLA. Planned maintenance, customer-caused issues and force majeure events are excluded, as defined in the agreement.
- Approach to resilience
-
Azzido Cloud is designed using a resilient, cloud-native architecture to support the continuous delivery of critical passenger information services. The platform is built with redundancy across application components, data storage and network layers, reducing single points of failure and supporting rapid recovery from incidents.
The service is hosted on Microsoft Azure, using resilient datacentre infrastructure with geographic separation, fault tolerance and automated failover capabilities. This ensures service continuity in the event of infrastructure, hardware or network failures. Monitoring, alerting and capacity management are used to proactively manage performance and availability.
Data is protected through regular backups, controlled retention policies and secure recovery processes. Edge capabilities further enhance resilience by allowing continued local operation if central connectivity is temporarily unavailable.
Detailed datacentre architecture and resilience arrangements can be provided on request to support customer assurance and security reviews. - Outage reporting
- Service outages are reported through multiple channels to ensure clear and timely communication. A public service status dashboard provides current and historical outage information. Incidents are recorded and tracked within the Azzido QuAD service portal, with status information available programmatically via an API where required. Email alerts are issued to registered contacts. Where agreed, an incident communications plan may also include direct telephone updates with customer operational teams during major incidents.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted through role-based access controls (RBAC), secure authentication and single sign-on (SSO). Access is granted on a least-privilege basis and reviewed regularly. Management and support access is logged and auditable, and administrative functions are limited to authorised personnel only
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Compliant with the ISO27001 standard, including:
* Data Protection
* Asset Management
* AI Usage
* Information Protection
* Application Security
* Business Continuity
* IDAM
* System and Network Security
* Threat and Vulnerability Management
An ISO Management Group is responsible for policy implementation and reports regularly to the executive team - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Blackbox operates structured configuration and change management processes aligned to ITIL principles. Service components, including applications, integrations and configurations, are recorded and tracked throughout their lifecycle to support traceability and audit. All changes are assessed for operational risk and potential security impact, including access control, data protection and service availability. Changes are approved through defined controls, scheduled to minimise disruption, and communicated where appropriate. Emergency changes follow an expedited process with post-implementation review. All activities are logged and auditable through the Azzido QuAD service portal.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Threats are assessed by evaluating vulnerabilities against their impact on confidentiality, integrity and availability. Risk scoring considers exploitability, exposure, affected components and operational criticality, including passenger information services.
Security patches are prioritised by severity. Critical and high-risk vulnerabilities are remediated as soon as practicable, typically within 14 days, using controlled emergency processes. Lower-risk updates are deployed during planned maintenance.
Vulnerability intelligence is sourced from Microsoft Defender Vulnerability Management (MDVM), Microsoft Azure security advisories, vendor bulletins and dependency monitoring. Actions are logged and reviewed as part of service operations. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Blackbox operates supplier-defined protective monitoring controls aligned to ISO/IEC 27001 operational security principles and cloud best practice. Monitoring is implemented to detect, impede and respond to security threats affecting service availability, integrity and confidentiality. This includes platform monitoring, security alerting, audit logging and incident investigation, supported by Microsoft Azure security services and Microsoft Defender Vulnerability Management (MDVM). Monitoring outputs are reviewed by authorised personnel and integrated with incident and change management processes to ensure timely response and remediation.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Blackbox operates a formal incident management process aligned to ITIL principles, following the lifecycle of detect, respond, recover and improve. Incidents are detected through monitoring and user reporting, with pre-defined processes for common events. Incidents are logged, categorised and prioritised via the Azzido QuAD service portal, email or agreed contacts. Response and recovery focus on rapid service restoration, supported by an agreed communications plan including QuAD updates, email alerts and telephone dialogue. Post-incident reviews identify root causes and improvements.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Azzido Connect can be provided as a time-limited trial within a controlled test environment, using Darwin staging data where appropriate. The scope and duration are agreed in advance, allowing customers to evaluate functionality and integration without impacting live services. Access is restricted, isolated from production and withdrawn at trial end.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR Limited
- ISO/IEC 27001 accreditation date
- Thursday 16 April 2026
- What the ISO/IEC 27001 doesn’t cover
-
Staff mobile devices
Staff home networks
ISO 9001:2015 Clause 7.1.5.2 - Measurement traceability
Our ISO Accreditation Audit Stage One : 28th January 2026, Audit Stage Two is scheduled on 28th February 2026. A letter from the Accreditation supplier is available on request. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-