XER Schedule Toolkit
The XER Schedule Toolkit is a collaborative cloud software application that
compliments the project planning process. It predominantly interacts with
Oracle’s Primavera P6 and Microsoft’s Project software but can also work with schedules developed in other applications, such as Asta Powerproject.
Features
- Project Planning Schedule Collaboration
- Oracle Primavera P6 XER XML MPP Schedule Reader
- Schedule Analysis & Quality Metrics
- Project Progress Capture & Reporting
- Project Schedule Comparison & Trend Reporting
- Earned Value Analysis Metrics & Reporting
- Share Access to Project Schedules With Entire Project Team
- Calender Working Time and Shift Pattern Visibility
- Period end reporting with AI summarisation
Benefits
- Helps Drive Successful Project Delivery
- Promotes Awareness of Individual Responsibility Within the Project Schedule
- Saves Time analysing Project Schedules
- Helps to Track & Analyse Project Performance over Time
- Saves Money Compared to Oracle Primavera P6 LIcence
- Can Be Accessed From Any Device, Anywhere in the World.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 6 2 6 4 1 2 1 1 2 7 6 3 3 1
Contact
XER LIMITED
Sales
Telephone: 01482 766340
Email: sales@xertoolkit.com
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
-
Oracle Primavera P6
Microsoft Project
Asta Powerproject - Cloud deployment model
- Private cloud
- Service constraints
-
XER Schedule Toolkit is hosted on AWS. Users require access to supported web browsers (includes up to date installations of Chrome and Edge).
Planned maintenance occurs outside business hours unless prior notice is given.
Full functionality requires access to supported scheduling tools such as Oracle Primavera P6 or Microsoft Project. - System requirements
- Supported and up to date web browser with internet access
User support
- Email or online ticketing support
- Yes
- Support response times
-
For critical incidents (service unavailable or severe business impact) we aim to respond within 12 hours.
For non-critical incidents (all other issues) we aim to respond within 2 working days (GMT based).
Standard support hours are 08:30–17:00 UK time, Monday to Friday (excluding UK public holidays).
Critical issues are monitored and addressed 24x7. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Product and technical support is included within the cost of licence sales.
For any enterprise package purchases, customers benefit from priority support and an online training session. You will be assigned an account manager who will also aid with any communication to the technical team. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide:
- Demo projects and starting tutorial videos for new users
- Various self-help video tutorial resources via our website
- A knowledge base forum including FAQs
- Regular webinars hosted by one of our product experts
- Online training sessions for our enterprise customers or otherwise subject to agreement - Service documentation
- No
- End-of-contract data extraction
-
Users can initiate extraction into exportable formats where possible.
All data can be extracted on request but given the nature of the tool, XER does not hold original copies of user's project/planning data which is held within their P6, MS Project or other solution's installation. - End-of-contract process
-
At the end of a contract, if the renewal option is not taken up, all customer data is deleted inline with our data retention policy and access to
the application will be terminated.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- XER Schedule Toolkit provides a cloud-based web interface accessible via modern web browsers. A REST API is also available for enterprise customers.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Users can navigate menus and dashboards via keyboard and read text content using standard screen readers. Users can also comment, review, and collaborate on schedules. However, certain advanced schedule visualisations and charts may not be fully compatible with screen readers, and mobile or tablet access is limited. The interface uses a clear layout and plain language to improve usability for all users.
- Accessibility testing
- XER Schedule Toolkit has not yet undergone formal testing with users of assistive technologies. Accessibility features such as keyboard navigation and screen reader compatibility have been considered in the design, and plans are in place to conduct formal user testing in the future.
- API
- Yes
- What users can and can't do using the API
- A REST API is available but limited to enterprise package users. Functions are currently limited to data querying and export into JSON format for third party integration.
- API documentation
- No
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- We provide an enterprise solution that is hosted on customer dedicated resources.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Our enterprise version of the software can provide metrics for
application-usage based on individual user's total time used. Network/hardware usage reports can also be provided by request. - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Data stored by XER Schedule Toolkit on AWS is encrypted at rest using AES-256 via AWS-managed KMS. This ensures that all customer data is protected even if storage media were compromised. Physical access is controlled by AWS, with strict security measures at their data centres.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- There are a variety of export reports available throughout the application. Export options are available for Microsoft Excel and PDF.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLSX
- Data import formats
-
- CSV
- Other
- Other data import formats
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- Data transmitted internally between application components within XER Schedule Toolkit is protected using AWS VPC private networking and security group controls, ensuring that traffic is segregated and restricted to authorised servers.
Availability and resilience
- Guaranteed availability
-
Target Uptime: 99.5% per calendar month.
Measurement: Uptime excludes planned maintenance, force majeure events, and outages of AWS at a regional level.
