Skip to main content

Help us improve the Digital Marketplace - send your feedback

XER LIMITED

XER Schedule Toolkit

The XER Schedule Toolkit is a collaborative cloud software application that
compliments the project planning process. It predominantly interacts with
Oracle’s Primavera P6 and Microsoft’s Project software but can also work with schedules developed in other applications, such as Asta Powerproject.

Features

  • Project Planning Schedule Collaboration
  • Oracle Primavera P6 XER XML MPP Schedule Reader
  • Schedule Analysis & Quality Metrics
  • Project Progress Capture & Reporting
  • Project Schedule Comparison & Trend Reporting
  • Earned Value Analysis Metrics & Reporting
  • Share Access to Project Schedules With Entire Project Team
  • Calender Working Time and Shift Pattern Visibility
  • Period end reporting with AI summarisation

Benefits

  • Helps Drive Successful Project Delivery
  • Promotes Awareness of Individual Responsibility Within the Project Schedule
  • Saves Time analysing Project Schedules
  • Helps to Track & Analyse Project Performance over Time
  • Saves Money Compared to Oracle Primavera P6 LIcence
  • Can Be Accessed From Any Device, Anywhere in the World.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@xertoolkit.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 6 2 6 4 1 2 1 1 2 7 6 3 3 1

Contact

XER LIMITED Sales
Telephone: 01482 766340
Email: sales@xertoolkit.com

About your service

Service categories

Applications

Collaborative

  • Team collaboration
Multi cloud support
No

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
Oracle Primavera P6
Microsoft Project
Asta Powerproject
Cloud deployment model
Private cloud
Service constraints
XER Schedule Toolkit is hosted on AWS. Users require access to supported web browsers (includes up to date installations of Chrome and Edge).

Planned maintenance occurs outside business hours unless prior notice is given.

Full functionality requires access to supported scheduling tools such as Oracle Primavera P6 or Microsoft Project.
System requirements
Supported and up to date web browser with internet access

User support

Email or online ticketing support
Yes
Support response times
For critical incidents (service unavailable or severe business impact) we aim to respond within 12 hours.

For non-critical incidents (all other issues) we aim to respond within 2 working days (GMT based).

Standard support hours are 08:30–17:00 UK time, Monday to Friday (excluding UK public holidays).

Critical issues are monitored and addressed 24x7.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Product and technical support is included within the cost of licence sales.

For any enterprise package purchases, customers benefit from priority support and an online training session. You will be assigned an account manager who will also aid with any communication to the technical team.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide:
- Demo projects and starting tutorial videos for new users
- Various self-help video tutorial resources via our website
- A knowledge base forum including FAQs
- Regular webinars hosted by one of our product experts
- Online training sessions for our enterprise customers or otherwise subject to agreement
Service documentation
No
End-of-contract data extraction
Users can initiate extraction into exportable formats where possible.

All data can be extracted on request but given the nature of the tool, XER does not hold original copies of user's project/planning data which is held within their P6, MS Project or other solution's installation.
End-of-contract process
At the end of a contract, if the renewal option is not taken up, all customer data is deleted inline with our data retention policy and access to
the application will be terminated.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
XER Schedule Toolkit provides a cloud-based web interface accessible via modern web browsers. A REST API is also available for enterprise customers.
Accessibility standards
None or don’t know
Description of accessibility
Users can navigate menus and dashboards via keyboard and read text content using standard screen readers. Users can also comment, review, and collaborate on schedules. However, certain advanced schedule visualisations and charts may not be fully compatible with screen readers, and mobile or tablet access is limited. The interface uses a clear layout and plain language to improve usability for all users.
Accessibility testing
XER Schedule Toolkit has not yet undergone formal testing with users of assistive technologies. Accessibility features such as keyboard navigation and screen reader compatibility have been considered in the design, and plans are in place to conduct formal user testing in the future.
API
Yes
What users can and can't do using the API
A REST API is available but limited to enterprise package users. Functions are currently limited to data querying and export into JSON format for third party integration.
API documentation
No
API sandbox or test environment
Yes
Customisation available
No

Scaling

Independence of resources
We provide an enterprise solution that is hosted on customer dedicated resources.

Analytics

Service usage metrics
Yes
Metrics types
Our enterprise version of the software can provide metrics for
application-usage based on individual user's total time used. Network/hardware usage reports can also be provided by request.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Data stored by XER Schedule Toolkit on AWS is encrypted at rest using AES-256 via AWS-managed KMS. This ensures that all customer data is protected even if storage media were compromised. Physical access is controlled by AWS, with strict security measures at their data centres.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
There are a variety of export reports available throughout the application. Export options are available for Microsoft Excel and PDF.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • XLSX
Data import formats
  • CSV
  • Other
Other data import formats
XML

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Data transmitted internally between application components within XER Schedule Toolkit is protected using AWS VPC private networking and security group controls, ensuring that traffic is segregated and restricted to authorised servers.

Availability and resilience

Guaranteed availability
Target Uptime: 99.5% per calendar month.

Measurement: Uptime excludes planned maintenance, force majeure events, and outages of AWS at a regional level.