Planned maintenance that will knowingly cause service interruptions will be notified to the Customer with at least 48 hours’ notice. For enterprise clients, wherever possible, this work will be carried out during non-business hours (relative to the client’s location).
This SLA does not include financial penalties or service credits. XER Limited’s commitment is to resolve issues promptly and maintain high availability, as demonstrated by historical performance where unplanned outages have been exceptionally rare. - Approach to resilience
- XER Schedule Toolkit is designed for resilience through the use of AWS cloud infrastructure, including redundant compute, networking, and storage resources across multiple Availability Zones. Backups are encrypted and stored separately to ensure recoverability in the event of failure. Monitoring and automated failover mechanisms support continuous availability.
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted based on role and need-to-know principles. Administrative and operational access is limited to authorised personnel only, with unique accounts and strong password policies. Multi-factor authentication (MFA) is enforced for all privileged access. Support staff have access only to customer environments relevant to their role and cannot access unrelated client data. All actions are logged and monitored, with audit trails retained for accountability. Access is regularly reviewed, and any changes to roles or staff are promptly reflected in permissions to ensure continuous enforcement of the principle of least privilege.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- While not certified at present, we follow an ISO27001 approach to security governance with detailed policies identifying responsible personnel within the organisation, their access control levels and risk assessments associated with any security activities.
- Information security policies and processes
- Our organisation maintains an Information Security Policy (ISP) aligned with ISO 27001 principles. The ISP defines roles, responsibilities, and procedures for protecting data, managing access, and ensuring secure software development. The CIO oversees information security and is responsible for operational enforcement, monitoring adherence and regulatory alignment. All staff receive mandatory security training on data handling, password hygiene, and reporting incidents. Policies cover secure development practices, encryption of data at rest and in transit, secure access controls, vulnerability management, and incident response procedures. Compliance is enforced through regular audits, automated system checks, and peer reviews, with any deviations reported to senior management. We maintain incident reporting procedures, ensuring that any security concerns are escalated promptly and remediated according to documented processes. This framework ensures that XER Schedule Toolkit is delivered securely and consistently, protecting buyer data while supporting operational resilience and regulatory compliance.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- XER follows a formal configuration and change management process to ensure service stability and security. All software components are tracked in version control (Git) throughout their lifecycle, with each change logged. Changes undergo peer review and automated testing in staging environments before deployment. Potential security impacts are assessed during the review process, including dependency vulnerabilities, and access control implications. Deployments to production are executed via automated CI/CD pipelines, ensuring that only approved, tested changes are released. Rollback procedures and monitoring are in place to address any issues. Infrastructure changes follow similar controlled procedures, with configuration items documented, approved, and audited.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- XER Schedule Toolkit follows a structured vulnerability management process. Potential threats are assessed through a combination of automated vulnerability scans, dependency monitoring, and threat intelligence feeds from trusted sources. Findings are prioritised based on risk impact and likelihood, and remediation plans are created accordingly. Patches and updates are tested in staging environments before deployment and applied to production as quickly as possible, typically within defined SLAs for critical and high-severity issues. Our team continuously monitors security bulletins, vendor advisories, and industry sources to stay informed about emerging threats, ensuring that our service remains secure and resilient.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- XER Schedule Toolkit implements continuous protective monitoring to identify potential compromises. Application and infrastructure logs are collected and analysed using AWS monitoring tools and internal alerting systems to detect anomalies, unusual access patterns, or suspicious activity. When a potential compromise is identified, our security team investigates immediately, containing the incident to prevent impact and following documented escalation procedures. Critical incidents are addressed within hours, with resolution or mitigation tracked through our incident management system. Lessons learned are used to improve controls. Our approach ensures rapid detection, response, and recovery, maintaining the security and availability of buyer data.
- Incident management type
- Supplier-defined controls
- Incident management approach
- XER Schedule Toolkit follows a structured incident management process. We maintain pre-defined procedures for common events, including service outages, security incidents, and data issues. Users report incidents via email, support portal, or helpdesk, which automatically logs and assigns the ticket to the appropriate team. All incidents are triaged, investigated, and contained according to priority and impact. Resolutions are tracked in our system, and users are provided with incident reports summarising the cause, impact, and remedial actions. Post-incident reviews are conducted to identify improvements, ensuring lessons learned are applied to prevent recurrence and maintain service reliability and security.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
Standard trial accounts are limited to:
- 10 projects
- 10,000 activities
- Limited reporting results
- Restricted document exports
- Initial 30 day usage period but can be extended another 30 days
Fully functional extended trials, including enterprise trials, are available on request at the company’s discretion. - Link to free trial
- https://xertoolkit.com/pricing/30-day-trial/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2%
- Between £250,000 and £500,000
- 4%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 8%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 89aa52fb-4d0e-4040-acc5-10bb53d73492
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 227c99c5-9f2d-47f0-a18b-e661838ee465
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-