Planned maintenance that will knowingly cause service interruptions will be notified to the Customer with at least 48 hours’ notice. For enterprise clients, wherever possible, this work will be carried out during non-business hours (relative to the client’s location).

This SLA does not include financial penalties or service credits. XER Limited’s commitment is to resolve issues promptly and maintain high availability, as demonstrated by historical performance where unplanned outages have been exceptionally rare.
Approach to resilience
XER Schedule Toolkit is designed for resilience through the use of AWS cloud infrastructure, including redundant compute, networking, and storage resources across multiple Availability Zones. Backups are encrypted and stored separately to ensure recoverability in the event of failure. Monitoring and automated failover mechanisms support continuous availability.
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted based on role and need-to-know principles. Administrative and operational access is limited to authorised personnel only, with unique accounts and strong password policies. Multi-factor authentication (MFA) is enforced for all privileged access. Support staff have access only to customer environments relevant to their role and cannot access unrelated client data. All actions are logged and monitored, with audit trails retained for accountability. Access is regularly reviewed, and any changes to roles or staff are promptly reflected in permissions to ensure continuous enforcement of the principle of least privilege.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
No audit information available
Access to supplier activity audit information
No audit information available
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
While not certified at present, we follow an ISO27001 approach to security governance with detailed policies identifying responsible personnel within the organisation, their access control levels and risk assessments associated with any security activities.
Information security policies and processes
Our organisation maintains an Information Security Policy (ISP) aligned with ISO 27001 principles. The ISP defines roles, responsibilities, and procedures for protecting data, managing access, and ensuring secure software development. The CIO oversees information security and is responsible for operational enforcement, monitoring adherence and regulatory alignment. All staff receive mandatory security training on data handling, password hygiene, and reporting incidents. Policies cover secure development practices, encryption of data at rest and in transit, secure access controls, vulnerability management, and incident response procedures. Compliance is enforced through regular audits, automated system checks, and peer reviews, with any deviations reported to senior management. We maintain incident reporting procedures, ensuring that any security concerns are escalated promptly and remediated according to documented processes. This framework ensures that XER Schedule Toolkit is delivered securely and consistently, protecting buyer data while supporting operational resilience and regulatory compliance.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
XER follows a formal configuration and change management process to ensure service stability and security. All software components are tracked in version control (Git) throughout their lifecycle, with each change logged. Changes undergo peer review and automated testing in staging environments before deployment. Potential security impacts are assessed during the review process, including dependency vulnerabilities, and access control implications. Deployments to production are executed via automated CI/CD pipelines, ensuring that only approved, tested changes are released. Rollback procedures and monitoring are in place to address any issues. Infrastructure changes follow similar controlled procedures, with configuration items documented, approved, and audited.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
XER Schedule Toolkit follows a structured vulnerability management process. Potential threats are assessed through a combination of automated vulnerability scans, dependency monitoring, and threat intelligence feeds from trusted sources. Findings are prioritised based on risk impact and likelihood, and remediation plans are created accordingly. Patches and updates are tested in staging environments before deployment and applied to production as quickly as possible, typically within defined SLAs for critical and high-severity issues. Our team continuously monitors security bulletins, vendor advisories, and industry sources to stay informed about emerging threats, ensuring that our service remains secure and resilient.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
XER Schedule Toolkit implements continuous protective monitoring to identify potential compromises. Application and infrastructure logs are collected and analysed using AWS monitoring tools and internal alerting systems to detect anomalies, unusual access patterns, or suspicious activity. When a potential compromise is identified, our security team investigates immediately, containing the incident to prevent impact and following documented escalation procedures. Critical incidents are addressed within hours, with resolution or mitigation tracked through our incident management system. Lessons learned are used to improve controls. Our approach ensures rapid detection, response, and recovery, maintaining the security and availability of buyer data.
Incident management type
Supplier-defined controls
Incident management approach
XER Schedule Toolkit follows a structured incident management process. We maintain pre-defined procedures for common events, including service outages, security incidents, and data issues. Users report incidents via email, support portal, or helpdesk, which automatically logs and assigns the ticket to the appropriate team. All incidents are triaged, investigated, and contained according to priority and impact. Resolutions are tracked in our system, and users are provided with incident reports summarising the cause, impact, and remedial actions. Post-incident reviews are conducted to identify improvements, ensuring lessons learned are applied to prevent recurrence and maintain service reliability and security.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Standard trial accounts are limited to:
- 10 projects
- 10,000 activities
- Limited reporting results
- Restricted document exports
- Initial 30 day usage period but can be extended another 30 days

Fully functional extended trials, including enterprise trials, are available on request at the company’s discretion.
Link to free trial
https://xertoolkit.com/pricing/30-day-trial/

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
2%
Between £250,000 and £500,000
4%
Between £500,001 and £1,000,000
6%
Between £1,000,001 and £2,500,000
8%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
89aa52fb-4d0e-4040-acc5-10bb53d73492
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
227c99c5-9f2d-47f0-a18b-e661838ee465
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@xertoolkit.com. Tell them what format you need. It will help if you say what assistive technology you use.